blob: 740d3960ad21c4d4a45d66ddaecfbacb9937add6 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
Pau Espin Pedrole979c402021-04-28 17:29:54 +020019import from GSM_Types all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010020
21import from M3UA_Types all;
22import from M3UA_Emulation all;
23
24import from MTP3asp_Types all;
25import from MTP3asp_PortType all;
26
27import from SCCPasp_Types all;
28import from SCCP_Types all;
29import from SCCP_Emulation all;
30
31import from SCTPasp_Types all;
32import from SCTPasp_PortType all;
33
Harald Weltea49e36e2018-01-21 19:29:33 +010034import from Osmocom_CTRL_Functions all;
35import from Osmocom_CTRL_Types all;
36import from Osmocom_CTRL_Adapter all;
37
Harald Welte3ca1c902018-01-24 18:51:27 +010038import from TELNETasp_PortType all;
39import from Osmocom_VTY_Functions all;
40
Harald Weltea49e36e2018-01-21 19:29:33 +010041import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010042import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010043
Harald Welte4aa970c2018-01-26 10:38:09 +010044import from MGCP_Emulation all;
45import from MGCP_Types all;
46import from MGCP_Templates all;
47import from SDP_Types all;
48
Harald Weltea49e36e2018-01-21 19:29:33 +010049import from GSUP_Emulation all;
50import from GSUP_Types all;
51import from IPA_Emulation all;
52
Harald Weltef6dd64d2017-11-19 12:09:51 +010053import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020054import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010055import from BSSAP_CodecPort all;
56import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020057import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010058import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020059import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010060
Harald Welte4263c522018-12-06 11:56:27 +010061import from SGsAP_Templates all;
62import from SGsAP_Types all;
63import from SGsAP_Emulation all;
64
Harald Weltea49e36e2018-01-21 19:29:33 +010065import from MobileL3_Types all;
66import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070067import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010068import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010069import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010070
Harald Weltef640a012018-04-14 17:49:21 +020071import from SMPP_Types all;
72import from SMPP_Templates all;
73import from SMPP_Emulation all;
74
Stefan Sperlingc307e682018-06-14 15:15:46 +020075import from SCCP_Templates all;
76
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070077import from SS_Types all;
78import from SS_Templates all;
79import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010080import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070081
Philipp Maier948747b2019-04-02 15:22:33 +020082import from TCCConversion_Functions all;
83
Harald Welte9b751a62019-04-14 17:39:29 +020084const integer NUM_BSC := 3;
Harald Weltef6dd64d2017-11-19 12:09:51 +010085
Harald Welte4263c522018-12-06 11:56:27 +010086/* Needed for SGsAP SMS */
87import from MobileL3_SMS_Types all;
88
Harald Weltea4ca4462018-02-09 00:17:14 +010089type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010090 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010091
Harald Welte6811d102019-04-14 22:23:14 +020092 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010093
Harald Weltea49e36e2018-01-21 19:29:33 +010094 /* no 'adapter_CT' for MNCC or GSUP */
95 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010096 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010097 var GSUP_Emulation_CT vc_GSUP;
98 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020099 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +0100100 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100101
102 /* only to get events from IPA underneath GSUP */
103 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100104 /* VTY to MSC */
105 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100106
107 /* A port to directly send BSSAP messages. This port is used for
108 * tests that require low level access to sen arbitrary BSSAP
109 * messages. Run f_init_bssap_direct() to connect and initialize */
110 port BSSAP_CODEC_PT BSSAP_DIRECT;
111
112 /* When BSSAP messages are directly sent, then the connection
113 * handler is not active, which means that also no guard timer is
114 * set up. The following timer will serve as a replacement */
115 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100116
117 /* Configure T(tias) over VTY, seconds */
118 var integer g_msc_sccp_timer_ias := 7 * 60;
119 /* Configure T(tiar) over VTY, seconds */
120 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100121}
122
123modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100124 /* remote parameters of IUT */
125 charstring mp_msc_ip := "127.0.0.1";
126 integer mp_msc_ctrl_port := 4255;
127 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100128
Harald Weltea49e36e2018-01-21 19:29:33 +0100129 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100130 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100131 charstring mp_hlr_ip := "127.0.0.1";
132 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100133 charstring mp_mgw_ip := "127.0.0.1";
134 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100135
Harald Weltea49e36e2018-01-21 19:29:33 +0100136 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100137
Harald Weltef640a012018-04-14 17:49:21 +0200138 integer mp_msc_smpp_port := 2775;
139 charstring mp_smpp_system_id := "msc_tester";
140 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100141 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
142 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200143
Harald Welte6811d102019-04-14 22:23:14 +0200144 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200145 {
146 sccp_service_type := "mtp3_itu",
147 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
148 own_pc := 185,
149 own_ssn := 254,
150 peer_pc := 187,
151 peer_ssn := 254,
152 sio := '83'O,
153 rctx := 0
154 },
155 {
156 sccp_service_type := "mtp3_itu",
157 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
158 own_pc := 186,
159 own_ssn := 254,
160 peer_pc := 187,
161 peer_ssn := 254,
162 sio := '83'O,
163 rctx := 1
164 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100165 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100166}
167
Philipp Maier328d1662018-03-07 10:40:27 +0100168/* altstep for the global guard timer (only used when BSSAP_DIRECT
169 * is used for communication */
170private altstep as_Tguard_direct() runs on MTC_CT {
171 [] Tguard_direct.timeout {
172 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200173 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100174 }
175}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100176
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100177private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
178 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
179 if (respond) {
180 var BIT1 tid_remote := '1'B;
181 if (cpars.mo_call) {
182 tid_remote := '0'B;
183 }
184 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
185 }
186 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100187}
188
Harald Weltef640a012018-04-14 17:49:21 +0200189function f_init_smpp(charstring id) runs on MTC_CT {
190 id := id & "-SMPP";
191 var EsmePars pars := {
192 mode := MODE_TRANSCEIVER,
193 bind := {
194 system_id := mp_smpp_system_id,
195 password := mp_smpp_password,
196 system_type := "MSC_Tests",
197 interface_version := hex2int('34'H),
198 addr_ton := unknown,
199 addr_npi := unknown,
200 address_range := ""
201 },
202 esme_role := true
203 }
204
205 vc_SMPP := SMPP_Emulation_CT.create(id);
206 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
Harald Welte4698a4c2020-08-18 22:57:52 +0200207 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", 0));
Harald Weltef640a012018-04-14 17:49:21 +0200208}
209
210
Harald Weltea49e36e2018-01-21 19:29:33 +0100211function f_init_mncc(charstring id) runs on MTC_CT {
212 id := id & "-MNCC";
213 var MnccOps ops := {
214 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
215 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
216 }
217
218 vc_MNCC := MNCC_Emulation_CT.create(id);
219 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
220 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100221}
222
Harald Welte4aa970c2018-01-26 10:38:09 +0100223function f_init_mgcp(charstring id) runs on MTC_CT {
224 id := id & "-MGCP";
225 var MGCPOps ops := {
226 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
227 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
228 }
229 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100230 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100231 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100232 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200233 mgw_udp_port := mp_mgw_port,
234 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100235 }
236
237 vc_MGCP := MGCP_Emulation_CT.create(id);
238 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
239 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
240}
241
Philipp Maierc09a1312019-04-09 16:05:26 +0200242function ForwardUnitdataCallback(PDU_SGsAP msg)
243runs on SGsAP_Emulation_CT return template PDU_SGsAP {
244 SGsAP_CLIENT.send(msg);
245 return omit;
246}
247
Harald Welte4263c522018-12-06 11:56:27 +0100248function f_init_sgsap(charstring id) runs on MTC_CT {
249 id := id & "-SGsAP";
250 var SGsAPOps ops := {
251 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200252 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100253 }
254 var SGsAP_conn_parameters pars := {
255 remote_ip := mp_msc_ip,
256 remote_sctp_port := 29118,
257 local_ip := "",
258 local_sctp_port := -1
259 }
260
261 vc_SGsAP := SGsAP_Emulation_CT.create(id);
262 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
263 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
264}
265
266
Harald Weltea49e36e2018-01-21 19:29:33 +0100267function f_init_gsup(charstring id) runs on MTC_CT {
268 id := id & "-GSUP";
269 var GsupOps ops := {
270 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
271 }
272
273 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
274 vc_GSUP := GSUP_Emulation_CT.create(id);
275
276 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
277 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
278 /* we use this hack to get events like ASP_IPA_EVENT_UP */
279 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
280
281 vc_GSUP.start(GSUP_Emulation.main(ops, id));
282 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
283
284 /* wait for incoming connection to GSUP port before proceeding */
285 timer T := 10.0;
286 T.start;
287 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700288 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100289 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100290 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200291 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100292 }
293 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100294}
295
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200296function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100297
298 if (g_initialized == true) {
299 return;
300 }
301 g_initialized := true;
302
Philipp Maier75932982018-03-27 14:52:35 +0200303 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200304 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200305 }
306
307 for (var integer i := 0; i < num_bsc; i := i + 1) {
308 if (isbound(mp_bssap_cfg[i])) {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200309 var RanOps ranops := BSC_RanOps;
310 ranops.use_osmux := osmux;
311 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
Harald Welte3ca0ce12019-04-23 17:18:48 +0200312 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200313 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200314 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200315 }
316 }
317
Pau Espin Pedrol9a5b8ff2021-01-04 19:01:31 +0100318 f_ipa_ctrl_start_client(mp_msc_ip, mp_msc_ctrl_port);
Harald Weltea49e36e2018-01-21 19:29:33 +0100319 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100320 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200321
322 if (gsup == true) {
323 f_init_gsup("MSC_Test");
324 }
Harald Weltef640a012018-04-14 17:49:21 +0200325 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100326
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100327 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100328 f_init_sgsap("MSC_Test");
329 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100330
331 map(self:MSCVTY, system:MSCVTY);
332 f_vty_set_prompts(MSCVTY);
333 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100334
335 /* set some defaults */
336 f_vty_config(MSCVTY, "network", "authentication optional");
337 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200338 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100339 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100340 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
341 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +0200342 if (osmux) {
343 f_vty_config(MSCVTY, "msc", "osmux on");
344 } else {
345 f_vty_config(MSCVTY, "msc", "osmux off");
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200346 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100347}
348
Philipp Maier328d1662018-03-07 10:40:27 +0100349/* Initialize for a direct connection to BSSAP. This function is an alternative
350 * to f_init() when the high level functions of the BSC_ConnectionHandler are
351 * not needed. */
352function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200353 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200354 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100355
356 /* Start guard timer and activate it as default */
357 Tguard_direct.start
358 activate(as_Tguard_direct());
359}
360
Harald Weltea49e36e2018-01-21 19:29:33 +0100361type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100362
Harald Weltea49e36e2018-01-21 19:29:33 +0100363/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200364function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200365 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O,
366 boolean verify_cell_id := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200367runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100368 var BSC_ConnHdlrNetworkPars net_pars := {
369 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
370 expect_tmsi := true,
371 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200372 expect_ciph := false,
373 expect_imei := false,
374 expect_imei_early := false,
375 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
376 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100377 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100378 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200379 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
380 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100381 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100382 imei := f_gen_imei(imsi_suffix),
383 imsi := f_gen_imsi(imsi_suffix),
384 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100385 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100386 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100387 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100388 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100389 vec := omit,
Neels Hofmeyrb00c5b02021-06-23 20:05:25 +0200390 vec_keep := false,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100391 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100392 send_early_cm := true,
393 ipa_ctrl_ip := mp_msc_ip,
394 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100395 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100396 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200397 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200398 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100399 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200400 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200401 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200402 ran_is_geran := ran_is_geran,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200403 use_osmux := use_osmux,
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200404 use_ipv6 := false,
Pau Espin Pedrole979c402021-04-28 17:29:54 +0200405 verify_cell_id := verify_cell_id,
406 common_id_last_eutran_plmn := omit
Harald Weltea49e36e2018-01-21 19:29:33 +0100407 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200408 if (not ran_is_geran) {
409 pars.use_umts_aka := true;
410 pars.net.expect_auth := true;
411 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100412 return pars;
413}
414
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200415function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100416 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200417 var charstring id := testcasename() & int2str(pars.ran_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100418
419 vc_conn := BSC_ConnHdlr.create(id);
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200420
Harald Weltea49e36e2018-01-21 19:29:33 +0100421 /* BSSMAP part / A interface */
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200422 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx].vc_RAN:CLIENT);
423 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100424 /* MNCC part */
425 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
426 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100427 /* MGCP part */
428 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
429 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100430 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200431 if (pars.gsup_enable == true) {
432 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
433 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
434 }
Harald Weltef640a012018-04-14 17:49:21 +0200435 /* SMPP part */
436 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
437 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100438 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100439 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100440 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
441 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
442 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100443
Harald Weltea10db902018-01-27 12:44:49 +0100444 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
445 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100446 vc_conn.start(derefers(fn)(id, pars));
447 return vc_conn;
448}
449
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200450function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false,
451 boolean verify_cell_id := true)
Harald Welte9b751a62019-04-14 17:39:29 +0200452runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200453 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux, verify_cell_id := verify_cell_id));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100454}
455
Harald Weltea49e36e2018-01-21 19:29:33 +0100456private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100457 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100458 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100459}
Harald Weltea49e36e2018-01-21 19:29:33 +0100460testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
461 var BSC_ConnHdlr vc_conn;
462 f_init();
463
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100464 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100465 vc_conn.done;
466}
467
468private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100469 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100470 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100471 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100472}
Harald Weltea49e36e2018-01-21 19:29:33 +0100473testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
474 var BSC_ConnHdlr vc_conn;
475 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100476 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100477
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100478 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100479 vc_conn.done;
480}
481
482/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200483friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100484 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100485 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
486
487 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200488 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100489 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100490 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
491 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
492 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100493 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
494 f_expect_clear();
495 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100496 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
497 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200498 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100499 }
500 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100501}
502testcase TC_lu_imsi_reject() runs on MTC_CT {
503 var BSC_ConnHdlr vc_conn;
504 f_init();
505
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200506 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100507 vc_conn.done;
508}
509
Harald Weltee13cfb22019-04-23 16:52:02 +0200510
511
Harald Weltea49e36e2018-01-21 19:29:33 +0100512/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200513friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100514 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100515 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
516
517 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200518 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100519 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100520 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
521 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
522 alt {
523 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100524 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
525 f_expect_clear();
526 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100527 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
528 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200529 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100530 }
531 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100532}
533testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
534 var BSC_ConnHdlr vc_conn;
535 f_init();
536
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200537 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100538 vc_conn.done;
539}
540
Harald Weltee13cfb22019-04-23 16:52:02 +0200541
Harald Welte7b1b2812018-01-22 21:23:06 +0100542private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100543 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100544 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100545 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100546}
547testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
548 var BSC_ConnHdlr vc_conn;
549 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100550 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100551
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100552 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100553 vc_conn.done;
554}
555
Harald Weltee13cfb22019-04-23 16:52:02 +0200556
557friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200558 pars.net.expect_auth := true;
559 pars.use_umts_aka := true;
560 f_init_handler(pars);
561 f_perform_lu();
562}
563testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
564 var BSC_ConnHdlr vc_conn;
565 f_init();
566 f_vty_config(MSCVTY, "network", "authentication required");
567
568 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
569 vc_conn.done;
570}
Harald Weltea49e36e2018-01-21 19:29:33 +0100571
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100572/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
573 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
574 */
575friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
576
577 f_init_handler(pars);
578
579 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
580 var PDU_DTAP_MT dtap_mt;
581
582 /* tell GSUP dispatcher to send this IMSI to us */
583 f_create_gsup_expect(hex2str(g_pars.imsi));
584
585 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
586 if (g_pars.ran_is_geran) {
587 f_bssap_compl_l3(l3_lu);
588 if (g_pars.send_early_cm) {
589 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
590 }
591 } else {
592 f_ranap_initial_ue(l3_lu);
593 }
594
595 f_mm_imei_early();
596 f_mm_common();
597 f_msc_lu_hlr();
598 f_mm_imei();
599
600 alt {
601 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
602 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
603 setverdict(fail, "Expected LU ACK, but received LU REJ");
604 mtc.stop;
605 }
606 }
607
608 /* currently (due to bug OS#4337), an extra LU reject is received before
609 terminating the connection. Enabling following line makes the test
610 pass: */
611 //f_expect_lu_reject('16'O); /* Cause: congestion */
612
613 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
614 extra time to avoid race conditons... */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200615 f_expect_clear(7.0, verify_vlr_cell_id := false);
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100616
617 setverdict(pass);
618}
619testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
620 var BSC_ConnHdlr vc_conn;
621 f_init();
622
623 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
624 vc_conn.done;
625}
626
Harald Weltee13cfb22019-04-23 16:52:02 +0200627
Harald Weltea49e36e2018-01-21 19:29:33 +0100628/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200629friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100630runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100631 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100632
633 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100634 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100635 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100636
637 f_create_gsup_expect(hex2str(g_pars.imsi));
638
639 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200640 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200641 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100642
643 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100644 T.start;
645 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100646 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
647 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200648 [] BSSAP.receive {
649 setverdict(fail, "Received unexpected BSSAP");
650 mtc.stop;
651 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100652 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
653 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200654 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100655 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200656 [] T.timeout {
Neels Hofmeyrf1c3c212020-08-19 13:15:32 +0000657 setverdict(fail, "Timeout waiting for CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200658 mtc.stop;
659 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100660 }
661
Harald Welte1ddc7162018-01-27 14:25:46 +0100662 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100663}
Harald Weltea49e36e2018-01-21 19:29:33 +0100664testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
665 var BSC_ConnHdlr vc_conn;
666 f_init();
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200667 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100668 vc_conn.done;
669}
670
Harald Weltee13cfb22019-04-23 16:52:02 +0200671
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000672/* Send CM SERVICE REQ for TMSI that has never performed LU before */
673friend function f_tc_cmserv_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
674runs on BSC_ConnHdlr {
675 f_init_handler(pars);
676
677 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('57111111'O));
678 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
679 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
680
681 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
682 f_cl3_or_initial_ue(l3_info);
683 f_mm_auth();
684
685 timer T := 10.0;
686 T.start;
687 alt {
688 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
689 [] BSSAP.receive {
690 setverdict(fail, "Received unexpected BSSAP");
691 mtc.stop;
692 }
693 [] T.timeout {
694 setverdict(fail, "Timeout waiting for CM SERV REJ");
695 mtc.stop;
696 }
697 }
698
699 f_expect_clear();
700}
701testcase TC_cmserv_tmsi_unknown() runs on MTC_CT {
702 var BSC_ConnHdlr vc_conn;
703 f_init();
704 vc_conn := f_start_handler(refers(f_tc_cmserv_tmsi_unknown), 57, verify_cell_id := false);
705 vc_conn.done;
706}
707
Neels Hofmeyr14d0b132020-08-19 13:49:05 +0000708/* Send Paging Response for IMSI that has never performed LU before */
709friend function f_tc_paging_response_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
710runs on BSC_ConnHdlr {
711 f_init_handler(pars);
712
713 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
714 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
715 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
716
717 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
718 f_cl3_or_initial_ue(l3_info);
719
720 /* The Paging Response gets rejected by a direct Clear Command */
721 f_expect_clear();
722}
723testcase TC_paging_response_imsi_unknown() runs on MTC_CT {
724 var BSC_ConnHdlr vc_conn;
725 f_init();
726 vc_conn := f_start_handler(refers(f_tc_paging_response_imsi_unknown), 58, verify_cell_id := false);
727 vc_conn.done;
728}
729
730/* Send Paging Response for TMSI that has never performed LU before */
731friend function f_tc_paging_response_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
732runs on BSC_ConnHdlr {
733 f_init_handler(pars);
734
735 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('59111111'O));
736 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
737 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
738
739 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
740 f_cl3_or_initial_ue(l3_info);
741
742 /* The Paging Response gets rejected by a direct Clear Command */
743 f_expect_clear();
744}
745testcase TC_paging_response_tmsi_unknown() runs on MTC_CT {
746 var BSC_ConnHdlr vc_conn;
747 f_init();
748 vc_conn := f_start_handler(refers(f_tc_paging_response_tmsi_unknown), 59, verify_cell_id := false);
749 vc_conn.done;
750}
751
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000752
Harald Weltee13cfb22019-04-23 16:52:02 +0200753friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100754 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200755 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100756 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100757 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100758}
759testcase TC_lu_and_mo_call() runs on MTC_CT {
760 var BSC_ConnHdlr vc_conn;
761 f_init();
762
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100763 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100764 vc_conn.done;
765}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200766friend function f_tc_lu_and_mo_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
767 f_init_handler(pars);
768 var CallParameters cpars := valueof(t_CallParams);
769 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
770 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
771 cpars.bss_rtp_ip := "::3";
772 f_perform_lu();
773 f_mo_call(cpars);
774}
775testcase TC_lu_and_mo_call_ipv6() runs on MTC_CT {
776 var BSC_ConnHdlr vc_conn;
777 f_init();
778
779 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call_ipv6), 7);
780 vc_conn.done;
781}
Harald Welte071ed732018-01-23 19:53:52 +0100782
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100783/* Verify T(iar) triggers and releases the channel */
784friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
785 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
786 f_init_handler(pars);
787 var CallParameters cpars := valueof(t_CallParams);
788 f_perform_lu();
789 f_mo_call_establish(cpars);
790
791 /* Expect the channel cleared upon T(iar) triggered: */
792 T_wait_iar.start;
793 alt {
794 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
795 T_wait_iar.stop
796 setverdict(pass);
797 }
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100798 [] T_wait_iar.timeout {
799 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
800 mtc.stop;
801 }
802 }
Harald Welte4a3fa712020-08-19 08:57:33 +0200803 /* DLCX for both directions; if we don't do this, we might receive either of the two during
804 * shutdown causing race conditions */
805 MGCP.receive(tr_DLCX(?));
806 MGCP.receive(tr_DLCX(?));
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100807
808 setverdict(pass);
809}
810testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
811 var BSC_ConnHdlr vc_conn;
812
813 /* Set T(iar) in MSC low enough that it will trigger before other side
814 has time to keep alive with a T(ias). Keep recommended ratio of
815 T(iar) >= T(ias)*2 */
816 g_msc_sccp_timer_ias := 2;
817 g_msc_sccp_timer_iar := 5;
818
819 f_init();
820
821 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
822 vc_conn.done;
823}
824
Harald Weltee13cfb22019-04-23 16:52:02 +0200825
Harald Welte071ed732018-01-23 19:53:52 +0100826/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200827friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100828 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100829
830 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
831 var PDU_DTAP_MT dtap_mt;
832
833 /* tell GSUP dispatcher to send this IMSI to us */
834 f_create_gsup_expect(hex2str(g_pars.imsi));
835
836 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200837 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100838
839 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200840 if (pars.ran_is_geran) {
841 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
842 }
Harald Welte071ed732018-01-23 19:53:52 +0100843
844 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
845 /* The HLR would normally return an auth vector here, but we fail to do so. */
846
847 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100848 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100849}
850testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
851 var BSC_ConnHdlr vc_conn;
852 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100853 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100854
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200855 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8, verify_cell_id := false);
Harald Welte071ed732018-01-23 19:53:52 +0100856 vc_conn.done;
857}
858
Harald Weltee13cfb22019-04-23 16:52:02 +0200859
Harald Welte071ed732018-01-23 19:53:52 +0100860/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200861friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100862 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100863
864 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
865 var PDU_DTAP_MT dtap_mt;
866
867 /* tell GSUP dispatcher to send this IMSI to us */
868 f_create_gsup_expect(hex2str(g_pars.imsi));
869
870 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200871 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100872
873 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200874 if (pars.ran_is_geran) {
875 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
876 }
Harald Welte071ed732018-01-23 19:53:52 +0100877
878 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
879 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
880
881 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100882 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100883}
884testcase TC_lu_auth_sai_err() runs on MTC_CT {
885 var BSC_ConnHdlr vc_conn;
886 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100887 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100888
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200889 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9, verify_cell_id := false);
Harald Welte2bb825f2018-01-22 11:31:18 +0100890 vc_conn.done;
891}
Harald Weltea49e36e2018-01-21 19:29:33 +0100892
Harald Weltee13cfb22019-04-23 16:52:02 +0200893
Harald Weltebc881782018-01-23 20:09:15 +0100894/* Test LU but BSC will send a clear request in the middle */
895private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100896 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100897
898 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
899 var PDU_DTAP_MT dtap_mt;
900
901 /* tell GSUP dispatcher to send this IMSI to us */
902 f_create_gsup_expect(hex2str(g_pars.imsi));
903
904 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200905 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +0200906 f_expect_common_id();
Harald Weltebc881782018-01-23 20:09:15 +0100907
908 /* Send Early Classmark, just for the fun of it */
909 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
910
911 f_sleep(1.0);
912 /* send clear request in the middle of the LU */
913 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200914 alt {
915 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
916 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
917 }
Harald Weltebc881782018-01-23 20:09:15 +0100918 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100919 alt {
920 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200921 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
922 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200923 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200924 repeat;
925 }
Harald Welte6811d102019-04-14 22:23:14 +0200926 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100927 }
Harald Weltebc881782018-01-23 20:09:15 +0100928 setverdict(pass);
929}
930testcase TC_lu_clear_request() runs on MTC_CT {
931 var BSC_ConnHdlr vc_conn;
932 f_init();
933
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100934 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100935 vc_conn.done;
936}
937
Vadim Yanitskiy109e7552021-02-05 05:36:02 +0100938/* Test reaction on Clear Request during a MO Call */
939friend function f_TC_mo_mt_call_clear_request(charstring id, BSC_ConnHdlrPars pars)
940runs on BSC_ConnHdlr {
941 var CallParameters cpars := valueof(t_CallParams);
942 var MNCC_PDU mncc_pdu;
943 timer T := 2.0;
944
945 f_init_handler(pars);
946
947 f_perform_lu();
948
949 /* HACK: reducing code duplication ('66'H - MO, '68'H - MT) */
950 if (pars.imsi == '262420002532766'H)
951 { f_mo_call_establish(cpars); }
952 else
953 { f_mt_call_establish(cpars); }
954
955 /* Hold the line for a while... */
956 f_sleep(2.0);
957
958 /* BSC sends BSSMAP Clear Request (e.g. due to RR failure) */
959 BSSAP.send(ts_BSSMAP_ClearRequest(1));
960
961 /* Expect (optional) CC RELEASE and Clear Command */
962 var default ccrel := activate(as_optional_cc_rel(cpars));
963 f_expect_clear();
964 deactivate(ccrel);
965
966 /* Expect RELease indication on the MNCC socket */
967 T.start;
968 alt {
969 [] MNCC.receive(tr_MNCC_REL_ind(cpars.mncc_callref)) -> value mncc_pdu {
970 log("Rx MNCC REL.ind, cause := ", mncc_pdu.u.signal.cause);
971 setverdict(pass);
972 }
973 [] MNCC.receive(MNCC_PDU:?) -> value mncc_pdu {
974 setverdict(fail, "Rx unexpected MNCC PDU: ", mncc_pdu);
975 }
976 [] T.timeout {
977 setverdict(fail, "Timeout waiting for MNCC REL.ind");
978 }
979 }
980}
981testcase TC_mo_call_clear_request() runs on MTC_CT {
982 var BSC_ConnHdlr vc_conn;
983
984 f_init();
985
986 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532766); // '66'H - MO
987 vc_conn.done;
988}
989testcase TC_mt_call_clear_request() runs on MTC_CT {
990 var BSC_ConnHdlr vc_conn;
991
992 f_init();
993
994 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532768); // '68'H - MT
995 vc_conn.done;
996}
997
Harald Welte66af9e62018-01-24 17:28:21 +0100998/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200999friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001000 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +01001001
1002 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1003 var PDU_DTAP_MT dtap_mt;
1004
1005 /* tell GSUP dispatcher to send this IMSI to us */
1006 f_create_gsup_expect(hex2str(g_pars.imsi));
1007
1008 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001009 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +01001010
1011 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001012 if (pars.ran_is_geran) {
1013 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1014 }
Harald Welte66af9e62018-01-24 17:28:21 +01001015
1016 f_sleep(1.0);
1017 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +02001018 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +01001019 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +01001020 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +01001021}
1022testcase TC_lu_disconnect() runs on MTC_CT {
1023 var BSC_ConnHdlr vc_conn;
1024 f_init();
1025
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001026 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +01001027 vc_conn.done;
1028}
1029
Harald Welteba7b6d92018-01-23 21:32:34 +01001030/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +02001031friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001032 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001033
Harald Welte256571e2018-01-24 18:47:19 +01001034 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +01001035 var PDU_DTAP_MT dtap_mt;
1036
1037 /* tell GSUP dispatcher to send this IMSI to us */
1038 f_create_gsup_expect(hex2str(g_pars.imsi));
1039
1040 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001041 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001042
1043 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001044 if (pars.ran_is_geran) {
1045 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1046 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001047 /* wait for LU reject, ignore any ID REQ */
1048 alt {
1049 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
1050 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
1051 }
1052 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001053 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001054}
1055testcase TC_lu_by_imei() runs on MTC_CT {
1056 var BSC_ConnHdlr vc_conn;
1057 f_init();
1058
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001059 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12, verify_cell_id := false);
Harald Welteba7b6d92018-01-23 21:32:34 +01001060 vc_conn.done;
1061}
1062
Harald Weltee13cfb22019-04-23 16:52:02 +02001063
Harald Welteba7b6d92018-01-23 21:32:34 +01001064/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
1065private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001066 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
1067 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +01001068 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001069
1070 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
1071 var PDU_DTAP_MT dtap_mt;
1072
1073 /* tell GSUP dispatcher to send this IMSI to us */
1074 f_create_gsup_expect(hex2str(g_pars.imsi));
1075
1076 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001077 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001078
1079 /* Send Early Classmark, just for the fun of it */
1080 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1081
1082 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +02001083 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001084 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +01001085 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
Harald Welte79f1e452020-08-18 22:55:02 +02001086 f_expect_common_id();
Harald Welteba7b6d92018-01-23 21:32:34 +01001087
1088 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1089 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1090 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1091 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1092 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1093
1094 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +01001095 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1096 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1097 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001098 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1099 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001100 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +01001101 }
1102 }
1103
Philipp Maier9b690e42018-12-21 11:50:03 +01001104 /* Wait for MM-Information (if enabled) */
1105 f_expect_mm_info();
1106
Harald Welteba7b6d92018-01-23 21:32:34 +01001107 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001108 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001109}
1110testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
1111 var BSC_ConnHdlr vc_conn;
1112 f_init();
1113
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001114 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +01001115 vc_conn.done;
1116}
1117
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001118/* Test LU by unknown TMSI, while the IMSI is already attached: osmo-msc should switch to the attached vlr_subscr. */
1119private function f_tc_attached_imsi_lu_unknown_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1120 f_init_handler(pars);
1121
1122 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('56111111'O);
1123 var PDU_DTAP_MT dtap_mt;
1124
1125 /* tell GSUP dispatcher to send this IMSI to us */
1126 f_create_gsup_expect(hex2str(g_pars.imsi));
1127
1128 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1129 f_cl3_or_initial_ue(l3_lu);
1130
1131 /* Send Early Classmark, just for the fun of it */
1132 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1133
1134 /* Wait for + respond to ID REQ (IMSI) */
1135 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1136 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1137 f_expect_common_id();
1138
1139 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1140 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1141 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1142 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1143 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1144
1145 alt {
1146 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1147 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1148 }
1149 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1150 setverdict(fail, "Expected LU ACK, but received REJ");
1151 mtc.stop;
1152 }
1153 }
1154
1155 /* Wait for MM-Information (if enabled) */
1156 f_expect_mm_info();
1157
1158 /* wait for normal teardown */
1159 f_expect_clear();
1160
1161 /* Now the same IMSI is still attached in the VLR, and a LU with an unknown TMSI reveals the same IMSI only
1162 * later during ID Response. osmo-msc first creates a new vlr_subscr for the unknown TMSI, and as soon as the
1163 * IMSI becomes known, must notice that this IMSI is still regarded as attached, and must not create evil twins.
1164 */
1165
1166 /* (since the TMSI Reallocation happened, we could do this with exactly the same TMSI as above, but for test
1167 * readability just use a different one.) */
1168 l3_lu := f_build_lu_tmsi('56222222'O);
1169 f_cl3_or_initial_ue(l3_lu);
1170
1171 /* Wait for + respond to ID REQ (IMSI) */
1172 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1173 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1174 f_expect_common_id();
1175
1176 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1177 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1178 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1179 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1180 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1181
1182 alt {
1183 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1184 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1185 }
1186 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1187 setverdict(fail, "Expected LU ACK, but received REJ");
1188 mtc.stop;
1189 }
1190 }
1191
1192 /* Wait for MM-Information (if enabled) */
1193 f_expect_mm_info();
1194
1195 /* wait for normal teardown */
1196 f_expect_clear();
1197}
1198testcase TC_attached_imsi_lu_unknown_tmsi() runs on MTC_CT {
1199 var BSC_ConnHdlr vc_conn;
1200 f_init();
1201
1202 vc_conn := f_start_handler(refers(f_tc_attached_imsi_lu_unknown_tmsi), 56);
1203 vc_conn.done;
1204}
1205
Harald Welte4d15fa72020-08-19 08:58:28 +02001206friend function f_imsi_detach_by_imsi() runs on BSC_ConnHdlr {
Harald Welte45164da2018-01-24 12:51:27 +01001207 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1208
1209 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001210 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001211
1212 /* Send Early Classmark, just for the fun of it? */
Harald Welte4d15fa72020-08-19 08:58:28 +02001213 if (g_pars.ran_is_geran) {
Harald Weltee13cfb22019-04-23 16:52:02 +02001214 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1215 }
Harald Welte45164da2018-01-24 12:51:27 +01001216
1217 /* wait for normal teardown */
Harald Welte4d15fa72020-08-19 08:58:28 +02001218 f_expect_clear(verify_vlr_cell_id := false);
1219}
1220
1221
1222/* Test IMSI DETACH (MI=IMSI) */
1223friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1224 f_init_handler(pars);
1225
1226 f_imsi_detach_by_imsi();
Harald Welte45164da2018-01-24 12:51:27 +01001227}
1228testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
1229 var BSC_ConnHdlr vc_conn;
1230 f_init();
1231
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001232 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001233 vc_conn.done;
1234}
1235
Harald Weltee13cfb22019-04-23 16:52:02 +02001236
Harald Welte45164da2018-01-24 12:51:27 +01001237/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001238friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001239 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001240
1241 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
1242
1243 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001244 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001245
1246 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001247 if (pars.ran_is_geran) {
1248 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1249 }
Harald Welte45164da2018-01-24 12:51:27 +01001250
1251 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001252 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001253}
1254testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1255 var BSC_ConnHdlr vc_conn;
1256 f_init();
1257
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001258 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001259 vc_conn.done;
1260}
1261
Harald Weltee13cfb22019-04-23 16:52:02 +02001262
Harald Welte45164da2018-01-24 12:51:27 +01001263/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001264friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001265 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001266
Harald Welte256571e2018-01-24 18:47:19 +01001267 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001268
1269 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001270 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001271
1272 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001273 if (pars.ran_is_geran) {
1274 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1275 }
Harald Welte45164da2018-01-24 12:51:27 +01001276
1277 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001278 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001279}
1280testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1281 var BSC_ConnHdlr vc_conn;
1282 f_init();
1283
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001284 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001285 vc_conn.done;
1286}
1287
1288
1289/* helper function for an emergency call. caller passes in mobile identity to use */
1290private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001291 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1292 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001293
Harald Welte0bef21e2018-02-10 09:48:23 +01001294 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001295}
1296
1297/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001298friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001299 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001300
Harald Welte256571e2018-01-24 18:47:19 +01001301 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001302 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001303 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001304 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001305 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001306}
1307testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1308 var BSC_ConnHdlr vc_conn;
1309 f_init();
1310
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001311 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001312 vc_conn.done;
1313}
1314
Harald Weltee13cfb22019-04-23 16:52:02 +02001315
Harald Welted5b91402018-01-24 18:48:16 +01001316/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001317friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001318 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001319 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001320 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001321 /* Then issue emergency call identified by IMSI */
1322 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1323}
1324testcase TC_emerg_call_imsi() runs on MTC_CT {
1325 var BSC_ConnHdlr vc_conn;
1326 f_init();
1327
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001328 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001329 vc_conn.done;
1330}
1331
Harald Weltee13cfb22019-04-23 16:52:02 +02001332
Harald Welte45164da2018-01-24 12:51:27 +01001333/* CM Service Request for VGCS -> reject */
1334private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001335 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001336
1337 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001338 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001339
1340 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001341 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001342 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001343 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001344 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001345}
1346testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1347 var BSC_ConnHdlr vc_conn;
1348 f_init();
1349
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001350 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001351 vc_conn.done;
1352}
1353
1354/* CM Service Request for VBS -> reject */
1355private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001356 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001357
1358 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001359 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001360
1361 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001362 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001363 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001364 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001365 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001366}
1367testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1368 var BSC_ConnHdlr vc_conn;
1369 f_init();
1370
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001371 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001372 vc_conn.done;
1373}
1374
1375/* CM Service Request for LCS -> reject */
1376private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001377 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001378
1379 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001380 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001381
1382 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001383 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001384 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001385 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001386 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001387}
1388testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1389 var BSC_ConnHdlr vc_conn;
1390 f_init();
1391
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001392 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001393 vc_conn.done;
1394}
1395
Harald Welte0195ab12018-01-24 21:50:20 +01001396/* CM Re-Establishment Request */
1397private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001398 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001399
1400 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001401 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001402
1403 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1404 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001405 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001406 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001407 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001408}
1409testcase TC_cm_reest_req_reject() runs on MTC_CT {
1410 var BSC_ConnHdlr vc_conn;
1411 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001412
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001413 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001414 vc_conn.done;
1415}
1416
Harald Weltec638f4d2018-01-24 22:00:36 +01001417/* Test LU (with authentication enabled), with wrong response from MS */
1418private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001419 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001420
1421 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1422
1423 /* tell GSUP dispatcher to send this IMSI to us */
1424 f_create_gsup_expect(hex2str(g_pars.imsi));
1425
1426 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001427 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001428
1429 /* Send Early Classmark, just for the fun of it */
1430 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1431
1432 var AuthVector vec := f_gen_auth_vec_2g();
1433 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1434 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1435 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1436
1437 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1438 /* Send back wrong auth response */
1439 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1440
1441 /* Expect GSUP AUTH FAIL REP to HLR */
1442 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1443
1444 /* Expect LU REJECT with Cause == Illegal MS */
1445 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001446 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001447}
1448testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1449 var BSC_ConnHdlr vc_conn;
1450 f_init();
1451 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001452
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001453 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23, verify_cell_id := false);
Harald Weltec638f4d2018-01-24 22:00:36 +01001454 vc_conn.done;
1455}
1456
Harald Weltede371492018-01-27 23:44:41 +01001457/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001458private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001459 pars.net.expect_auth := true;
1460 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001461 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001462 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001463}
1464testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1465 var BSC_ConnHdlr vc_conn;
1466 f_init();
1467 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001468 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1469
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001470 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001471 vc_conn.done;
1472}
1473
Harald Welte1af6ea82018-01-25 18:33:15 +01001474/* Test Complete L3 without payload */
1475private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001476 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001477
1478 /* Send Complete L3 Info with empty L3 frame */
1479 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1480 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1481
Harald Weltef466eb42018-01-27 14:26:54 +01001482 timer T := 5.0;
1483 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001484 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001485 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001486 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001487 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001488 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001489 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001490 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001491 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001492 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001493 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001494 }
1495 setverdict(pass);
1496}
1497testcase TC_cl3_no_payload() runs on MTC_CT {
1498 var BSC_ConnHdlr vc_conn;
1499 f_init();
1500
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001501 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001502 vc_conn.done;
1503}
1504
1505/* Test Complete L3 with random payload */
1506private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001507 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001508
Daniel Willmannaa14a382018-07-26 08:29:45 +02001509 /* length is limited by PDU_BSSAP length field which includes some
1510 * other fields beside l3info payload. So payl can only be 240 bytes
1511 * Since rnd() returns values < 1 multiply with 241
1512 */
1513 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001514 var octetstring payl := f_rnd_octstring(len);
1515
1516 /* Send Complete L3 Info with empty L3 frame */
1517 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1518 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1519
Harald Weltef466eb42018-01-27 14:26:54 +01001520 timer T := 5.0;
1521 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001522 alt {
1523 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001524 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001525 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001526 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001527 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001528 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001529 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001530 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001531 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001532 }
1533 setverdict(pass);
1534}
1535testcase TC_cl3_rnd_payload() runs on MTC_CT {
1536 var BSC_ConnHdlr vc_conn;
1537 f_init();
1538
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001539 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001540 vc_conn.done;
1541}
1542
Harald Welte116e4332018-01-26 22:17:48 +01001543/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001544friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001545 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001546
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001547 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001548
Harald Welteb9e86fa2018-04-09 18:18:31 +02001549 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001550 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001551}
1552testcase TC_establish_and_nothing() runs on MTC_CT {
1553 var BSC_ConnHdlr vc_conn;
1554 f_init();
1555
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001556 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001557 vc_conn.done;
1558}
1559
Harald Weltee13cfb22019-04-23 16:52:02 +02001560
Harald Welte12510c52018-01-26 22:26:24 +01001561/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001562friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001563 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001564
Harald Welte12510c52018-01-26 22:26:24 +01001565 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001566 cpars.mgw_conn_2.resp := 0;
1567 cpars.stop_after_cc_setup := true;
1568
1569 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001570
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001571 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001572
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001573 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001574
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001575 var default ccrel := activate(as_optional_cc_rel(cpars));
1576
Philipp Maier109e6aa2018-10-17 10:53:32 +02001577 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001578
1579 deactivate(ccrel);
1580
1581 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001582}
1583testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1584 var BSC_ConnHdlr vc_conn;
1585 f_init();
1586
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001587 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001588 vc_conn.done;
1589}
1590
Harald Weltee13cfb22019-04-23 16:52:02 +02001591
Harald Welte3ab88002018-01-26 22:37:25 +01001592/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001593friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001594 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001595 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1596 var MNCC_PDU mncc;
1597 var MgcpCommand mgcp_cmd;
1598
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001599 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001600 /* Do not respond to the second CRCX */
1601 cpars.mgw_conn_2.resp := 0;
1602 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001603
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001604 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001605
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001606 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001607
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001608 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001609}
1610testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1611 var BSC_ConnHdlr vc_conn;
1612 f_init();
1613
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001614 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001615 vc_conn.done;
1616}
1617
Harald Weltee13cfb22019-04-23 16:52:02 +02001618
Harald Welte0cc82d92018-01-26 22:52:34 +01001619/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001620friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001621 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001622
Harald Welte0cc82d92018-01-26 22:52:34 +01001623 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001624
1625 /* Respond with error for the first CRCX */
1626 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001627
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001628 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001629 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001630
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001631 var default ccrel := activate(as_optional_cc_rel(cpars));
1632 f_expect_clear(60.0);
1633 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001634}
1635testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1636 var BSC_ConnHdlr vc_conn;
1637 f_init();
1638
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001639 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001640 vc_conn.done;
1641}
1642
Harald Welte3ab88002018-01-26 22:37:25 +01001643
Harald Welte812f7a42018-01-27 00:49:18 +01001644/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1645private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1646 var MNCC_PDU mncc;
1647 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001648
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001649 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001650 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001651
1652 /* Allocate call reference and send SETUP via MNCC to MSC */
1653 cpars.mncc_callref := f_rnd_int(2147483648);
1654 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1655 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1656
1657 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001658 f_expect_paging();
1659
Harald Welte812f7a42018-01-27 00:49:18 +01001660 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001661 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001662
1663 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1664
1665 /* MSC->MS: SETUP */
1666 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1667}
1668
1669/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001670friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001671 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001672 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1673 var MNCC_PDU mncc;
1674 var MgcpCommand mgcp_cmd;
1675
1676 f_mt_call_start(cpars);
1677
1678 /* MS->MSC: CALL CONFIRMED */
1679 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1680
1681 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1682
1683 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1684 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001685
1686 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1687 * set an endpoint name that fits the pattern. If not, just use the
1688 * endpoint name from the request */
1689 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1690 cpars.mgcp_ep := "rtpbridge/1@mgw";
1691 } else {
1692 cpars.mgcp_ep := mgcp_cmd.line.ep;
1693 }
1694
Harald Welte812f7a42018-01-27 00:49:18 +01001695 /* Respond to CRCX with error */
1696 var MgcpResponse mgcp_rsp := {
1697 line := {
1698 code := "542",
1699 trans_id := mgcp_cmd.line.trans_id,
1700 string := "FORCED_FAIL"
1701 },
Harald Welte812f7a42018-01-27 00:49:18 +01001702 sdp := omit
1703 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001704 var MgcpParameter mgcp_rsp_param := {
1705 code := "Z",
1706 val := cpars.mgcp_ep
1707 };
1708 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001709 MGCP.send(mgcp_rsp);
1710
1711 timer T := 30.0;
1712 T.start;
1713 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001714 [] T.timeout {
1715 setverdict(fail, "Timeout waiting for channel release");
1716 mtc.stop;
1717 }
Harald Welte812f7a42018-01-27 00:49:18 +01001718 [] MNCC.receive { repeat; }
1719 [] GSUP.receive { repeat; }
1720 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1721 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1722 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1723 repeat;
1724 }
1725 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001726 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001727 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001728 }
1729}
1730testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1731 var BSC_ConnHdlr vc_conn;
1732 f_init();
1733
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001734 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001735 vc_conn.done;
1736}
1737
1738
Harald Weltee13cfb22019-04-23 16:52:02 +02001739
Harald Welte812f7a42018-01-27 00:49:18 +01001740/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001741friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte812f7a42018-01-27 00:49:18 +01001742 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Harald Welte812f7a42018-01-27 00:49:18 +01001743 var MgcpCommand mgcp_cmd;
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001744 var PDU_BSSAP bssap;
1745 timer T310;
Harald Welte812f7a42018-01-27 00:49:18 +01001746
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001747 f_init_handler(pars);
1748
1749 /* Initiate a MT call, establish connection */
Harald Welte812f7a42018-01-27 00:49:18 +01001750 f_mt_call_start(cpars);
1751
1752 /* MS->MSC: CALL CONFIRMED */
1753 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1754 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1755
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001756 /* NOTE: MSC is expected to start T310 here */
Harald Welte812f7a42018-01-27 00:49:18 +01001757
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001758 /* MSC->MGW: CRCX (first) */
1759 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1760 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
1761
1762 /* BSC->BSC: BSSMAP ASSIGNMENT REQ */
1763 BSSAP.receive(tr_BSSMAP_AssignmentReq(omit, ?)) -> value bssap;
1764 BSSAP.send(ts_BSSMAP_AssignmentComplete(omit,
1765 aoip := f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port),
1766 speechCodec := ts_BSSMAP_IE_SpeechCodec({ ts_CodecFR })));
1767
1768 /* MSC->MGW: MDCX */
1769 MGCP.receive(tr_MDCX) -> value mgcp_cmd;
1770 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_1.mgcp_connection_id,
1771 sdp := omit));
1772
1773 /* MSC->MGW: CRCX (second) */
1774 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1775 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
1776 MNCC.receive(tr_MNCC_RTP_CREATE(cpars.mncc_callref));
1777
1778 /* Reschedule the guard timeout */
1779 g_Tguard.start(30.0 + 10.0);
1780
1781 /* NOTE: the BSC is expected to respond with CC ALERTING at this state, so
1782 * the MSC would stop T310. However, the idea is to verify T310 expiration
1783 * here, so grab some popcorn and wait for MNCC DISC.ind. */
1784 T310.start(30.0 + 2.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001785 alt {
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001786 [] T310.timeout {
1787 setverdict(fail, "Timeout waiting for MNCC DISC.ind due to T310");
Daniel Willmannafce8662018-07-06 23:11:32 +02001788 mtc.stop;
1789 }
Harald Welte812f7a42018-01-27 00:49:18 +01001790 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1791 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001792 log("Rx MNCC DISC.ind, T310.read yelds ", T310.read);
1793 setverdict(pass);
Harald Welte812f7a42018-01-27 00:49:18 +01001794 }
1795 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001796
Harald Welte812f7a42018-01-27 00:49:18 +01001797 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1798 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001799 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, '1'B)));
Harald Welte812f7a42018-01-27 00:49:18 +01001800
1801 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001802 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1803 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001804 // FIXME: f_create_mgcp_delete_ep(cpars.mgcp_ep);
Harald Welte812f7a42018-01-27 00:49:18 +01001805 repeat;
1806 }
Harald Welte5946b332018-03-18 23:32:21 +01001807 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001808 }
1809}
1810testcase TC_mt_t310() runs on MTC_CT {
1811 var BSC_ConnHdlr vc_conn;
1812 f_init();
1813
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001814 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001815 vc_conn.done;
1816}
1817
Harald Weltee13cfb22019-04-23 16:52:02 +02001818
Harald Welte167458a2018-01-27 15:58:16 +01001819/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001820friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001821 f_init_handler(pars);
1822 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001823
1824 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001825 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001826
1827 /* First MO call should succeed */
1828 f_mo_call(cpars);
1829
1830 /* Cancel the subscriber in the VLR */
1831 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1832 alt {
1833 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1834 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1835 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001836 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001837 }
1838 }
1839
1840 /* Follow-up transactions should fail */
1841 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1842 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001843 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001844 alt {
1845 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1846 [] BSSAP.receive {
1847 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001848 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001849 }
1850 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001851
1852 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001853 setverdict(pass);
1854}
1855testcase TC_gsup_cancel() runs on MTC_CT {
1856 var BSC_ConnHdlr vc_conn;
1857 f_init();
1858
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001859 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33, verify_cell_id := false);
Harald Welte167458a2018-01-27 15:58:16 +01001860 vc_conn.done;
1861}
1862
Harald Weltee13cfb22019-04-23 16:52:02 +02001863
Harald Welte9de84792018-01-28 01:06:35 +01001864/* A5/1 only permitted on network side, and MS capable to do it */
1865private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1866 pars.net.expect_auth := true;
1867 pars.net.expect_ciph := true;
1868 pars.net.kc_support := '02'O; /* A5/1 only */
1869 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001870 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001871}
1872testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1873 var BSC_ConnHdlr vc_conn;
1874 f_init();
1875 f_vty_config(MSCVTY, "network", "authentication required");
1876 f_vty_config(MSCVTY, "network", "encryption a5 1");
1877
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001878 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001879 vc_conn.done;
1880}
1881
1882/* A5/3 only permitted on network side, and MS capable to do it */
1883private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1884 pars.net.expect_auth := true;
1885 pars.net.expect_ciph := true;
1886 pars.net.kc_support := '08'O; /* A5/3 only */
1887 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001888 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001889}
1890testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1891 var BSC_ConnHdlr vc_conn;
1892 f_init();
1893 f_vty_config(MSCVTY, "network", "authentication required");
1894 f_vty_config(MSCVTY, "network", "encryption a5 3");
1895
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001896 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001897 vc_conn.done;
1898}
1899
1900/* A5/3 only permitted on network side, and MS with only A5/1 support */
1901private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1902 pars.net.expect_auth := true;
1903 pars.net.expect_ciph := true;
1904 pars.net.kc_support := '08'O; /* A5/3 only */
1905 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1906 f_init_handler(pars, 15.0);
1907
1908 /* cannot use f_perform_lu() as we expect a reject */
1909 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1910 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001911 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001912 if (pars.send_early_cm) {
1913 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1914 } else {
1915 pars.cm1.esind := '0'B;
1916 }
Harald Welte9de84792018-01-28 01:06:35 +01001917 f_mm_auth();
1918 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001919 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1920 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1921 repeat;
1922 }
Harald Welte5946b332018-03-18 23:32:21 +01001923 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1924 f_expect_clear();
1925 }
Harald Welte9de84792018-01-28 01:06:35 +01001926 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1927 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001928 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001929 }
1930 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001931 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001932 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001933 }
1934 }
1935 setverdict(pass);
1936}
1937testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1938 var BSC_ConnHdlr vc_conn;
1939 f_init();
1940 f_vty_config(MSCVTY, "network", "authentication required");
1941 f_vty_config(MSCVTY, "network", "encryption a5 3");
1942
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001943 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001944 vc_conn.done;
1945}
1946testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1947 var BSC_ConnHdlrPars pars;
1948 var BSC_ConnHdlr vc_conn;
1949 f_init();
1950 f_vty_config(MSCVTY, "network", "authentication required");
1951 f_vty_config(MSCVTY, "network", "encryption a5 3");
1952
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001953 pars := f_init_pars(361, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001954 pars.send_early_cm := false;
1955 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001956 vc_conn.done;
1957}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001958testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1959 var BSC_ConnHdlr vc_conn;
1960 f_init();
1961 f_vty_config(MSCVTY, "network", "authentication required");
1962 f_vty_config(MSCVTY, "network", "encryption a5 3");
1963
1964 /* Make sure the MSC category is on DEBUG level to trigger the log
1965 * message that is reported in OS#2947 to trigger the segfault */
1966 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1967
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001968 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362, verify_cell_id := false);
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001969 vc_conn.done;
1970}
Harald Welte9de84792018-01-28 01:06:35 +01001971
1972/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1973private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1974 pars.net.expect_auth := true;
1975 pars.net.expect_ciph := true;
1976 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1977 pars.cm1.a5_1 := '1'B;
1978 pars.cm2.a5_1 := '1'B;
1979 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1980 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1981 f_init_handler(pars, 15.0);
1982
1983 /* cannot use f_perform_lu() as we expect a reject */
1984 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1985 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001986 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001987 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1988 f_mm_auth();
1989 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001990 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1991 f_expect_clear();
1992 }
Harald Welte9de84792018-01-28 01:06:35 +01001993 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1994 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001995 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001996 }
1997 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001998 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001999 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01002000 }
2001 }
2002 setverdict(pass);
2003}
2004testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
2005 var BSC_ConnHdlr vc_conn;
2006 f_init();
2007 f_vty_config(MSCVTY, "network", "authentication required");
2008 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
2009
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02002010 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37, verify_cell_id := false);
Harald Welte9de84792018-01-28 01:06:35 +01002011 vc_conn.done;
2012}
2013
Eric Wild26f4a622021-05-17 15:27:05 +02002014/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with only A5/1 support */
2015private function f_tc_lu_imsi_auth_tmsi_encr_0134_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2016 pars.net.expect_auth := true;
2017 pars.net.expect_ciph := true;
2018 pars.net.kc_support := '03'O; /* A5/0 + A5/1 */
2019 pars.cm1.a5_1 := '0'B;
2020 pars.cm2.a5_1 := '0'B;
2021 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2022 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2023 pars.cm2.classmarkInformationType2_oct5.cm3 := '0'B;
2024 pars.cm3 := omit;
2025 pars.use_umts_aka := true;
2026
2027 f_init_handler(pars, 15.0);
2028 f_perform_lu();
2029}
2030testcase TC_lu_imsi_auth_tmsi_encr_0134_1() runs on MTC_CT {
2031 var BSC_ConnHdlr vc_conn;
2032 f_init();
2033 f_vty_config(MSCVTY, "network", "authentication required");
2034 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2035
2036 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_1), 39);
2037 vc_conn.done;
2038}
2039
2040/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with A5/3 + A5/4 support */
2041private function f_tc_lu_imsi_auth_tmsi_encr_0134_34(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2042 pars.net.expect_auth := true;
2043 pars.net.expect_ciph := true;
2044 pars.net.kc_support := '19'O; /* A5/3 + A5/4 */
2045 pars.cm1.a5_1 := '1'B;
2046 pars.cm2.a5_1 := '1'B;
2047 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
2048 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2049 pars.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
2050 pars.cm3 := valueof(ts_CM3_default);
2051 pars.use_umts_aka := true;
2052
2053 f_init_handler(pars, 15.0);
2054 f_perform_lu();
2055}
2056testcase TC_lu_imsi_auth_tmsi_encr_0134_34() runs on MTC_CT {
2057 var BSC_ConnHdlr vc_conn;
2058 f_init();
2059 f_vty_config(MSCVTY, "network", "authentication required");
2060 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2061
2062 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_34), 40);
2063 vc_conn.done;
2064}
2065
2066/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with A5/3 support but no CM3 */
2067private function f_tc_lu_imsi_auth_tmsi_encr_0134_34_no_cm3(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2068 pars.net.expect_auth := true;
2069 pars.net.expect_ciph := true;
2070 pars.net.kc_support := '19'O; /* A5/3 + A5/4 */
2071 pars.cm1.a5_1 := '1'B;
2072 pars.cm2.a5_1 := '1'B;
2073 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
2074 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2075 pars.cm2.classmarkInformationType2_oct5.cm3 := '0'B;
2076 pars.cm3 := omit;
2077 pars.use_umts_aka := true;
2078
2079 f_init_handler(pars, 15.0);
2080 f_perform_lu();
2081}
2082testcase TC_lu_imsi_auth_tmsi_encr_0134_34_no_cm3() runs on MTC_CT {
2083 var BSC_ConnHdlr vc_conn;
2084 f_init();
2085 f_vty_config(MSCVTY, "network", "authentication required");
2086 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2087
2088 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_34_no_cm3), 41);
2089 vc_conn.done;
2090}
2091
Harald Welte9de84792018-01-28 01:06:35 +01002092/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
2093private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2094 pars.net.expect_auth := true;
2095 pars.net.expect_ciph := true;
2096 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
2097 pars.cm1.a5_1 := '1'B;
2098 pars.cm2.a5_1 := '1'B;
2099 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2100 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
2101 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002102 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01002103}
2104testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
2105 var BSC_ConnHdlr vc_conn;
2106 f_init();
2107 f_vty_config(MSCVTY, "network", "authentication required");
2108 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
2109
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002110 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01002111 vc_conn.done;
2112}
2113
Harald Welte33ec09b2018-02-10 15:34:46 +01002114/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01002115friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01002116 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002117 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002118 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01002119
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002120 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01002121 f_mt_call(cpars);
2122}
2123testcase TC_lu_and_mt_call() runs on MTC_CT {
2124 var BSC_ConnHdlr vc_conn;
2125 f_init();
2126
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002127 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01002128 vc_conn.done;
2129}
2130
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002131testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
2132 var BSC_ConnHdlr vc_conn;
2133 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002134
2135 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
2136 vc_conn.done;
2137}
2138
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002139/* LU followed by MT call (including paging) */
2140friend function f_tc_lu_and_mt_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2141 f_init_handler(pars);
2142 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2143 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
2144 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
2145 cpars.bss_rtp_ip := "::3";
Pau Espin Pedrol563b3d02020-09-09 20:19:52 +02002146 cpars.mncc_rtp_ip := "::9";
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002147 f_perform_lu();
2148 f_mt_call(cpars);
2149}
2150testcase TC_lu_and_mt_call_ipv6() runs on MTC_CT {
2151 var BSC_ConnHdlr vc_conn;
2152 f_init();
2153
2154 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_ipv6), 39);
2155 vc_conn.done;
2156}
2157
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002158/* MT call while already Paging */
2159friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2160 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
2161 var SmsParameters spars := valueof(t_SmsPars);
2162 var OCT4 tmsi;
2163
2164 f_init_handler(pars);
2165
2166 /* Perform location update */
2167 f_perform_lu();
2168
2169 /* register an 'expect' for given IMSI (+TMSI) */
2170 if (isvalue(g_pars.tmsi)) {
2171 tmsi := g_pars.tmsi;
2172 } else {
2173 tmsi := 'FFFFFFFF'O;
2174 }
2175 f_ran_register_imsi(g_pars.imsi, tmsi);
2176
2177 log("start Paging by an SMS");
2178 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2179
2180 /* MSC->BSC: expect PAGING from MSC */
2181 f_expect_paging();
2182
2183 log("MNCC signals MT call, before Paging Response");
2184 f_mt_call_initate(cpars);
2185 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
2186
2187 f_sleep(0.5);
2188 log("phone answers Paging, expecting both SMS and MT call to be established");
2189 f_establish_fully(EST_TYPE_PAG_RESP);
2190 spars.tp.ud := 'C8329BFD064D9B53'O;
2191 interleave {
2192 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
2193 log("Got SMS-DELIVER");
2194 };
2195 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
2196 log("Got CC Setup");
2197 };
2198 }
2199 setverdict(pass);
2200 log("success, tear down");
2201 var default ccrel := activate(as_optional_cc_rel(cpars));
2202 if (g_pars.ran_is_geran) {
2203 BSSAP.send(ts_BSSMAP_ClearRequest(0));
2204 } else {
2205 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
2206 }
2207 f_expect_clear();
2208 deactivate(ccrel);
2209 f_vty_sms_clear(hex2str(g_pars.imsi));
2210}
2211testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
2212 var BSC_ConnHdlrPars pars;
2213 var BSC_ConnHdlr vc_conn;
2214 f_init();
2215 pars := f_init_pars(391);
2216 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
2217 vc_conn.done;
2218}
2219
Daniel Willmann8b084372018-02-04 13:35:26 +01002220/* Test MO Call SETUP with DTMF */
2221private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2222 f_init_handler(pars);
2223 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01002224
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002225 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01002226 f_mo_seq_dtmf_dup(cpars);
2227}
2228testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
2229 var BSC_ConnHdlr vc_conn;
2230 f_init();
2231
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002232 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01002233 vc_conn.done;
2234}
Harald Welte9de84792018-01-28 01:06:35 +01002235
Philipp Maier328d1662018-03-07 10:40:27 +01002236testcase TC_cr_before_reset() runs on MTC_CT {
2237 timer T := 4.0;
2238 var boolean reset_ack_seen := false;
2239 f_init_bssap_direct();
2240
Harald Welte3ca0ce12019-04-23 17:18:48 +02002241 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02002242
Daniel Willmanne8018962018-08-21 14:18:00 +02002243 f_sleep(3.0);
2244
Philipp Maier328d1662018-03-07 10:40:27 +01002245 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02002246 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01002247
2248 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02002249 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01002250 T.start
2251 alt {
2252 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
2253 reset_ack_seen := true;
2254 repeat;
2255 }
2256
2257 /* Acknowledge MSC sided reset requests */
2258 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02002259 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01002260 repeat;
2261 }
2262
2263 /* Ignore all other messages (e.g CR from the connection request) */
2264 [] BSSAP_DIRECT.receive { repeat }
2265
2266 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
2267 * deadlock situation. The MSC is then unable to respond to any
2268 * further BSSMAP RESET or any other sort of traffic. */
2269 [reset_ack_seen == true] T.timeout { setverdict(pass) }
2270 [reset_ack_seen == false] T.timeout {
2271 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02002272 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01002273 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01002274 }
Philipp Maier328d1662018-03-07 10:40:27 +01002275}
Harald Welte9de84792018-01-28 01:06:35 +01002276
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002277/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02002278friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002279 f_init_handler(pars);
2280 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2281 var MNCC_PDU mncc;
2282 var MgcpCommand mgcp_cmd;
2283
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002284 /* Do not respond to the second CRCX */
2285 cpars.mgw_conn_2.resp := 0;
2286
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002287 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002288 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002289
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002290 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002291
2292 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002293
2294 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002295}
2296testcase TC_mo_release_timeout() runs on MTC_CT {
2297 var BSC_ConnHdlr vc_conn;
2298 f_init();
2299
2300 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
2301 vc_conn.done;
2302}
2303
Harald Welte12510c52018-01-26 22:26:24 +01002304
Philipp Maier2a98a732018-03-19 16:06:12 +01002305/* LU followed by MT call (including paging) */
2306private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2307 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002308 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01002309
2310 /* Intentionally disable the CRCX response */
2311 cpars.mgw_drop_dlcx := true;
2312
2313 /* Perform location update and call */
2314 f_perform_lu();
2315 f_mt_call(cpars);
2316}
2317testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
2318 var BSC_ConnHdlr vc_conn;
2319 f_init();
2320
2321 /* Perform an almost normal looking locationupdate + mt-call, but do
2322 * not respond to the DLCX at the end of the call */
2323 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
2324 vc_conn.done;
2325
2326 /* Wait a guard period until the MGCP layer in the MSC times out,
2327 * if the MSC is vulnerable to the use-after-free situation that is
2328 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
2329 * segfault now */
2330 f_sleep(6.0);
2331
2332 /* Run the init procedures once more. If the MSC has crashed, this
2333 * this will fail */
2334 f_init();
2335}
Harald Welte45164da2018-01-24 12:51:27 +01002336
Philipp Maier75932982018-03-27 14:52:35 +02002337/* Two BSSMAP resets from two different BSCs */
2338testcase TC_reset_two() runs on MTC_CT {
2339 var BSC_ConnHdlr vc_conn;
2340 f_init(2);
2341 f_sleep(2.0);
2342 setverdict(pass);
2343}
2344
Harald Weltee13cfb22019-04-23 16:52:02 +02002345/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
2346testcase TC_reset_two_1iu() runs on MTC_CT {
2347 var BSC_ConnHdlr vc_conn;
2348 f_init(3);
2349 f_sleep(2.0);
2350 setverdict(pass);
2351}
2352
Harald Weltef640a012018-04-14 17:49:21 +02002353/***********************************************************************
2354 * SMS Testing
2355 ***********************************************************************/
2356
Harald Weltef45efeb2018-04-09 18:19:24 +02002357/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002358friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002359 var SmsParameters spars := valueof(t_SmsPars);
2360
2361 f_init_handler(pars);
2362
2363 /* Perform location update and call */
2364 f_perform_lu();
2365
2366 f_establish_fully(EST_TYPE_MO_SMS);
2367
2368 //spars.exp_rp_err := 96; /* invalid mandatory information */
2369 f_mo_sms(spars);
2370
2371 f_expect_clear();
2372}
2373testcase TC_lu_and_mo_sms() runs on MTC_CT {
2374 var BSC_ConnHdlr vc_conn;
2375 f_init();
2376 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2377 vc_conn.done;
2378}
2379
Harald Weltee13cfb22019-04-23 16:52:02 +02002380
Harald Weltef45efeb2018-04-09 18:19:24 +02002381private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002382runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002383 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2384}
2385
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002386/* Remove still pending SMS */
2387private function f_vty_sms_clear(charstring imsi)
2388runs on BSC_ConnHdlr {
2389 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2390 f_vty_transceive(MSCVTY, "sms-queue clear");
2391}
2392
Harald Weltef45efeb2018-04-09 18:19:24 +02002393/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002394friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002395 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002396
2397 f_init_handler(pars);
2398
2399 /* Perform location update and call */
2400 f_perform_lu();
2401
2402 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002403 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002404
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002405 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002406
2407 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002408 f_expect_paging();
2409
Harald Weltef45efeb2018-04-09 18:19:24 +02002410 /* Establish DTAP / BSSAP / SCCP connection */
2411 f_establish_fully(EST_TYPE_PAG_RESP);
2412
2413 spars.tp.ud := 'C8329BFD064D9B53'O;
2414 f_mt_sms(spars);
2415
2416 f_expect_clear();
2417}
2418testcase TC_lu_and_mt_sms() runs on MTC_CT {
2419 var BSC_ConnHdlrPars pars;
2420 var BSC_ConnHdlr vc_conn;
2421 f_init();
2422 pars := f_init_pars(43);
2423 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002424 vc_conn.done;
2425}
2426
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002427/* SMS added while already Paging */
2428friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2429 var SmsParameters spars := valueof(t_SmsPars);
2430 var OCT4 tmsi;
2431
2432 f_init_handler(pars);
2433
2434 f_perform_lu();
2435
2436 /* register an 'expect' for given IMSI (+TMSI) */
2437 if (isvalue(g_pars.tmsi)) {
2438 tmsi := g_pars.tmsi;
2439 } else {
2440 tmsi := 'FFFFFFFF'O;
2441 }
2442 f_ran_register_imsi(g_pars.imsi, tmsi);
2443
2444 log("first SMS");
2445 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2446
2447 /* MSC->BSC: expect PAGING from MSC */
2448 f_expect_paging();
2449
2450 log("second SMS");
2451 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2452 * with the pending paging. Another SMS: */
2453 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2454
2455 /* Establish DTAP / BSSAP / SCCP connection */
2456 f_establish_fully(EST_TYPE_PAG_RESP);
2457
2458 spars.tp.ud := 'C8329BFD064D9B53'O;
2459 f_mt_sms(spars);
2460
2461 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2462 f_mt_sms(spars);
2463
2464 f_expect_clear();
2465}
2466testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2467 var BSC_ConnHdlrPars pars;
2468 var BSC_ConnHdlr vc_conn;
2469 f_init();
2470 pars := f_init_pars(44);
2471 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2472 vc_conn.done;
2473}
Harald Weltee13cfb22019-04-23 16:52:02 +02002474
Philipp Maier3983e702018-11-22 19:01:33 +01002475/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002476friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002477 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002478
Philipp Maier3983e702018-11-22 19:01:33 +01002479 f_init_handler(pars, 150.0);
2480
2481 /* Perform location update */
2482 f_perform_lu();
2483
2484 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002485 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002486
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002487 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2488
Neels Hofmeyr16237742019-03-06 15:34:01 +01002489 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002490 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002491
2492 /* Wait some time to make sure the MSC is not delivering any further
2493 * paging messages or anything else that could be unexpected. */
2494 timer T := 20.0;
2495 T.start
2496 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002497 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2498 setverdict(fail, "paging seems not to stop!");
2499 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002500 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002501 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2502 setverdict(fail, "paging seems not to stop!");
2503 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002504 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002505 [] BSSAP.receive {
2506 setverdict(fail, "unexpected BSSAP message received");
2507 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002508 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002509 [] T.timeout {
2510 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002511 }
2512 }
2513
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002514 f_vty_sms_clear(hex2str(g_pars.imsi));
2515
Philipp Maier3983e702018-11-22 19:01:33 +01002516 setverdict(pass);
2517}
2518testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2519 var BSC_ConnHdlrPars pars;
2520 var BSC_ConnHdlr vc_conn;
2521 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002522 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002523 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002524 vc_conn.done;
2525}
2526
Alexander Couzensfc02f242019-09-12 03:43:18 +02002527/* LU followed by MT SMS with repeated paging */
2528friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2529 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002530
2531 f_init_handler(pars);
2532
2533 /* Perform location update and call */
2534 f_perform_lu();
2535
2536 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002537 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002538
2539 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2540
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002541 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002542 /* MSC->BSC: expect PAGING from MSC */
2543 f_expect_paging();
2544
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002545 if (g_pars.ran_is_geran) {
2546 log("GERAN: expect no further Paging");
2547 } else {
2548 log("UTRAN: expect more Paging");
2549 }
2550
2551 timer T := 5.0;
2552 T.start;
2553 alt {
2554 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2555 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2556 mtc.stop;
2557 }
2558 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2559 log("UTRAN: second Paging received, as expected");
2560 setverdict(pass);
2561 }
2562 [] T.timeout {
2563 if (g_pars.ran_is_geran) {
2564 log("GERAN: No further Paging received, as expected");
2565 setverdict(pass);
2566 } else {
2567 setverdict(fail, "UTRAN: Expected a second Paging");
2568 mtc.stop;
2569 }
2570 }
2571 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002572
2573 /* Establish DTAP / BSSAP / SCCP connection */
2574 f_establish_fully(EST_TYPE_PAG_RESP);
2575
2576 spars.tp.ud := 'C8329BFD064D9B53'O;
2577 f_mt_sms(spars);
2578
2579 f_expect_clear();
2580}
2581testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2582 var BSC_ConnHdlrPars pars;
2583 var BSC_ConnHdlr vc_conn;
2584 f_init();
2585 pars := f_init_pars(1844);
2586 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2587 vc_conn.done;
2588}
Harald Weltee13cfb22019-04-23 16:52:02 +02002589
Harald Weltef640a012018-04-14 17:49:21 +02002590/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002591friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002592 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002593
Harald Weltef640a012018-04-14 17:49:21 +02002594 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002595
Harald Weltef640a012018-04-14 17:49:21 +02002596 /* Perform location update so IMSI is known + registered in MSC/VLR */
2597 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002598
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002599 /* MS/UE submits a MO SMS */
2600 f_establish_fully(EST_TYPE_MO_SMS);
2601 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002602
2603 var SMPP_PDU smpp;
2604 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2605 tr_smpp.body.deliver_sm := {
2606 service_type := "CMT",
2607 source_addr_ton := network_specific,
2608 source_addr_npi := isdn,
2609 source_addr := hex2str(pars.msisdn),
2610 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2611 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2612 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2613 esm_class := '00000001'B,
2614 protocol_id := 0,
2615 priority_flag := 0,
2616 schedule_delivery_time := "",
2617 replace_if_present := 0,
2618 data_coding := '00000001'B,
2619 sm_default_msg_id := 0,
2620 sm_length := ?,
2621 short_message := spars.tp.ud,
2622 opt_pars := {
2623 {
2624 tag := user_message_reference,
2625 len := 2,
2626 opt_value := {
2627 int2_val := oct2int(spars.tp.msg_ref)
2628 }
2629 }
2630 }
2631 };
2632 alt {
2633 [] SMPP.receive(tr_smpp) -> value smpp {
2634 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2635 }
2636 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2637 }
2638
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002639 /* MSC terminates the SMS transaction with RP-ACK */
2640 f_mo_sms_wait_rp_ack(spars);
2641
Harald Weltef640a012018-04-14 17:49:21 +02002642 f_expect_clear();
2643}
2644testcase TC_smpp_mo_sms() runs on MTC_CT {
2645 var BSC_ConnHdlr vc_conn;
2646 f_init();
2647 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2648 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2649 vc_conn.done;
2650 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2651}
2652
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002653/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2654friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2655runs on BSC_ConnHdlr {
2656 var SmsParameters spars := valueof(t_SmsPars);
2657 var SMPP_PDU smpp_pdu;
2658 timer T := 3.0;
2659
2660 f_init_handler(pars);
2661
2662 /* Perform location update */
2663 f_perform_lu();
2664
2665 /* MS/UE submits a MO SMS */
2666 f_establish_fully(EST_TYPE_MO_SMS);
2667 f_mo_sms_submit(spars);
2668
2669 /* ESME responds with an error (Invalid Destination Address) */
2670 T.start;
2671 alt {
2672 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2673 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2674 }
2675 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2676 [] T.timeout {
2677 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2678 mtc.stop;
2679 }
2680 }
2681
2682 /* Expect RP-ERROR on BSSAP interface */
2683 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2684 f_mo_sms_wait_rp_ack(spars);
2685
2686 f_expect_clear();
2687}
2688testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2689 var BSC_ConnHdlr vc_conn;
2690 f_init();
2691 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2692 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2693 vc_conn.done;
2694 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2695}
2696
Harald Weltee13cfb22019-04-23 16:52:02 +02002697
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002698/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002699friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002700runs on BSC_ConnHdlr {
2701 var SmsParameters spars := valueof(t_SmsPars);
2702 var GSUP_PDU gsup_msg_rx;
2703 var octetstring sm_tpdu;
2704
2705 f_init_handler(pars);
2706
2707 /* We need to inspect GSUP activity */
2708 f_create_gsup_expect(hex2str(g_pars.imsi));
2709
2710 /* Perform location update */
2711 f_perform_lu();
2712
2713 /* Send CM Service Request for SMS */
2714 f_establish_fully(EST_TYPE_MO_SMS);
2715
2716 /* Prepare expected SM-RP-UI (SM TPDU) */
2717 enc_TPDU_RP_DATA_MS_SGSN_fast(
2718 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2719 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2720 spars.tp.udl, spars.tp.ud)),
2721 sm_tpdu);
2722
2723 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2724 imsi := g_pars.imsi,
2725 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002726 /* SM-RP-DA: SMSC address */
2727 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2728 number := spars.rp.smsc_addr.rP_NumberDigits,
2729 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2730 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2731 ext := spars.rp.smsc_addr.rP_Ext)),
2732 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2733 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2734 number := g_pars.msisdn,
2735 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2736 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002737 /* TODO: can we use decmatch here? */
2738 sm_rp_ui := sm_tpdu
2739 );
2740
2741 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2742 f_mo_sms_submit(spars);
2743 alt {
2744 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002745 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002746 setverdict(pass);
2747 }
2748 [] GSUP.receive {
2749 log("RX unexpected GSUP message");
2750 setverdict(fail);
2751 mtc.stop;
2752 }
2753 }
2754
2755 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2756 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2757 imsi := g_pars.imsi,
2758 sm_rp_mr := spars.rp.msg_ref)));
2759 /* Expect RP-ACK on DTAP */
2760 f_mo_sms_wait_rp_ack(spars);
2761
2762 f_expect_clear();
2763}
2764testcase TC_gsup_mo_sms() runs on MTC_CT {
2765 var BSC_ConnHdlr vc_conn;
2766 f_init();
2767 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2768 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2769 vc_conn.done;
2770 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2771}
2772
Harald Weltee13cfb22019-04-23 16:52:02 +02002773
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002774/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002775friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002776runs on BSC_ConnHdlr {
2777 var SmsParameters spars := valueof(t_SmsPars);
2778 var GSUP_PDU gsup_msg_rx;
2779
2780 f_init_handler(pars);
2781
2782 /* We need to inspect GSUP activity */
2783 f_create_gsup_expect(hex2str(g_pars.imsi));
2784
2785 /* Perform location update */
2786 f_perform_lu();
2787
2788 /* Send CM Service Request for SMS */
2789 f_establish_fully(EST_TYPE_MO_SMS);
2790
2791 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2792 imsi := g_pars.imsi,
2793 sm_rp_mr := spars.rp.msg_ref,
2794 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2795 );
2796
2797 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2798 f_mo_smma(spars);
2799 alt {
2800 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002801 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002802 setverdict(pass);
2803 }
2804 [] GSUP.receive {
2805 log("RX unexpected GSUP message");
2806 setverdict(fail);
2807 mtc.stop;
2808 }
2809 }
2810
2811 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2812 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2813 imsi := g_pars.imsi,
2814 sm_rp_mr := spars.rp.msg_ref)));
2815 /* Expect RP-ACK on DTAP */
2816 f_mo_sms_wait_rp_ack(spars);
2817
2818 f_expect_clear();
2819}
2820testcase TC_gsup_mo_smma() runs on MTC_CT {
2821 var BSC_ConnHdlr vc_conn;
2822 f_init();
2823 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2824 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2825 vc_conn.done;
2826 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2827}
2828
Harald Weltee13cfb22019-04-23 16:52:02 +02002829
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002830/* Helper for sending MT SMS over GSUP */
2831private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2832runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002833 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002834 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2835 number := spars.rp.smsc_addr.rP_NumberDigits,
2836 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2837 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2838 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002839
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002840 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2841 imsi := g_pars.imsi,
2842 /* NOTE: MSC should assign RP-MR itself */
2843 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002844 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002845 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002846 /* Encoded SMS TPDU (taken from Wireshark)
2847 * FIXME: we should encode spars somehow */
2848 sm_rp_ui := '00068021436500008111328130858200'O,
2849 sm_rp_mms := mms
2850 ));
2851}
2852
2853/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002854friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002855runs on BSC_ConnHdlr {
2856 var SmsParameters spars := valueof(t_SmsPars);
2857
2858 f_init_handler(pars);
2859
2860 /* We need to inspect GSUP activity */
2861 f_create_gsup_expect(hex2str(g_pars.imsi));
2862
2863 /* Perform location update */
2864 f_perform_lu();
2865
2866 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002867 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002868
2869 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2870 imsi := g_pars.imsi,
2871 /* NOTE: MSC should assign RP-MR itself */
2872 sm_rp_mr := ?
2873 );
2874
2875 /* Submit a MT SMS on GSUP */
2876 f_gsup_forwardSM_req(spars);
2877
2878 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002879 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002880 f_establish_fully(EST_TYPE_PAG_RESP);
2881
2882 /* Wait for MT SMS on DTAP */
2883 f_mt_sms_expect(spars);
2884
2885 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2886 f_mt_sms_send_rp_ack(spars);
2887 alt {
2888 [] GSUP.receive(mt_forwardSM_res) {
2889 log("RX MT-forwardSM-Res (RP-ACK)");
2890 setverdict(pass);
2891 }
2892 [] GSUP.receive {
2893 log("RX unexpected GSUP message");
2894 setverdict(fail);
2895 mtc.stop;
2896 }
2897 }
2898
2899 f_expect_clear();
2900}
2901testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2902 var BSC_ConnHdlrPars pars;
2903 var BSC_ConnHdlr vc_conn;
2904 f_init();
2905 pars := f_init_pars(90);
2906 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2907 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2908 vc_conn.done;
2909 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2910}
2911
Harald Weltee13cfb22019-04-23 16:52:02 +02002912
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002913/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002914friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002915runs on BSC_ConnHdlr {
2916 var SmsParameters spars := valueof(t_SmsPars);
2917 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2918
2919 f_init_handler(pars);
2920
2921 /* We need to inspect GSUP activity */
2922 f_create_gsup_expect(hex2str(g_pars.imsi));
2923
2924 /* Perform location update */
2925 f_perform_lu();
2926
2927 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002928 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002929
2930 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2931 imsi := g_pars.imsi,
2932 /* NOTE: MSC should assign RP-MR itself */
2933 sm_rp_mr := ?,
2934 sm_rp_cause := sm_rp_cause
2935 );
2936
2937 /* Submit a MT SMS on GSUP */
2938 f_gsup_forwardSM_req(spars);
2939
2940 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002941 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002942 f_establish_fully(EST_TYPE_PAG_RESP);
2943
2944 /* Wait for MT SMS on DTAP */
2945 f_mt_sms_expect(spars);
2946
2947 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2948 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2949 alt {
2950 [] GSUP.receive(mt_forwardSM_err) {
2951 log("RX MT-forwardSM-Err (RP-ERROR)");
2952 setverdict(pass);
2953 mtc.stop;
2954 }
2955 [] GSUP.receive {
2956 log("RX unexpected GSUP message");
2957 setverdict(fail);
2958 mtc.stop;
2959 }
2960 }
2961
2962 f_expect_clear();
2963}
2964testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2965 var BSC_ConnHdlrPars pars;
2966 var BSC_ConnHdlr vc_conn;
2967 f_init();
2968 pars := f_init_pars(91);
2969 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2970 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2971 vc_conn.done;
2972 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2973}
2974
Harald Weltee13cfb22019-04-23 16:52:02 +02002975
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002976/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002977friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002978runs on BSC_ConnHdlr {
2979 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2980 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2981
2982 f_init_handler(pars);
2983
2984 /* We need to inspect GSUP activity */
2985 f_create_gsup_expect(hex2str(g_pars.imsi));
2986
2987 /* Perform location update */
2988 f_perform_lu();
2989
2990 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002991 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002992
2993 /* Submit the 1st MT SMS on GSUP */
2994 log("TX MT-forwardSM-Req for the 1st SMS");
2995 f_gsup_forwardSM_req(spars1);
2996
2997 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002998 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002999 f_establish_fully(EST_TYPE_PAG_RESP);
3000
3001 /* Wait for 1st MT SMS on DTAP */
3002 f_mt_sms_expect(spars1);
3003 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
3004 ", SM-RP-MR is ", spars1.rp.msg_ref);
3005
3006 /* Submit the 2nd MT SMS on GSUP */
3007 log("TX MT-forwardSM-Req for the 2nd SMS");
3008 f_gsup_forwardSM_req(spars2);
3009
3010 /* Wait for 2nd MT SMS on DTAP */
3011 f_mt_sms_expect(spars2);
3012 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
3013 ", SM-RP-MR is ", spars2.rp.msg_ref);
3014
3015 /* Both transaction IDs shall be different */
3016 if (spars1.tid == spars2.tid) {
3017 log("Both DTAP transaction IDs shall be different");
3018 setverdict(fail);
3019 }
3020
3021 /* Both SM-RP-MR values shall be different */
3022 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
3023 log("Both SM-RP-MR values shall be different");
3024 setverdict(fail);
3025 }
3026
3027 /* Both SM-RP-MR values shall be assigned */
3028 if (spars1.rp.msg_ref == 'FF'O) {
3029 log("Unassigned SM-RP-MR value for the 1st SMS");
3030 setverdict(fail);
3031 }
3032 if (spars2.rp.msg_ref == 'FF'O) {
3033 log("Unassigned SM-RP-MR value for the 2nd SMS");
3034 setverdict(fail);
3035 }
3036
3037 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
3038 f_mt_sms_send_rp_ack(spars1);
3039 alt {
3040 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3041 imsi := g_pars.imsi,
3042 sm_rp_mr := spars1.rp.msg_ref
3043 )) {
3044 log("RX MT-forwardSM-Res (RP-ACK)");
3045 setverdict(pass);
3046 }
3047 [] GSUP.receive {
3048 log("RX unexpected GSUP message");
3049 setverdict(fail);
3050 mtc.stop;
3051 }
3052 }
3053
3054 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
3055 f_mt_sms_send_rp_ack(spars2);
3056 alt {
3057 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3058 imsi := g_pars.imsi,
3059 sm_rp_mr := spars2.rp.msg_ref
3060 )) {
3061 log("RX MT-forwardSM-Res (RP-ACK)");
3062 setverdict(pass);
3063 }
3064 [] GSUP.receive {
3065 log("RX unexpected GSUP message");
3066 setverdict(fail);
3067 mtc.stop;
3068 }
3069 }
3070
3071 f_expect_clear();
3072}
3073testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
3074 var BSC_ConnHdlrPars pars;
3075 var BSC_ConnHdlr vc_conn;
3076 f_init();
3077 pars := f_init_pars(92);
3078 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3079 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
3080 vc_conn.done;
3081 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3082}
3083
Harald Weltee13cfb22019-04-23 16:52:02 +02003084
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003085/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02003086friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003087runs on BSC_ConnHdlr {
3088 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
3089 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
3090
3091 f_init_handler(pars);
3092
3093 /* We need to inspect GSUP activity */
3094 f_create_gsup_expect(hex2str(g_pars.imsi));
3095
3096 /* Perform location update */
3097 f_perform_lu();
3098
3099 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003100 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003101
3102 /* Send CM Service Request for MO SMMA */
3103 f_establish_fully(EST_TYPE_MO_SMS);
3104
3105 /* Submit MO SMMA on DTAP */
3106 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
3107 spars_mo.rp.msg_ref := '00'O;
3108 f_mo_smma(spars_mo);
3109
3110 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
3111 alt {
3112 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
3113 imsi := g_pars.imsi,
3114 sm_rp_mr := spars_mo.rp.msg_ref,
3115 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
3116 )) {
3117 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
3118 setverdict(pass);
3119 }
3120 [] GSUP.receive {
3121 log("RX unexpected GSUP message");
3122 setverdict(fail);
3123 mtc.stop;
3124 }
3125 }
3126
3127 /* Submit MT SMS on GSUP */
3128 log("TX MT-forwardSM-Req for the MT SMS");
3129 f_gsup_forwardSM_req(spars_mt);
3130
3131 /* Wait for MT SMS on DTAP */
3132 f_mt_sms_expect(spars_mt);
3133 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
3134 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
3135
3136 /* Both SM-RP-MR values shall be different */
3137 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
3138 log("Both SM-RP-MR values shall be different");
3139 setverdict(fail);
3140 }
3141
3142 /* SM-RP-MR value for MT SMS shall be assigned */
3143 if (spars_mt.rp.msg_ref == 'FF'O) {
3144 log("Unassigned SM-RP-MR value for the MT SMS");
3145 setverdict(fail);
3146 }
3147
3148 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
3149 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
3150 imsi := g_pars.imsi,
3151 sm_rp_mr := spars_mo.rp.msg_ref)));
3152 /* Expect RP-ACK for MO SMMA on DTAP */
3153 f_mo_sms_wait_rp_ack(spars_mo);
3154
3155 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
3156 f_mt_sms_send_rp_ack(spars_mt);
3157 alt {
3158 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3159 imsi := g_pars.imsi,
3160 sm_rp_mr := spars_mt.rp.msg_ref
3161 )) {
3162 log("RX MT-forwardSM-Res (RP-ACK)");
3163 setverdict(pass);
3164 }
3165 [] GSUP.receive {
3166 log("RX unexpected GSUP message");
3167 setverdict(fail);
3168 mtc.stop;
3169 }
3170 }
3171
3172 f_expect_clear();
3173}
3174testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
3175 var BSC_ConnHdlrPars pars;
3176 var BSC_ConnHdlr vc_conn;
3177 f_init();
3178 pars := f_init_pars(93);
3179 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3180 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
3181 vc_conn.done;
3182 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3183}
3184
Harald Weltee13cfb22019-04-23 16:52:02 +02003185
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003186/* Test multi-part MT-SMS over GSUP */
3187private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
3188runs on BSC_ConnHdlr {
3189 var SmsParameters spars := valueof(t_SmsPars);
3190
3191 f_init_handler(pars);
3192
3193 /* We need to inspect GSUP activity */
3194 f_create_gsup_expect(hex2str(g_pars.imsi));
3195
3196 /* Perform location update */
3197 f_perform_lu();
3198
3199 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003200 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003201
3202 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
3203 imsi := g_pars.imsi,
3204 /* NOTE: MSC should assign RP-MR itself */
3205 sm_rp_mr := ?
3206 );
3207
3208 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
3209 for (var integer i := 3; i >= 0; i := i-1) {
3210 /* Submit a MT SMS on GSUP (MMS is decremented) */
3211 f_gsup_forwardSM_req(spars, int2oct(i, 1));
3212
3213 /* Expect Paging Request and Establish connection */
3214 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02003215 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003216 f_establish_fully(EST_TYPE_PAG_RESP);
3217 }
3218
3219 /* Wait for MT SMS on DTAP */
3220 f_mt_sms_expect(spars);
3221
3222 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
3223 f_mt_sms_send_rp_ack(spars);
3224 alt {
3225 [] GSUP.receive(mt_forwardSM_res) {
3226 log("RX MT-forwardSM-Res (RP-ACK)");
3227 setverdict(pass);
3228 }
3229 [] GSUP.receive {
3230 log("RX unexpected GSUP message");
3231 setverdict(fail);
3232 mtc.stop;
3233 }
3234 }
3235
3236 /* Keep some 'distance' between transmissions */
3237 f_sleep(1.5);
3238 }
3239
3240 f_expect_clear();
3241}
3242testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
3243 var BSC_ConnHdlrPars pars;
3244 var BSC_ConnHdlr vc_conn;
3245 f_init();
3246 pars := f_init_pars(91);
3247 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3248 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
3249 vc_conn.done;
3250 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3251}
3252
Harald Weltef640a012018-04-14 17:49:21 +02003253/* convert GSM L3 TON to SMPP_TON enum */
3254function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
3255 select (ton) {
3256 case ('000'B) { return unknown; }
3257 case ('001'B) { return international; }
3258 case ('010'B) { return national; }
3259 case ('011'B) { return network_specific; }
3260 case ('100'B) { return subscriber_number; }
3261 case ('101'B) { return alphanumeric; }
3262 case ('110'B) { return abbreviated; }
3263 }
3264 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02003265 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003266}
3267/* convert GSM L3 NPI to SMPP_NPI enum */
3268function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
3269 select (npi) {
3270 case ('0000'B) { return unknown; }
3271 case ('0001'B) { return isdn; }
3272 case ('0011'B) { return data; }
3273 case ('0100'B) { return telex; }
3274 case ('0110'B) { return land_mobile; }
3275 case ('1000'B) { return national; }
3276 case ('1001'B) { return private_; }
3277 case ('1010'B) { return ermes; }
3278 }
3279 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02003280 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003281}
3282
3283/* build a SMPP_SM from SmsParameters */
3284function f_mt_sm_from_spars(SmsParameters spars)
3285runs on BSC_ConnHdlr return SMPP_SM {
3286 var SMPP_SM sm := {
3287 service_type := "CMT",
3288 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
3289 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
3290 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
3291 dest_addr_ton := international,
3292 dest_addr_npi := isdn,
3293 destination_addr := hex2str(g_pars.msisdn),
3294 esm_class := '00000001'B,
3295 protocol_id := 0,
3296 priority_flag := 0,
3297 schedule_delivery_time := "",
3298 validity_period := "",
3299 registered_delivery := '00000000'B,
3300 replace_if_present := 0,
3301 data_coding := '00000001'B,
3302 sm_default_msg_id := 0,
3303 sm_length := spars.tp.udl,
3304 short_message := spars.tp.ud,
3305 opt_pars := {}
3306 };
3307 return sm;
3308}
3309
3310/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
3311private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
3312 var SMPP_SM sm := f_mt_sm_from_spars(spars);
3313 if (trans_mode) {
3314 sm.esm_class := '00000010'B;
3315 }
3316
3317 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
3318 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
3319 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3320 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
3321 * before we expect the SMS delivery on the BSC/radio side */
3322 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3323 }
3324
3325 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02003326 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02003327 /* Establish DTAP / BSSAP / SCCP connection */
3328 f_establish_fully(EST_TYPE_PAG_RESP);
3329 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3330
3331 f_mt_sms(spars);
3332
3333 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3334 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3335 }
3336 f_expect_clear();
3337}
3338
3339/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
3340private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3341 f_init_handler(pars);
3342
3343 /* Perform location update so IMSI is known + registered in MSC/VLR */
3344 f_perform_lu();
3345 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3346
3347 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003348 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02003349
3350 var SmsParameters spars := valueof(t_SmsPars);
3351 /* TODO: test with more intelligent user data; test different coding schemes */
3352 spars.tp.ud := '00'O;
3353 spars.tp.udl := 1;
3354
3355 /* first test the non-transaction store+forward mode */
3356 f_smpp_mt_sms(spars, false);
3357
3358 /* then test the transaction mode */
3359 f_smpp_mt_sms(spars, true);
3360}
3361testcase TC_smpp_mt_sms() runs on MTC_CT {
3362 var BSC_ConnHdlr vc_conn;
3363 f_init();
3364 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
3365 vc_conn.done;
3366}
3367
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003368/***********************************************************************
3369 * USSD Testing
3370 ***********************************************************************/
3371
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003372private altstep as_unexp_gsup_or_bssap_msg()
3373runs on BSC_ConnHdlr {
3374 [] GSUP.receive {
3375 setverdict(fail, "Unknown/unexpected GSUP received");
3376 self.stop;
3377 }
3378 [] BSSAP.receive {
3379 setverdict(fail, "Unknown/unexpected BSSAP message received");
3380 self.stop;
3381 }
3382}
3383
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003384private function f_expect_gsup_msg(template GSUP_PDU msg,
3385 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003386runs on BSC_ConnHdlr return GSUP_PDU {
3387 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003388 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003389
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003390 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003391 alt {
3392 [] GSUP.receive(msg) -> value gsup_msg_complete {
3393 setverdict(pass);
3394 }
3395 /* We don't expect anything else */
3396 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003397 [] T.timeout {
3398 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3399 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003400 }
3401
3402 return gsup_msg_complete;
3403}
3404
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003405private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3406 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003407runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3408 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003409 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003410
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003411 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003412 alt {
3413 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3414 setverdict(pass);
3415 }
3416 /* We don't expect anything else */
3417 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003418 [] T.timeout {
3419 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3420 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003421 }
3422
3423 return bssap_msg_complete.dtap;
3424}
3425
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003426/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003427friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003428runs on BSC_ConnHdlr {
3429 f_init_handler(pars);
3430
3431 /* Perform location update */
3432 f_perform_lu();
3433
3434 /* Send CM Service Request for SS/USSD */
3435 f_establish_fully(EST_TYPE_SS_ACT);
3436
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003437 /* We need to inspect GSUP activity */
3438 f_create_gsup_expect(hex2str(g_pars.imsi));
3439
3440 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3441 invoke_id := 5, /* Phone may not start from 0 or 1 */
3442 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3443 ussd_string := "*#100#"
3444 );
3445
3446 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3447 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3448 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3449 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3450 )
3451
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003452 /* Compose a new SS/REGISTER message with request */
3453 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3454 tid := 1, /* We just need a single transaction */
3455 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003456 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003457 );
3458
3459 /* Compose SS/RELEASE_COMPLETE template with expected response */
3460 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3461 tid := 1, /* Response should arrive within the same transaction */
3462 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003463 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003464 );
3465
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003466 /* Compose expected MSC -> HLR message */
3467 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3468 imsi := g_pars.imsi,
3469 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3470 ss := valueof(facility_req)
3471 );
3472
3473 /* To be used for sending response with correct session ID */
3474 var GSUP_PDU gsup_req_complete;
3475
3476 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003477 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003478 /* Expect GSUP message containing the SS payload */
3479 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3480
3481 /* Compose the response from HLR using received session ID */
3482 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3483 imsi := g_pars.imsi,
3484 sid := gsup_req_complete.ies[1].val.session_id,
3485 state := OSMO_GSUP_SESSION_STATE_END,
3486 ss := valueof(facility_rsp)
3487 );
3488
3489 /* Finally, HLR terminates the session */
3490 GSUP.send(gsup_rsp);
3491 /* Expect RELEASE_COMPLETE message with the response */
3492 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003493
3494 f_expect_clear();
3495}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003496testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003497 var BSC_ConnHdlr vc_conn;
3498 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003499 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003500 vc_conn.done;
3501}
3502
Harald Weltee13cfb22019-04-23 16:52:02 +02003503
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003504/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003505friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003506runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003507 timer T := 5.0;
3508
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003509 f_init_handler(pars);
3510
3511 /* Perform location update */
3512 f_perform_lu();
3513
Harald Welte6811d102019-04-14 22:23:14 +02003514 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003515
3516 /* We need to inspect GSUP activity */
3517 f_create_gsup_expect(hex2str(g_pars.imsi));
3518
3519 /* Facility IE with network-originated USSD notification */
3520 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3521 op_code := SS_OP_CODE_USS_NOTIFY,
3522 ussd_string := "Mahlzeit!"
3523 );
3524
3525 /* Facility IE with acknowledgment to the USSD notification */
3526 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3527 /* In case of USSD notification, Return Result is empty */
3528 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3529 );
3530
3531 /* Compose a new MT SS/REGISTER message with USSD notification */
3532 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3533 tid := 0, /* FIXME: most likely, it should be 0 */
3534 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3535 facility := valueof(facility_req)
3536 );
3537
3538 /* Compose HLR -> MSC GSUP message */
3539 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3540 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003541 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003542 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3543 ss := valueof(facility_req)
3544 );
3545
3546 /* Send it to MSC and expect Paging Request */
3547 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003548 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003549 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003550 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3551 setverdict(pass);
3552 }
Harald Welte62113fc2019-05-09 13:04:02 +02003553 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003554 setverdict(pass);
3555 }
3556 /* We don't expect anything else */
3557 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003558 [] T.timeout {
3559 setverdict(fail, "Timeout waiting for Paging Request");
3560 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003561 }
3562
3563 /* Send Paging Response and expect USSD notification */
3564 f_establish_fully(EST_TYPE_PAG_RESP);
3565 /* Expect MT REGISTER message with USSD notification */
3566 f_expect_mt_dtap_msg(ussd_ntf);
3567
3568 /* Compose a new MO SS/FACILITY message with empty response */
3569 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3570 tid := 0, /* FIXME: it shall match the request tid */
3571 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3572 facility := valueof(facility_rsp)
3573 );
3574
3575 /* Compose expected MSC -> HLR GSUP message */
3576 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3577 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003578 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003579 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3580 ss := valueof(facility_rsp)
3581 );
3582
3583 /* MS sends response to the notification */
3584 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3585 /* Expect GSUP message containing the SS payload */
3586 f_expect_gsup_msg(gsup_rsp);
3587
3588 /* Compose expected MT SS/RELEASE COMPLETE message */
3589 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3590 tid := 0, /* FIXME: it shall match the request tid */
3591 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3592 facility := omit
3593 );
3594
3595 /* Compose MSC -> HLR GSUP message */
3596 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3597 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003598 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003599 state := OSMO_GSUP_SESSION_STATE_END
3600 );
3601
3602 /* Finally, HLR terminates the session */
3603 GSUP.send(gsup_term)
3604 /* Expect MT RELEASE COMPLETE without Facility IE */
3605 f_expect_mt_dtap_msg(ussd_term);
3606
3607 f_expect_clear();
3608}
3609testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3610 var BSC_ConnHdlr vc_conn;
3611 f_init();
3612 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3613 vc_conn.done;
3614}
3615
Harald Weltee13cfb22019-04-23 16:52:02 +02003616
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003617/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003618friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003619runs on BSC_ConnHdlr {
3620 f_init_handler(pars);
3621
3622 /* Call parameters taken from f_tc_lu_and_mt_call */
3623 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003624
3625 /* Perform location update */
3626 f_perform_lu();
3627
3628 /* Establish a MT call */
3629 f_mt_call_establish(cpars);
3630
3631 /* Hold the call for some time */
3632 f_sleep(1.0);
3633
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003634 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3635 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3636 ussd_string := "*#100#"
3637 );
3638
3639 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3640 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3641 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3642 )
3643
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003644 /* Compose a new SS/REGISTER message with request */
3645 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3646 tid := 1, /* We just need a single transaction */
3647 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003648 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003649 );
3650
3651 /* Compose SS/RELEASE_COMPLETE template with expected response */
3652 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3653 tid := 1, /* Response should arrive within the same transaction */
3654 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003655 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003656 );
3657
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003658 /* Compose expected MSC -> HLR message */
3659 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3660 imsi := g_pars.imsi,
3661 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3662 ss := valueof(facility_req)
3663 );
3664
3665 /* To be used for sending response with correct session ID */
3666 var GSUP_PDU gsup_req_complete;
3667
3668 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003669 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003670 /* Expect GSUP message containing the SS payload */
3671 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3672
3673 /* Compose the response from HLR using received session ID */
3674 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3675 imsi := g_pars.imsi,
3676 sid := gsup_req_complete.ies[1].val.session_id,
3677 state := OSMO_GSUP_SESSION_STATE_END,
3678 ss := valueof(facility_rsp)
3679 );
3680
3681 /* Finally, HLR terminates the session */
3682 GSUP.send(gsup_rsp);
3683 /* Expect RELEASE_COMPLETE message with the response */
3684 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003685
3686 /* Hold the call for some time */
3687 f_sleep(1.0);
3688
3689 /* Release the call (does Clear Complete itself) */
3690 f_call_hangup(cpars, true);
3691}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003692testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003693 var BSC_ConnHdlr vc_conn;
3694 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003695 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003696 vc_conn.done;
3697}
3698
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003699/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003700friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003701 f_init_handler(pars);
3702 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003703 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003704
3705 f_perform_lu();
3706
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003707 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003708 f_mo_call_establish(cpars);
3709 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003710 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003711
3712 f_sleep(1.0);
3713}
3714testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3715 var BSC_ConnHdlr vc_conn;
3716 f_init();
3717
3718 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3719 vc_conn.done;
3720}
3721
Harald Weltee13cfb22019-04-23 16:52:02 +02003722
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003723/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003724friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003725runs on BSC_ConnHdlr {
3726 f_init_handler(pars);
3727
3728 /* Call parameters taken from f_tc_lu_and_mt_call */
3729 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003730
3731 /* Perform location update */
3732 f_perform_lu();
3733
3734 /* Establish a MT call */
3735 f_mt_call_establish(cpars);
3736
3737 /* Hold the call for some time */
3738 f_sleep(1.0);
3739
3740 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3741 op_code := SS_OP_CODE_USS_REQUEST,
3742 ussd_string := "Please type anything..."
3743 );
3744
3745 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3746 op_code := SS_OP_CODE_USS_REQUEST,
3747 ussd_string := "Nope."
3748 )
3749
3750 /* Compose MT SS/REGISTER message with network-originated request */
3751 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3752 tid := 0, /* FIXME: most likely, it should be 0 */
3753 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3754 facility := valueof(facility_req)
3755 );
3756
3757 /* Compose HLR -> MSC GSUP message */
3758 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3759 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003760 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003761 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3762 ss := valueof(facility_req)
3763 );
3764
3765 /* Send it to MSC */
3766 GSUP.send(gsup_req);
3767 /* Expect MT REGISTER message with USSD request */
3768 f_expect_mt_dtap_msg(ussd_req);
3769
3770 /* Compose a new MO SS/FACILITY message with response */
3771 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3772 tid := 0, /* FIXME: it shall match the request tid */
3773 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3774 facility := valueof(facility_rsp)
3775 );
3776
3777 /* Compose expected MSC -> HLR GSUP message */
3778 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3779 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003780 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003781 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3782 ss := valueof(facility_rsp)
3783 );
3784
3785 /* MS sends response */
3786 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3787 f_expect_gsup_msg(gsup_rsp);
3788
3789 /* Compose expected MT SS/RELEASE COMPLETE message */
3790 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3791 tid := 0, /* FIXME: it shall match the request tid */
3792 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3793 facility := omit
3794 );
3795
3796 /* Compose MSC -> HLR GSUP message */
3797 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3798 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003799 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003800 state := OSMO_GSUP_SESSION_STATE_END
3801 );
3802
3803 /* Finally, HLR terminates the session */
3804 GSUP.send(gsup_term);
3805 /* Expect MT RELEASE COMPLETE without Facility IE */
3806 f_expect_mt_dtap_msg(ussd_term);
3807
3808 /* Hold the call for some time */
3809 f_sleep(1.0);
3810
3811 /* Release the call (does Clear Complete itself) */
3812 f_call_hangup(cpars, true);
3813}
3814testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3815 var BSC_ConnHdlr vc_conn;
3816 f_init();
3817 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3818 vc_conn.done;
3819}
3820
Harald Weltee13cfb22019-04-23 16:52:02 +02003821
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003822/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003823friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003824runs on BSC_ConnHdlr {
3825 f_init_handler(pars);
3826
3827 /* Perform location update */
3828 f_perform_lu();
3829
3830 /* Send CM Service Request for SS/USSD */
3831 f_establish_fully(EST_TYPE_SS_ACT);
3832
3833 /* We need to inspect GSUP activity */
3834 f_create_gsup_expect(hex2str(g_pars.imsi));
3835
3836 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3837 invoke_id := 1, /* Initial request */
3838 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3839 ussd_string := "*6766*266#"
3840 );
3841
3842 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3843 invoke_id := 2, /* Counter request */
3844 op_code := SS_OP_CODE_USS_REQUEST,
3845 ussd_string := "Password?!?"
3846 )
3847
3848 /* Compose MO SS/REGISTER message with request */
3849 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3850 tid := 1, /* We just need a single transaction */
3851 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3852 facility := valueof(facility_ms_req)
3853 );
3854
3855 /* Compose expected MSC -> HLR message */
3856 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3857 imsi := g_pars.imsi,
3858 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3859 ss := valueof(facility_ms_req)
3860 );
3861
3862 /* To be used for sending response with correct session ID */
3863 var GSUP_PDU gsup_ms_req_complete;
3864
3865 /* Initiate a new transaction */
3866 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3867 /* Expect GSUP request with original Facility IE */
3868 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3869
3870 /* Compose the response from HLR using received session ID */
3871 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3872 imsi := g_pars.imsi,
3873 sid := gsup_ms_req_complete.ies[1].val.session_id,
3874 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3875 ss := valueof(facility_net_req)
3876 );
3877
3878 /* Compose expected MT SS/FACILITY template with counter request */
3879 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3880 tid := 1, /* Response should arrive within the same transaction */
3881 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3882 facility := valueof(facility_net_req)
3883 );
3884
3885 /* Send response over GSUP */
3886 GSUP.send(gsup_net_req);
3887 /* Expect MT SS/FACILITY message with counter request */
3888 f_expect_mt_dtap_msg(ussd_net_req);
3889
3890 /* Compose MO SS/RELEASE COMPLETE */
3891 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3892 tid := 1, /* Response should arrive within the same transaction */
3893 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3894 facility := omit
3895 /* TODO: cause? */
3896 );
3897
3898 /* Compose expected HLR -> MSC abort message */
3899 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3900 imsi := g_pars.imsi,
3901 sid := gsup_ms_req_complete.ies[1].val.session_id,
3902 state := OSMO_GSUP_SESSION_STATE_END
3903 );
3904
3905 /* Abort transaction */
3906 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3907 /* Expect GSUP message indicating abort */
3908 f_expect_gsup_msg(gsup_abort);
3909
3910 f_expect_clear();
3911}
3912testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3913 var BSC_ConnHdlr vc_conn;
3914 f_init();
3915 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3916 vc_conn.done;
3917}
3918
Harald Weltee13cfb22019-04-23 16:52:02 +02003919
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003920/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003921friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003922runs on BSC_ConnHdlr {
3923 f_init_handler(pars);
3924
3925 /* Perform location update */
3926 f_perform_lu();
3927
3928 /* Send CM Service Request for SS/USSD */
3929 f_establish_fully(EST_TYPE_SS_ACT);
3930
3931 /* We need to inspect GSUP activity */
3932 f_create_gsup_expect(hex2str(g_pars.imsi));
3933
3934 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3935 invoke_id := 1,
3936 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3937 ussd_string := "#release_me");
3938
3939 /* Compose MO SS/REGISTER message with request */
3940 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3941 tid := 1, /* An arbitrary transaction identifier */
3942 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3943 facility := valueof(facility_ms_req));
3944
3945 /* Compose expected MSC -> HLR message */
3946 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3947 imsi := g_pars.imsi,
3948 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3949 ss := valueof(facility_ms_req));
3950
3951 /* To be used for sending response with correct session ID */
3952 var GSUP_PDU gsup_ms_req_complete;
3953
3954 /* Initiate a new SS transaction */
3955 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3956 /* Expect GSUP request with original Facility IE */
3957 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3958
3959 /* Don't respond, wait for timeout */
3960 f_sleep(3.0);
3961
3962 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3963 tid := 1, /* Should match the request's tid */
3964 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3965 cause := *, /* TODO: expect some specific value */
3966 facility := omit);
3967
3968 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3969 imsi := g_pars.imsi,
3970 sid := gsup_ms_req_complete.ies[1].val.session_id,
3971 state := OSMO_GSUP_SESSION_STATE_END,
3972 cause := ?); /* TODO: expect some specific value */
3973
3974 /* Expect release on both interfaces */
3975 interleave {
3976 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3977 [] GSUP.receive(gsup_rel) { };
3978 }
3979
3980 f_expect_clear();
3981 setverdict(pass);
3982}
3983testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3984 var BSC_ConnHdlr vc_conn;
3985 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003986 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003987 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3988 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003989 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003990}
3991
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003992/* MT (network-originated) USSD for unknown subscriber */
3993friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
3994runs on BSC_ConnHdlr {
3995 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
3996 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003997
3998 f_init_handler(pars);
3999 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
4000 f_create_gsup_expect(hex2str(imsi));
4001
4002 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4003 imsi := imsi,
4004 sid := sid,
4005 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4006 ss := f_rnd_octstring(23)
4007 );
4008
4009 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
4010 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4011 imsi := imsi,
4012 sid := sid,
4013 state := OSMO_GSUP_SESSION_STATE_END,
4014 cause := 2 /* FIXME: introduce an enumerated type! */
4015 );
4016
4017 /* Initiate a MT USSD notification */
4018 GSUP.send(gsup_req);
4019
4020 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07004021 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004022}
4023testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
4024 var BSC_ConnHdlr vc_conn;
4025 f_init();
4026 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
4027 vc_conn.done;
4028}
4029
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07004030/* MO (mobile-originated) SS/USSD for unknown transaction */
4031friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
4032runs on BSC_ConnHdlr {
4033 f_init_handler(pars);
4034
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004035 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07004036 f_create_gsup_expect(hex2str(g_pars.imsi));
4037
4038 /* Perform location update */
4039 f_perform_lu();
4040
4041 /* Send CM Service Request for SS/USSD */
4042 f_establish_fully(EST_TYPE_SS_ACT);
4043
4044 /* GSM 04.80 FACILITY message for a non-existing transaction */
4045 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
4046 tid := 1, /* An arbitrary transaction identifier */
4047 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4048 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
4049 );
4050
4051 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
4052 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
4053 tid := 1, /* An arbitrary transaction identifier */
4054 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4055 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
4056 );
4057
4058 /* Expected response from the network */
4059 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4060 tid := 1, /* Same as in the FACILITY message */
4061 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
4062 facility := omit
4063 );
4064
4065 /* Send GSM 04.80 FACILITY for non-existing transaction */
4066 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
4067
4068 /* Expect GSM 04.80 RELEASE COMPLETE message */
4069 f_expect_mt_dtap_msg(mt_ss_rel);
4070 f_expect_clear();
4071
4072 /* Send another CM Service Request for SS/USSD */
4073 f_establish_fully(EST_TYPE_SS_ACT);
4074
4075 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
4076 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
4077
4078 /* Expect GSM 04.80 RELEASE COMPLETE message */
4079 f_expect_mt_dtap_msg(mt_ss_rel);
4080 f_expect_clear();
4081}
4082testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
4083 var BSC_ConnHdlr vc_conn;
4084 f_init();
4085 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
4086 vc_conn.done;
4087}
4088
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004089/* MT (network-originated) USSD for unknown session */
4090friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
4091runs on BSC_ConnHdlr {
4092 var OCT4 sid := '20000333'O;
4093
4094 f_init_handler(pars);
4095
4096 /* Perform location update */
4097 f_perform_lu();
4098
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004099 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004100 f_create_gsup_expect(hex2str(g_pars.imsi));
4101
4102 /* Request referencing a non-existing SS session */
4103 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4104 imsi := g_pars.imsi,
4105 sid := sid,
4106 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
4107 ss := f_rnd_octstring(23)
4108 );
4109
4110 /* Error with some cause value */
4111 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4112 imsi := g_pars.imsi,
4113 sid := sid,
4114 state := OSMO_GSUP_SESSION_STATE_END,
4115 cause := ? /* FIXME: introduce an enumerated type! */
4116 );
4117
4118 /* Initiate a MT USSD notification */
4119 GSUP.send(gsup_req);
4120
4121 /* Expect GSUP PROC_SS_ERROR message */
4122 f_expect_gsup_msg(gsup_rsp);
4123}
4124testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
4125 var BSC_ConnHdlr vc_conn;
4126 f_init();
4127 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
4128 vc_conn.done;
4129}
4130
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004131/* MT (network-originated) USSD and no response to Paging Request */
4132friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
4133runs on BSC_ConnHdlr {
4134 timer TP := 2.0; /* Paging timer */
4135
4136 f_init_handler(pars);
4137
4138 /* Perform location update */
4139 f_perform_lu();
4140
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004141 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004142 f_create_gsup_expect(hex2str(g_pars.imsi));
4143
4144 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4145 imsi := g_pars.imsi,
4146 sid := '20000444'O,
4147 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4148 ss := f_rnd_octstring(23)
4149 );
4150
4151 /* Error with some cause value */
4152 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4153 imsi := g_pars.imsi,
4154 sid := '20000444'O,
4155 state := OSMO_GSUP_SESSION_STATE_END,
4156 cause := ? /* FIXME: introduce an enumerated type! */
4157 );
4158
4159 /* Initiate a MT USSD notification */
4160 GSUP.send(gsup_req);
4161
4162 /* Send it to MSC and expect Paging Request */
4163 TP.start;
4164 alt {
4165 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4166 setverdict(pass);
4167 }
4168 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4169 setverdict(pass);
4170 }
4171 /* We don't expect anything else */
4172 [] as_unexp_gsup_or_bssap_msg();
4173 [] TP.timeout {
4174 setverdict(fail, "Timeout waiting for Paging Request");
4175 }
4176 }
4177
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07004178 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
4179 * OsmoMSC waits for Paging Response 10 seconds by default. */
4180 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004181}
4182testcase TC_proc_ss_paging_fail() runs on MTC_CT {
4183 var BSC_ConnHdlr vc_conn;
4184 f_init();
4185 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
4186 vc_conn.done;
4187}
4188
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004189/* MT (network-originated) USSD followed by immediate abort */
4190friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
4191runs on BSC_ConnHdlr {
4192 var octetstring facility := f_rnd_octstring(23);
4193 var OCT4 sid := '20000555'O;
4194 timer TP := 2.0;
4195
4196 f_init_handler(pars);
4197
4198 /* Perform location update */
4199 f_perform_lu();
4200
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004201 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004202 f_create_gsup_expect(hex2str(g_pars.imsi));
4203
4204 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
4205 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4206 imsi := g_pars.imsi, sid := sid,
4207 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4208 ss := facility
4209 );
4210
4211 /* On the MS side, we expect GSM 04.80 REGISTER message */
4212 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
4213 tid := 0, /* Most likely, it should be 0 */
4214 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4215 facility := facility
4216 );
4217
4218 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
4219 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
4220 imsi := g_pars.imsi, sid := sid,
4221 state := OSMO_GSUP_SESSION_STATE_END,
4222 cause := 0 /* FIXME: introduce an enumerated type! */
4223 );
4224
4225 /* On the MS side, we expect GSM 04.80 REGISTER message */
4226 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4227 tid := 0, /* Most likely, it should be 0 */
4228 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4229 cause := *, /* FIXME: expect some specific cause value */
4230 facility := omit
4231 );
4232
4233 /* Initiate a MT USSD with random payload */
4234 GSUP.send(gsup_req);
4235
4236 /* Expect Paging Request */
4237 TP.start;
4238 alt {
4239 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4240 setverdict(pass);
4241 }
4242 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4243 setverdict(pass);
4244 }
4245 /* We don't expect anything else */
4246 [] as_unexp_gsup_or_bssap_msg();
4247 [] TP.timeout {
4248 setverdict(fail, "Timeout waiting for Paging Request");
4249 }
4250 }
4251
4252 /* Send Paging Response and establish connection */
4253 f_establish_fully(EST_TYPE_PAG_RESP);
4254 /* Expect MT REGISTER message with random facility */
4255 f_expect_mt_dtap_msg(dtap_reg);
4256
4257 /* HLR/EUSE decides to abort the session even
4258 * before getting any response from the MS */
4259 /* Initiate a MT USSD with random payload */
4260 GSUP.send(gsup_abort);
4261
4262 /* Expect RELEASE COMPLETE on ths MS side */
4263 f_expect_mt_dtap_msg(dtap_rel);
4264
4265 f_expect_clear();
4266}
4267testcase TC_proc_ss_abort() runs on MTC_CT {
4268 var BSC_ConnHdlr vc_conn;
4269 f_init();
4270 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
4271 vc_conn.done;
4272}
4273
Harald Weltee13cfb22019-04-23 16:52:02 +02004274
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01004275/* Verify multiple concurrent MO SS/USSD transactions
4276 * (one subscriber - one transaction) */
4277testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
4278 var BSC_ConnHdlr vc_conn[16];
4279 var integer i;
4280
4281 f_init();
4282
4283 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4284 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
4285 }
4286
4287 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4288 vc_conn[i].done;
4289 }
4290}
4291
4292/* Verify multiple concurrent MT SS/USSD transactions
4293 * (one subscriber - one transaction) */
4294testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
4295 var BSC_ConnHdlr vc_conn[16];
4296 var integer i;
4297 var OCT4 sid;
4298
4299 f_init();
4300
4301 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4302 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
4303 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
4304 f_init_pars(226 + i, gsup_sid := sid));
4305 }
4306
4307 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4308 vc_conn[i].done;
4309 }
4310}
4311
4312
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004313/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
4314private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4315 pars.net.expect_auth := true;
4316 pars.net.expect_ciph := true;
4317 pars.net.kc_support := '02'O; /* A5/1 only */
4318 f_init_handler(pars);
4319
4320 g_pars.vec := f_gen_auth_vec_2g();
4321
4322 /* Can't use f_perform_lu() directly. Code below is based on it. */
4323
4324 /* tell GSUP dispatcher to send this IMSI to us */
4325 f_create_gsup_expect(hex2str(g_pars.imsi));
4326
4327 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4328 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02004329 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004330
4331 f_mm_auth();
4332
4333 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4334 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4335 alt {
4336 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4337 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
4338 }
4339 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4340 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4341 mtc.stop;
4342 }
4343 [] BSSAP.receive {
4344 setverdict(fail, "Unknown/unexpected BSSAP received");
4345 mtc.stop;
4346 }
4347 }
Harald Welte79f1e452020-08-18 22:55:02 +02004348 f_expect_common_id();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004349
4350 /* Expect LU reject from MSC. */
4351 alt {
4352 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4353 setverdict(pass);
4354 }
4355 [] BSSAP.receive {
4356 setverdict(fail, "Unknown/unexpected BSSAP received");
4357 mtc.stop;
4358 }
4359 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01004360 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004361}
4362
4363testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
4364 var BSC_ConnHdlr vc_conn;
4365 f_init();
4366 f_vty_config(MSCVTY, "network", "encryption a5 1");
4367
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02004368 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52, verify_cell_id := false);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004369 vc_conn.done;
4370}
4371
Harald Welteb2284bd2019-05-10 11:30:43 +02004372/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
4373friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4374 f_init_handler(pars);
4375
4376 /* tell GSUP dispatcher to send this IMSI to us */
4377 f_create_gsup_expect(hex2str(g_pars.imsi));
4378
4379 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4380 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4381
4382 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4383 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4384 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +02004385 f_expect_common_id();
Harald Welteb2284bd2019-05-10 11:30:43 +02004386
4387 /* Expect LU reject from MSC. */
4388 alt {
4389 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4390 setverdict(pass);
4391 }
4392 [] BSSAP.receive {
4393 setverdict(fail, "Unknown/unexpected BSSAP received");
4394 mtc.stop;
4395 }
4396 }
4397 f_expect_clear();
4398}
4399testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4400 var BSC_ConnHdlr vc_conn;
4401 f_init();
4402 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4403 vc_conn.done;
4404}
4405
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004406private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4407 pars.net.expect_auth := true;
4408 pars.net.expect_ciph := true;
4409 pars.net.kc_support := kc_support;
4410 f_init_handler(pars);
4411
4412 g_pars.vec := f_gen_auth_vec_2g();
4413
4414 /* Can't use f_perform_lu() directly. Code below is based on it. */
4415
4416 /* tell GSUP dispatcher to send this IMSI to us */
4417 f_create_gsup_expect(hex2str(g_pars.imsi));
4418
4419 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4420 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4421 f_cl3_or_initial_ue(l3_lu);
4422
4423 f_mm_auth();
4424
4425 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4426 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4427 alt {
4428 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4429 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4430 }
4431 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4432 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4433 repeat;
4434 }
4435 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4436 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4437 mtc.stop;
4438 }
4439 [] BSSAP.receive {
4440 setverdict(fail, "Unknown/unexpected BSSAP received");
4441 mtc.stop;
4442 }
4443 }
Harald Welte79f1e452020-08-18 22:55:02 +02004444 f_expect_common_id();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004445
4446 /* TODO: Verify MSC is using the best cipher available! How? */
4447
4448 f_msc_lu_hlr();
4449 f_accept_reject_lu();
4450 f_expect_clear();
4451 setverdict(pass);
4452}
4453
4454/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4455private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4456 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4457}
4458
4459/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4460private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4461 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4462}
4463
4464/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4465private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4466 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4467}
4468
4469testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4470 var BSC_ConnHdlr vc_conn;
4471 f_init();
4472 f_vty_config(MSCVTY, "network", "encryption a5 1");
4473
4474 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4475 vc_conn.done;
4476}
4477
4478testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4479 var BSC_ConnHdlr vc_conn;
4480 f_init();
4481 f_vty_config(MSCVTY, "network", "encryption a5 3");
4482
4483 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4484 vc_conn.done;
4485}
4486
4487testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4488 var BSC_ConnHdlr vc_conn;
4489 f_init();
4490 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4491
4492 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4493 vc_conn.done;
4494}
Harald Welteb2284bd2019-05-10 11:30:43 +02004495
Harald Weltef640a012018-04-14 17:49:21 +02004496/* TODO (SMS):
4497 * different user data lengths
4498 * SMPP transaction mode with unsuccessful delivery
4499 * queued MT-SMS with no paging response + later delivery
4500 * different data coding schemes
4501 * multi-part SMS
4502 * user-data headers
4503 * TP-PID for SMS to SIM
4504 * behavior if SMS memory is full + RP-SMMA
4505 * delivery reports
4506 * SMPP osmocom extensions
4507 * more-messages-to-send
4508 * SMS during ongoing call (SACCH/SAPI3)
4509 */
4510
4511/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004512 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4513 * malformed messages (missing IE, invalid message type): properly rejected?
4514 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4515 * 3G/2G auth permutations
4516 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004517 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004518 * too long L3 INFO in DTAP
4519 * too long / padded BSSAP
4520 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004521 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004522
Harald Weltee13cfb22019-04-23 16:52:02 +02004523/***********************************************************************
4524 * SGsAP Testing
4525 ***********************************************************************/
4526
Philipp Maier948747b2019-04-02 15:22:33 +02004527/* Check if a subscriber exists in the VLR */
4528private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4529
4530 var CtrlValue active_subsribers;
4531 var integer rc;
4532 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4533
4534 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4535 if (rc < 0) {
4536 return false;
4537 }
4538
4539 return true;
4540}
4541
Pau Espin Pedrolcefe9da2021-07-02 18:38:27 +02004542/* Perform a Location Update at the A-Interface and run some checks to confirm
Harald Welte4263c522018-12-06 11:56:27 +01004543 * that everything is back to normal. */
4544private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4545 var SmsParameters spars := valueof(t_SmsPars);
4546
Pau Espin Pedrol7593a8a2021-07-02 18:55:16 +02004547 /* From now on, since we initiated LU from A-Interface, we expect no
4548 * LastEutranPLMNId on Common Id, since the SGs interface should be gone
4549 */
4550 g_pars.common_id_last_eutran_plmn := omit;
4551
Harald Welte4263c522018-12-06 11:56:27 +01004552 /* Perform a location update, the SGs association is expected to fall
4553 * back to NULL */
4554 f_perform_lu();
4555 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4556
4557 /* Trigger a paging request and expect the paging on BSSMAP, this is
4558 * to make sure that pagings are sent throught the A-Interface again
4559 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004560 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004561 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4562
4563 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004564 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4565 setverdict(pass);
4566 }
Harald Welte62113fc2019-05-09 13:04:02 +02004567 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004568 setverdict(pass);
4569 }
4570 [] SGsAP.receive {
4571 setverdict(fail, "Received unexpected message on SGs");
4572 }
4573 }
4574
4575 /* Send an SMS to make sure that also payload messages are routed
4576 * throught the A-Interface again */
4577 f_establish_fully(EST_TYPE_MO_SMS);
4578 f_mo_sms(spars);
4579 f_expect_clear();
4580}
4581
4582private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4583 var charstring vlr_name;
4584 f_init_handler(pars);
4585
4586 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4587 log("VLR name: ", vlr_name);
4588 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004589 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004590}
4591
4592testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004593 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004594 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004595 f_init(1, true);
4596 pars := f_init_pars(11810, true);
4597 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004598 vc_conn.done;
4599}
4600
4601/* like f_mm_auth() but for SGs */
4602function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4603 if (g_pars.net.expect_auth) {
4604 g_pars.vec := f_gen_auth_vec_3g();
4605 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4606 g_pars.vec.sres,
4607 g_pars.vec.kc,
4608 g_pars.vec.ik,
4609 g_pars.vec.ck,
4610 g_pars.vec.autn,
4611 g_pars.vec.res));
4612 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4613 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4614 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4615 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4616 }
4617}
4618
4619/* like f_perform_lu(), but on SGs rather than BSSAP */
4620function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4621 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4622 var PDU_SGsAP lur;
4623 var PDU_SGsAP lua;
4624 var PDU_SGsAP mm_info;
4625 var octetstring mm_info_dtap;
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004626 var GsmMcc mcc;
4627 var GsmMnc mnc;
4628 var template (omit) TrackingAreaIdentityValue tai := omit;
Harald Welte4263c522018-12-06 11:56:27 +01004629
4630 /* tell GSUP dispatcher to send this IMSI to us */
4631 f_create_gsup_expect(hex2str(g_pars.imsi));
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004632 if (g_pars.common_id_last_eutran_plmn != omit) {
4633 f_dec_mcc_mnc(g_pars.common_id_last_eutran_plmn, mcc, mnc);
4634 tai := ts_SGsAP_TAI(mcc, mnc, 555);
4635 }
Harald Welte4263c522018-12-06 11:56:27 +01004636 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
Pau Espin Pedrol3768a6f2021-04-28 14:24:23 +02004637 ts_SGsAP_LAI('901'H, '70'H, 2342),
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004638 tai));
Harald Welte4263c522018-12-06 11:56:27 +01004639 /* Old LAI, if MS sends it */
4640 /* TMSI status, if MS has no valid TMSI */
4641 /* IMEISV, if it supports "automatic device detection" */
4642 /* TAI, if available in MME */
4643 /* E-CGI, if available in MME */
4644 SGsAP.send(lur);
4645
4646 /* FIXME: is this really done over SGs? The Ue is already authenticated
4647 * via the MME ... */
4648 f_mm_auth_sgs();
4649
4650 /* Expect MSC to perform LU with HLR */
4651 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4652 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4653 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4654 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4655
4656 alt {
4657 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4658 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4659 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4660 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4661 }
4662 setverdict(pass);
4663 }
4664 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4665 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4666 }
4667 [] SGsAP.receive {
4668 setverdict(fail, "Received unexpected message on SGs");
4669 }
4670 }
4671
4672 /* Check MM information */
4673 if (mp_mm_info == true) {
4674 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4675 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4676 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4677 setverdict(fail, "Unexpected MM Information");
4678 }
4679 }
4680
4681 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4682}
4683
4684private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4685 f_init_handler(pars);
4686 f_sgs_perform_lu();
4687 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4688
4689 f_sgsap_bssmap_screening();
4690
4691 setverdict(pass);
4692}
4693testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004694 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004695 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004696 f_init(1, true);
4697 pars := f_init_pars(11811, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004698 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004699 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004700 vc_conn.done;
4701}
4702
4703/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4704private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4705 f_init_handler(pars);
4706 var PDU_SGsAP lur;
4707
4708 f_create_gsup_expect(hex2str(g_pars.imsi));
4709 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4710 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4711 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4712 SGsAP.send(lur);
4713
4714 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4715 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4716 alt {
4717 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4718 setverdict(pass);
4719 }
4720 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4721 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4722 mtc.stop;
4723 }
4724 [] SGsAP.receive {
4725 setverdict(fail, "Received unexpected message on SGs");
4726 }
4727 }
4728
4729 f_sgsap_bssmap_screening();
4730
4731 setverdict(pass);
4732}
4733testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004734 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004735 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004736 f_init(1, true);
4737 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004738
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004739 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004740 vc_conn.done;
4741}
4742
4743/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4744private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4745 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4746 var PDU_SGsAP lur;
4747
4748 f_init_handler(pars);
4749
4750 /* tell GSUP dispatcher to send this IMSI to us */
4751 f_create_gsup_expect(hex2str(g_pars.imsi));
4752
4753 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4754 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4755 /* Old LAI, if MS sends it */
4756 /* TMSI status, if MS has no valid TMSI */
4757 /* IMEISV, if it supports "automatic device detection" */
4758 /* TAI, if available in MME */
4759 /* E-CGI, if available in MME */
4760 SGsAP.send(lur);
4761
4762 /* FIXME: is this really done over SGs? The Ue is already authenticated
4763 * via the MME ... */
4764 f_mm_auth_sgs();
4765
4766 /* Expect MSC to perform LU with HLR */
4767 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4768 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4769 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4770 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4771
4772 alt {
4773 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4774 setverdict(pass);
4775 }
4776 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4777 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4778 }
4779 [] SGsAP.receive {
4780 setverdict(fail, "Received unexpected message on SGs");
4781 }
4782 }
4783
4784 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4785
4786 /* Wait until the VLR has abort the TMSI reallocation procedure */
4787 f_sleep(45.0);
4788
4789 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4790 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4791
4792 f_sgsap_bssmap_screening();
4793
4794 setverdict(pass);
4795}
4796testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004797 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004798 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004799 f_init(1, true);
4800 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004801
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004802 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004803 vc_conn.done;
4804}
4805
4806private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4807runs on BSC_ConnHdlr {
4808 f_init_handler(pars);
4809 f_sgs_perform_lu();
4810 f_sleep(3.0);
4811
4812 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4813 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4814 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4815 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4816
4817 f_sgsap_bssmap_screening();
4818
4819 setverdict(pass);
4820}
4821testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004822 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004823 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004824 f_init(1, true);
4825 pars := f_init_pars(11814, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004826 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004827 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004828 vc_conn.done;
4829}
4830
Philipp Maierfc19f172019-03-21 11:17:54 +01004831private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4832runs on BSC_ConnHdlr {
4833 f_init_handler(pars);
4834 f_sgs_perform_lu();
4835 f_sleep(3.0);
4836
4837 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4838 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4839 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4840 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4841
4842 f_sgsap_bssmap_screening();
4843
4844 setverdict(pass);
4845}
4846testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4847 var BSC_ConnHdlrPars pars;
4848 var BSC_ConnHdlr vc_conn;
4849 f_init(1, true);
4850 pars := f_init_pars(11814, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004851 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maierfc19f172019-03-21 11:17:54 +01004852 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4853 vc_conn.done;
4854}
4855
Harald Welte4263c522018-12-06 11:56:27 +01004856private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4857runs on BSC_ConnHdlr {
4858 f_init_handler(pars);
4859 f_sgs_perform_lu();
4860 f_sleep(3.0);
4861
4862 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4863 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4864 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004865
4866 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4867 setverdict(fail, "subscriber not removed from VLR");
4868 }
Harald Welte4263c522018-12-06 11:56:27 +01004869
4870 f_sgsap_bssmap_screening();
4871
4872 setverdict(pass);
4873}
4874testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004875 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004876 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004877 f_init(1, true);
4878 pars := f_init_pars(11815, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004879 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004880 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004881 vc_conn.done;
4882}
4883
Philipp Maier5d812702019-03-21 10:51:26 +01004884private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4885runs on BSC_ConnHdlr {
4886 f_init_handler(pars);
4887 f_sgs_perform_lu();
4888 f_sleep(3.0);
4889
4890 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4891 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4892 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4893
4894 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4895 setverdict(fail, "subscriber not removed from VLR");
4896 }
4897
4898 f_sgsap_bssmap_screening();
4899
4900 setverdict(pass);
4901}
4902testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4903 var BSC_ConnHdlrPars pars;
4904 var BSC_ConnHdlr vc_conn;
4905 f_init(1, true);
4906 pars := f_init_pars(11815, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004907 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier5d812702019-03-21 10:51:26 +01004908 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4909 vc_conn.done;
4910}
4911
Harald Welte4263c522018-12-06 11:56:27 +01004912/* Trigger a paging request via VTY and send a paging reject in response */
4913private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4914runs on BSC_ConnHdlr {
4915 f_init_handler(pars);
4916 f_sgs_perform_lu();
4917 f_sleep(1.0);
4918
4919 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4920 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4921 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4922 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4923
4924 /* Initiate paging via VTY */
4925 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4926 alt {
4927 [] SGsAP.receive(exp_resp) {
4928 setverdict(pass);
4929 }
4930 [] SGsAP.receive {
4931 setverdict(fail, "Received unexpected message on SGs");
4932 }
4933 }
4934
4935 /* Now reject the paging */
4936 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4937
4938 /* Wait for the states inside the MSC to settle and check the state
4939 * of the SGs Association */
4940 f_sleep(1.0);
4941 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4942
4943 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4944 * but we also need to cover tha case where the cause code indicates an
4945 * "IMSI detached for EPS services". In those cases the VLR is expected to
4946 * try paging on tha A/Iu interface. This will be another testcase similar to
4947 * this one, but extended with checks for the presence of the A/Iu paging
4948 * messages. */
4949
4950 f_sgsap_bssmap_screening();
4951
4952 setverdict(pass);
4953}
4954testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004955 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004956 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004957 f_init(1, true);
4958 pars := f_init_pars(11816, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004959 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004960 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004961 vc_conn.done;
4962}
4963
4964/* Trigger a paging request via VTY and send a paging reject that indicates
4965 * that the subscriber intentionally rejected the call. */
4966private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4967runs on BSC_ConnHdlr {
4968 f_init_handler(pars);
4969 f_sgs_perform_lu();
4970 f_sleep(1.0);
4971
4972 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4973 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4974 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4975 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4976
4977 /* Initiate paging via VTY */
4978 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4979 alt {
4980 [] SGsAP.receive(exp_resp) {
4981 setverdict(pass);
4982 }
4983 [] SGsAP.receive {
4984 setverdict(fail, "Received unexpected message on SGs");
4985 }
4986 }
4987
4988 /* Now reject the paging */
4989 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4990
4991 /* Wait for the states inside the MSC to settle and check the state
4992 * of the SGs Association */
4993 f_sleep(1.0);
4994 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4995
4996 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4997 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4998 * to check back how this works and how it can be tested */
4999
5000 f_sgsap_bssmap_screening();
5001
5002 setverdict(pass);
5003}
5004testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005005 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005006 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005007 f_init(1, true);
5008 pars := f_init_pars(11817, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005009 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005010 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005011 vc_conn.done;
5012}
5013
5014/* Trigger a paging request via VTY and send an UE unreacable messge in response */
5015private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
5016runs on BSC_ConnHdlr {
5017 f_init_handler(pars);
5018 f_sgs_perform_lu();
5019 f_sleep(1.0);
5020
5021 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5022 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
5023 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5024 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5025
5026 /* Initiate paging via VTY */
5027 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5028 alt {
5029 [] SGsAP.receive(exp_resp) {
5030 setverdict(pass);
5031 }
5032 [] SGsAP.receive {
5033 setverdict(fail, "Received unexpected message on SGs");
5034 }
5035 }
5036
5037 /* Now pretend that the UE is unreachable */
5038 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
5039
5040 /* Wait for the states inside the MSC to settle and check the state
5041 * of the SGs Association. */
5042 f_sleep(1.0);
5043 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5044
5045 f_sgsap_bssmap_screening();
5046
5047 setverdict(pass);
5048}
5049testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005050 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005051 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005052 f_init(1, true);
5053 pars := f_init_pars(11818, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005054 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005055 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005056 vc_conn.done;
5057}
5058
5059/* Trigger a paging request via VTY but don't respond to it */
5060private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
5061runs on BSC_ConnHdlr {
5062 f_init_handler(pars);
5063 f_sgs_perform_lu();
5064 f_sleep(1.0);
5065
5066 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5067 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02005068 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01005069 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5070 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5071
5072 /* Initiate paging via VTY */
5073 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5074 alt {
5075 [] SGsAP.receive(exp_resp) {
5076 setverdict(pass);
5077 }
5078 [] SGsAP.receive {
5079 setverdict(fail, "Received unexpected message on SGs");
5080 }
5081 }
5082
Philipp Maier34218102019-09-24 09:15:49 +02005083 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
5084 * after some time */
5085 timer T := 10.0;
5086 T.start
5087 alt {
5088 [] SGsAP.receive(exp_serv_abrt)
5089 {
5090 setverdict(pass);
5091 }
5092 [] SGsAP.receive {
5093 setverdict(fail, "unexpected SGsAP message received");
5094 self.stop;
5095 }
5096 [] T.timeout {
5097 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
5098 self.stop;
5099 }
5100 }
5101
5102 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01005103 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5104
5105 f_sgsap_bssmap_screening();
5106
5107 setverdict(pass);
5108}
5109testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005110 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005111 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005112 f_init(1, true);
5113 pars := f_init_pars(11819, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005114 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005115 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005116 vc_conn.done;
5117}
5118
5119/* Trigger a paging request via VTY and slip in an LU */
5120private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
5121runs on BSC_ConnHdlr {
5122 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5123 f_init_handler(pars);
5124
5125 /* First we prepar the situation, where the SGs association is in state
5126 * NULL and the confirmed by radio contact indicator is set to false
5127 * as well. This can be archived by performing an SGs LU and then
5128 * resetting the VLR */
5129 f_sgs_perform_lu();
5130 f_sgsap_reset_mme(mp_mme_name);
5131 f_sleep(1.0);
5132 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5133
5134 /* Perform a paging, expect the paging messages on the SGs interface */
5135 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5136 alt {
5137 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5138 setverdict(pass);
5139 }
5140 [] SGsAP.receive {
5141 setverdict(fail, "Received unexpected message on SGs");
5142 }
5143 }
5144
5145 /* Perform the LU as normal */
5146 f_sgs_perform_lu();
5147 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5148
5149 /* Expect a new paging request right after the LU */
5150 alt {
5151 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5152 setverdict(pass);
5153 }
5154 [] SGsAP.receive {
5155 setverdict(fail, "Received unexpected message on SGs");
5156 }
5157 }
5158
5159 /* Test is done now, lets round everything up by rejecting the paging
5160 * cleanly. */
5161 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
5162 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5163
5164 f_sgsap_bssmap_screening();
5165
5166 setverdict(pass);
5167}
5168testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005169 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005170 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005171 f_init(1, true);
5172 pars := f_init_pars(11820, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005173 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005174 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005175 vc_conn.done;
5176}
5177
5178/* Send unexpected unit-data through the SGs interface */
5179private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5180 f_init_handler(pars);
5181 f_sleep(1.0);
5182
5183 /* This simulates what happens when a subscriber without SGs
5184 * association gets unitdata via the SGs interface. */
5185
5186 /* Make sure the subscriber exists and the SGs association
5187 * is in NULL state */
5188 f_perform_lu();
5189 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5190
5191 /* Send some random unit data, the MSC/VLR should send a release
5192 * immediately. */
5193 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5194 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
5195
5196 f_sgsap_bssmap_screening();
5197
5198 setverdict(pass);
5199}
5200testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005201 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005202 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005203 f_init(1, true);
5204 pars := f_init_pars(11821, true);
5205 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005206 vc_conn.done;
5207}
5208
5209/* Send unsolicited unit-data through the SGs interface */
5210private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5211 f_init_handler(pars);
5212 f_sleep(1.0);
5213
5214 /* This simulates what happens when the MME attempts to send unitdata
5215 * to a subscriber that is completely unknown to the VLR */
5216
5217 /* Send some random unit data, the MSC/VLR should send a release
5218 * immediately. */
5219 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5220 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
5221
5222 f_sgsap_bssmap_screening();
5223
Harald Welte4d15fa72020-08-19 08:58:28 +02005224 /* clean-up VLR state about this subscriber */
5225 f_imsi_detach_by_imsi();
5226
Harald Welte4263c522018-12-06 11:56:27 +01005227 setverdict(pass);
5228}
5229testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005230 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005231 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005232 f_init(1, true);
5233 pars := f_init_pars(11822, true);
5234 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005235 vc_conn.done;
5236}
5237
5238private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
5239 /* FIXME: Match an actual payload (second questionmark), the type is
5240 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
5241 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
5242 setverdict(fail, "Unexpected SMS related PDU from MSC");
5243 mtc.stop;
5244 }
5245}
5246
5247/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
5248function f_mt_sms_sgs(inout SmsParameters spars)
5249runs on BSC_ConnHdlr {
5250 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5251 var template (value) RPDU_MS_SGSN rp_mo;
5252 var template (value) PDU_ML3_MS_NW l3_mo;
5253
5254 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5255 var template RPDU_SGSN_MS rp_mt;
5256 var template PDU_ML3_NW_MS l3_mt;
5257
5258 var PDU_ML3_NW_MS sgsap_l3_mt;
5259
5260 var default d := activate(as_other_sms_sgs());
5261
5262 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
5263 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09005264 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01005265 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
5266
5267 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
5268
5269 /* Extract relevant identifiers */
5270 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
5271 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
5272
5273 /* send CP-ACK for CP-DATA just received */
5274 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
5275
5276 SGsAP.send(l3_mo);
5277
5278 /* send RP-ACK for RP-DATA */
5279 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
5280 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
5281
5282 SGsAP.send(l3_mo);
5283
5284 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
5285 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
5286
5287 SGsAP.receive(l3_mt);
5288
5289 deactivate(d);
5290
5291 setverdict(pass);
5292}
5293
5294/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
5295function f_mo_sms_sgs(inout SmsParameters spars)
5296runs on BSC_ConnHdlr {
5297 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5298 var template (value) RPDU_MS_SGSN rp_mo;
5299 var template (value) PDU_ML3_MS_NW l3_mo;
5300
5301 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5302 var template RPDU_SGSN_MS rp_mt;
5303 var template PDU_ML3_NW_MS l3_mt;
5304
5305 var default d := activate(as_other_sms_sgs());
5306
5307 /* just in case this is routed to SMPP.. */
5308 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
5309
5310 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
5311 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09005312 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01005313 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
5314
5315 SGsAP.send(l3_mo);
5316
5317 /* receive CP-ACK for CP-DATA above */
5318 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
5319
5320 if (ispresent(spars.exp_rp_err)) {
5321 /* expect an RP-ERROR message from MSC with given cause */
5322 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
5323 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5324 SGsAP.receive(l3_mt);
5325 /* send CP-ACK for CP-DATA just received */
5326 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5327 SGsAP.send(l3_mo);
5328 } else {
5329 /* expect RP-ACK for RP-DATA */
5330 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
5331 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5332 SGsAP.receive(l3_mt);
5333 /* send CP-ACO for CP-DATA just received */
5334 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5335 SGsAP.send(l3_mo);
5336 }
5337
5338 deactivate(d);
5339
5340 setverdict(pass);
5341}
5342
5343private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
5344runs on BSC_ConnHdlr {
5345 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
5346}
5347
5348/* Send a MT SMS via SGs interface */
5349private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5350 f_init_handler(pars);
5351 f_sgs_perform_lu();
5352 f_sleep(1.0);
5353 var SmsParameters spars := valueof(t_SmsPars);
5354 spars.tp.ud := 'C8329BFD064D9B53'O;
5355
5356 /* Trigger SMS via VTY */
5357 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5358 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5359
5360 /* Expect a paging request and respond accordingly with a service request */
5361 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
5362 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
5363
5364 /* Connection is now live, receive the MT-SMS */
5365 f_mt_sms_sgs(spars);
5366
5367 /* Expect a concluding release from the MSC */
5368 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5369
5370 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5371 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5372
5373 f_sgsap_bssmap_screening();
5374
5375 setverdict(pass);
5376}
5377testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005378 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005379 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005380 f_init(1, true);
5381 pars := f_init_pars(11823, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005382 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005383 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005384 vc_conn.done;
5385}
5386
5387/* Send a MO SMS via SGs interface */
5388private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5389 f_init_handler(pars);
5390 f_sgs_perform_lu();
5391 f_sleep(1.0);
5392 var SmsParameters spars := valueof(t_SmsPars);
5393 spars.tp.ud := 'C8329BFD064D9B53'O;
5394
5395 /* Send the MO-SMS */
5396 f_mo_sms_sgs(spars);
5397
5398 /* Expect a concluding release from the MSC/VLR */
5399 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5400
5401 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5402 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5403
5404 setverdict(pass);
5405
5406 f_sgsap_bssmap_screening()
5407}
5408testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005409 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005410 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005411 f_init(1, true);
5412 pars := f_init_pars(11824, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005413 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005414 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005415 vc_conn.done;
5416}
5417
5418/* Trigger sending of an MT sms via VTY but never respond to anything */
5419private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5420 f_init_handler(pars, 170.0);
5421 f_sgs_perform_lu();
5422 f_sleep(1.0);
5423
5424 var SmsParameters spars := valueof(t_SmsPars);
5425 spars.tp.ud := 'C8329BFD064D9B53'O;
5426 var integer page_count := 0;
5427 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5428 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5429 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5430 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5431
5432 /* Trigger SMS via VTY */
5433 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5434
Neels Hofmeyr16237742019-03-06 15:34:01 +01005435 /* Expect the MSC/VLR to page exactly once */
5436 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005437
5438 /* Wait some time to make sure the MSC is not delivering any further
5439 * paging messages or anything else that could be unexpected. */
5440 timer T := 20.0;
5441 T.start
5442 alt {
5443 [] SGsAP.receive(exp_pag_req)
5444 {
5445 setverdict(fail, "paging seems not to stop!");
5446 mtc.stop;
5447 }
5448 [] SGsAP.receive {
5449 setverdict(fail, "unexpected SGsAP message received");
5450 self.stop;
5451 }
5452 [] T.timeout {
5453 setverdict(pass);
5454 }
5455 }
5456
5457 /* Even on a failed paging the SGs Association should stay intact */
5458 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5459
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005460 /* Make sure that the SMS we just inserted is cleared and the
5461 * subscriber is expired. This is necessary because otherwise the MSC
5462 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005463
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005464 f_vty_sms_clear(hex2str(g_pars.imsi));
5465
Harald Welte4263c522018-12-06 11:56:27 +01005466 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5467
5468 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005469
5470 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005471}
5472testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005473 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005474 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005475 f_init(1, true);
5476 pars := f_init_pars(11825, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005477 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005478 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005479 vc_conn.done;
5480}
5481
5482/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5483private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5484 f_init_handler(pars, 150.0);
5485 f_sgs_perform_lu();
5486 f_sleep(1.0);
5487
5488 var SmsParameters spars := valueof(t_SmsPars);
5489 spars.tp.ud := 'C8329BFD064D9B53'O;
5490 var integer page_count := 0;
5491 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5492 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5493 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5494 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5495
5496 /* Trigger SMS via VTY */
5497 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5498
5499 /* Expect a paging request and reject it immediately */
5500 SGsAP.receive(exp_pag_req);
5501 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5502
5503 /* The MSC/VLR should no longer try to page once the paging has been
5504 * rejected. Wait some time and check if there are no unexpected
5505 * messages on the SGs interface. */
5506 timer T := 20.0;
5507 T.start
5508 alt {
5509 [] SGsAP.receive(exp_pag_req)
5510 {
5511 setverdict(fail, "paging seems not to stop!");
5512 mtc.stop;
5513 }
5514 [] SGsAP.receive {
5515 setverdict(fail, "unexpected SGsAP message received");
5516 self.stop;
5517 }
5518 [] T.timeout {
5519 setverdict(pass);
5520 }
5521 }
5522
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005523 f_vty_sms_clear(hex2str(g_pars.imsi));
5524
Harald Welte4263c522018-12-06 11:56:27 +01005525 /* A rejected paging with IMSI_unknown (see above) should always send
5526 * the SGs association to NULL. */
5527 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5528
5529 f_sgsap_bssmap_screening();
5530
Harald Welte4263c522018-12-06 11:56:27 +01005531 setverdict(pass);
5532}
5533testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005534 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005535 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005536 f_init(1, true);
5537 pars := f_init_pars(11826, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005538 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005539 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005540 vc_conn.done;
5541}
5542
Pau Espin Pedrol3acd19e2021-04-28 12:59:52 +02005543/* Perform an MT CSFB call including LU */
Harald Welte4263c522018-12-06 11:56:27 +01005544private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5545 f_init_handler(pars);
5546
5547 /* Be sure that the BSSMAP reset is done before we begin. */
5548 f_sleep(2.0);
5549
5550 /* Testcase variation: See what happens when we do a regular BSSMAP
5551 * LU first (this should not hurt in any way!) */
5552 if (bssmap_lu) {
5553 f_perform_lu();
5554 }
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005555 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Harald Welte4263c522018-12-06 11:56:27 +01005556
5557 f_sgs_perform_lu();
5558 f_sleep(1.0);
5559
5560 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5561 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005562
5563 /* Initiate a call via MNCC interface */
5564 f_mt_call_initate(cpars);
5565
5566 /* Expect a paging request and respond accordingly with a service request */
5567 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5568 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5569
5570 /* Complete the call, hold it for some time and then tear it down */
5571 f_mt_call_complete(cpars);
5572 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005573 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005574
5575 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5576 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5577
Harald Welte4263c522018-12-06 11:56:27 +01005578 /* Test for successful return by triggering a paging, when the paging
5579 * request is received via SGs, we can be sure that the MSC/VLR has
5580 * recognized that the UE is now back on 4G */
5581 f_sleep(1.0);
5582 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5583 alt {
5584 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5585 setverdict(pass);
5586 }
5587 [] SGsAP.receive {
5588 setverdict(fail, "Received unexpected message on SGs");
5589 }
5590 }
5591
5592 f_sgsap_bssmap_screening();
5593
5594 setverdict(pass);
5595}
5596
5597/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5598private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5599 f_mt_lu_and_csfb_call(id, pars, true);
5600}
5601testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005602 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005603 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005604 f_init(1, true);
5605 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005606
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005607 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005608 vc_conn.done;
5609}
5610
Harald Welte4263c522018-12-06 11:56:27 +01005611/* Perform a SGSAP LU and then make a CSFB call */
5612private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5613 f_mt_lu_and_csfb_call(id, pars, false);
5614}
5615testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005616 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005617 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005618 f_init(1, true);
5619 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005620
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005621 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005622 vc_conn.done;
5623}
5624
Philipp Maier628c0052019-04-09 17:36:57 +02005625/* Simulate an HLR/VLR failure */
5626private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5627 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5628 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5629
5630 var PDU_SGsAP lur;
5631
5632 f_init_handler(pars);
5633
5634 /* Attempt location update (which is expected to fail) */
5635 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5636 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5637 SGsAP.send(lur);
5638
5639 /* Respond to SGsAP-RESET-INDICATION from VLR */
5640 alt {
5641 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5642 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5643 setverdict(pass);
5644 }
5645 [] SGsAP.receive {
5646 setverdict(fail, "Received unexpected message on SGs");
5647 }
5648 }
5649
5650 f_sleep(1.0);
5651 setverdict(pass);
5652}
5653testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5654 var BSC_ConnHdlrPars pars;
5655 var BSC_ConnHdlr vc_conn;
5656 f_init(1, true, false);
5657 pars := f_init_pars(11811, true, false);
5658 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5659 vc_conn.done;
5660}
5661
Harald Welte4263c522018-12-06 11:56:27 +01005662/* SGs TODO:
5663 * LU attempt for IMSI without NAM_PS in HLR
5664 * LU attempt with AUTH FAIL due to invalid RES/SRES
5665 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5666 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5667 * implicit IMSI detach from EPS
5668 * implicit IMSI detach from non-EPS
5669 * MM INFO
5670 *
5671 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005672
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005673private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5674 f_init_handler(pars);
5675 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005676
5677 f_perform_lu();
5678 f_mo_call_establish(cpars);
5679
5680 f_sleep(1.0);
5681
5682 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5683 var BssmapCause cause := enum2int(cause_val);
5684
5685 var template BSSMAP_FIELD_CellIdentificationList cil;
5686 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5687
5688 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5689 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5690
5691 f_call_hangup(cpars, true);
5692}
5693testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5694 var BSC_ConnHdlr vc_conn;
5695 f_init();
5696
5697 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5698 vc_conn.done;
5699}
5700
5701private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5702 var MgcpCommand mgcp_cmd;
5703 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr8913b9e2021-07-27 22:33:45 +02005704 var charstring conn_id;
5705 f_mgcp_find_param_entry(mgcp_cmd.params, "I", conn_id);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005706 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005707 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005708 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005709 { int2str(cpars.rtp_payload_type) },
5710 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5711 cpars.rtp_sdp_format)),
5712 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr8913b9e2021-07-27 22:33:45 +02005713 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, str2hex(conn_id), sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005714 repeat;
5715 }
5716}
5717
5718private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005719 var CallParameters cpars;
5720
5721 cpars := valueof(t_CallParams('12345'H, 0));
5722 if (pars.use_ipv6) {
5723 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5724 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5725 cpars.bss_rtp_ip := "::3";
5726 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005727
5728 f_init_handler(pars);
5729
5730 f_vty_transceive(MSCVTY, "configure terminal");
5731 f_vty_transceive(MSCVTY, "msc");
5732 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005733 f_vty_transceive(MSCVTY, "neighbor a cgi 023 42 5 6 ran-pc 0.24.2");
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005734 f_vty_transceive(MSCVTY, "exit");
5735 f_vty_transceive(MSCVTY, "exit");
5736
5737 f_perform_lu();
5738 f_mo_call_establish(cpars);
5739
5740 f_sleep(1.0);
5741
5742 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5743
5744 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5745 var BssmapCause cause := enum2int(cause_val);
5746
5747 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005748 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('023'H, '42'H, 5, 6) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005749
5750 /* old BSS sends Handover Required */
5751 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5752
5753 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5754
5755 /* MSC forwards the RR Handover Command to old BSS */
5756 var PDU_BSSAP ho_command;
5757 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5758
5759 log("GOT HandoverCommand", ho_command);
5760
5761 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5762
5763 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5764 f_expect_clear();
5765
5766 log("FIRST inter-BSC Handover done");
5767
5768
5769 /* ------------------------ */
5770
5771 /* Ok, that went well, now the other BSC is handovering back here --
5772 * from now on this here is the new BSS. */
5773 f_create_bssmap_exp_handoverRequest(193);
5774
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005775 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
5776 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
5777 var template BSSMAP_IE_KC128 kC128;
5778 var OCT1 a5_perm_alg;
5779 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
5780 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005781 var PDU_BSSAP ho_request;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005782 alt {
5783 [] BSSAP.receive(expect_ho_request);
5784 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
5785 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
5786 " got ", ho_request);
5787 setverdict(fail, "Wrong handoverRequest received");
5788 mtc.stop;
5789 }
5790 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005791
5792 /* new BSS composes a RR Handover Command */
5793 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5794 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005795 var BSSMAP_IE_AoIP_TransportLayerAddress tla tla :=
5796 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005797 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5798 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5799
5800 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5801
5802 f_sleep(0.5);
5803
5804 /* Notify that the MS is now over here */
5805
5806 BSSAP.send(ts_BSSMAP_HandoverDetect);
5807 f_sleep(0.1);
5808 BSSAP.send(ts_BSSMAP_HandoverComplete);
5809
5810 f_sleep(3.0);
5811
5812 deactivate(ack_mdcx);
5813
5814 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5815
5816 /* blatant cheating */
5817 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5818 last_n_sd[0] := 3;
5819 f_bssmap_continue_after_n_sd(last_n_sd);
5820
5821 f_call_hangup(cpars, true);
5822 f_sleep(1.0);
5823 deactivate(ccrel);
5824
5825 setverdict(pass);
5826}
5827private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005828 var charstring bss_rtp_ip;
5829 if (pars.use_ipv6) {
5830 bss_rtp_ip := "::8";
5831 } else {
5832 bss_rtp_ip := "1.2.3.4";
5833 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005834 f_init_handler(pars);
5835 f_create_bssmap_exp_handoverRequest(194);
5836
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005837 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
5838 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
5839 var template BSSMAP_IE_KC128 kC128;
5840 var OCT1 a5_perm_alg;
5841 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
5842 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005843 var PDU_BSSAP ho_request;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005844 alt {
5845 [] BSSAP.receive(expect_ho_request);
5846 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
5847 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
5848 " got ", ho_request);
5849 setverdict(fail, "Wrong handoverRequest received");
5850 mtc.stop;
5851 }
5852 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005853 /* new BSS composes a RR Handover Command */
5854 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5855 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005856 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
5857 valueof(f_ts_BSSMAP_IE_AoIP_TLA(bss_rtp_ip, 2342));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005858 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5859 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5860
5861 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5862
5863 f_sleep(0.5);
5864
5865 /* Notify that the MS is now over here */
5866
5867 BSSAP.send(ts_BSSMAP_HandoverDetect);
5868 f_sleep(0.1);
5869 BSSAP.send(ts_BSSMAP_HandoverComplete);
5870
5871 f_sleep(3.0);
5872
5873 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5874 * ... handover back to the first BSC :P */
5875
5876 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5877 var BssmapCause cause := enum2int(cause_val);
5878
5879 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005880 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005881
5882 /* old BSS sends Handover Required */
5883 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5884
5885 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5886
5887 /* MSC forwards the RR Handover Command to old BSS */
5888 var PDU_BSSAP ho_command;
5889 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5890
5891 log("GOT HandoverCommand", ho_command);
5892
5893 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5894
5895 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5896 f_expect_clear();
5897 setverdict(pass);
5898}
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005899function f_tc_ho_inter_bsc_main(boolean use_ipv6 := false, integer a5_n := 0) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005900 var BSC_ConnHdlr vc_conn0;
5901 var BSC_ConnHdlr vc_conn1;
5902 f_init(2);
5903
5904 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005905 pars0.use_ipv6 := use_ipv6;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005906 pars0.net.expect_ciph := a5_n > 0;
5907 pars0.net.expect_auth := pars0.net.expect_ciph;
5908 pars0.net.kc_support := bit2oct('00000001'B << a5_n);
5909 pars0.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
5910 pars0.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
5911 pars0.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
5912 pars0.cm3 := valueof(ts_CM3_default);
5913 pars0.use_umts_aka := true;
5914 pars0.vec := f_gen_auth_vec_3g();
5915 pars0.vec_keep := true;
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005916 pars0.ran_idx := 0;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005917
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005918 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005919 pars1.use_ipv6 := use_ipv6;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005920 pars1.net.expect_ciph := pars0.net.expect_ciph;
5921 pars1.net.expect_auth := pars0.net.expect_ciph;
5922 pars1.net.kc_support := bit2oct('00000001'B << a5_n);
5923 pars1.cm2 := pars0.cm2;
5924 pars1.cm3 := pars0.cm3;
5925 pars1.use_umts_aka := true;
5926 /* Both components need the same auth vector info because we expect f_tc_ho_inter_bsc0's ciphering key to be
5927 * identical to the one that shows up in f_tc_ho_inter_bsc1. Can only do that by feeding in a vector to both
5928 * components and then not overwriting it in BSC_ConnectionHandler. */
5929 pars1.vec := pars0.vec;
5930 pars1.vec_keep := true;
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005931 pars1.ran_idx := 1;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005932
5933 if (a5_n > 0) {
5934 f_vty_config(MSCVTY, "network", "authentication required");
5935 }
5936 f_vty_config(MSCVTY, "network", "encryption a5 " & int2str(a5_n));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005937
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005938 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0);
5939 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005940 vc_conn0.done;
5941 vc_conn1.done;
5942}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005943testcase TC_ho_inter_bsc() runs on MTC_CT {
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005944 f_tc_ho_inter_bsc_main(false, a5_n := 0);
5945}
5946testcase TC_ho_inter_bsc_a5_1() runs on MTC_CT {
5947 f_tc_ho_inter_bsc_main(false, a5_n := 1);
5948}
5949testcase TC_ho_inter_bsc_a5_3() runs on MTC_CT {
5950 f_tc_ho_inter_bsc_main(false, a5_n := 3);
5951}
5952testcase TC_ho_inter_bsc_a5_4() runs on MTC_CT {
5953 f_tc_ho_inter_bsc_main(false, a5_n := 4);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005954}
5955testcase TC_ho_inter_bsc_ipv6() runs on MTC_CT {
5956 f_tc_ho_inter_bsc_main(true);
5957}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005958
5959function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5960 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5961 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5962 log("MS_NW patched enc_l3: ", enc_l3);
5963}
5964
5965private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005966 var CallParameters cpars;
Neels Hofmeyr906af102021-07-01 12:08:35 +02005967 var PDU_BSSAP ho_request;
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005968
5969 cpars := valueof(t_CallParams('12345'H, 0));
5970 if (pars.use_ipv6) {
5971 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5972 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5973 cpars.bss_rtp_ip := "::3";
5974 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005975 var hexstring ho_number := f_gen_msisdn(99999);
5976
5977 f_init_handler(pars);
5978
5979 f_create_mncc_expect(hex2str(ho_number));
5980
5981 f_vty_transceive(MSCVTY, "configure terminal");
5982 f_vty_transceive(MSCVTY, "msc");
5983 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
5984 f_vty_transceive(MSCVTY, "exit");
5985 f_vty_transceive(MSCVTY, "exit");
5986
5987 f_perform_lu();
5988 f_mo_call_establish(cpars);
5989
5990 f_sleep(1.0);
5991
5992 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5993
5994 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5995 var BssmapCause cause := enum2int(cause_val);
5996
5997 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr36ebc332021-06-23 03:20:32 +02005998 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('017'H, '017'H, 1, 1) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005999
6000 /* old BSS sends Handover Required */
6001 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
6002
6003 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
6004 * This MSC tries to reach the other MSC via GSUP. */
6005
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006006 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
6007 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
6008 var template BSSMAP_IE_KC128 kC128;
6009 var OCT1 a5_perm_alg;
6010 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
6011 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
6012
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006013 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
6014 var GSUP_PDU prep_ho_req;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006015 alt {
6016 [] GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
6017 pars.imsi, destination_name := remote_msc_name,
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006018 an_apdu := t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, pdu := ?))) -> value prep_ho_req;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006019 [] GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST)) {
6020 setverdict(fail, "Wrong OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST message received");
6021 mtc.stop;
6022 }
6023 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006024
6025 var GSUP_IeValue source_name_ie;
6026 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
6027 var octetstring local_msc_name := source_name_ie.source_name;
6028
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006029 /* Decode PDU to 1) match with expect_ho_request and 2) to forward the actual chosen encryption algorithm. */
Neels Hofmeyr906af102021-07-01 12:08:35 +02006030 var GSUP_IeValue an_apdu_ie;
6031 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_AN_APDU_IE, an_apdu_ie);
6032 ho_request := dec_PDU_BSSAP(an_apdu_ie.an_apdu.pdu);
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006033 if (not match(ho_request, expect_ho_request)) {
6034 setverdict(fail, "Wrong PDU in OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST message received");
6035 mtc.stop;
6036 }
Neels Hofmeyr906af102021-07-01 12:08:35 +02006037
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006038 /* Remote MSC has figured out its BSC and signals success */
6039 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
6040 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
6041 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
Neels Hofmeyr906af102021-07-01 12:08:35 +02006042 aoIPTransportLayer := omit,
6043 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}),
6044 chosenEncryptionAlgorithm := ho_request.pdu.bssmap.handoverRequest.chosenEncryptionAlgorithm));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006045 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
6046 pars.imsi,
6047 ho_number,
6048 remote_msc_name, local_msc_name,
6049 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
6050
6051 /* MSC forwards the RR Handover Command to old BSS */
6052 BSSAP.receive(tr_BSSMAP_HandoverCommand);
6053
6054 /* The MS shows up at remote new BSS */
6055
6056 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
6057 pars.imsi, remote_msc_name, local_msc_name,
6058 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6059 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
6060 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
6061 f_sleep(0.1);
6062
6063 /* Save the MS sequence counters for use on the other connection */
6064 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
6065
6066 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
6067 pars.imsi, remote_msc_name, local_msc_name,
6068 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6069 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
6070
6071 /* The local BSS conn clears, all communication goes via remote MSC now */
6072 f_expect_clear();
6073
6074 /**********************************/
6075 /* Play through some signalling across the inter-MSC link.
6076 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
6077
6078 if (false) {
6079 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
6080 invoke_id := 5, /* Phone may not start from 0 or 1 */
6081 op_code := SS_OP_CODE_PROCESS_USS_REQ,
6082 ussd_string := "*#100#"
6083 );
6084
6085 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
6086 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
6087 op_code := SS_OP_CODE_PROCESS_USS_REQ,
6088 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
6089 )
6090
6091 /* Compose a new SS/REGISTER message with request */
6092 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
6093 tid := 1, /* We just need a single transaction */
6094 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
6095 facility := valueof(facility_req)
6096 );
6097 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
6098
6099 /* Compose SS/RELEASE_COMPLETE template with expected response */
6100 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
6101 tid := 1, /* Response should arrive within the same transaction */
6102 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
6103 facility := valueof(facility_rsp)
6104 );
6105
6106 /* Compose expected MSC -> HLR message */
6107 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
6108 imsi := g_pars.imsi,
6109 state := OSMO_GSUP_SESSION_STATE_BEGIN,
6110 ss := valueof(facility_req)
6111 );
6112
6113 /* To be used for sending response with correct session ID */
6114 var GSUP_PDU gsup_req_complete;
6115
6116 /* Request own number */
6117 /* From remote MSC instead of BSSAP directly */
6118 /* Patch the correct N_SD value into the message. */
6119 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
6120 var RAN_Emulation.ConnectionData cd;
6121 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
6122 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
6123 pars.imsi, remote_msc_name, local_msc_name,
6124 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6125 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
6126 ))
6127 ));
6128
6129 /* Expect GSUP message containing the SS payload */
6130 gsup_req_complete := f_expect_gsup_msg(gsup_req);
6131
6132 /* Compose the response from HLR using received session ID */
6133 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
6134 imsi := g_pars.imsi,
6135 sid := gsup_req_complete.ies[1].val.session_id,
6136 state := OSMO_GSUP_SESSION_STATE_END,
6137 ss := valueof(facility_rsp)
6138 );
6139
6140 /* Finally, HLR terminates the session */
6141 GSUP.send(gsup_rsp);
6142
6143 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
6144 var GSUP_PDU gsup_ussd_rsp;
6145 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
6146 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
6147
6148 var GSUP_IeValue an_apdu;
6149 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
6150 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
6151 mtc.stop;
6152 }
6153 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
6154 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
6155 log("Expecting", ussd_rsp);
6156 log("Got", dtap_mt);
6157 if (not match(dtap_mt, ussd_rsp)) {
6158 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
6159 mtc.stop;
6160 }
6161 }
6162 /**********************************/
6163
6164
6165 /* inter-MSC handover back to the first MSC */
6166 f_create_bssmap_exp_handoverRequest(193);
6167 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
6168
6169 /* old BSS sends Handover Required, via inter-MSC E link: like
6170 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
6171 * but via GSUP */
6172 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
6173 pars.imsi, remote_msc_name, local_msc_name,
6174 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6175 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
6176 ))
6177 ));
6178
6179 /* MSC asks local BSS to prepare Handover to it */
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006180 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
6181 expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006182 alt {
Neels Hofmeyr906af102021-07-01 12:08:35 +02006183 [] BSSAP.receive(expect_ho_request) -> value ho_request;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006184 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
6185 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
6186 " got ", ho_request);
6187 setverdict(fail, "Wrong handoverRequest received");
6188 mtc.stop;
6189 }
6190 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006191
6192 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
6193 f_bssmap_continue_after_n_sd(last_n_sd);
6194
6195 /* new BSS composes a RR Handover Command */
6196 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
6197 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006198 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
6199 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006200 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
Neels Hofmeyr906af102021-07-01 12:08:35 +02006201 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}),
6202 chosenEncryptionAlgorithm := ho_request.pdu.bssmap.handoverRequest.chosenEncryptionAlgorithm));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006203
6204 /* HandoverCommand goes out via remote MSC-I */
6205 var GSUP_PDU prep_subsq_ho_res;
6206 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
6207 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
6208
6209 /* MS shows up at the local BSS */
6210 BSSAP.send(ts_BSSMAP_HandoverDetect);
6211 f_sleep(0.1);
6212 BSSAP.send(ts_BSSMAP_HandoverComplete);
6213
6214 /* Handover Succeeded message */
6215 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
6216 pars.imsi, destination_name := remote_msc_name));
6217
6218 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
6219 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
6220 pars.imsi, destination_name := remote_msc_name));
6221
6222 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
6223
6224 f_sleep(1.0);
6225 deactivate(ack_mdcx);
6226
6227 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
6228 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
6229 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
6230 MNCC.clear;
6231
6232 var default ccrel := activate(as_optional_cc_rel(cpars, true));
6233 f_call_hangup(cpars, true);
6234 f_sleep(1.0);
6235 deactivate(ccrel);
6236
6237 setverdict(pass);
6238}
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006239function f_tc_ho_inter_msc_out_a5(integer a5_n) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006240 var BSC_ConnHdlr vc_conn;
6241 f_init(1);
6242
6243 var BSC_ConnHdlrPars pars := f_init_pars(54);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006244 pars.net.expect_ciph := a5_n > 0;
6245 pars.net.expect_auth := pars.net.expect_ciph;
6246 pars.net.kc_support := bit2oct('00000001'B << a5_n);
6247 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
6248 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
6249 pars.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
6250 pars.cm3 := valueof(ts_CM3_default);
6251 pars.use_umts_aka := true;
6252
6253 if (a5_n > 0) {
6254 f_vty_config(MSCVTY, "network", "authentication required");
6255 }
6256 f_vty_config(MSCVTY, "network", "encryption a5 " & int2str(a5_n));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006257
Neels Hofmeyr60122f82021-07-28 17:59:38 +02006258 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006259 vc_conn.done;
6260}
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006261testcase TC_ho_inter_msc_out() runs on MTC_CT {
6262 f_tc_ho_inter_msc_out_a5(0);
6263}
6264testcase TC_ho_inter_msc_out_a5_1() runs on MTC_CT {
6265 f_tc_ho_inter_msc_out_a5(1);
6266}
6267testcase TC_ho_inter_msc_out_a5_3() runs on MTC_CT {
6268 f_tc_ho_inter_msc_out_a5(3);
6269}
6270testcase TC_ho_inter_msc_out_a5_4() runs on MTC_CT {
6271 f_tc_ho_inter_msc_out_a5(4);
6272}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006273testcase TC_ho_inter_msc_out_ipv6() runs on MTC_CT {
6274 var BSC_ConnHdlr vc_conn;
6275 f_init(1);
6276
6277 var BSC_ConnHdlrPars pars := f_init_pars(54);
6278 pars.use_ipv6 := true;
6279
Neels Hofmeyr60122f82021-07-28 17:59:38 +02006280 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006281 vc_conn.done;
6282}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006283
Oliver Smith1d118ff2019-07-03 10:57:35 +02006284private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6285 pars.net.expect_auth := true;
6286 pars.net.expect_imei := true;
6287 f_init_handler(pars);
6288 f_perform_lu();
6289}
6290testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
6291 var BSC_ConnHdlr vc_conn;
6292 f_init();
6293 f_vty_config(MSCVTY, "network", "authentication required");
6294 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6295
6296 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
6297 vc_conn.done;
6298}
6299
6300private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6301 pars.net.expect_auth := true;
6302 pars.use_umts_aka := true;
6303 pars.net.expect_imei := true;
6304 f_init_handler(pars);
6305 f_perform_lu();
6306}
6307testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
6308 var BSC_ConnHdlr vc_conn;
6309 f_init();
6310 f_vty_config(MSCVTY, "network", "authentication required");
6311 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6312
6313 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
6314 vc_conn.done;
6315}
6316
6317private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6318 pars.net.expect_imei := true;
6319 f_init_handler(pars);
6320 f_perform_lu();
6321}
6322testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
6323 var BSC_ConnHdlr vc_conn;
6324 f_init();
6325 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6326
6327 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
6328 vc_conn.done;
6329}
6330
6331private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6332 pars.net.expect_tmsi := false;
6333 pars.net.expect_imei := true;
6334 f_init_handler(pars);
6335 f_perform_lu();
6336}
6337testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
6338 var BSC_ConnHdlr vc_conn;
6339 f_init();
6340 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6341 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6342
6343 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
6344 vc_conn.done;
6345}
6346
6347private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6348 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006349
6350 pars.net.expect_auth := true;
6351 pars.net.expect_imei := true;
6352 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6353 f_init_handler(pars);
6354
6355 /* Cannot use f_perform_lu() as we expect a reject */
6356 l3_lu := f_build_lu_imsi(g_pars.imsi)
6357 f_create_gsup_expect(hex2str(g_pars.imsi));
6358 f_bssap_compl_l3(l3_lu);
6359 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6360
6361 f_mm_common();
6362 f_msc_lu_hlr();
6363 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006364 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006365 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006366}
6367testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
6368 var BSC_ConnHdlr vc_conn;
6369 f_init();
6370 f_vty_config(MSCVTY, "network", "authentication required");
6371 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6372
6373 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
6374 vc_conn.done;
6375}
6376
6377private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6378 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006379
6380 pars.net.expect_auth := true;
6381 pars.net.expect_imei := true;
6382 pars.net.check_imei_error := true;
6383 f_init_handler(pars);
6384
6385 /* Cannot use f_perform_lu() as we expect a reject */
6386 l3_lu := f_build_lu_imsi(g_pars.imsi)
6387 f_create_gsup_expect(hex2str(g_pars.imsi));
6388 f_bssap_compl_l3(l3_lu);
6389 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6390
6391 f_mm_common();
6392 f_msc_lu_hlr();
6393 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006394 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006395 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006396}
6397testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
6398 var BSC_ConnHdlr vc_conn;
6399 f_init();
6400 f_vty_config(MSCVTY, "network", "authentication required");
6401 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6402
6403 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
6404 vc_conn.done;
6405}
6406
6407private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6408 pars.net.expect_auth := true;
6409 pars.net.expect_imei_early := true;
6410 f_init_handler(pars);
6411 f_perform_lu();
6412}
6413testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
6414 var BSC_ConnHdlr vc_conn;
6415 f_init();
6416 f_vty_config(MSCVTY, "network", "authentication required");
6417 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6418
6419 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
6420 vc_conn.done;
6421}
6422
6423private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6424 pars.net.expect_auth := true;
6425 pars.use_umts_aka := true;
6426 pars.net.expect_imei_early := true;
6427 f_init_handler(pars);
6428 f_perform_lu();
6429}
6430testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
6431 var BSC_ConnHdlr vc_conn;
6432 f_init();
6433 f_vty_config(MSCVTY, "network", "authentication required");
6434 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6435
6436 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
6437 vc_conn.done;
6438}
6439
6440private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6441 pars.net.expect_imei_early := true;
6442 f_init_handler(pars);
6443 f_perform_lu();
6444}
6445testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
6446 var BSC_ConnHdlr vc_conn;
6447 f_init();
6448 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6449
6450 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
6451 vc_conn.done;
6452}
6453
6454private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6455 pars.net.expect_tmsi := false;
6456 pars.net.expect_imei_early := true;
6457 f_init_handler(pars);
6458 f_perform_lu();
6459}
6460testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
6461 var BSC_ConnHdlr vc_conn;
6462 f_init();
6463 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6464 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6465
6466 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
6467 vc_conn.done;
6468}
6469
6470private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6471 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006472
6473 pars.net.expect_auth := true;
6474 pars.net.expect_imei_early := true;
6475 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6476 f_init_handler(pars);
6477
6478 /* Cannot use f_perform_lu() as we expect a reject */
6479 l3_lu := f_build_lu_imsi(g_pars.imsi)
6480 f_create_gsup_expect(hex2str(g_pars.imsi));
6481 f_bssap_compl_l3(l3_lu);
6482 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6483
6484 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006485 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006486 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006487}
6488testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
6489 var BSC_ConnHdlr vc_conn;
6490 f_init();
6491 f_vty_config(MSCVTY, "network", "authentication required");
6492 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6493
6494 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
6495 vc_conn.done;
6496}
6497
6498private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6499 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006500
6501 pars.net.expect_auth := true;
6502 pars.net.expect_imei_early := true;
6503 pars.net.check_imei_error := true;
6504 f_init_handler(pars);
6505
6506 /* Cannot use f_perform_lu() as we expect a reject */
6507 l3_lu := f_build_lu_imsi(g_pars.imsi)
6508 f_create_gsup_expect(hex2str(g_pars.imsi));
6509 f_bssap_compl_l3(l3_lu);
6510 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6511
6512 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006513 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006514 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006515}
6516testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
6517 var BSC_ConnHdlr vc_conn;
6518 f_init();
6519 f_vty_config(MSCVTY, "network", "authentication required");
6520 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6521
6522 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
6523 vc_conn.done;
6524}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006525
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006526friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6527 f_init_handler(pars);
6528 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6529
6530 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
6531 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
6532 * will cause a use-after-free after that event dispatch. */
6533 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
6534 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
6535 cpars.rtp_sdp_format := "FOO/8000";
6536 cpars.expect_release := true;
6537
6538 f_perform_lu();
6539 f_mo_call_establish(cpars);
6540}
6541testcase TC_invalid_mgcp_crash() runs on MTC_CT {
6542 var BSC_ConnHdlr vc_conn;
6543 f_init();
6544
6545 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
6546 vc_conn.done;
6547}
6548
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006549friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
6550runs on BSC_ConnHdlr {
6551 pars.tmsi := 'FFFFFFFF'O;
6552 f_init_handler(pars);
6553
6554 f_create_gsup_expect(hex2str(g_pars.imsi));
6555
6556 /* Initiate Location Updating using an unknown TMSI */
6557 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
6558
6559 /* Expect an Identity Request, send response with no identity */
6560 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
6561 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
6562 lengthIndicator := 1,
6563 mobileIdentityV := {
6564 typeOfIdentity := '000'B,
6565 oddEvenInd_identity := {
6566 no_identity := {
6567 oddevenIndicator := '0'B,
6568 fillerDigits := '00000'H
6569 }
6570 }
6571 }
6572 })));
6573
6574 f_expect_lu_reject();
6575 f_expect_clear();
6576}
6577testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
6578 var BSC_ConnHdlr vc_conn;
6579
6580 f_init();
6581
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006582 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7, verify_cell_id := false);
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006583 vc_conn.done;
6584}
6585
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006586/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6587 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6588 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6589friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6590runs on BSC_ConnHdlr {
6591 var charstring imsi := hex2str(pars.imsi);
6592
6593 f_init_handler(pars);
6594
6595 /* Perform location update */
6596 f_perform_lu();
6597
6598 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6599 f_create_gsup_expect(hex2str(g_pars.imsi));
6600
6601 /* Initiate paging procedure from the VTY */
6602 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6603 f_expect_paging();
6604
6605 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6606 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6607
6608 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6609 f_establish_fully(EST_TYPE_PAG_RESP);
6610
6611 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6612 * In this case we do not send anything and just wait for a Clear Command. */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006613 f_expect_clear(verify_vlr_cell_id := false);
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006614}
6615testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6616 var BSC_ConnHdlr vc_conn;
6617
6618 f_init();
6619
6620 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6621 vc_conn.done;
6622}
6623
Harald Weltef6dd64d2017-11-19 12:09:51 +01006624control {
Philipp Maier328d1662018-03-07 10:40:27 +01006625 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006626 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01006627 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006628 execute( TC_lu_imsi_reject() );
6629 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01006630 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02006631 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01006632 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01006633 execute( TC_cmserv_imsi_unknown() );
Neels Hofmeyr13737fb2020-08-19 13:16:14 +00006634 execute( TC_cmserv_tmsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01006635 execute( TC_lu_and_mo_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006636 execute( TC_lu_and_mo_call_ipv6() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01006637 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01006638 execute( TC_lu_auth_sai_timeout() );
6639 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006640 execute( TC_lu_clear_request() );
Vadim Yanitskiy109e7552021-02-05 05:36:02 +01006641 execute( TC_mo_call_clear_request() );
6642 execute( TC_mt_call_clear_request() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006643 execute( TC_lu_disconnect() );
6644 execute( TC_lu_by_imei() );
6645 execute( TC_lu_by_tmsi_noauth_unknown() );
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00006646 execute( TC_attached_imsi_lu_unknown_tmsi() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006647 execute( TC_imsi_detach_by_imsi() );
6648 execute( TC_imsi_detach_by_tmsi() );
6649 execute( TC_imsi_detach_by_imei() );
6650 execute( TC_emerg_call_imei_reject() );
6651 execute( TC_emerg_call_imsi() );
6652 execute( TC_cm_serv_req_vgcs_reject() );
6653 execute( TC_cm_serv_req_vbs_reject() );
6654 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01006655 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01006656 execute( TC_lu_auth_2G_fail() );
6657 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
6658 execute( TC_cl3_no_payload() );
6659 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01006660 execute( TC_establish_and_nothing() );
6661 execute( TC_mo_setup_and_nothing() );
6662 execute( TC_mo_crcx_ran_timeout() );
6663 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01006664 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01006665 execute( TC_mo_setup_and_dtmf_dup() );
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01006666 execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01006667 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01006668 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
6669 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
6670 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01006671 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01006672 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
6673 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Eric Wild26f4a622021-05-17 15:27:05 +02006674 execute( TC_lu_imsi_auth_tmsi_encr_0134_1() );
6675 execute( TC_lu_imsi_auth_tmsi_encr_0134_34() );
6676 execute( TC_lu_imsi_auth_tmsi_encr_0134_34_no_cm3() );
6677
Philipp Maier94f3f1b2018-03-15 18:54:13 +01006678 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01006679 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02006680 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006681
6682 execute( TC_lu_and_mt_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006683 execute( TC_lu_and_mt_call_ipv6() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006684 execute( TC_lu_and_mt_call_already_paging() );
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +02006685 execute( TC_lu_and_mt_call_osmux() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006686
Harald Weltef45efeb2018-04-09 18:19:24 +02006687 execute( TC_lu_and_mo_sms() );
6688 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006689 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01006690 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02006691 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02006692 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07006693 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02006694 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02006695
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006696 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07006697 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07006698 execute( TC_gsup_mt_sms_ack() );
6699 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07006700 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07006701 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07006702 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006703
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006704 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006705 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006706 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006707 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07006708 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07006709 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07006710
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006711 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07006712 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07006713 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07006714 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07006715 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006716
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01006717 execute( TC_multi_lu_and_mo_ussd() );
6718 execute( TC_multi_lu_and_mt_ussd() );
6719
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006720 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01006721 execute( TC_cipher_complete_1_without_cipher() );
6722 execute( TC_cipher_complete_3_without_cipher() );
6723 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02006724 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006725
Harald Welte4263c522018-12-06 11:56:27 +01006726 execute( TC_sgsap_reset() );
6727 execute( TC_sgsap_lu() );
6728 execute( TC_sgsap_lu_imsi_reject() );
6729 execute( TC_sgsap_lu_and_nothing() );
6730 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01006731 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01006732 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01006733 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01006734 execute( TC_sgsap_paging_rej() );
6735 execute( TC_sgsap_paging_subscr_rej() );
6736 execute( TC_sgsap_paging_ue_unr() );
6737 execute( TC_sgsap_paging_and_nothing() );
6738 execute( TC_sgsap_paging_and_lu() );
6739 execute( TC_sgsap_mt_sms() );
6740 execute( TC_sgsap_mo_sms() );
6741 execute( TC_sgsap_mt_sms_and_nothing() );
6742 execute( TC_sgsap_mt_sms_and_reject() );
6743 execute( TC_sgsap_unexp_ud() );
6744 execute( TC_sgsap_unsol_ud() );
6745 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
6746 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02006747 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01006748
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006749 execute( TC_ho_inter_bsc_unknown_cell() );
6750 execute( TC_ho_inter_bsc() );
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02006751 execute( TC_ho_inter_bsc_a5_1() );
6752 execute( TC_ho_inter_bsc_a5_3() );
6753 execute( TC_ho_inter_bsc_a5_4() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006754 execute( TC_ho_inter_bsc_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006755
6756 execute( TC_ho_inter_msc_out() );
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006757 execute( TC_ho_inter_msc_out_a5_1() );
6758 execute( TC_ho_inter_msc_out_a5_3() );
6759 execute( TC_ho_inter_msc_out_a5_4() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006760 execute( TC_ho_inter_msc_out_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006761
Oliver Smith1d118ff2019-07-03 10:57:35 +02006762 execute( TC_lu_imsi_auth_tmsi_check_imei() );
6763 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
6764 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
6765 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
6766 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
6767 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
6768 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
6769 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
6770 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
6771 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
6772 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
6773 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01006774 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Pau Espin Pedrol609f1d62020-09-15 16:01:55 +02006775
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02006776 execute( TC_mo_cc_bssmap_clear() );
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006777 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006778 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006779 execute( TC_lu_and_expire_while_paging() );
Pau Espin Pedrol174fac22021-02-26 13:20:10 +01006780 execute( TC_paging_response_imsi_unknown() );
6781 execute( TC_paging_response_tmsi_unknown() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01006782}
6783
6784
6785}