blob: 659ac36a632d51c5559b04fda1f3ae0c12c89bee [file] [log] [blame]
Harald Welte28d943e2017-11-25 15:00:50 +01001module MSC_ConnectionHandler {
2
3import from General_Types all;
4import from Osmocom_Types all;
Harald Weltec1a2fff2017-12-17 11:06:19 +01005import from GSM_Types all;
Harald Welte28d943e2017-11-25 15:00:50 +01006import from SCCPasp_Types all;
7import from BSSAP_Types all;
8import from BSSMAP_Emulation all;
9import from BSSMAP_Templates all;
10
Harald Welte211219e2018-01-29 22:03:36 +010011import from IPL4asp_Types all;
12import from Native_Functions all;
13
Harald Welte28d943e2017-11-25 15:00:50 +010014import from MGCP_Types all;
15import from MGCP_Templates all;
Daniel Willmann191e0d92018-01-17 12:44:35 +010016import from MGCP_Emulation all;
Harald Welte28d943e2017-11-25 15:00:50 +010017import from SDP_Types all;
18
Harald Weltec1a2fff2017-12-17 11:06:19 +010019import from RSL_Emulation all;
20import from RSL_Types all;
21
22import from MobileL3_Types all;
23import from MobileL3_CommonIE_Types all;
Harald Welte211219e2018-01-29 22:03:36 +010024import from MobileL3_RRM_Types all;
Harald Weltec1a2fff2017-12-17 11:06:19 +010025import from L3_Templates all;
26
Harald Weltec20b1c42018-02-12 20:50:08 +010027import from TELNETasp_PortType all;
28import from Osmocom_VTY_Functions all;
29
Harald Weltec1a2fff2017-12-17 11:06:19 +010030
Harald Welte211219e2018-01-29 22:03:36 +010031/***********************************************************************
32 * Media related handling
33 ***********************************************************************/
34
35/* Tuple containing host/ip and port */
36type record HostPort {
37 HostName host,
38 PortNumber port_nr
39};
40
41/* State encapsulating one MGCP Connection */
42type record MgcpConnState {
43 boolean crcx_seen,
44 MgcpConnectionId conn_id,
45 charstring mime_type, /* e.g. AMR */
46 integer sample_rate, /* 8000 */
47 integer ptime, /* 20 */
48 uint7_t rtp_pt, /* RTP Payload Type */
49 HostPort mgw, /* MGW side */
50 HostPort peer /* CA side */
51};
52
53/* BTS media state */
54type record BtsMediaState {
55 boolean ipa_crcx_seen,
56 uint16_t conn_id,
57 uint7_t rtp_pt,
58 HostPort bts,
59 HostPort peer
60};
61
62type record MediaState {
63 MgcpEndpoint mgcp_ep,
64 MgcpConnState mgcp_conn[2],
Harald Welte261af4b2018-02-12 21:20:39 +010065 BtsMediaState bts,
66 BtsMediaState bts1 /* only during hand-over */
Harald Welte211219e2018-01-29 22:03:36 +010067};
68
69function f_MediaState_init(inout MediaState g_media, integer nr, HostName bts, HostName mgw) {
70 /* BTS Side */
71 g_media.bts := {
72 ipa_crcx_seen := false,
73 conn_id := nr,
74 rtp_pt := 0,
75 bts := {
76 host := bts,
77 port_nr := 9000 + nr*2
78 },
79 peer := -
80 }
81
Harald Welte261af4b2018-02-12 21:20:39 +010082 g_media.bts1 := {
83 ipa_crcx_seen := false,
84 conn_id := nr,
85 rtp_pt := 0,
86 bts := {
87 host := bts, /* FIXME */
88 port_nr := 9000 + nr*2
89 },
90 peer := -
91 }
92
Harald Welte363cb0a2018-01-30 19:35:53 +010093 g_media.mgcp_ep := "rtpbridge/" & int2str(nr) & "@mgw";
Harald Welte211219e2018-01-29 22:03:36 +010094
95 for (var integer i:= 0; i < sizeof(g_media.mgcp_conn); i := i+1) {
96 g_media.mgcp_conn[i].mime_type := "AMR";
97 g_media.mgcp_conn[i].sample_rate := 8000;
98 g_media.mgcp_conn[i].ptime := 20;
99 g_media.mgcp_conn[i].rtp_pt := 98;
100 g_media.mgcp_conn[i].crcx_seen := false;
101 g_media.mgcp_conn[i].conn_id := f_mgcp_alloc_conn_id();
102 }
103
104 g_media.mgcp_conn[0].mgw := {
105 host := mgw,
106 port_nr := 10000 + nr*2
107 }
108 g_media.mgcp_conn[1].mgw := {
109 host := mgw,
110 port_nr := 11000 + nr*2
111 }
112}
113
114private function f_get_free_mgcp_conn() runs on MSC_ConnHdlr return integer {
115 for (var integer i:= 0; i < sizeof(g_media.mgcp_conn); i := i+1) {
116 if (not g_media.mgcp_conn[i].crcx_seen) {
117 return i;
118 }
119 }
120 setverdict(fail, "Only 2 Connections per EP!");
121 self.stop;
122 return -1;
123}
124
125private function f_get_mgcp_conn(MgcpConnectionId cid) runs on MSC_ConnHdlr return integer {
126 for (var integer i:= 0; i < sizeof(g_media.mgcp_conn); i := i+1) {
127 if (g_media.mgcp_conn[i].conn_id == cid and g_media.mgcp_conn[i].crcx_seen) {
128 return i;
129 }
130 }
131 setverdict(fail, "No Connection for ID ", cid);
132 self.stop;
133 return -1;
134}
135
136
137/* altstep for handling of IPA + MGCP media related commands. Can be activated by a given
138 * test case if it expects to see media related handling (i.e. voice calls */
139altstep as_Media() runs on MSC_ConnHdlr {
140 var RSL_Message rsl;
141 var MgcpCommand mgcp_cmd;
142 var RSL_IE_Body ie;
143 [not g_media.bts.ipa_crcx_seen] RSL.receive(tr_RSL_IPA_CRCX(g_chan_nr)) -> value rsl {
144 /* Extract parameters from request + use in response */
145 if (f_rsl_find_ie(rsl, RSL_IE_IPAC_RTP_PAYLOAD, ie)) {
146 g_media.bts.rtp_pt := ie.ipa_rtp_pt;
147 }
148 if (f_rsl_find_ie(rsl, RSL_IE_IPAC_RTP_PAYLOAD2, ie)) {
149 g_media.bts.rtp_pt := ie.ipa_rtp_pt2;
150 }
151 RSL.send(ts_RSL_IPA_CRCX_ACK(g_chan_nr, g_media.bts.conn_id,
152 oct2int(f_inet_addr(g_media.bts.bts.host)),
153 g_media.bts.bts.port_nr,
154 g_media.bts.rtp_pt));
155 g_media.bts.ipa_crcx_seen := true;
156 repeat;
157 }
158 [g_media.bts.ipa_crcx_seen] RSL.receive(tr_RSL_IPA_MDCX(g_chan_nr, ?)) -> value rsl{
159 /* Extract conn_id, ip, port, rtp_pt2 from request + use in response */
160 f_rsl_find_ie(rsl, RSL_IE_IPAC_CONN_ID, ie);
161 if (g_media.bts.conn_id != ie.ipa_conn_id) {
162 setverdict(fail, "IPA MDCX for unknown ConnId", rsl);
163 self.stop;
164 }
165 /* mandatory */
166 f_rsl_find_ie(rsl, RSL_IE_IPAC_REMOTE_IP, ie);
167 g_media.bts.peer.host := f_inet_ntoa(int2oct(ie.ipa_remote_ip, 4));
168 f_rsl_find_ie(rsl, RSL_IE_IPAC_REMOTE_PORT, ie);
169 g_media.bts.peer.port_nr := ie.ipa_remote_port;
170 /* optional */
171 if (f_rsl_find_ie(rsl, RSL_IE_IPAC_RTP_PAYLOAD, ie)) {
172 g_media.bts.rtp_pt := ie.ipa_rtp_pt;
173 }
174 if (f_rsl_find_ie(rsl, RSL_IE_IPAC_RTP_PAYLOAD2, ie)) {
175 g_media.bts.rtp_pt := ie.ipa_rtp_pt2;
176 }
177 RSL.send(ts_RSL_IPA_MDCX_ACK(g_chan_nr, g_media.bts.conn_id,
178 oct2int(f_inet_addr(g_media.bts.peer.host)),
179 g_media.bts.peer.port_nr,
180 g_media.bts.rtp_pt));
Harald Welte261af4b2018-02-12 21:20:39 +0100181 //g_media.bts.ipa_mdcx_seen := true;
Harald Welte211219e2018-01-29 22:03:36 +0100182 repeat;
183 }
Harald Welte261af4b2018-02-12 21:20:39 +0100184
185 /* on second (new) BTS during hand-over */
186 [not g_media.bts1.ipa_crcx_seen] RSL1.receive(tr_RSL_IPA_CRCX(g_chan_nr)) -> value rsl {
187 /* Extract parameters from request + use in response */
188 if (f_rsl_find_ie(rsl, RSL_IE_IPAC_RTP_PAYLOAD, ie)) {
189 g_media.bts1.rtp_pt := ie.ipa_rtp_pt;
190 }
191 if (f_rsl_find_ie(rsl, RSL_IE_IPAC_RTP_PAYLOAD2, ie)) {
192 g_media.bts1.rtp_pt := ie.ipa_rtp_pt2;
193 }
194 RSL1.send(ts_RSL_IPA_CRCX_ACK(g_chan_nr, g_media.bts1.conn_id,
195 oct2int(f_inet_addr(g_media.bts1.bts.host)),
196 g_media.bts1.bts.port_nr,
197 g_media.bts1.rtp_pt));
198 g_media.bts1.ipa_crcx_seen := true;
199 repeat;
200 }
201 /* on second (new) BTS during hand-over */
202 [g_media.bts1.ipa_crcx_seen] RSL1.receive(tr_RSL_IPA_MDCX(g_chan_nr, ?)) -> value rsl{
203 /* Extract conn_id, ip, port, rtp_pt2 from request + use in response */
204 f_rsl_find_ie(rsl, RSL_IE_IPAC_CONN_ID, ie);
205 if (g_media.bts1.conn_id != ie.ipa_conn_id) {
206 setverdict(fail, "IPA MDCX for unknown ConnId", rsl);
207 self.stop;
208 }
209 /* mandatory */
210 f_rsl_find_ie(rsl, RSL_IE_IPAC_REMOTE_IP, ie);
211 g_media.bts1.peer.host := f_inet_ntoa(int2oct(ie.ipa_remote_ip, 4));
212 f_rsl_find_ie(rsl, RSL_IE_IPAC_REMOTE_PORT, ie);
213 g_media.bts1.peer.port_nr := ie.ipa_remote_port;
214 /* optional */
215 if (f_rsl_find_ie(rsl, RSL_IE_IPAC_RTP_PAYLOAD, ie)) {
216 g_media.bts1.rtp_pt := ie.ipa_rtp_pt;
217 }
218 if (f_rsl_find_ie(rsl, RSL_IE_IPAC_RTP_PAYLOAD2, ie)) {
219 g_media.bts1.rtp_pt := ie.ipa_rtp_pt2;
220 }
221 RSL1.send(ts_RSL_IPA_MDCX_ACK(g_chan_nr, g_media.bts1.conn_id,
222 oct2int(f_inet_addr(g_media.bts1.peer.host)),
223 g_media.bts1.peer.port_nr,
224 g_media.bts1.rtp_pt));
225 //g_media.bts1.ipa_mdcx_seen := true;
226 repeat;
227 }
228
Harald Welte211219e2018-01-29 22:03:36 +0100229 [] MGCP.receive(tr_CRCX) -> value mgcp_cmd {
230 var SDP_Message sdp;
231 var integer cid := f_get_free_mgcp_conn();
Harald Welte363cb0a2018-01-30 19:35:53 +0100232 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
233 if (cid != 0) {
234 setverdict(fail, "MGCP wildcard EP only works in first CRCX");
235 self.stop;
236 }
237 /* we keep the endpoint name allocated during MediaState_init */
238 } else {
239 /* Call Agent allocated endpoint, trust/use it always */
240 g_media.mgcp_ep := mgcp_cmd.line.ep;
241 }
Harald Welte211219e2018-01-29 22:03:36 +0100242 if (isvalue(mgcp_cmd.sdp)) {
243 sdp := mgcp_cmd.sdp;
244 g_media.mgcp_conn[cid].peer.host := sdp.connection.conn_addr.addr;
245 g_media.mgcp_conn[cid].peer.port_nr := sdp.media_list[0].media_field.ports.port_number;
246 }
247 var MgcpConnState mgcp_conn := g_media.mgcp_conn[cid];
248 sdp := valueof(ts_SDP(mgcp_conn.mgw.host, mgcp_conn.mgw.host, "foo", "21",
249 mgcp_conn.mgw.port_nr, { int2str(mgcp_conn.rtp_pt) },
250 {valueof(ts_SDP_rtpmap(mgcp_conn.rtp_pt,
251 mgcp_conn.mime_type & "/" &
252 int2str(mgcp_conn.sample_rate))),
253 valueof(ts_SDP_ptime(mgcp_conn.ptime)) } ));
Harald Welte363cb0a2018-01-30 19:35:53 +0100254 var template MgcpResponse mgcp_resp;
255 mgcp_resp := ts_CRCX_ACK(mgcp_cmd.line.trans_id, mgcp_conn.conn_id, sdp);
256 f_mgcp_par_append(mgcp_resp.params, ts_MgcpParSpecEP(g_media.mgcp_ep));
257 MGCP.send(mgcp_resp);
Harald Welte211219e2018-01-29 22:03:36 +0100258 g_media.mgcp_conn[cid].crcx_seen := true;
259 repeat;
260 }
261 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
262 var SDP_Message sdp;
263 var integer cid := f_get_mgcp_conn(f_MgcpCmd_extract_conn_id(mgcp_cmd));
264 if (isvalue(mgcp_cmd.sdp)) {
265 sdp := mgcp_cmd.sdp;
266 g_media.mgcp_conn[cid].peer.host := sdp.connection.conn_addr.addr;
267 g_media.mgcp_conn[cid].peer.port_nr := sdp.media_list[0].media_field.ports.port_number;
268 } else {
269 setverdict(fail, "MDCX has no [recognizable] SDP");
Harald Welte211219e2018-01-29 22:03:36 +0100270 }
271 var MgcpConnState mgcp_conn := g_media.mgcp_conn[cid];
272 sdp := valueof(ts_SDP(mgcp_conn.peer.host, mgcp_conn.peer.host, "foo", "21",
273 mgcp_conn.peer.port_nr, { int2str(mgcp_conn.rtp_pt) },
274 {valueof(ts_SDP_rtpmap(mgcp_conn.rtp_pt,
275 mgcp_conn.mime_type & "/" &
276 int2str(mgcp_conn.sample_rate))),
277 valueof(ts_SDP_ptime(mgcp_conn.ptime)) } ));
278 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, mgcp_conn.conn_id, sdp));
Harald Welte261af4b2018-02-12 21:20:39 +0100279 //g_media.mgcp_mdcx_seen := true;
Harald Welte211219e2018-01-29 22:03:36 +0100280 repeat;
281 }
282}
283
284
285
286
Harald Welte28d943e2017-11-25 15:00:50 +0100287/* this component represents a single subscriber connection at the MSC.
288 * There is a 1:1 mapping between SCCP connections and BSSAP_ConnHdlr components.
289 * We inherit all component variables, ports, functions, ... from BSSAP_ConnHdlr */
Daniel Willmann191e0d92018-01-17 12:44:35 +0100290type component MSC_ConnHdlr extends BSSAP_ConnHdlr, RSL_DchanHdlr, MGCP_ConnHdlr {
Harald Welte28d943e2017-11-25 15:00:50 +0100291 /* SCCP Connecction Identifier for the underlying SCCP connection */
292 var integer g_sccp_conn_id;
293
Harald Weltec1a2fff2017-12-17 11:06:19 +0100294 /* procedure port back to our parent (BSSMAP_Emulation_CT) for control */
295 port BSSMAPEM_PROC_PT BSSMAPEM;
Harald Weltec20b1c42018-02-12 20:50:08 +0100296 port TELNETasp_PT BSCVTY;
Harald Welte28d943e2017-11-25 15:00:50 +0100297
Harald Welte211219e2018-01-29 22:03:36 +0100298 var MediaState g_media;
Harald Weltea0630032018-03-20 21:09:55 +0100299 var TestHdlrParams g_pars;
Harald Weltee97eab42018-03-21 18:46:06 +0100300
301 var boolean g_vty_initialized := false;
Harald Welte211219e2018-01-29 22:03:36 +0100302}
303
304/* initialize all parameters */
305function f_MscConnHdlr_init(integer i, HostName bts, HostName mgw) runs on MSC_ConnHdlr {
306 f_MediaState_init(g_media, i, bts, mgw);
Harald Weltee97eab42018-03-21 18:46:06 +0100307 if (not g_vty_initialized) {
308 map(self:BSCVTY, system:BSCVTY);
309 f_vty_set_prompts(BSCVTY);
310 f_vty_transceive(BSCVTY, "enable");
311 g_vty_initialized := true;
312 }
Harald Welte28d943e2017-11-25 15:00:50 +0100313}
314
315/* Callback function from general BSSMAP_Emulation whenever a connectionless
316 * BSSMAP message arrives. Can retunr a PDU_BSSAP that should be sent in return */
317private function UnitdataCallback(PDU_BSSAP bssap)
318runs on BSSMAP_Emulation_CT return template PDU_BSSAP {
319 var template PDU_BSSAP resp := omit;
320
Harald Weltec1a2fff2017-12-17 11:06:19 +0100321 /* answer all RESET with a RESET ACK */
Harald Welte28d943e2017-11-25 15:00:50 +0100322 if (match(bssap, tr_BSSMAP_Reset)) {
323 resp := ts_BSSMAP_ResetAck;
324 }
325
326 return resp;
327}
328
329const BssmapOps MSC_BssmapOps := {
Harald Weltec1a2fff2017-12-17 11:06:19 +0100330 create_cb := refers(BSSMAP_Emulation.ExpectedCreateCallback),
Harald Welte0b476062018-01-21 19:07:32 +0100331 unitdata_cb := refers(UnitdataCallback),
332 decode_dtap := false,
333 role_ms := false
Harald Welte28d943e2017-11-25 15:00:50 +0100334}
335
Daniel Willmann191e0d92018-01-17 12:44:35 +0100336const MGCPOps MSC_MGCPOps := {
337 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback)
338}
339
Harald Weltec1a2fff2017-12-17 11:06:19 +0100340/* register an expect with the BSSMAP core */
Daniel Willmann191e0d92018-01-17 12:44:35 +0100341private function f_create_bssmap_exp(octetstring l3_enc) runs on MSC_ConnHdlr {
Harald Weltec1a2fff2017-12-17 11:06:19 +0100342 BSSMAPEM.call(BSSMAPEM_register:{l3_enc, self}) {
343 [] BSSMAPEM.getreply(BSSMAPEM_register:{?, ?}) {};
Harald Welte28d943e2017-11-25 15:00:50 +0100344 }
345}
346
Harald Weltec1a2fff2017-12-17 11:06:19 +0100347type record TestHdlrParams {
348 OCT1 ra,
349 GsmFrameNumber fn,
350 hexstring imsi,
Harald Welte60aa5762018-03-21 19:33:13 +0100351 RslLinkId link_id,
352 BSSMAP_IE_SpeechCodecList ass_codec_list optional
Harald Weltec1a2fff2017-12-17 11:06:19 +0100353};
354
355template (value) TestHdlrParams t_def_TestHdlrPars := {
356 ra := '23'O,
357 fn := 23,
358 imsi := '001019876543210'H,
Harald Welte60aa5762018-03-21 19:33:13 +0100359 link_id := valueof(ts_RslLinkID_DCCH(0)),
360 ass_codec_list := omit
Harald Weltec1a2fff2017-12-17 11:06:19 +0100361}
362
Harald Weltea0630032018-03-20 21:09:55 +0100363function f_create_chan_and_exp() runs on MSC_ConnHdlr {
364 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100365 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltec1a2fff2017-12-17 11:06:19 +0100366 var octetstring l3_enc := enc_PDU_ML3_MS_NW(l3_info);
367
368 /* call helper function for CHAN_RQD -> IMM ASS ->EST_IND */
Harald Weltea0630032018-03-20 21:09:55 +0100369 RSL_Emulation.f_chan_est(g_pars.ra, l3_enc, g_pars.link_id, g_pars.fn);
Daniel Willmann191e0d92018-01-17 12:44:35 +0100370 f_create_bssmap_exp(l3_enc);
Harald Weltec1a2fff2017-12-17 11:06:19 +0100371}
372
Harald Welte898113b2018-01-31 18:32:21 +0100373function f_rsl_send_l3(template PDU_ML3_MS_NW l3, template (omit) RslLinkId link_id := omit,
374 template (omit) RslChannelNr chan_nr := omit) runs on MSC_ConnHdlr {
375 if (not isvalue(link_id)) {
376 link_id := ts_RslLinkID_DCCH(0);
377 }
378 if (not isvalue(chan_nr)) {
379 chan_nr := g_chan_nr;
380 }
381 RSL.send(ts_RSL_DATA_IND(valueof(chan_nr), valueof(link_id), enc_PDU_ML3_MS_NW(valueof(l3))));
382}
383
Harald Weltec1a2fff2017-12-17 11:06:19 +0100384function f_rsl_reply(template PDU_ML3_MS_NW l3, RSL_Message orig) runs on MSC_ConnHdlr {
385 var RslChannelNr chan_nr := orig.ies[0].body.chan_nr;
Harald Welte1a40de62017-12-23 02:28:34 +0100386 var RslLinkId link_id;
Harald Welte8d5eead2017-12-17 18:56:45 +0100387 if (orig.msg_type == RSL_MT_ENCR_CMD) {
388 link_id := orig.ies[2].body.link_id;
389 } else {
390 link_id := orig.ies[1].body.link_id;
391 }
Harald Welte898113b2018-01-31 18:32:21 +0100392 f_rsl_send_l3(l3, link_id, chan_nr);
Harald Weltec1a2fff2017-12-17 11:06:19 +0100393}
394
Philipp Maierb20c3dc2018-02-07 18:36:25 +0100395/* Convert the chipher representation on BSSMAP to the representation used on RSL */
396function f_chipher_mode_bssmap_to_rsl(OCT1 alg_bssmap) return OCT1
397{
398 /* A5 0 */
399 if (alg_bssmap == '01'O) {
400 return '01'O;
401 }
402 /* A5 1 */
403 else if (alg_bssmap == '02'O) {
404 return '02'O;
405 }
406 /* A5 2 */
407 else if (alg_bssmap == '04'O) {
408 return '03'O;
409 }
410 /* A5 3 */
411 else if (alg_bssmap == '08'O) {
412 return '04'O;
413 }
414 /* A5 4 */
415 else if (alg_bssmap == '10'O) {
416 return '05'O;
417 }
418 /* A5 5 */
419 else if (alg_bssmap == '20'O) {
420 return '06'O;
421 }
422 /* A5 6 */
423 else if (alg_bssmap == '40'O) {
424 return '07'O;
425 }
426 /* A5 7 */
427 else if (alg_bssmap == '80'O) {
428 return '08'O;
429 } else {
430 setverdict(fail, "Unexpected Encryption Algorithm");
431 return '00'O;
432 }
433}
434
Harald Welte38b2a102017-12-23 02:42:58 +0100435function f_cipher_mode(OCT1 alg, OCT8 key, template OCT16 kc128 := omit, boolean exp_fail := false)
436runs on MSC_ConnHdlr {
Harald Welte73cd2712017-12-17 00:44:52 +0100437 var PDU_BSSAP bssap;
438 var RSL_Message rsl;
Philipp Maierb20c3dc2018-02-07 18:36:25 +0100439 var OCT1 alg_rsl;
Harald Welte73cd2712017-12-17 00:44:52 +0100440
441 if (isvalue(kc128)) {
442 BSSAP.send(ts_BSSMAP_CipherModeCmdKc128(alg, key, valueof(kc128)));
443 } else {
444 BSSAP.send(ts_BSSMAP_CipherModeCmd(alg, key));
445 }
Philipp Maierb20c3dc2018-02-07 18:36:25 +0100446
447 /* RSL uses a different representation of the encryption algorithm,
448 * so we need to convert first */
449 alg_rsl := f_chipher_mode_bssmap_to_rsl(alg);
450
Harald Welte73cd2712017-12-17 00:44:52 +0100451 alt {
452 /* RSL/UE Side */
Philipp Maierb20c3dc2018-02-07 18:36:25 +0100453 [] RSL.receive(tr_RSL_ENCR_CMD(g_chan_nr, ?, alg_rsl, key)) -> value rsl {
Harald Welte73cd2712017-12-17 00:44:52 +0100454 var PDU_ML3_NW_MS l3 := dec_PDU_ML3_NW_MS(rsl.ies[3].body.l3_info.payload);
455 log("Rx L3 from net: ", l3);
456 if (ischosen(l3.msgs.rrm.cipheringModeCommand)) {
457 f_rsl_reply(ts_RRM_CiphModeCompl, rsl);
458 }
459 repeat;
460 }
461 [] BSSAP.receive(tr_BSSMAP_CipherModeCompl) -> value bssap {
462 // bssap.bssmap.cipherModeComplete.chosenEncryptionAlgorithm.algoritmhIdentifier
Harald Welte38b2a102017-12-23 02:42:58 +0100463 if (exp_fail == true) {
464 setverdict(fail, "Unexpected Cipher Mode Complete");
465 } else {
466 setverdict(pass);
467 }
Harald Welte73cd2712017-12-17 00:44:52 +0100468 }
469 [] BSSAP.receive(tr_BSSMAP_CipherModeRej) -> value bssap {
Harald Welte38b2a102017-12-23 02:42:58 +0100470 if (exp_fail == false) {
471 setverdict(fail, "Ciphering Mode Reject");
472 } else {
473 setverdict(pass);
474 }
Harald Welte73cd2712017-12-17 00:44:52 +0100475 }
476 }
477}
478
Harald Welte211219e2018-01-29 22:03:36 +0100479/* Convert from Ericsson ChanDesc2 format to Osmocom RslChannelNr format */
480function f_ChDesc2RslChanNr(ChannelDescription2_V ch_desc, out RslChannelNr chan_nr, out GsmArfcn arfcn) {
481 var BIT5 inp := ch_desc.channelTypeandTDMAOffset;
Harald Welte6fa1f732018-03-21 22:46:16 +0100482 var uint3_t tn := bit2int(ch_desc.timeslotNumber);
Harald Welte211219e2018-01-29 22:03:36 +0100483
484 if (match(inp, '00001'B)) { /* TCH/F */
Harald Welte6fa1f732018-03-21 22:46:16 +0100485 chan_nr := valueof(t_RslChanNr_Bm(tn));
Harald Welte211219e2018-01-29 22:03:36 +0100486 }
487 else if (match(inp, '0001?'B)) { /* TCH/H */
Harald Welte6fa1f732018-03-21 22:46:16 +0100488 chan_nr := valueof(t_RslChanNr_Lm(tn, bit2int(substr(inp, 4, 1))));
Harald Welte211219e2018-01-29 22:03:36 +0100489 }
490 else if (match(inp, '001??'B)) { /* SDCCH/4 */
Harald Welte6fa1f732018-03-21 22:46:16 +0100491 chan_nr := valueof(t_RslChanNr_SDCCH4(tn, bit2int(substr(inp, 3, 2))));
Harald Welte211219e2018-01-29 22:03:36 +0100492 }
493 else if (match(inp, '01???'B)) { /* SDCCH/8 */
Harald Welte6fa1f732018-03-21 22:46:16 +0100494 chan_nr := valueof(t_RslChanNr_SDCCH8(tn, bit2int(substr(inp, 2, 3))));
Harald Welte211219e2018-01-29 22:03:36 +0100495 }
496 else {
497 setverdict(fail, "Unknown ChDesc!");
498 self.stop;
499 }
500
501 if (ch_desc.octet3 and4b '10'O == '10'O) {
502 setverdict(fail, "No support for Hopping");
503 self.stop;
504 } else {
505 var OCT2 concat := ch_desc.octet3 & ch_desc.octet4;
506 arfcn := oct2int(concat);
507 }
508}
509
510type record AssignmentState {
511 /* global */
512 boolean voice_call,
513 boolean is_assignment,
514 /* Assignment related bits */
515 boolean rr_ass_cmpl_seen,
Harald Welte21583082018-01-29 22:28:26 +0100516 boolean assignment_done,
Harald Welte211219e2018-01-29 22:03:36 +0100517 RslChannelNr old_chan_nr,
518 /* Modify related bits */
519 boolean rr_modify_seen,
Harald Welte21583082018-01-29 22:28:26 +0100520 boolean modify_done
Harald Welte211219e2018-01-29 22:03:36 +0100521}
522
523template (value) AssignmentState ts_AssignmentStateInit := {
524 voice_call := false,
525 is_assignment := false,
526 rr_ass_cmpl_seen := false,
Harald Welte21583082018-01-29 22:28:26 +0100527 assignment_done := false,
Harald Welte211219e2018-01-29 22:03:36 +0100528 old_chan_nr := -,
529 rr_modify_seen := false,
Harald Welte21583082018-01-29 22:28:26 +0100530 modify_done := false
Harald Welte211219e2018-01-29 22:03:36 +0100531}
532
533altstep as_assignment(inout AssignmentState st) runs on MSC_ConnHdlr {
Harald Weltec1a2fff2017-12-17 11:06:19 +0100534 var RSL_Message rsl;
Harald Welte211219e2018-01-29 22:03:36 +0100535 [not st.rr_ass_cmpl_seen] RSL.receive(tr_RSL_DATA_REQ(g_chan_nr)) -> value rsl {
536 var PDU_ML3_NW_MS l3 := dec_PDU_ML3_NW_MS(rsl.ies[2].body.l3_info.payload);
537 log("Rx L3 from net: ", l3);
538 if (ischosen(l3.msgs.rrm.assignmentCommand)) {
539 var RslChannelNr new_chan_nr;
540 var GsmArfcn arfcn;
541 f_ChDesc2RslChanNr(l3.msgs.rrm.assignmentCommand.descrOf1stChAfterTime,
542 new_chan_nr, arfcn);
543 /* FIXME: Determine TRX NR by ARFCN, instead of hard-coded TRX0! */
Harald Weltec1a2fff2017-12-17 11:06:19 +0100544
Harald Welte211219e2018-01-29 22:03:36 +0100545 /* register our component for this channel number at the RSL Emulation */
546 f_rslem_register(0, new_chan_nr);
547 var PDU_ML3_MS_NW l3_tx := valueof(ts_RRM_AssignmentComplete('00'O));
548 /* send assignment complete over the new channel */
549 RSL.send(ts_RSL_DATA_IND(new_chan_nr, valueof(ts_RslLinkID_DCCH(0)),
550 enc_PDU_ML3_MS_NW(l3_tx)));
551 /* by default, send via the new channel from now */
552 st.old_chan_nr := g_chan_nr;
553 g_chan_nr := new_chan_nr;
554 st.rr_ass_cmpl_seen := true;
555 repeat;
556 } else {
557 setverdict(fail, "Unexpected L3 received", l3);
558 self.stop;
Harald Weltec1a2fff2017-12-17 11:06:19 +0100559 }
Harald Welte211219e2018-01-29 22:03:36 +0100560 }
561 [st.rr_ass_cmpl_seen] RSL.receive(tr_RSL_REL_REQ(st.old_chan_nr, tr_RslLinkID_DCCH(0))) {
562 RSL.send(ts_RSL_REL_CONF(st.old_chan_nr, valueof(ts_RslLinkID_DCCH(0))));
563 repeat;
564 }
565 [st.rr_ass_cmpl_seen] RSL.receive(tr_RSL_RF_CHAN_REL(st.old_chan_nr)) {
566 RSL.send(ts_RSL_RF_CHAN_REL_ACK(st.old_chan_nr));
Harald Welte1909f462018-01-29 22:29:29 +0100567 /* unregister for old channel number in RSL emulation */
568 /* FIXME: Determine TRX NR by ARFCN, instead of hard-coded TRX0! */
569 f_rslem_unregister(0, st.old_chan_nr);
Harald Welte21583082018-01-29 22:28:26 +0100570 st.assignment_done := true;
Harald Welte211219e2018-01-29 22:03:36 +0100571 repeat;
572 }
573}
574
575altstep as_modify(inout AssignmentState st) runs on MSC_ConnHdlr {
576 /* no assignment, just mode modify */
577 var RSL_Message rsl;
578
579 [st.voice_call and not st.rr_modify_seen] RSL.receive(tr_RSL_DATA_REQ(g_chan_nr)) -> value rsl {
Harald Weltec1a2fff2017-12-17 11:06:19 +0100580 var PDU_ML3_NW_MS l3 := dec_PDU_ML3_NW_MS(rsl.ies[2].body.l3_info.payload);
581 log("Rx L3 from net: ", l3);
582 if (ischosen(l3.msgs.rrm.channelModeModify)) {
583 f_rsl_reply(ts_RRM_ModeModifyAck(l3.msgs.rrm.channelModeModify.channelDescription,
584 l3.msgs.rrm.channelModeModify.channelMode), rsl);
Harald Welte211219e2018-01-29 22:03:36 +0100585 st.rr_modify_seen := true;
Harald Weltec1a2fff2017-12-17 11:06:19 +0100586 }
587 repeat;
588 }
Harald Welte211219e2018-01-29 22:03:36 +0100589 [st.voice_call and st.rr_modify_seen] RSL.receive(tr_RSL_MsgTypeD(RSL_MT_MODE_MODIFY_REQ)) -> value rsl {
Harald Weltec1a2fff2017-12-17 11:06:19 +0100590 RSL.send(ts_RSL_MODE_MODIFY_ACK(g_chan_nr));
Harald Welte21583082018-01-29 22:28:26 +0100591 st.modify_done := true;
Harald Weltec1a2fff2017-12-17 11:06:19 +0100592 repeat;
593 }
Harald Welte211219e2018-01-29 22:03:36 +0100594}
Daniel Willmann191e0d92018-01-17 12:44:35 +0100595
Harald Welte211219e2018-01-29 22:03:36 +0100596/* Determine if given rsl_chan_nr is compatible with given BSSMAP ChannelType */
597function f_channel_compatible(BSSMAP_IE_ChannelType bssmap, RslChannelNr rsl_chan_nr)
598return boolean {
599 select (bssmap.speechOrDataIndicator) {
600 case ('0011'B) { /* Signalling */
601 /* all channels support signalling */
602 return true;
603 }
604 case else { /* Speech, Speech+CTM or CSD */
605 select (bssmap.channelRateAndType) {
606 case ('08'O) { /* TCH/F */
607 select (rsl_chan_nr) {
608 case (t_RslChanNr_Bm(?)) { return true; }
609 }
610 }
611 case ('09'O) { /* TCH/H */
612 select (rsl_chan_nr) {
613 case (t_RslChanNr_Lm(?, ?)) { return true; }
614 }
615 }
616 case else { /* full or half-rate */
617 select (rsl_chan_nr) {
618 case (t_RslChanNr_Bm(?)) { return true; }
619 case (t_RslChanNr_Lm(?, ?)) { return true; }
620 }
621 }
622 }
Harald Weltec1a2fff2017-12-17 11:06:19 +0100623 }
Harald Welte211219e2018-01-29 22:03:36 +0100624 }
625 return false;
626}
Daniel Willmann191e0d92018-01-17 12:44:35 +0100627
Harald Welte211219e2018-01-29 22:03:36 +0100628/* establish a channel fully, expecting an assignment matching 'exp' */
Harald Weltea0630032018-03-20 21:09:55 +0100629function f_establish_fully(PDU_BSSAP ass_cmd, template PDU_BSSAP exp_ass_cpl)
Harald Welte211219e2018-01-29 22:03:36 +0100630runs on MSC_ConnHdlr return PDU_BSSAP {
631 var PDU_BSSAP bssap;
632 timer T := 10.0;
633 var boolean exp_compl := ischosen(exp_ass_cpl.pdu.bssmap.assignmentComplete);
Philipp Maier86f39202018-02-07 14:40:09 +0100634 var boolean exp_fail := ischosen(exp_ass_cpl.pdu.bssmap.assignmentFailure);
Harald Welte211219e2018-01-29 22:03:36 +0100635 var ExpectCriteria mgcpcrit := {
636 connid := omit,
637 endpoint := omit,
638 transid := omit
639 };
640 var AssignmentState st := valueof(ts_AssignmentStateInit);
641 /* if the channel type is SIGNAL, we're not handling a voice call */
642 if (ass_cmd.pdu.bssmap.assignmentRequest.channelType.speechOrDataIndicator != '0011'B) {
643 st.voice_call := true;
644 }
645 /* determine if the current channel can support the given service or not */
646 if (not f_channel_compatible(ass_cmd.pdu.bssmap.assignmentRequest.channelType, g_chan_nr)) {
647 st.is_assignment := true;
648 }
649
Harald Weltec20b1c42018-02-12 20:50:08 +0100650 f_MscConnHdlr_init(1, "127.0.0.2", "127.0.0.3");
Harald Welte211219e2018-01-29 22:03:36 +0100651
Harald Weltea0630032018-03-20 21:09:55 +0100652 f_create_chan_and_exp();
Harald Welte211219e2018-01-29 22:03:36 +0100653 /* we should now have a COMPL_L3 at the MSC */
654 BSSAP.receive(tr_BSSMAP_ComplL3);
655 f_create_mgcp_expect(mgcpcrit);
656 BSSAP.send(ass_cmd);
657
658 T.start;
659 alt {
660 /* assignment related bits */
661 [st.is_assignment] as_assignment(st);
662
663 /* modify related bits */
664 [not st.is_assignment] as_modify(st);
665
666 /* voice call related bits (IPA CRCX/MDCX + MGCP) */
667 [st.voice_call] as_Media();
668
669 /* if we receive exactly what we expected, always return + pass */
Harald Welte21583082018-01-29 22:28:26 +0100670 [st.is_assignment and st.assignment_done or
671 (not st.is_assignment and st.modify_done)] BSSAP.receive(exp_ass_cpl) -> value bssap {
Harald Welte211219e2018-01-29 22:03:36 +0100672 setverdict(pass);
673 }
Philipp Maier86f39202018-02-07 14:40:09 +0100674 [exp_fail] BSSAP.receive(exp_ass_cpl) -> value bssap {
675 setverdict(pass);
676 }
Harald Welte21583082018-01-29 22:28:26 +0100677 [(st.is_assignment and st.assignment_done or
678 (not st.is_assignment and st.modify_done)) and
679 exp_compl] BSSAP.receive(tr_BSSMAP_AssignmentComplete) {
Harald Weltec1a2fff2017-12-17 11:06:19 +0100680 setverdict(fail, "Received non-matching ASSIGNMENT COMPLETE");
681 }
682 [exp_compl] BSSAP.receive(tr_BSSMAP_AssignmentFail) {
683 setverdict(fail, "Received unexpected ASSIGNMENT FAIL");
684 }
685 [not exp_compl] BSSAP.receive(tr_BSSMAP_AssignmentComplete) {
686 setverdict(fail, "Received unexpected ASSIGNMENT COMPLETE");
687 }
688 [not exp_compl] BSSAP.receive(tr_BSSMAP_AssignmentFail) {
689 setverdict(fail, "Received non-matching ASSIGNMENT FAIL");
690 }
691 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100692 setverdict(fail, "Timeout waiting for ASSIGNMENT COMPLETE");
Harald Weltec1a2fff2017-12-17 11:06:19 +0100693 }
694 }
Harald Welte211219e2018-01-29 22:03:36 +0100695 log("g_media ", g_media);
696 if (not isbound(bssap)) {
697 self.stop;
698 }
699 return bssap;
Harald Weltec1a2fff2017-12-17 11:06:19 +0100700}
701
Harald Welte261af4b2018-02-12 21:20:39 +0100702type record HandoverState {
703 /* Assignment related bits */
704 boolean rr_ho_cmpl_seen,
705 boolean handover_done,
706 RslChannelNr old_chan_nr
707};
708
709altstep as_handover(inout HandoverState st) runs on MSC_ConnHdlr {
710 var RSL_Message rsl;
711 [not st.rr_ho_cmpl_seen] RSL.receive(tr_RSL_DATA_REQ(g_chan_nr)) -> value rsl {
712 var PDU_ML3_NW_MS l3 := dec_PDU_ML3_NW_MS(rsl.ies[2].body.l3_info.payload);
713 log("Rx L3 from net: ", l3);
714 if (ischosen(l3.msgs.rrm.handoverCommand)) {
715 var RslChannelNr new_chan_nr;
716 var GsmArfcn arfcn;
717 f_ChDesc2RslChanNr(l3.msgs.rrm.handoverCommand.channelDescription2,
718 new_chan_nr, arfcn);
719 /* FIXME: Determine TRX NR by ARFCN, instead of hard-coded TRX0! */
720
721 /* register our component for this channel number at the RSL Emulation */
722 f_rslem_register(0, new_chan_nr, RSL1_PROC);
723
724 /* resume processing of RSL DChan messages, which was temporarily suspended
725 * before performing a hand-over */
726 f_rslem_resume(RSL1_PROC);
727
728 /* send handover complete over the new channel */
729 var PDU_ML3_MS_NW l3_tx := valueof(ts_RRM_HandoverComplete('00'O));
730 RSL1.send(ts_RSL_DATA_IND(new_chan_nr, valueof(ts_RslLinkID_DCCH(0)),
731 enc_PDU_ML3_MS_NW(l3_tx)));
732 /* by default, send via the new channel from now */
733 st.old_chan_nr := g_chan_nr;
734 g_chan_nr := new_chan_nr;
735 st.rr_ho_cmpl_seen := true;
736 repeat;
737 } else {
738 setverdict(fail, "Unexpected L3 received", l3);
739 self.stop;
740 }
741 }
742 [st.rr_ho_cmpl_seen] as_Media();
743 [st.rr_ho_cmpl_seen] RSL.receive(tr_RSL_REL_REQ(st.old_chan_nr, tr_RslLinkID_DCCH(0))) {
744 RSL.send(ts_RSL_REL_CONF(st.old_chan_nr, valueof(ts_RslLinkID_DCCH(0))));
745 repeat;
746 }
747 [st.rr_ho_cmpl_seen] RSL.receive(tr_RSL_RF_CHAN_REL(st.old_chan_nr)) {
748 RSL.send(ts_RSL_RF_CHAN_REL_ACK(st.old_chan_nr));
749 /* unregister for old channel number in RSL emulation */
750 /* FIXME: Determine TRX NR by ARFCN, instead of hard-coded TRX0! */
751 f_rslem_unregister(0, st.old_chan_nr);
752 st.handover_done := true;
Harald Welte261af4b2018-02-12 21:20:39 +0100753 }
754}
755
756
Harald Weltec1a2fff2017-12-17 11:06:19 +0100757
Harald Welte28d943e2017-11-25 15:00:50 +0100758}