blob: 529a39623f796454b1783d3b655a95243bb46641 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
19
20import from M3UA_Types all;
21import from M3UA_Emulation all;
22
23import from MTP3asp_Types all;
24import from MTP3asp_PortType all;
25
26import from SCCPasp_Types all;
27import from SCCP_Types all;
28import from SCCP_Emulation all;
29
30import from SCTPasp_Types all;
31import from SCTPasp_PortType all;
32
Harald Weltea49e36e2018-01-21 19:29:33 +010033import from Osmocom_CTRL_Functions all;
34import from Osmocom_CTRL_Types all;
35import from Osmocom_CTRL_Adapter all;
36
Harald Welte3ca1c902018-01-24 18:51:27 +010037import from TELNETasp_PortType all;
38import from Osmocom_VTY_Functions all;
39
Harald Weltea49e36e2018-01-21 19:29:33 +010040import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010041import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010042
Harald Welte4aa970c2018-01-26 10:38:09 +010043import from MGCP_Emulation all;
44import from MGCP_Types all;
45import from MGCP_Templates all;
46import from SDP_Types all;
47
Harald Weltea49e36e2018-01-21 19:29:33 +010048import from GSUP_Emulation all;
49import from GSUP_Types all;
50import from IPA_Emulation all;
51
Harald Weltef6dd64d2017-11-19 12:09:51 +010052import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020053import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010054import from BSSAP_CodecPort all;
55import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020056import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010057import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020058import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010059
Harald Welte4263c522018-12-06 11:56:27 +010060import from SGsAP_Templates all;
61import from SGsAP_Types all;
62import from SGsAP_Emulation all;
63
Harald Weltea49e36e2018-01-21 19:29:33 +010064import from MobileL3_Types all;
65import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070066import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010067import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010068import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010069
Harald Weltef640a012018-04-14 17:49:21 +020070import from SMPP_Types all;
71import from SMPP_Templates all;
72import from SMPP_Emulation all;
73
Stefan Sperlingc307e682018-06-14 15:15:46 +020074import from SCCP_Templates all;
75
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070076import from SS_Types all;
77import from SS_Templates all;
78import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010079import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070080
Philipp Maier948747b2019-04-02 15:22:33 +020081import from TCCConversion_Functions all;
82
Harald Welte9b751a62019-04-14 17:39:29 +020083const integer NUM_BSC := 3;
Harald Welte6811d102019-04-14 22:23:14 +020084type record of RAN_Configuration RAN_Configurations;
Harald Weltef6dd64d2017-11-19 12:09:51 +010085
Harald Welte4263c522018-12-06 11:56:27 +010086/* Needed for SGsAP SMS */
87import from MobileL3_SMS_Types all;
88
Harald Weltea4ca4462018-02-09 00:17:14 +010089type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010090 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010091
Harald Welte6811d102019-04-14 22:23:14 +020092 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010093
Harald Weltea49e36e2018-01-21 19:29:33 +010094 /* no 'adapter_CT' for MNCC or GSUP */
95 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010096 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010097 var GSUP_Emulation_CT vc_GSUP;
98 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020099 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +0100100 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100101
102 /* only to get events from IPA underneath GSUP */
103 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100104 /* VTY to MSC */
105 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100106
107 /* A port to directly send BSSAP messages. This port is used for
108 * tests that require low level access to sen arbitrary BSSAP
109 * messages. Run f_init_bssap_direct() to connect and initialize */
110 port BSSAP_CODEC_PT BSSAP_DIRECT;
111
112 /* When BSSAP messages are directly sent, then the connection
113 * handler is not active, which means that also no guard timer is
114 * set up. The following timer will serve as a replacement */
115 timer Tguard_direct := 60.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100116}
117
118modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100119 /* remote parameters of IUT */
120 charstring mp_msc_ip := "127.0.0.1";
121 integer mp_msc_ctrl_port := 4255;
122 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100123
Harald Weltea49e36e2018-01-21 19:29:33 +0100124 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100125 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100126 charstring mp_hlr_ip := "127.0.0.1";
127 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100128 charstring mp_mgw_ip := "127.0.0.1";
129 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100130
Harald Weltea49e36e2018-01-21 19:29:33 +0100131 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100132
Harald Weltef640a012018-04-14 17:49:21 +0200133 integer mp_msc_smpp_port := 2775;
134 charstring mp_smpp_system_id := "msc_tester";
135 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100136 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
137 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200138
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200139 /* Whether to enable osmux tests. Can be dropped completely and enable
140 unconditionally once new version of osmo-msc is released (current
141 version: 1.3.1) */
142 boolean mp_enable_osmux_test := true;
143
Harald Welte6811d102019-04-14 22:23:14 +0200144 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200145 {
146 sccp_service_type := "mtp3_itu",
147 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
148 own_pc := 185,
149 own_ssn := 254,
150 peer_pc := 187,
151 peer_ssn := 254,
152 sio := '83'O,
153 rctx := 0
154 },
155 {
156 sccp_service_type := "mtp3_itu",
157 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
158 own_pc := 186,
159 own_ssn := 254,
160 peer_pc := 187,
161 peer_ssn := 254,
162 sio := '83'O,
163 rctx := 1
164 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100165 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100166}
167
Philipp Maier328d1662018-03-07 10:40:27 +0100168/* altstep for the global guard timer (only used when BSSAP_DIRECT
169 * is used for communication */
170private altstep as_Tguard_direct() runs on MTC_CT {
171 [] Tguard_direct.timeout {
172 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200173 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100174 }
175}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100176
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100177private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
178 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
179 if (respond) {
180 var BIT1 tid_remote := '1'B;
181 if (cpars.mo_call) {
182 tid_remote := '0'B;
183 }
184 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
185 }
186 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100187}
188
Harald Weltef640a012018-04-14 17:49:21 +0200189function f_init_smpp(charstring id) runs on MTC_CT {
190 id := id & "-SMPP";
191 var EsmePars pars := {
192 mode := MODE_TRANSCEIVER,
193 bind := {
194 system_id := mp_smpp_system_id,
195 password := mp_smpp_password,
196 system_type := "MSC_Tests",
197 interface_version := hex2int('34'H),
198 addr_ton := unknown,
199 addr_npi := unknown,
200 address_range := ""
201 },
202 esme_role := true
203 }
204
205 vc_SMPP := SMPP_Emulation_CT.create(id);
206 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
207 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", -1));
208}
209
210
Harald Weltea49e36e2018-01-21 19:29:33 +0100211function f_init_mncc(charstring id) runs on MTC_CT {
212 id := id & "-MNCC";
213 var MnccOps ops := {
214 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
215 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
216 }
217
218 vc_MNCC := MNCC_Emulation_CT.create(id);
219 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
220 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100221}
222
Harald Welte4aa970c2018-01-26 10:38:09 +0100223function f_init_mgcp(charstring id) runs on MTC_CT {
224 id := id & "-MGCP";
225 var MGCPOps ops := {
226 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
227 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
228 }
229 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100230 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100231 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100232 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200233 mgw_udp_port := mp_mgw_port,
234 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100235 }
236
237 vc_MGCP := MGCP_Emulation_CT.create(id);
238 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
239 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
240}
241
Philipp Maierc09a1312019-04-09 16:05:26 +0200242function ForwardUnitdataCallback(PDU_SGsAP msg)
243runs on SGsAP_Emulation_CT return template PDU_SGsAP {
244 SGsAP_CLIENT.send(msg);
245 return omit;
246}
247
Harald Welte4263c522018-12-06 11:56:27 +0100248function f_init_sgsap(charstring id) runs on MTC_CT {
249 id := id & "-SGsAP";
250 var SGsAPOps ops := {
251 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200252 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100253 }
254 var SGsAP_conn_parameters pars := {
255 remote_ip := mp_msc_ip,
256 remote_sctp_port := 29118,
257 local_ip := "",
258 local_sctp_port := -1
259 }
260
261 vc_SGsAP := SGsAP_Emulation_CT.create(id);
262 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
263 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
264}
265
266
Harald Weltea49e36e2018-01-21 19:29:33 +0100267function f_init_gsup(charstring id) runs on MTC_CT {
268 id := id & "-GSUP";
269 var GsupOps ops := {
270 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
271 }
272
273 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
274 vc_GSUP := GSUP_Emulation_CT.create(id);
275
276 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
277 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
278 /* we use this hack to get events like ASP_IPA_EVENT_UP */
279 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
280
281 vc_GSUP.start(GSUP_Emulation.main(ops, id));
282 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
283
284 /* wait for incoming connection to GSUP port before proceeding */
285 timer T := 10.0;
286 T.start;
287 alt {
288 [] GSUP_IPA_EVENT.receive(t_ASP_IPA_EVT_UD(ASP_IPA_EVENT_UP)) { }
289 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100290 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200291 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100292 }
293 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100294}
295
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200296function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100297
298 if (g_initialized == true) {
299 return;
300 }
301 g_initialized := true;
302
Philipp Maier75932982018-03-27 14:52:35 +0200303 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200304 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200305 }
306
307 for (var integer i := 0; i < num_bsc; i := i + 1) {
308 if (isbound(mp_bssap_cfg[i])) {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200309 var RanOps ranops := BSC_RanOps;
310 ranops.use_osmux := osmux;
311 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
Harald Welte3ca0ce12019-04-23 17:18:48 +0200312 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200313 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200314 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200315 }
316 }
317
Harald Weltea49e36e2018-01-21 19:29:33 +0100318 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
319 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100320 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200321
322 if (gsup == true) {
323 f_init_gsup("MSC_Test");
324 }
Harald Weltef640a012018-04-14 17:49:21 +0200325 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100326
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100327 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100328 f_init_sgsap("MSC_Test");
329 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100330
331 map(self:MSCVTY, system:MSCVTY);
332 f_vty_set_prompts(MSCVTY);
333 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100334
335 /* set some defaults */
336 f_vty_config(MSCVTY, "network", "authentication optional");
337 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200338 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100339 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200340 if (mp_enable_osmux_test) {
341 if (osmux) {
342 f_vty_config(MSCVTY, "msc", "osmux on");
343 } else {
344 f_vty_config(MSCVTY, "msc", "osmux off");
345 }
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200346 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100347}
348
Philipp Maier328d1662018-03-07 10:40:27 +0100349/* Initialize for a direct connection to BSSAP. This function is an alternative
350 * to f_init() when the high level functions of the BSC_ConnectionHandler are
351 * not needed. */
352function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200353 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200354 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100355
356 /* Start guard timer and activate it as default */
357 Tguard_direct.start
358 activate(as_Tguard_direct());
359}
360
Harald Weltea49e36e2018-01-21 19:29:33 +0100361type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100362
Harald Weltea49e36e2018-01-21 19:29:33 +0100363/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200364function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100365 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200366runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100367 var BSC_ConnHdlrNetworkPars net_pars := {
368 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
369 expect_tmsi := true,
370 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200371 expect_ciph := false,
372 expect_imei := false,
373 expect_imei_early := false,
374 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
375 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100376 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100377 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200378 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
379 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100380 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100381 imei := f_gen_imei(imsi_suffix),
382 imsi := f_gen_imsi(imsi_suffix),
383 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100384 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100385 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100386 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100387 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100388 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100389 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100390 send_early_cm := true,
391 ipa_ctrl_ip := mp_msc_ip,
392 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100393 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100394 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200395 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200396 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100397 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200398 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200399 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200400 ran_is_geran := ran_is_geran,
401 use_osmux := use_osmux
Harald Weltea49e36e2018-01-21 19:29:33 +0100402 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200403 if (not ran_is_geran) {
404 pars.use_umts_aka := true;
405 pars.net.expect_auth := true;
406 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100407 return pars;
408}
409
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200410function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars, integer bssap_idx := 0) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100411 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200412 var charstring id := testcasename() & int2str(bssap_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100413
414 vc_conn := BSC_ConnHdlr.create(id);
415 /* BSSMAP part / A interface */
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200416 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:CLIENT);
417 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100418 /* MNCC part */
419 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
420 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100421 /* MGCP part */
422 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
423 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100424 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200425 if (pars.gsup_enable == true) {
426 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
427 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
428 }
Harald Weltef640a012018-04-14 17:49:21 +0200429 /* SMPP part */
430 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
431 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100432 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100433 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100434 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
435 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
436 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100437
Harald Weltea10db902018-01-27 12:44:49 +0100438 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
439 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100440 vc_conn.start(derefers(fn)(id, pars));
441 return vc_conn;
442}
443
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200444function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false)
Harald Welte9b751a62019-04-14 17:39:29 +0200445runs on MTC_CT return BSC_ConnHdlr {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200446 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100447}
448
Harald Weltea49e36e2018-01-21 19:29:33 +0100449private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100450 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100451 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100452}
Harald Weltea49e36e2018-01-21 19:29:33 +0100453testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
454 var BSC_ConnHdlr vc_conn;
455 f_init();
456
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100457 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100458 vc_conn.done;
459}
460
461private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100462 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100463 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100464 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100465}
Harald Weltea49e36e2018-01-21 19:29:33 +0100466testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
467 var BSC_ConnHdlr vc_conn;
468 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100469 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100470
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100471 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100472 vc_conn.done;
473}
474
475/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200476friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100477 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100478 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
479
480 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200481 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100482 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100483 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
484 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
485 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100486 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
487 f_expect_clear();
488 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100489 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
490 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200491 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100492 }
493 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100494}
495testcase TC_lu_imsi_reject() runs on MTC_CT {
496 var BSC_ConnHdlr vc_conn;
497 f_init();
498
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100499 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3);
Harald Weltea49e36e2018-01-21 19:29:33 +0100500 vc_conn.done;
501}
502
Harald Weltee13cfb22019-04-23 16:52:02 +0200503
504
Harald Weltea49e36e2018-01-21 19:29:33 +0100505/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200506friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100507 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100508 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
509
510 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200511 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100512 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100513 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
514 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
515 alt {
516 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100517 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
518 f_expect_clear();
519 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100520 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
521 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200522 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100523 }
524 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100525}
526testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
527 var BSC_ConnHdlr vc_conn;
528 f_init();
529
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100530 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4);
Harald Weltea49e36e2018-01-21 19:29:33 +0100531 vc_conn.done;
532}
533
Harald Weltee13cfb22019-04-23 16:52:02 +0200534
Harald Welte7b1b2812018-01-22 21:23:06 +0100535private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100536 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100537 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100538 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100539}
540testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
541 var BSC_ConnHdlr vc_conn;
542 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100543 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100544
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100545 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100546 vc_conn.done;
547}
548
Harald Weltee13cfb22019-04-23 16:52:02 +0200549
550friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200551 pars.net.expect_auth := true;
552 pars.use_umts_aka := true;
553 f_init_handler(pars);
554 f_perform_lu();
555}
556testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
557 var BSC_ConnHdlr vc_conn;
558 f_init();
559 f_vty_config(MSCVTY, "network", "authentication required");
560
561 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
562 vc_conn.done;
563}
Harald Weltea49e36e2018-01-21 19:29:33 +0100564
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100565/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
566 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
567 */
568friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
569
570 f_init_handler(pars);
571
572 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
573 var PDU_DTAP_MT dtap_mt;
574
575 /* tell GSUP dispatcher to send this IMSI to us */
576 f_create_gsup_expect(hex2str(g_pars.imsi));
577
578 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
579 if (g_pars.ran_is_geran) {
580 f_bssap_compl_l3(l3_lu);
581 if (g_pars.send_early_cm) {
582 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
583 }
584 } else {
585 f_ranap_initial_ue(l3_lu);
586 }
587
588 f_mm_imei_early();
589 f_mm_common();
590 f_msc_lu_hlr();
591 f_mm_imei();
592
593 alt {
594 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
595 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
596 setverdict(fail, "Expected LU ACK, but received LU REJ");
597 mtc.stop;
598 }
599 }
600
601 /* currently (due to bug OS#4337), an extra LU reject is received before
602 terminating the connection. Enabling following line makes the test
603 pass: */
604 //f_expect_lu_reject('16'O); /* Cause: congestion */
605
606 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
607 extra time to avoid race conditons... */
608 f_expect_clear(7.0);
609
610 setverdict(pass);
611}
612testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
613 var BSC_ConnHdlr vc_conn;
614 f_init();
615
616 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
617 vc_conn.done;
618}
619
Harald Weltee13cfb22019-04-23 16:52:02 +0200620
Harald Weltea49e36e2018-01-21 19:29:33 +0100621/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200622friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100623runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100624 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100625
626 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100627 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100628 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100629
630 f_create_gsup_expect(hex2str(g_pars.imsi));
631
632 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200633 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200634 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100635
636 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100637 T.start;
638 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100639 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
640 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200641 [] BSSAP.receive {
642 setverdict(fail, "Received unexpected BSSAP");
643 mtc.stop;
644 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100645 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
646 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200647 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100648 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200649 [] T.timeout {
650 setverdict(fail, "Timeout waiting for CM SERV REQ");
651 mtc.stop;
652 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100653 }
654
Harald Welte1ddc7162018-01-27 14:25:46 +0100655 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100656}
Harald Weltea49e36e2018-01-21 19:29:33 +0100657testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
658 var BSC_ConnHdlr vc_conn;
659 f_init();
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100660 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6);
Harald Weltea49e36e2018-01-21 19:29:33 +0100661 vc_conn.done;
662}
663
Harald Weltee13cfb22019-04-23 16:52:02 +0200664
665friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100666 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200667 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100668 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100669 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100670}
671testcase TC_lu_and_mo_call() runs on MTC_CT {
672 var BSC_ConnHdlr vc_conn;
673 f_init();
674
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100675 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100676 vc_conn.done;
677}
678
Harald Weltee13cfb22019-04-23 16:52:02 +0200679
Harald Welte071ed732018-01-23 19:53:52 +0100680/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200681friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100682 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100683
684 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
685 var PDU_DTAP_MT dtap_mt;
686
687 /* tell GSUP dispatcher to send this IMSI to us */
688 f_create_gsup_expect(hex2str(g_pars.imsi));
689
690 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200691 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100692
693 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200694 if (pars.ran_is_geran) {
695 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
696 }
Harald Welte071ed732018-01-23 19:53:52 +0100697
698 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
699 /* The HLR would normally return an auth vector here, but we fail to do so. */
700
701 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100702 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100703}
704testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
705 var BSC_ConnHdlr vc_conn;
706 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100707 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100708
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100709 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8);
Harald Welte071ed732018-01-23 19:53:52 +0100710 vc_conn.done;
711}
712
Harald Weltee13cfb22019-04-23 16:52:02 +0200713
Harald Welte071ed732018-01-23 19:53:52 +0100714/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200715friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100716 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100717
718 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
719 var PDU_DTAP_MT dtap_mt;
720
721 /* tell GSUP dispatcher to send this IMSI to us */
722 f_create_gsup_expect(hex2str(g_pars.imsi));
723
724 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200725 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100726
727 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200728 if (pars.ran_is_geran) {
729 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
730 }
Harald Welte071ed732018-01-23 19:53:52 +0100731
732 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
733 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
734
735 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100736 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100737}
738testcase TC_lu_auth_sai_err() runs on MTC_CT {
739 var BSC_ConnHdlr vc_conn;
740 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100741 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100742
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100743 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9);
Harald Welte2bb825f2018-01-22 11:31:18 +0100744 vc_conn.done;
745}
Harald Weltea49e36e2018-01-21 19:29:33 +0100746
Harald Weltee13cfb22019-04-23 16:52:02 +0200747
Harald Weltebc881782018-01-23 20:09:15 +0100748/* Test LU but BSC will send a clear request in the middle */
749private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100750 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100751
752 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
753 var PDU_DTAP_MT dtap_mt;
754
755 /* tell GSUP dispatcher to send this IMSI to us */
756 f_create_gsup_expect(hex2str(g_pars.imsi));
757
758 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200759 f_cl3_or_initial_ue(l3_lu);
Harald Weltebc881782018-01-23 20:09:15 +0100760
761 /* Send Early Classmark, just for the fun of it */
762 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
763
764 f_sleep(1.0);
765 /* send clear request in the middle of the LU */
766 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200767 alt {
768 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
769 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
770 }
Harald Weltebc881782018-01-23 20:09:15 +0100771 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100772 alt {
773 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200774 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
775 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200776 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200777 repeat;
778 }
Harald Welte6811d102019-04-14 22:23:14 +0200779 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100780 }
Harald Weltebc881782018-01-23 20:09:15 +0100781 setverdict(pass);
782}
783testcase TC_lu_clear_request() runs on MTC_CT {
784 var BSC_ConnHdlr vc_conn;
785 f_init();
786
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100787 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100788 vc_conn.done;
789}
790
Harald Welte66af9e62018-01-24 17:28:21 +0100791/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200792friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100793 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100794
795 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
796 var PDU_DTAP_MT dtap_mt;
797
798 /* tell GSUP dispatcher to send this IMSI to us */
799 f_create_gsup_expect(hex2str(g_pars.imsi));
800
801 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200802 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +0100803
804 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200805 if (pars.ran_is_geran) {
806 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
807 }
Harald Welte66af9e62018-01-24 17:28:21 +0100808
809 f_sleep(1.0);
810 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +0200811 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +0100812 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +0100813 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +0100814}
815testcase TC_lu_disconnect() runs on MTC_CT {
816 var BSC_ConnHdlr vc_conn;
817 f_init();
818
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100819 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100820 vc_conn.done;
821}
822
Harald Welteba7b6d92018-01-23 21:32:34 +0100823/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +0200824friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100825 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100826
Harald Welte256571e2018-01-24 18:47:19 +0100827 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100828 var PDU_DTAP_MT dtap_mt;
829
830 /* tell GSUP dispatcher to send this IMSI to us */
831 f_create_gsup_expect(hex2str(g_pars.imsi));
832
833 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200834 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100835
836 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200837 if (pars.ran_is_geran) {
838 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
839 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100840 /* wait for LU reject, ignore any ID REQ */
841 alt {
842 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
843 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
844 }
845 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100846 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100847}
848testcase TC_lu_by_imei() runs on MTC_CT {
849 var BSC_ConnHdlr vc_conn;
850 f_init();
851
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100852 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12);
Harald Welteba7b6d92018-01-23 21:32:34 +0100853 vc_conn.done;
854}
855
Harald Weltee13cfb22019-04-23 16:52:02 +0200856
Harald Welteba7b6d92018-01-23 21:32:34 +0100857/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
858private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200859 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
860 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100861 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100862
863 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
864 var PDU_DTAP_MT dtap_mt;
865
866 /* tell GSUP dispatcher to send this IMSI to us */
867 f_create_gsup_expect(hex2str(g_pars.imsi));
868
869 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200870 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100871
872 /* Send Early Classmark, just for the fun of it */
873 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
874
875 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +0200876 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200877 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100878 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
879
880 /* Expect MSC to do UpdateLocation to HLR; respond to it */
881 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
882 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
883 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
884 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
885
886 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100887 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
888 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
889 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100890 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
891 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200892 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +0100893 }
894 }
895
Philipp Maier9b690e42018-12-21 11:50:03 +0100896 /* Wait for MM-Information (if enabled) */
897 f_expect_mm_info();
898
Harald Welteba7b6d92018-01-23 21:32:34 +0100899 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100900 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100901}
902testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
903 var BSC_ConnHdlr vc_conn;
904 f_init();
905
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100906 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100907 vc_conn.done;
908}
909
910
Harald Welte45164da2018-01-24 12:51:27 +0100911/* Test IMSI DETACH (MI=IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200912friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100913 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100914
915 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
916
917 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200918 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100919
920 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200921 if (pars.ran_is_geran) {
922 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
923 }
Harald Welte45164da2018-01-24 12:51:27 +0100924
925 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100926 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100927}
928testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
929 var BSC_ConnHdlr vc_conn;
930 f_init();
931
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100932 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14);
Harald Welte45164da2018-01-24 12:51:27 +0100933 vc_conn.done;
934}
935
Harald Weltee13cfb22019-04-23 16:52:02 +0200936
Harald Welte45164da2018-01-24 12:51:27 +0100937/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200938friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100939 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100940
941 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
942
943 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200944 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100945
946 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200947 if (pars.ran_is_geran) {
948 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
949 }
Harald Welte45164da2018-01-24 12:51:27 +0100950
951 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100952 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100953}
954testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
955 var BSC_ConnHdlr vc_conn;
956 f_init();
957
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100958 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15);
Harald Welte45164da2018-01-24 12:51:27 +0100959 vc_conn.done;
960}
961
Harald Weltee13cfb22019-04-23 16:52:02 +0200962
Harald Welte45164da2018-01-24 12:51:27 +0100963/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +0200964friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100965 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100966
Harald Welte256571e2018-01-24 18:47:19 +0100967 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +0100968
969 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200970 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100971
972 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200973 if (pars.ran_is_geran) {
974 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
975 }
Harald Welte45164da2018-01-24 12:51:27 +0100976
977 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100978 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100979}
980testcase TC_imsi_detach_by_imei() runs on MTC_CT {
981 var BSC_ConnHdlr vc_conn;
982 f_init();
983
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100984 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16);
Harald Welte45164da2018-01-24 12:51:27 +0100985 vc_conn.done;
986}
987
988
989/* helper function for an emergency call. caller passes in mobile identity to use */
990private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +0100991 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
992 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +0100993
Harald Welte0bef21e2018-02-10 09:48:23 +0100994 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +0100995}
996
997/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200998friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100999 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001000
Harald Welte256571e2018-01-24 18:47:19 +01001001 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001002 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001003 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001004 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001005 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001006}
1007testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1008 var BSC_ConnHdlr vc_conn;
1009 f_init();
1010
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001011 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17);
Harald Welte45164da2018-01-24 12:51:27 +01001012 vc_conn.done;
1013}
1014
Harald Weltee13cfb22019-04-23 16:52:02 +02001015
Harald Welted5b91402018-01-24 18:48:16 +01001016/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001017friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001018 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001019 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001020 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001021 /* Then issue emergency call identified by IMSI */
1022 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1023}
1024testcase TC_emerg_call_imsi() runs on MTC_CT {
1025 var BSC_ConnHdlr vc_conn;
1026 f_init();
1027
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001028 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001029 vc_conn.done;
1030}
1031
Harald Weltee13cfb22019-04-23 16:52:02 +02001032
Harald Welte45164da2018-01-24 12:51:27 +01001033/* CM Service Request for VGCS -> reject */
1034private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001035 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001036
1037 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001038 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001039
1040 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001041 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001042 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001043 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001044 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001045}
1046testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1047 var BSC_ConnHdlr vc_conn;
1048 f_init();
1049
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001050 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001051 vc_conn.done;
1052}
1053
1054/* CM Service Request for VBS -> reject */
1055private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001056 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001057
1058 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001059 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001060
1061 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001062 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001063 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001064 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001065 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001066}
1067testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1068 var BSC_ConnHdlr vc_conn;
1069 f_init();
1070
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001071 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001072 vc_conn.done;
1073}
1074
1075/* CM Service Request for LCS -> reject */
1076private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001077 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001078
1079 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001080 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001081
1082 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001083 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001084 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001085 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001086 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001087}
1088testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1089 var BSC_ConnHdlr vc_conn;
1090 f_init();
1091
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001092 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001093 vc_conn.done;
1094}
1095
Harald Welte0195ab12018-01-24 21:50:20 +01001096/* CM Re-Establishment Request */
1097private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001098 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001099
1100 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001101 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001102
1103 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1104 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001105 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001106 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001107 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001108}
1109testcase TC_cm_reest_req_reject() runs on MTC_CT {
1110 var BSC_ConnHdlr vc_conn;
1111 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001112
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001113 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001114 vc_conn.done;
1115}
1116
Harald Weltec638f4d2018-01-24 22:00:36 +01001117/* Test LU (with authentication enabled), with wrong response from MS */
1118private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001119 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001120
1121 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1122
1123 /* tell GSUP dispatcher to send this IMSI to us */
1124 f_create_gsup_expect(hex2str(g_pars.imsi));
1125
1126 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001127 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001128
1129 /* Send Early Classmark, just for the fun of it */
1130 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1131
1132 var AuthVector vec := f_gen_auth_vec_2g();
1133 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1134 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1135 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1136
1137 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1138 /* Send back wrong auth response */
1139 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1140
1141 /* Expect GSUP AUTH FAIL REP to HLR */
1142 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1143
1144 /* Expect LU REJECT with Cause == Illegal MS */
1145 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001146 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001147}
1148testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1149 var BSC_ConnHdlr vc_conn;
1150 f_init();
1151 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001152
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001153 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23);
Harald Weltec638f4d2018-01-24 22:00:36 +01001154 vc_conn.done;
1155}
1156
Harald Weltede371492018-01-27 23:44:41 +01001157/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001158private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001159 pars.net.expect_auth := true;
1160 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001161 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001162 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001163}
1164testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1165 var BSC_ConnHdlr vc_conn;
1166 f_init();
1167 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001168 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1169
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001170 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001171 vc_conn.done;
1172}
1173
Harald Welte1af6ea82018-01-25 18:33:15 +01001174/* Test Complete L3 without payload */
1175private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001176 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001177
1178 /* Send Complete L3 Info with empty L3 frame */
1179 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1180 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1181
Harald Weltef466eb42018-01-27 14:26:54 +01001182 timer T := 5.0;
1183 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001184 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001185 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001186 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001187 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001188 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001189 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001190 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001191 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001192 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001193 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001194 }
1195 setverdict(pass);
1196}
1197testcase TC_cl3_no_payload() runs on MTC_CT {
1198 var BSC_ConnHdlr vc_conn;
1199 f_init();
1200
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001201 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001202 vc_conn.done;
1203}
1204
1205/* Test Complete L3 with random payload */
1206private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001207 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001208
Daniel Willmannaa14a382018-07-26 08:29:45 +02001209 /* length is limited by PDU_BSSAP length field which includes some
1210 * other fields beside l3info payload. So payl can only be 240 bytes
1211 * Since rnd() returns values < 1 multiply with 241
1212 */
1213 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001214 var octetstring payl := f_rnd_octstring(len);
1215
1216 /* Send Complete L3 Info with empty L3 frame */
1217 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1218 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1219
Harald Weltef466eb42018-01-27 14:26:54 +01001220 timer T := 5.0;
1221 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001222 alt {
1223 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001224 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001225 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001226 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001227 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001228 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001229 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001230 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001231 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001232 }
1233 setverdict(pass);
1234}
1235testcase TC_cl3_rnd_payload() runs on MTC_CT {
1236 var BSC_ConnHdlr vc_conn;
1237 f_init();
1238
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001239 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001240 vc_conn.done;
1241}
1242
Harald Welte116e4332018-01-26 22:17:48 +01001243/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001244friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001245 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001246
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001247 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001248
Harald Welteb9e86fa2018-04-09 18:18:31 +02001249 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001250 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001251}
1252testcase TC_establish_and_nothing() runs on MTC_CT {
1253 var BSC_ConnHdlr vc_conn;
1254 f_init();
1255
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001256 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001257 vc_conn.done;
1258}
1259
Harald Weltee13cfb22019-04-23 16:52:02 +02001260
Harald Welte12510c52018-01-26 22:26:24 +01001261/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001262friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001263 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001264
Harald Welte12510c52018-01-26 22:26:24 +01001265 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001266 cpars.mgw_conn_2.resp := 0;
1267 cpars.stop_after_cc_setup := true;
1268
1269 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001270
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001271 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001272
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001273 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001274
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001275 var default ccrel := activate(as_optional_cc_rel(cpars));
1276
Philipp Maier109e6aa2018-10-17 10:53:32 +02001277 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001278
1279 deactivate(ccrel);
1280
1281 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001282}
1283testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1284 var BSC_ConnHdlr vc_conn;
1285 f_init();
1286
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001287 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001288 vc_conn.done;
1289}
1290
Harald Weltee13cfb22019-04-23 16:52:02 +02001291
Harald Welte3ab88002018-01-26 22:37:25 +01001292/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001293friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001294 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001295 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1296 var MNCC_PDU mncc;
1297 var MgcpCommand mgcp_cmd;
1298
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001299 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001300 /* Do not respond to the second CRCX */
1301 cpars.mgw_conn_2.resp := 0;
1302 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001303
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001304 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001305
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001306 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001307
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001308 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001309}
1310testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1311 var BSC_ConnHdlr vc_conn;
1312 f_init();
1313
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001314 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001315 vc_conn.done;
1316}
1317
Harald Weltee13cfb22019-04-23 16:52:02 +02001318
Harald Welte0cc82d92018-01-26 22:52:34 +01001319/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001320friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001321 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001322
Harald Welte0cc82d92018-01-26 22:52:34 +01001323 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001324
1325 /* Respond with error for the first CRCX */
1326 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001327
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001328 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001329 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001330
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001331 var default ccrel := activate(as_optional_cc_rel(cpars));
1332 f_expect_clear(60.0);
1333 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001334}
1335testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1336 var BSC_ConnHdlr vc_conn;
1337 f_init();
1338
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001339 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001340 vc_conn.done;
1341}
1342
Harald Welte3ab88002018-01-26 22:37:25 +01001343
Harald Welte812f7a42018-01-27 00:49:18 +01001344/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1345private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1346 var MNCC_PDU mncc;
1347 var MgcpCommand mgcp_cmd;
1348 var OCT4 tmsi;
1349
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001350 f_perform_lu();
Harald Welte812f7a42018-01-27 00:49:18 +01001351 if (isvalue(g_pars.tmsi)) {
1352 tmsi := g_pars.tmsi;
1353 } else {
1354 tmsi := 'FFFFFFFF'O;
1355 }
Harald Welte6811d102019-04-14 22:23:14 +02001356 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001357
1358 /* Allocate call reference and send SETUP via MNCC to MSC */
1359 cpars.mncc_callref := f_rnd_int(2147483648);
1360 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1361 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1362
1363 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001364 f_expect_paging();
1365
Harald Welte812f7a42018-01-27 00:49:18 +01001366 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001367 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001368
1369 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1370
1371 /* MSC->MS: SETUP */
1372 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1373}
1374
1375/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001376friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001377 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001378 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1379 var MNCC_PDU mncc;
1380 var MgcpCommand mgcp_cmd;
1381
1382 f_mt_call_start(cpars);
1383
1384 /* MS->MSC: CALL CONFIRMED */
1385 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1386
1387 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1388
1389 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1390 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001391
1392 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1393 * set an endpoint name that fits the pattern. If not, just use the
1394 * endpoint name from the request */
1395 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1396 cpars.mgcp_ep := "rtpbridge/1@mgw";
1397 } else {
1398 cpars.mgcp_ep := mgcp_cmd.line.ep;
1399 }
1400
Harald Welte812f7a42018-01-27 00:49:18 +01001401 /* Respond to CRCX with error */
1402 var MgcpResponse mgcp_rsp := {
1403 line := {
1404 code := "542",
1405 trans_id := mgcp_cmd.line.trans_id,
1406 string := "FORCED_FAIL"
1407 },
Harald Welte812f7a42018-01-27 00:49:18 +01001408 sdp := omit
1409 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001410 var MgcpParameter mgcp_rsp_param := {
1411 code := "Z",
1412 val := cpars.mgcp_ep
1413 };
1414 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001415 MGCP.send(mgcp_rsp);
1416
1417 timer T := 30.0;
1418 T.start;
1419 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001420 [] T.timeout {
1421 setverdict(fail, "Timeout waiting for channel release");
1422 mtc.stop;
1423 }
Harald Welte812f7a42018-01-27 00:49:18 +01001424 [] MNCC.receive { repeat; }
1425 [] GSUP.receive { repeat; }
1426 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1427 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1428 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1429 repeat;
1430 }
1431 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001432 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001433 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001434 }
1435}
1436testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1437 var BSC_ConnHdlr vc_conn;
1438 f_init();
1439
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001440 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001441 vc_conn.done;
1442}
1443
1444
Harald Weltee13cfb22019-04-23 16:52:02 +02001445
Harald Welte812f7a42018-01-27 00:49:18 +01001446/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001447friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001448 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001449 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1450 var MNCC_PDU mncc;
1451 var MgcpCommand mgcp_cmd;
1452
1453 f_mt_call_start(cpars);
1454
1455 /* MS->MSC: CALL CONFIRMED */
1456 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1457 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1458
1459 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1460 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1461 cpars.mgcp_ep := mgcp_cmd.line.ep;
1462 /* FIXME: Respond to CRCX */
1463
1464 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1465 timer T := 190.0;
1466 T.start;
1467 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001468 [] T.timeout {
1469 setverdict(fail, "Timeout waiting for T310");
1470 mtc.stop;
1471 }
Harald Welte812f7a42018-01-27 00:49:18 +01001472 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1473 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1474 }
1475 }
1476 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1477 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1478 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1479 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1480
1481 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001482 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1483 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1484 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1485 repeat;
1486 }
Harald Welte5946b332018-03-18 23:32:21 +01001487 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001488 }
1489}
1490testcase TC_mt_t310() runs on MTC_CT {
1491 var BSC_ConnHdlr vc_conn;
1492 f_init();
1493
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001494 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001495 vc_conn.done;
1496}
1497
Harald Weltee13cfb22019-04-23 16:52:02 +02001498
Harald Welte167458a2018-01-27 15:58:16 +01001499/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001500friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001501 f_init_handler(pars);
1502 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001503
1504 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001505 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001506
1507 /* First MO call should succeed */
1508 f_mo_call(cpars);
1509
1510 /* Cancel the subscriber in the VLR */
1511 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1512 alt {
1513 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1514 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1515 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001516 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001517 }
1518 }
1519
1520 /* Follow-up transactions should fail */
1521 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1522 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001523 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001524 alt {
1525 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1526 [] BSSAP.receive {
1527 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001528 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001529 }
1530 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001531
1532 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001533 setverdict(pass);
1534}
1535testcase TC_gsup_cancel() runs on MTC_CT {
1536 var BSC_ConnHdlr vc_conn;
1537 f_init();
1538
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001539 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33);
Harald Welte167458a2018-01-27 15:58:16 +01001540 vc_conn.done;
1541}
1542
Harald Weltee13cfb22019-04-23 16:52:02 +02001543
Harald Welte9de84792018-01-28 01:06:35 +01001544/* A5/1 only permitted on network side, and MS capable to do it */
1545private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1546 pars.net.expect_auth := true;
1547 pars.net.expect_ciph := true;
1548 pars.net.kc_support := '02'O; /* A5/1 only */
1549 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001550 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001551}
1552testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1553 var BSC_ConnHdlr vc_conn;
1554 f_init();
1555 f_vty_config(MSCVTY, "network", "authentication required");
1556 f_vty_config(MSCVTY, "network", "encryption a5 1");
1557
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001558 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001559 vc_conn.done;
1560}
1561
1562/* A5/3 only permitted on network side, and MS capable to do it */
1563private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1564 pars.net.expect_auth := true;
1565 pars.net.expect_ciph := true;
1566 pars.net.kc_support := '08'O; /* A5/3 only */
1567 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001568 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001569}
1570testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1571 var BSC_ConnHdlr vc_conn;
1572 f_init();
1573 f_vty_config(MSCVTY, "network", "authentication required");
1574 f_vty_config(MSCVTY, "network", "encryption a5 3");
1575
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001576 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001577 vc_conn.done;
1578}
1579
1580/* A5/3 only permitted on network side, and MS with only A5/1 support */
1581private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1582 pars.net.expect_auth := true;
1583 pars.net.expect_ciph := true;
1584 pars.net.kc_support := '08'O; /* A5/3 only */
1585 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1586 f_init_handler(pars, 15.0);
1587
1588 /* cannot use f_perform_lu() as we expect a reject */
1589 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1590 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001591 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001592 if (pars.send_early_cm) {
1593 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1594 } else {
1595 pars.cm1.esind := '0'B;
1596 }
Harald Welte9de84792018-01-28 01:06:35 +01001597 f_mm_auth();
1598 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001599 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1600 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1601 repeat;
1602 }
Harald Welte5946b332018-03-18 23:32:21 +01001603 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1604 f_expect_clear();
1605 }
Harald Welte9de84792018-01-28 01:06:35 +01001606 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1607 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001608 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001609 }
1610 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001611 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001612 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001613 }
1614 }
1615 setverdict(pass);
1616}
1617testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1618 var BSC_ConnHdlr vc_conn;
1619 f_init();
1620 f_vty_config(MSCVTY, "network", "authentication required");
1621 f_vty_config(MSCVTY, "network", "encryption a5 3");
1622
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001623 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360);
1624 vc_conn.done;
1625}
1626testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1627 var BSC_ConnHdlrPars pars;
1628 var BSC_ConnHdlr vc_conn;
1629 f_init();
1630 f_vty_config(MSCVTY, "network", "authentication required");
1631 f_vty_config(MSCVTY, "network", "encryption a5 3");
1632
1633 pars := f_init_pars(361);
1634 pars.send_early_cm := false;
1635 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001636 vc_conn.done;
1637}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001638testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1639 var BSC_ConnHdlr vc_conn;
1640 f_init();
1641 f_vty_config(MSCVTY, "network", "authentication required");
1642 f_vty_config(MSCVTY, "network", "encryption a5 3");
1643
1644 /* Make sure the MSC category is on DEBUG level to trigger the log
1645 * message that is reported in OS#2947 to trigger the segfault */
1646 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1647
1648 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362);
1649 vc_conn.done;
1650}
Harald Welte9de84792018-01-28 01:06:35 +01001651
1652/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1653private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1654 pars.net.expect_auth := true;
1655 pars.net.expect_ciph := true;
1656 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1657 pars.cm1.a5_1 := '1'B;
1658 pars.cm2.a5_1 := '1'B;
1659 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1660 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1661 f_init_handler(pars, 15.0);
1662
1663 /* cannot use f_perform_lu() as we expect a reject */
1664 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1665 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001666 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001667 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1668 f_mm_auth();
1669 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001670 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1671 f_expect_clear();
1672 }
Harald Welte9de84792018-01-28 01:06:35 +01001673 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1674 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001675 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001676 }
1677 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001678 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001679 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001680 }
1681 }
1682 setverdict(pass);
1683}
1684testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1685 var BSC_ConnHdlr vc_conn;
1686 f_init();
1687 f_vty_config(MSCVTY, "network", "authentication required");
1688 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1689
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001690 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37);
Harald Welte9de84792018-01-28 01:06:35 +01001691 vc_conn.done;
1692}
1693
1694/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1695private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1696 pars.net.expect_auth := true;
1697 pars.net.expect_ciph := true;
1698 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1699 pars.cm1.a5_1 := '1'B;
1700 pars.cm2.a5_1 := '1'B;
1701 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1702 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1703 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001704 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001705}
1706testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1707 var BSC_ConnHdlr vc_conn;
1708 f_init();
1709 f_vty_config(MSCVTY, "network", "authentication required");
1710 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1711
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001712 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001713 vc_conn.done;
1714}
1715
Harald Welte33ec09b2018-02-10 15:34:46 +01001716/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01001717friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01001718 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001719 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001720 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01001721
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001722 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001723 f_mt_call(cpars);
1724}
1725testcase TC_lu_and_mt_call() runs on MTC_CT {
1726 var BSC_ConnHdlr vc_conn;
1727 f_init();
1728
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001729 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001730 vc_conn.done;
1731}
1732
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001733testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
1734 var BSC_ConnHdlr vc_conn;
1735 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001736
1737 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
1738 vc_conn.done;
1739}
1740
Daniel Willmann8b084372018-02-04 13:35:26 +01001741/* Test MO Call SETUP with DTMF */
1742private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1743 f_init_handler(pars);
1744 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01001745
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001746 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001747 f_mo_seq_dtmf_dup(cpars);
1748}
1749testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1750 var BSC_ConnHdlr vc_conn;
1751 f_init();
1752
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001753 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001754 vc_conn.done;
1755}
Harald Welte9de84792018-01-28 01:06:35 +01001756
Philipp Maier328d1662018-03-07 10:40:27 +01001757testcase TC_cr_before_reset() runs on MTC_CT {
1758 timer T := 4.0;
1759 var boolean reset_ack_seen := false;
1760 f_init_bssap_direct();
1761
Harald Welte3ca0ce12019-04-23 17:18:48 +02001762 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02001763
Daniel Willmanne8018962018-08-21 14:18:00 +02001764 f_sleep(3.0);
1765
Philipp Maier328d1662018-03-07 10:40:27 +01001766 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001767 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001768
1769 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001770 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001771 T.start
1772 alt {
1773 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1774 reset_ack_seen := true;
1775 repeat;
1776 }
1777
1778 /* Acknowledge MSC sided reset requests */
1779 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001780 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001781 repeat;
1782 }
1783
1784 /* Ignore all other messages (e.g CR from the connection request) */
1785 [] BSSAP_DIRECT.receive { repeat }
1786
1787 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1788 * deadlock situation. The MSC is then unable to respond to any
1789 * further BSSMAP RESET or any other sort of traffic. */
1790 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1791 [reset_ack_seen == false] T.timeout {
1792 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02001793 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01001794 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01001795 }
Philipp Maier328d1662018-03-07 10:40:27 +01001796}
Harald Welte9de84792018-01-28 01:06:35 +01001797
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001798/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02001799friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001800 f_init_handler(pars);
1801 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1802 var MNCC_PDU mncc;
1803 var MgcpCommand mgcp_cmd;
1804
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001805 /* Do not respond to the second CRCX */
1806 cpars.mgw_conn_2.resp := 0;
1807
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001808 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001809 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001810
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001811 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001812
1813 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001814
1815 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001816}
1817testcase TC_mo_release_timeout() runs on MTC_CT {
1818 var BSC_ConnHdlr vc_conn;
1819 f_init();
1820
1821 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1822 vc_conn.done;
1823}
1824
Harald Welte12510c52018-01-26 22:26:24 +01001825
Philipp Maier2a98a732018-03-19 16:06:12 +01001826/* LU followed by MT call (including paging) */
1827private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1828 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001829 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01001830
1831 /* Intentionally disable the CRCX response */
1832 cpars.mgw_drop_dlcx := true;
1833
1834 /* Perform location update and call */
1835 f_perform_lu();
1836 f_mt_call(cpars);
1837}
1838testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
1839 var BSC_ConnHdlr vc_conn;
1840 f_init();
1841
1842 /* Perform an almost normal looking locationupdate + mt-call, but do
1843 * not respond to the DLCX at the end of the call */
1844 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
1845 vc_conn.done;
1846
1847 /* Wait a guard period until the MGCP layer in the MSC times out,
1848 * if the MSC is vulnerable to the use-after-free situation that is
1849 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
1850 * segfault now */
1851 f_sleep(6.0);
1852
1853 /* Run the init procedures once more. If the MSC has crashed, this
1854 * this will fail */
1855 f_init();
1856}
Harald Welte45164da2018-01-24 12:51:27 +01001857
Philipp Maier75932982018-03-27 14:52:35 +02001858/* Two BSSMAP resets from two different BSCs */
1859testcase TC_reset_two() runs on MTC_CT {
1860 var BSC_ConnHdlr vc_conn;
1861 f_init(2);
1862 f_sleep(2.0);
1863 setverdict(pass);
1864}
1865
Harald Weltee13cfb22019-04-23 16:52:02 +02001866/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
1867testcase TC_reset_two_1iu() runs on MTC_CT {
1868 var BSC_ConnHdlr vc_conn;
1869 f_init(3);
1870 f_sleep(2.0);
1871 setverdict(pass);
1872}
1873
Harald Weltef640a012018-04-14 17:49:21 +02001874/***********************************************************************
1875 * SMS Testing
1876 ***********************************************************************/
1877
Harald Weltef45efeb2018-04-09 18:19:24 +02001878/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02001879friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02001880 var SmsParameters spars := valueof(t_SmsPars);
1881
1882 f_init_handler(pars);
1883
1884 /* Perform location update and call */
1885 f_perform_lu();
1886
1887 f_establish_fully(EST_TYPE_MO_SMS);
1888
1889 //spars.exp_rp_err := 96; /* invalid mandatory information */
1890 f_mo_sms(spars);
1891
1892 f_expect_clear();
1893}
1894testcase TC_lu_and_mo_sms() runs on MTC_CT {
1895 var BSC_ConnHdlr vc_conn;
1896 f_init();
1897 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
1898 vc_conn.done;
1899}
1900
Harald Weltee13cfb22019-04-23 16:52:02 +02001901
Harald Weltef45efeb2018-04-09 18:19:24 +02001902private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01001903runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02001904 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
1905}
1906
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01001907/* Remove still pending SMS */
1908private function f_vty_sms_clear(charstring imsi)
1909runs on BSC_ConnHdlr {
1910 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
1911 f_vty_transceive(MSCVTY, "sms-queue clear");
1912}
1913
Harald Weltef45efeb2018-04-09 18:19:24 +02001914/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02001915friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02001916 var SmsParameters spars := valueof(t_SmsPars);
1917 var OCT4 tmsi;
1918
1919 f_init_handler(pars);
1920
1921 /* Perform location update and call */
1922 f_perform_lu();
1923
1924 /* register an 'expect' for given IMSI (+TMSI) */
1925 if (isvalue(g_pars.tmsi)) {
1926 tmsi := g_pars.tmsi;
1927 } else {
1928 tmsi := 'FFFFFFFF'O;
1929 }
Harald Welte6811d102019-04-14 22:23:14 +02001930 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02001931
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01001932 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02001933
1934 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001935 f_expect_paging();
1936
Harald Weltef45efeb2018-04-09 18:19:24 +02001937 /* Establish DTAP / BSSAP / SCCP connection */
1938 f_establish_fully(EST_TYPE_PAG_RESP);
1939
1940 spars.tp.ud := 'C8329BFD064D9B53'O;
1941 f_mt_sms(spars);
1942
1943 f_expect_clear();
1944}
1945testcase TC_lu_and_mt_sms() runs on MTC_CT {
1946 var BSC_ConnHdlrPars pars;
1947 var BSC_ConnHdlr vc_conn;
1948 f_init();
1949 pars := f_init_pars(43);
1950 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02001951 vc_conn.done;
1952}
1953
Harald Weltee13cfb22019-04-23 16:52:02 +02001954
Philipp Maier3983e702018-11-22 19:01:33 +01001955/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02001956friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01001957 var SmsParameters spars := valueof(t_SmsPars);
1958 var OCT4 tmsi;
Philipp Maier3983e702018-11-22 19:01:33 +01001959 f_init_handler(pars, 150.0);
1960
1961 /* Perform location update */
1962 f_perform_lu();
1963
1964 /* register an 'expect' for given IMSI (+TMSI) */
1965 if (isvalue(g_pars.tmsi)) {
1966 tmsi := g_pars.tmsi;
1967 } else {
1968 tmsi := 'FFFFFFFF'O;
1969 }
Harald Welte6811d102019-04-14 22:23:14 +02001970 f_ran_register_imsi(g_pars.imsi, tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01001971
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01001972 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
1973
Neels Hofmeyr16237742019-03-06 15:34:01 +01001974 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02001975 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01001976
1977 /* Wait some time to make sure the MSC is not delivering any further
1978 * paging messages or anything else that could be unexpected. */
1979 timer T := 20.0;
1980 T.start
1981 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02001982 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi))
Philipp Maier3983e702018-11-22 19:01:33 +01001983 {
1984 setverdict(fail, "paging seems not to stop!");
1985 mtc.stop;
1986 }
Harald Welte62113fc2019-05-09 13:04:02 +02001987 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Weltee13cfb22019-04-23 16:52:02 +02001988 setverdict(fail, "paging seems not to stop!");
1989 mtc.stop;
1990 }
Philipp Maier3983e702018-11-22 19:01:33 +01001991 [] BSSAP.receive {
1992 setverdict(fail, "unexpected BSSAP message received");
1993 self.stop;
1994 }
1995 [] T.timeout {
1996 setverdict(pass);
1997 }
1998 }
1999
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002000 f_vty_sms_clear(hex2str(g_pars.imsi));
2001
Philipp Maier3983e702018-11-22 19:01:33 +01002002 setverdict(pass);
2003}
2004testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2005 var BSC_ConnHdlrPars pars;
2006 var BSC_ConnHdlr vc_conn;
2007 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002008 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002009 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002010 vc_conn.done;
2011}
2012
Alexander Couzensfc02f242019-09-12 03:43:18 +02002013/* LU followed by MT SMS with repeated paging */
2014friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2015 var SmsParameters spars := valueof(t_SmsPars);
2016 var OCT4 tmsi;
2017
2018 f_init_handler(pars);
2019
2020 /* Perform location update and call */
2021 f_perform_lu();
2022
2023 /* register an 'expect' for given IMSI (+TMSI) */
2024 if (isvalue(g_pars.tmsi)) {
2025 tmsi := g_pars.tmsi;
2026 } else {
2027 tmsi := 'FFFFFFFF'O;
2028 }
2029 f_ran_register_imsi(g_pars.imsi, tmsi);
2030
2031 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2032
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002033 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002034 /* MSC->BSC: expect PAGING from MSC */
2035 f_expect_paging();
2036
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002037 if (g_pars.ran_is_geran) {
2038 log("GERAN: expect no further Paging");
2039 } else {
2040 log("UTRAN: expect more Paging");
2041 }
2042
2043 timer T := 5.0;
2044 T.start;
2045 alt {
2046 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2047 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2048 mtc.stop;
2049 }
2050 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2051 log("UTRAN: second Paging received, as expected");
2052 setverdict(pass);
2053 }
2054 [] T.timeout {
2055 if (g_pars.ran_is_geran) {
2056 log("GERAN: No further Paging received, as expected");
2057 setverdict(pass);
2058 } else {
2059 setverdict(fail, "UTRAN: Expected a second Paging");
2060 mtc.stop;
2061 }
2062 }
2063 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002064
2065 /* Establish DTAP / BSSAP / SCCP connection */
2066 f_establish_fully(EST_TYPE_PAG_RESP);
2067
2068 spars.tp.ud := 'C8329BFD064D9B53'O;
2069 f_mt_sms(spars);
2070
2071 f_expect_clear();
2072}
2073testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2074 var BSC_ConnHdlrPars pars;
2075 var BSC_ConnHdlr vc_conn;
2076 f_init();
2077 pars := f_init_pars(1844);
2078 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2079 vc_conn.done;
2080}
Harald Weltee13cfb22019-04-23 16:52:02 +02002081
Harald Weltef640a012018-04-14 17:49:21 +02002082/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002083friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002084 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002085
Harald Weltef640a012018-04-14 17:49:21 +02002086 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002087
Harald Weltef640a012018-04-14 17:49:21 +02002088 /* Perform location update so IMSI is known + registered in MSC/VLR */
2089 f_perform_lu();
2090 f_establish_fully(EST_TYPE_MO_SMS);
2091
2092 f_mo_sms(spars);
2093
2094 var SMPP_PDU smpp;
2095 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2096 tr_smpp.body.deliver_sm := {
2097 service_type := "CMT",
2098 source_addr_ton := network_specific,
2099 source_addr_npi := isdn,
2100 source_addr := hex2str(pars.msisdn),
2101 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2102 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2103 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2104 esm_class := '00000001'B,
2105 protocol_id := 0,
2106 priority_flag := 0,
2107 schedule_delivery_time := "",
2108 replace_if_present := 0,
2109 data_coding := '00000001'B,
2110 sm_default_msg_id := 0,
2111 sm_length := ?,
2112 short_message := spars.tp.ud,
2113 opt_pars := {
2114 {
2115 tag := user_message_reference,
2116 len := 2,
2117 opt_value := {
2118 int2_val := oct2int(spars.tp.msg_ref)
2119 }
2120 }
2121 }
2122 };
2123 alt {
2124 [] SMPP.receive(tr_smpp) -> value smpp {
2125 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2126 }
2127 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2128 }
2129
2130 f_expect_clear();
2131}
2132testcase TC_smpp_mo_sms() runs on MTC_CT {
2133 var BSC_ConnHdlr vc_conn;
2134 f_init();
2135 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2136 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2137 vc_conn.done;
2138 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2139}
2140
Harald Weltee13cfb22019-04-23 16:52:02 +02002141
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002142/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002143friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002144runs on BSC_ConnHdlr {
2145 var SmsParameters spars := valueof(t_SmsPars);
2146 var GSUP_PDU gsup_msg_rx;
2147 var octetstring sm_tpdu;
2148
2149 f_init_handler(pars);
2150
2151 /* We need to inspect GSUP activity */
2152 f_create_gsup_expect(hex2str(g_pars.imsi));
2153
2154 /* Perform location update */
2155 f_perform_lu();
2156
2157 /* Send CM Service Request for SMS */
2158 f_establish_fully(EST_TYPE_MO_SMS);
2159
2160 /* Prepare expected SM-RP-UI (SM TPDU) */
2161 enc_TPDU_RP_DATA_MS_SGSN_fast(
2162 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2163 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2164 spars.tp.udl, spars.tp.ud)),
2165 sm_tpdu);
2166
2167 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2168 imsi := g_pars.imsi,
2169 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002170 /* SM-RP-DA: SMSC address */
2171 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2172 number := spars.rp.smsc_addr.rP_NumberDigits,
2173 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2174 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2175 ext := spars.rp.smsc_addr.rP_Ext)),
2176 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2177 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2178 number := g_pars.msisdn,
2179 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2180 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002181 /* TODO: can we use decmatch here? */
2182 sm_rp_ui := sm_tpdu
2183 );
2184
2185 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2186 f_mo_sms_submit(spars);
2187 alt {
2188 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
2189 log("RX MO-forwardSM-Req");
2190 log(gsup_msg_rx);
2191 setverdict(pass);
2192 }
2193 [] GSUP.receive {
2194 log("RX unexpected GSUP message");
2195 setverdict(fail);
2196 mtc.stop;
2197 }
2198 }
2199
2200 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2201 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2202 imsi := g_pars.imsi,
2203 sm_rp_mr := spars.rp.msg_ref)));
2204 /* Expect RP-ACK on DTAP */
2205 f_mo_sms_wait_rp_ack(spars);
2206
2207 f_expect_clear();
2208}
2209testcase TC_gsup_mo_sms() runs on MTC_CT {
2210 var BSC_ConnHdlr vc_conn;
2211 f_init();
2212 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2213 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2214 vc_conn.done;
2215 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2216}
2217
Harald Weltee13cfb22019-04-23 16:52:02 +02002218
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002219/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002220friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002221runs on BSC_ConnHdlr {
2222 var SmsParameters spars := valueof(t_SmsPars);
2223 var GSUP_PDU gsup_msg_rx;
2224
2225 f_init_handler(pars);
2226
2227 /* We need to inspect GSUP activity */
2228 f_create_gsup_expect(hex2str(g_pars.imsi));
2229
2230 /* Perform location update */
2231 f_perform_lu();
2232
2233 /* Send CM Service Request for SMS */
2234 f_establish_fully(EST_TYPE_MO_SMS);
2235
2236 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2237 imsi := g_pars.imsi,
2238 sm_rp_mr := spars.rp.msg_ref,
2239 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2240 );
2241
2242 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2243 f_mo_smma(spars);
2244 alt {
2245 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
2246 log("RX MO-ReadyForSM-Req");
2247 log(gsup_msg_rx);
2248 setverdict(pass);
2249 }
2250 [] GSUP.receive {
2251 log("RX unexpected GSUP message");
2252 setverdict(fail);
2253 mtc.stop;
2254 }
2255 }
2256
2257 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2258 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2259 imsi := g_pars.imsi,
2260 sm_rp_mr := spars.rp.msg_ref)));
2261 /* Expect RP-ACK on DTAP */
2262 f_mo_sms_wait_rp_ack(spars);
2263
2264 f_expect_clear();
2265}
2266testcase TC_gsup_mo_smma() runs on MTC_CT {
2267 var BSC_ConnHdlr vc_conn;
2268 f_init();
2269 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2270 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2271 vc_conn.done;
2272 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2273}
2274
Harald Weltee13cfb22019-04-23 16:52:02 +02002275
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002276/* Helper for sending MT SMS over GSUP */
2277private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2278runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002279 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002280 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2281 number := spars.rp.smsc_addr.rP_NumberDigits,
2282 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2283 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2284 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002285
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002286 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2287 imsi := g_pars.imsi,
2288 /* NOTE: MSC should assign RP-MR itself */
2289 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002290 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002291 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002292 /* Encoded SMS TPDU (taken from Wireshark)
2293 * FIXME: we should encode spars somehow */
2294 sm_rp_ui := '00068021436500008111328130858200'O,
2295 sm_rp_mms := mms
2296 ));
2297}
2298
2299/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002300friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002301runs on BSC_ConnHdlr {
2302 var SmsParameters spars := valueof(t_SmsPars);
2303
2304 f_init_handler(pars);
2305
2306 /* We need to inspect GSUP activity */
2307 f_create_gsup_expect(hex2str(g_pars.imsi));
2308
2309 /* Perform location update */
2310 f_perform_lu();
2311
2312 /* Register an 'expect' for given IMSI (+TMSI) */
2313 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002314 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002315 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002316 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002317 }
2318
2319 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2320 imsi := g_pars.imsi,
2321 /* NOTE: MSC should assign RP-MR itself */
2322 sm_rp_mr := ?
2323 );
2324
2325 /* Submit a MT SMS on GSUP */
2326 f_gsup_forwardSM_req(spars);
2327
2328 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002329 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002330 f_establish_fully(EST_TYPE_PAG_RESP);
2331
2332 /* Wait for MT SMS on DTAP */
2333 f_mt_sms_expect(spars);
2334
2335 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2336 f_mt_sms_send_rp_ack(spars);
2337 alt {
2338 [] GSUP.receive(mt_forwardSM_res) {
2339 log("RX MT-forwardSM-Res (RP-ACK)");
2340 setverdict(pass);
2341 }
2342 [] GSUP.receive {
2343 log("RX unexpected GSUP message");
2344 setverdict(fail);
2345 mtc.stop;
2346 }
2347 }
2348
2349 f_expect_clear();
2350}
2351testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2352 var BSC_ConnHdlrPars pars;
2353 var BSC_ConnHdlr vc_conn;
2354 f_init();
2355 pars := f_init_pars(90);
2356 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2357 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2358 vc_conn.done;
2359 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2360}
2361
Harald Weltee13cfb22019-04-23 16:52:02 +02002362
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002363/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002364friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002365runs on BSC_ConnHdlr {
2366 var SmsParameters spars := valueof(t_SmsPars);
2367 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2368
2369 f_init_handler(pars);
2370
2371 /* We need to inspect GSUP activity */
2372 f_create_gsup_expect(hex2str(g_pars.imsi));
2373
2374 /* Perform location update */
2375 f_perform_lu();
2376
2377 /* Register an 'expect' for given IMSI (+TMSI) */
2378 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002379 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002380 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002381 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002382 }
2383
2384 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2385 imsi := g_pars.imsi,
2386 /* NOTE: MSC should assign RP-MR itself */
2387 sm_rp_mr := ?,
2388 sm_rp_cause := sm_rp_cause
2389 );
2390
2391 /* Submit a MT SMS on GSUP */
2392 f_gsup_forwardSM_req(spars);
2393
2394 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002395 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002396 f_establish_fully(EST_TYPE_PAG_RESP);
2397
2398 /* Wait for MT SMS on DTAP */
2399 f_mt_sms_expect(spars);
2400
2401 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2402 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2403 alt {
2404 [] GSUP.receive(mt_forwardSM_err) {
2405 log("RX MT-forwardSM-Err (RP-ERROR)");
2406 setverdict(pass);
2407 mtc.stop;
2408 }
2409 [] GSUP.receive {
2410 log("RX unexpected GSUP message");
2411 setverdict(fail);
2412 mtc.stop;
2413 }
2414 }
2415
2416 f_expect_clear();
2417}
2418testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2419 var BSC_ConnHdlrPars pars;
2420 var BSC_ConnHdlr vc_conn;
2421 f_init();
2422 pars := f_init_pars(91);
2423 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2424 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2425 vc_conn.done;
2426 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2427}
2428
Harald Weltee13cfb22019-04-23 16:52:02 +02002429
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002430/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002431friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002432runs on BSC_ConnHdlr {
2433 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2434 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2435
2436 f_init_handler(pars);
2437
2438 /* We need to inspect GSUP activity */
2439 f_create_gsup_expect(hex2str(g_pars.imsi));
2440
2441 /* Perform location update */
2442 f_perform_lu();
2443
2444 /* Register an 'expect' for given IMSI (+TMSI) */
2445 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002446 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002447 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002448 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002449 }
2450
2451 /* Submit the 1st MT SMS on GSUP */
2452 log("TX MT-forwardSM-Req for the 1st SMS");
2453 f_gsup_forwardSM_req(spars1);
2454
2455 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002456 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002457 f_establish_fully(EST_TYPE_PAG_RESP);
2458
2459 /* Wait for 1st MT SMS on DTAP */
2460 f_mt_sms_expect(spars1);
2461 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2462 ", SM-RP-MR is ", spars1.rp.msg_ref);
2463
2464 /* Submit the 2nd MT SMS on GSUP */
2465 log("TX MT-forwardSM-Req for the 2nd SMS");
2466 f_gsup_forwardSM_req(spars2);
2467
2468 /* Wait for 2nd MT SMS on DTAP */
2469 f_mt_sms_expect(spars2);
2470 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2471 ", SM-RP-MR is ", spars2.rp.msg_ref);
2472
2473 /* Both transaction IDs shall be different */
2474 if (spars1.tid == spars2.tid) {
2475 log("Both DTAP transaction IDs shall be different");
2476 setverdict(fail);
2477 }
2478
2479 /* Both SM-RP-MR values shall be different */
2480 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2481 log("Both SM-RP-MR values shall be different");
2482 setverdict(fail);
2483 }
2484
2485 /* Both SM-RP-MR values shall be assigned */
2486 if (spars1.rp.msg_ref == 'FF'O) {
2487 log("Unassigned SM-RP-MR value for the 1st SMS");
2488 setverdict(fail);
2489 }
2490 if (spars2.rp.msg_ref == 'FF'O) {
2491 log("Unassigned SM-RP-MR value for the 2nd SMS");
2492 setverdict(fail);
2493 }
2494
2495 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2496 f_mt_sms_send_rp_ack(spars1);
2497 alt {
2498 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2499 imsi := g_pars.imsi,
2500 sm_rp_mr := spars1.rp.msg_ref
2501 )) {
2502 log("RX MT-forwardSM-Res (RP-ACK)");
2503 setverdict(pass);
2504 }
2505 [] GSUP.receive {
2506 log("RX unexpected GSUP message");
2507 setverdict(fail);
2508 mtc.stop;
2509 }
2510 }
2511
2512 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2513 f_mt_sms_send_rp_ack(spars2);
2514 alt {
2515 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2516 imsi := g_pars.imsi,
2517 sm_rp_mr := spars2.rp.msg_ref
2518 )) {
2519 log("RX MT-forwardSM-Res (RP-ACK)");
2520 setverdict(pass);
2521 }
2522 [] GSUP.receive {
2523 log("RX unexpected GSUP message");
2524 setverdict(fail);
2525 mtc.stop;
2526 }
2527 }
2528
2529 f_expect_clear();
2530}
2531testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2532 var BSC_ConnHdlrPars pars;
2533 var BSC_ConnHdlr vc_conn;
2534 f_init();
2535 pars := f_init_pars(92);
2536 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2537 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2538 vc_conn.done;
2539 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2540}
2541
Harald Weltee13cfb22019-04-23 16:52:02 +02002542
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002543/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002544friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002545runs on BSC_ConnHdlr {
2546 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2547 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2548
2549 f_init_handler(pars);
2550
2551 /* We need to inspect GSUP activity */
2552 f_create_gsup_expect(hex2str(g_pars.imsi));
2553
2554 /* Perform location update */
2555 f_perform_lu();
2556
2557 /* Register an 'expect' for given IMSI (+TMSI) */
2558 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002559 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002560 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002561 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002562 }
2563
2564 /* Send CM Service Request for MO SMMA */
2565 f_establish_fully(EST_TYPE_MO_SMS);
2566
2567 /* Submit MO SMMA on DTAP */
2568 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2569 spars_mo.rp.msg_ref := '00'O;
2570 f_mo_smma(spars_mo);
2571
2572 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2573 alt {
2574 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2575 imsi := g_pars.imsi,
2576 sm_rp_mr := spars_mo.rp.msg_ref,
2577 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2578 )) {
2579 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2580 setverdict(pass);
2581 }
2582 [] GSUP.receive {
2583 log("RX unexpected GSUP message");
2584 setverdict(fail);
2585 mtc.stop;
2586 }
2587 }
2588
2589 /* Submit MT SMS on GSUP */
2590 log("TX MT-forwardSM-Req for the MT SMS");
2591 f_gsup_forwardSM_req(spars_mt);
2592
2593 /* Wait for MT SMS on DTAP */
2594 f_mt_sms_expect(spars_mt);
2595 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2596 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2597
2598 /* Both SM-RP-MR values shall be different */
2599 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2600 log("Both SM-RP-MR values shall be different");
2601 setverdict(fail);
2602 }
2603
2604 /* SM-RP-MR value for MT SMS shall be assigned */
2605 if (spars_mt.rp.msg_ref == 'FF'O) {
2606 log("Unassigned SM-RP-MR value for the MT SMS");
2607 setverdict(fail);
2608 }
2609
2610 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2611 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2612 imsi := g_pars.imsi,
2613 sm_rp_mr := spars_mo.rp.msg_ref)));
2614 /* Expect RP-ACK for MO SMMA on DTAP */
2615 f_mo_sms_wait_rp_ack(spars_mo);
2616
2617 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2618 f_mt_sms_send_rp_ack(spars_mt);
2619 alt {
2620 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2621 imsi := g_pars.imsi,
2622 sm_rp_mr := spars_mt.rp.msg_ref
2623 )) {
2624 log("RX MT-forwardSM-Res (RP-ACK)");
2625 setverdict(pass);
2626 }
2627 [] GSUP.receive {
2628 log("RX unexpected GSUP message");
2629 setverdict(fail);
2630 mtc.stop;
2631 }
2632 }
2633
2634 f_expect_clear();
2635}
2636testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
2637 var BSC_ConnHdlrPars pars;
2638 var BSC_ConnHdlr vc_conn;
2639 f_init();
2640 pars := f_init_pars(93);
2641 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2642 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
2643 vc_conn.done;
2644 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2645}
2646
Harald Weltee13cfb22019-04-23 16:52:02 +02002647
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002648/* Test multi-part MT-SMS over GSUP */
2649private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
2650runs on BSC_ConnHdlr {
2651 var SmsParameters spars := valueof(t_SmsPars);
2652
2653 f_init_handler(pars);
2654
2655 /* We need to inspect GSUP activity */
2656 f_create_gsup_expect(hex2str(g_pars.imsi));
2657
2658 /* Perform location update */
2659 f_perform_lu();
2660
2661 /* Register an 'expect' for given IMSI (+TMSI) */
2662 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002663 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002664 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002665 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002666 }
2667
2668 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2669 imsi := g_pars.imsi,
2670 /* NOTE: MSC should assign RP-MR itself */
2671 sm_rp_mr := ?
2672 );
2673
2674 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
2675 for (var integer i := 3; i >= 0; i := i-1) {
2676 /* Submit a MT SMS on GSUP (MMS is decremented) */
2677 f_gsup_forwardSM_req(spars, int2oct(i, 1));
2678
2679 /* Expect Paging Request and Establish connection */
2680 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02002681 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002682 f_establish_fully(EST_TYPE_PAG_RESP);
2683 }
2684
2685 /* Wait for MT SMS on DTAP */
2686 f_mt_sms_expect(spars);
2687
2688 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2689 f_mt_sms_send_rp_ack(spars);
2690 alt {
2691 [] GSUP.receive(mt_forwardSM_res) {
2692 log("RX MT-forwardSM-Res (RP-ACK)");
2693 setverdict(pass);
2694 }
2695 [] GSUP.receive {
2696 log("RX unexpected GSUP message");
2697 setverdict(fail);
2698 mtc.stop;
2699 }
2700 }
2701
2702 /* Keep some 'distance' between transmissions */
2703 f_sleep(1.5);
2704 }
2705
2706 f_expect_clear();
2707}
2708testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
2709 var BSC_ConnHdlrPars pars;
2710 var BSC_ConnHdlr vc_conn;
2711 f_init();
2712 pars := f_init_pars(91);
2713 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2714 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
2715 vc_conn.done;
2716 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2717}
2718
Harald Weltef640a012018-04-14 17:49:21 +02002719/* convert GSM L3 TON to SMPP_TON enum */
2720function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
2721 select (ton) {
2722 case ('000'B) { return unknown; }
2723 case ('001'B) { return international; }
2724 case ('010'B) { return national; }
2725 case ('011'B) { return network_specific; }
2726 case ('100'B) { return subscriber_number; }
2727 case ('101'B) { return alphanumeric; }
2728 case ('110'B) { return abbreviated; }
2729 }
2730 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02002731 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002732}
2733/* convert GSM L3 NPI to SMPP_NPI enum */
2734function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2735 select (npi) {
2736 case ('0000'B) { return unknown; }
2737 case ('0001'B) { return isdn; }
2738 case ('0011'B) { return data; }
2739 case ('0100'B) { return telex; }
2740 case ('0110'B) { return land_mobile; }
2741 case ('1000'B) { return national; }
2742 case ('1001'B) { return private_; }
2743 case ('1010'B) { return ermes; }
2744 }
2745 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02002746 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002747}
2748
2749/* build a SMPP_SM from SmsParameters */
2750function f_mt_sm_from_spars(SmsParameters spars)
2751runs on BSC_ConnHdlr return SMPP_SM {
2752 var SMPP_SM sm := {
2753 service_type := "CMT",
2754 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2755 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2756 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2757 dest_addr_ton := international,
2758 dest_addr_npi := isdn,
2759 destination_addr := hex2str(g_pars.msisdn),
2760 esm_class := '00000001'B,
2761 protocol_id := 0,
2762 priority_flag := 0,
2763 schedule_delivery_time := "",
2764 validity_period := "",
2765 registered_delivery := '00000000'B,
2766 replace_if_present := 0,
2767 data_coding := '00000001'B,
2768 sm_default_msg_id := 0,
2769 sm_length := spars.tp.udl,
2770 short_message := spars.tp.ud,
2771 opt_pars := {}
2772 };
2773 return sm;
2774}
2775
2776/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2777private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2778 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2779 if (trans_mode) {
2780 sm.esm_class := '00000010'B;
2781 }
2782
2783 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2784 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2785 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2786 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2787 * before we expect the SMS delivery on the BSC/radio side */
2788 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2789 }
2790
2791 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002792 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02002793 /* Establish DTAP / BSSAP / SCCP connection */
2794 f_establish_fully(EST_TYPE_PAG_RESP);
2795 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2796
2797 f_mt_sms(spars);
2798
2799 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2800 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2801 }
2802 f_expect_clear();
2803}
2804
2805/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2806private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2807 f_init_handler(pars);
2808
2809 /* Perform location update so IMSI is known + registered in MSC/VLR */
2810 f_perform_lu();
2811 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2812
2813 /* register an 'expect' for given IMSI (+TMSI) */
2814 var OCT4 tmsi;
2815 if (isvalue(g_pars.tmsi)) {
2816 tmsi := g_pars.tmsi;
2817 } else {
2818 tmsi := 'FFFFFFFF'O;
2819 }
Harald Welte6811d102019-04-14 22:23:14 +02002820 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02002821
2822 var SmsParameters spars := valueof(t_SmsPars);
2823 /* TODO: test with more intelligent user data; test different coding schemes */
2824 spars.tp.ud := '00'O;
2825 spars.tp.udl := 1;
2826
2827 /* first test the non-transaction store+forward mode */
2828 f_smpp_mt_sms(spars, false);
2829
2830 /* then test the transaction mode */
2831 f_smpp_mt_sms(spars, true);
2832}
2833testcase TC_smpp_mt_sms() runs on MTC_CT {
2834 var BSC_ConnHdlr vc_conn;
2835 f_init();
2836 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
2837 vc_conn.done;
2838}
2839
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002840/***********************************************************************
2841 * USSD Testing
2842 ***********************************************************************/
2843
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002844private altstep as_unexp_gsup_or_bssap_msg()
2845runs on BSC_ConnHdlr {
2846 [] GSUP.receive {
2847 setverdict(fail, "Unknown/unexpected GSUP received");
2848 self.stop;
2849 }
2850 [] BSSAP.receive {
2851 setverdict(fail, "Unknown/unexpected BSSAP message received");
2852 self.stop;
2853 }
2854}
2855
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07002856private function f_expect_gsup_msg(template GSUP_PDU msg,
2857 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002858runs on BSC_ConnHdlr return GSUP_PDU {
2859 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07002860 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002861
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002862 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002863 alt {
2864 [] GSUP.receive(msg) -> value gsup_msg_complete {
2865 setverdict(pass);
2866 }
2867 /* We don't expect anything else */
2868 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002869 [] T.timeout {
2870 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
2871 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002872 }
2873
2874 return gsup_msg_complete;
2875}
2876
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07002877private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
2878 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002879runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
2880 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07002881 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002882
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002883 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002884 alt {
2885 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
2886 setverdict(pass);
2887 }
2888 /* We don't expect anything else */
2889 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002890 [] T.timeout {
2891 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
2892 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002893 }
2894
2895 return bssap_msg_complete.dtap;
2896}
2897
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002898/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02002899friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002900runs on BSC_ConnHdlr {
2901 f_init_handler(pars);
2902
2903 /* Perform location update */
2904 f_perform_lu();
2905
2906 /* Send CM Service Request for SS/USSD */
2907 f_establish_fully(EST_TYPE_SS_ACT);
2908
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002909 /* We need to inspect GSUP activity */
2910 f_create_gsup_expect(hex2str(g_pars.imsi));
2911
2912 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2913 invoke_id := 5, /* Phone may not start from 0 or 1 */
2914 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2915 ussd_string := "*#100#"
2916 );
2917
2918 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
2919 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
2920 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2921 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
2922 )
2923
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002924 /* Compose a new SS/REGISTER message with request */
2925 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
2926 tid := 1, /* We just need a single transaction */
2927 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002928 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002929 );
2930
2931 /* Compose SS/RELEASE_COMPLETE template with expected response */
2932 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
2933 tid := 1, /* Response should arrive within the same transaction */
2934 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002935 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002936 );
2937
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002938 /* Compose expected MSC -> HLR message */
2939 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
2940 imsi := g_pars.imsi,
2941 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2942 ss := valueof(facility_req)
2943 );
2944
2945 /* To be used for sending response with correct session ID */
2946 var GSUP_PDU gsup_req_complete;
2947
2948 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002949 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002950 /* Expect GSUP message containing the SS payload */
2951 gsup_req_complete := f_expect_gsup_msg(gsup_req);
2952
2953 /* Compose the response from HLR using received session ID */
2954 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
2955 imsi := g_pars.imsi,
2956 sid := gsup_req_complete.ies[1].val.session_id,
2957 state := OSMO_GSUP_SESSION_STATE_END,
2958 ss := valueof(facility_rsp)
2959 );
2960
2961 /* Finally, HLR terminates the session */
2962 GSUP.send(gsup_rsp);
2963 /* Expect RELEASE_COMPLETE message with the response */
2964 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002965
2966 f_expect_clear();
2967}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002968testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002969 var BSC_ConnHdlr vc_conn;
2970 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002971 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002972 vc_conn.done;
2973}
2974
Harald Weltee13cfb22019-04-23 16:52:02 +02002975
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002976/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02002977friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002978runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002979 timer T := 5.0;
2980
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002981 f_init_handler(pars);
2982
2983 /* Perform location update */
2984 f_perform_lu();
2985
Harald Welte6811d102019-04-14 22:23:14 +02002986 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002987
2988 /* We need to inspect GSUP activity */
2989 f_create_gsup_expect(hex2str(g_pars.imsi));
2990
2991 /* Facility IE with network-originated USSD notification */
2992 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2993 op_code := SS_OP_CODE_USS_NOTIFY,
2994 ussd_string := "Mahlzeit!"
2995 );
2996
2997 /* Facility IE with acknowledgment to the USSD notification */
2998 var template OCTN facility_rsp := enc_SS_FacilityInformation(
2999 /* In case of USSD notification, Return Result is empty */
3000 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3001 );
3002
3003 /* Compose a new MT SS/REGISTER message with USSD notification */
3004 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3005 tid := 0, /* FIXME: most likely, it should be 0 */
3006 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3007 facility := valueof(facility_req)
3008 );
3009
3010 /* Compose HLR -> MSC GSUP message */
3011 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3012 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003013 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003014 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3015 ss := valueof(facility_req)
3016 );
3017
3018 /* Send it to MSC and expect Paging Request */
3019 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003020 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003021 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003022 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3023 setverdict(pass);
3024 }
Harald Welte62113fc2019-05-09 13:04:02 +02003025 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003026 setverdict(pass);
3027 }
3028 /* We don't expect anything else */
3029 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003030 [] T.timeout {
3031 setverdict(fail, "Timeout waiting for Paging Request");
3032 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003033 }
3034
3035 /* Send Paging Response and expect USSD notification */
3036 f_establish_fully(EST_TYPE_PAG_RESP);
3037 /* Expect MT REGISTER message with USSD notification */
3038 f_expect_mt_dtap_msg(ussd_ntf);
3039
3040 /* Compose a new MO SS/FACILITY message with empty response */
3041 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3042 tid := 0, /* FIXME: it shall match the request tid */
3043 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3044 facility := valueof(facility_rsp)
3045 );
3046
3047 /* Compose expected MSC -> HLR GSUP message */
3048 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3049 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003050 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003051 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3052 ss := valueof(facility_rsp)
3053 );
3054
3055 /* MS sends response to the notification */
3056 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3057 /* Expect GSUP message containing the SS payload */
3058 f_expect_gsup_msg(gsup_rsp);
3059
3060 /* Compose expected MT SS/RELEASE COMPLETE message */
3061 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3062 tid := 0, /* FIXME: it shall match the request tid */
3063 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3064 facility := omit
3065 );
3066
3067 /* Compose MSC -> HLR GSUP message */
3068 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3069 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003070 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003071 state := OSMO_GSUP_SESSION_STATE_END
3072 );
3073
3074 /* Finally, HLR terminates the session */
3075 GSUP.send(gsup_term)
3076 /* Expect MT RELEASE COMPLETE without Facility IE */
3077 f_expect_mt_dtap_msg(ussd_term);
3078
3079 f_expect_clear();
3080}
3081testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3082 var BSC_ConnHdlr vc_conn;
3083 f_init();
3084 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3085 vc_conn.done;
3086}
3087
Harald Weltee13cfb22019-04-23 16:52:02 +02003088
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003089/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003090friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003091runs on BSC_ConnHdlr {
3092 f_init_handler(pars);
3093
3094 /* Call parameters taken from f_tc_lu_and_mt_call */
3095 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003096
3097 /* Perform location update */
3098 f_perform_lu();
3099
3100 /* Establish a MT call */
3101 f_mt_call_establish(cpars);
3102
3103 /* Hold the call for some time */
3104 f_sleep(1.0);
3105
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003106 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3107 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3108 ussd_string := "*#100#"
3109 );
3110
3111 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3112 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3113 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3114 )
3115
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003116 /* Compose a new SS/REGISTER message with request */
3117 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3118 tid := 1, /* We just need a single transaction */
3119 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003120 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003121 );
3122
3123 /* Compose SS/RELEASE_COMPLETE template with expected response */
3124 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3125 tid := 1, /* Response should arrive within the same transaction */
3126 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003127 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003128 );
3129
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003130 /* Compose expected MSC -> HLR message */
3131 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3132 imsi := g_pars.imsi,
3133 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3134 ss := valueof(facility_req)
3135 );
3136
3137 /* To be used for sending response with correct session ID */
3138 var GSUP_PDU gsup_req_complete;
3139
3140 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003141 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003142 /* Expect GSUP message containing the SS payload */
3143 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3144
3145 /* Compose the response from HLR using received session ID */
3146 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3147 imsi := g_pars.imsi,
3148 sid := gsup_req_complete.ies[1].val.session_id,
3149 state := OSMO_GSUP_SESSION_STATE_END,
3150 ss := valueof(facility_rsp)
3151 );
3152
3153 /* Finally, HLR terminates the session */
3154 GSUP.send(gsup_rsp);
3155 /* Expect RELEASE_COMPLETE message with the response */
3156 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003157
3158 /* Hold the call for some time */
3159 f_sleep(1.0);
3160
3161 /* Release the call (does Clear Complete itself) */
3162 f_call_hangup(cpars, true);
3163}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003164testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003165 var BSC_ConnHdlr vc_conn;
3166 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003167 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003168 vc_conn.done;
3169}
3170
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003171/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003172friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003173 f_init_handler(pars);
3174 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003175 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003176
3177 f_perform_lu();
3178
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003179 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003180 f_mo_call_establish(cpars);
3181 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003182 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003183
3184 f_sleep(1.0);
3185}
3186testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3187 var BSC_ConnHdlr vc_conn;
3188 f_init();
3189
3190 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3191 vc_conn.done;
3192}
3193
Harald Weltee13cfb22019-04-23 16:52:02 +02003194
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003195/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003196friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003197runs on BSC_ConnHdlr {
3198 f_init_handler(pars);
3199
3200 /* Call parameters taken from f_tc_lu_and_mt_call */
3201 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003202
3203 /* Perform location update */
3204 f_perform_lu();
3205
3206 /* Establish a MT call */
3207 f_mt_call_establish(cpars);
3208
3209 /* Hold the call for some time */
3210 f_sleep(1.0);
3211
3212 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3213 op_code := SS_OP_CODE_USS_REQUEST,
3214 ussd_string := "Please type anything..."
3215 );
3216
3217 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3218 op_code := SS_OP_CODE_USS_REQUEST,
3219 ussd_string := "Nope."
3220 )
3221
3222 /* Compose MT SS/REGISTER message with network-originated request */
3223 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3224 tid := 0, /* FIXME: most likely, it should be 0 */
3225 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3226 facility := valueof(facility_req)
3227 );
3228
3229 /* Compose HLR -> MSC GSUP message */
3230 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3231 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003232 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003233 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3234 ss := valueof(facility_req)
3235 );
3236
3237 /* Send it to MSC */
3238 GSUP.send(gsup_req);
3239 /* Expect MT REGISTER message with USSD request */
3240 f_expect_mt_dtap_msg(ussd_req);
3241
3242 /* Compose a new MO SS/FACILITY message with response */
3243 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3244 tid := 0, /* FIXME: it shall match the request tid */
3245 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3246 facility := valueof(facility_rsp)
3247 );
3248
3249 /* Compose expected MSC -> HLR GSUP message */
3250 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3251 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003252 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003253 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3254 ss := valueof(facility_rsp)
3255 );
3256
3257 /* MS sends response */
3258 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3259 f_expect_gsup_msg(gsup_rsp);
3260
3261 /* Compose expected MT SS/RELEASE COMPLETE message */
3262 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3263 tid := 0, /* FIXME: it shall match the request tid */
3264 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3265 facility := omit
3266 );
3267
3268 /* Compose MSC -> HLR GSUP message */
3269 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3270 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003271 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003272 state := OSMO_GSUP_SESSION_STATE_END
3273 );
3274
3275 /* Finally, HLR terminates the session */
3276 GSUP.send(gsup_term);
3277 /* Expect MT RELEASE COMPLETE without Facility IE */
3278 f_expect_mt_dtap_msg(ussd_term);
3279
3280 /* Hold the call for some time */
3281 f_sleep(1.0);
3282
3283 /* Release the call (does Clear Complete itself) */
3284 f_call_hangup(cpars, true);
3285}
3286testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3287 var BSC_ConnHdlr vc_conn;
3288 f_init();
3289 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3290 vc_conn.done;
3291}
3292
Harald Weltee13cfb22019-04-23 16:52:02 +02003293
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003294/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003295friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003296runs on BSC_ConnHdlr {
3297 f_init_handler(pars);
3298
3299 /* Perform location update */
3300 f_perform_lu();
3301
3302 /* Send CM Service Request for SS/USSD */
3303 f_establish_fully(EST_TYPE_SS_ACT);
3304
3305 /* We need to inspect GSUP activity */
3306 f_create_gsup_expect(hex2str(g_pars.imsi));
3307
3308 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3309 invoke_id := 1, /* Initial request */
3310 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3311 ussd_string := "*6766*266#"
3312 );
3313
3314 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3315 invoke_id := 2, /* Counter request */
3316 op_code := SS_OP_CODE_USS_REQUEST,
3317 ussd_string := "Password?!?"
3318 )
3319
3320 /* Compose MO SS/REGISTER message with request */
3321 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3322 tid := 1, /* We just need a single transaction */
3323 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3324 facility := valueof(facility_ms_req)
3325 );
3326
3327 /* Compose expected MSC -> HLR message */
3328 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3329 imsi := g_pars.imsi,
3330 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3331 ss := valueof(facility_ms_req)
3332 );
3333
3334 /* To be used for sending response with correct session ID */
3335 var GSUP_PDU gsup_ms_req_complete;
3336
3337 /* Initiate a new transaction */
3338 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3339 /* Expect GSUP request with original Facility IE */
3340 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3341
3342 /* Compose the response from HLR using received session ID */
3343 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3344 imsi := g_pars.imsi,
3345 sid := gsup_ms_req_complete.ies[1].val.session_id,
3346 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3347 ss := valueof(facility_net_req)
3348 );
3349
3350 /* Compose expected MT SS/FACILITY template with counter request */
3351 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3352 tid := 1, /* Response should arrive within the same transaction */
3353 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3354 facility := valueof(facility_net_req)
3355 );
3356
3357 /* Send response over GSUP */
3358 GSUP.send(gsup_net_req);
3359 /* Expect MT SS/FACILITY message with counter request */
3360 f_expect_mt_dtap_msg(ussd_net_req);
3361
3362 /* Compose MO SS/RELEASE COMPLETE */
3363 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3364 tid := 1, /* Response should arrive within the same transaction */
3365 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3366 facility := omit
3367 /* TODO: cause? */
3368 );
3369
3370 /* Compose expected HLR -> MSC abort message */
3371 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3372 imsi := g_pars.imsi,
3373 sid := gsup_ms_req_complete.ies[1].val.session_id,
3374 state := OSMO_GSUP_SESSION_STATE_END
3375 );
3376
3377 /* Abort transaction */
3378 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3379 /* Expect GSUP message indicating abort */
3380 f_expect_gsup_msg(gsup_abort);
3381
3382 f_expect_clear();
3383}
3384testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3385 var BSC_ConnHdlr vc_conn;
3386 f_init();
3387 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3388 vc_conn.done;
3389}
3390
Harald Weltee13cfb22019-04-23 16:52:02 +02003391
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003392/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003393friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003394runs on BSC_ConnHdlr {
3395 f_init_handler(pars);
3396
3397 /* Perform location update */
3398 f_perform_lu();
3399
3400 /* Send CM Service Request for SS/USSD */
3401 f_establish_fully(EST_TYPE_SS_ACT);
3402
3403 /* We need to inspect GSUP activity */
3404 f_create_gsup_expect(hex2str(g_pars.imsi));
3405
3406 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3407 invoke_id := 1,
3408 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3409 ussd_string := "#release_me");
3410
3411 /* Compose MO SS/REGISTER message with request */
3412 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3413 tid := 1, /* An arbitrary transaction identifier */
3414 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3415 facility := valueof(facility_ms_req));
3416
3417 /* Compose expected MSC -> HLR message */
3418 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3419 imsi := g_pars.imsi,
3420 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3421 ss := valueof(facility_ms_req));
3422
3423 /* To be used for sending response with correct session ID */
3424 var GSUP_PDU gsup_ms_req_complete;
3425
3426 /* Initiate a new SS transaction */
3427 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3428 /* Expect GSUP request with original Facility IE */
3429 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3430
3431 /* Don't respond, wait for timeout */
3432 f_sleep(3.0);
3433
3434 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3435 tid := 1, /* Should match the request's tid */
3436 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3437 cause := *, /* TODO: expect some specific value */
3438 facility := omit);
3439
3440 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3441 imsi := g_pars.imsi,
3442 sid := gsup_ms_req_complete.ies[1].val.session_id,
3443 state := OSMO_GSUP_SESSION_STATE_END,
3444 cause := ?); /* TODO: expect some specific value */
3445
3446 /* Expect release on both interfaces */
3447 interleave {
3448 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3449 [] GSUP.receive(gsup_rel) { };
3450 }
3451
3452 f_expect_clear();
3453 setverdict(pass);
3454}
3455testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3456 var BSC_ConnHdlr vc_conn;
3457 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003458 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003459 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3460 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003461 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003462}
3463
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003464/* MT (network-originated) USSD for unknown subscriber */
3465friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
3466runs on BSC_ConnHdlr {
3467 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
3468 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003469
3470 f_init_handler(pars);
3471 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
3472 f_create_gsup_expect(hex2str(imsi));
3473
3474 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3475 imsi := imsi,
3476 sid := sid,
3477 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3478 ss := f_rnd_octstring(23)
3479 );
3480
3481 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
3482 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3483 imsi := imsi,
3484 sid := sid,
3485 state := OSMO_GSUP_SESSION_STATE_END,
3486 cause := 2 /* FIXME: introduce an enumerated type! */
3487 );
3488
3489 /* Initiate a MT USSD notification */
3490 GSUP.send(gsup_req);
3491
3492 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07003493 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003494}
3495testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
3496 var BSC_ConnHdlr vc_conn;
3497 f_init();
3498 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
3499 vc_conn.done;
3500}
3501
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003502/* MO (mobile-originated) SS/USSD for unknown transaction */
3503friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
3504runs on BSC_ConnHdlr {
3505 f_init_handler(pars);
3506
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003507 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003508 f_create_gsup_expect(hex2str(g_pars.imsi));
3509
3510 /* Perform location update */
3511 f_perform_lu();
3512
3513 /* Send CM Service Request for SS/USSD */
3514 f_establish_fully(EST_TYPE_SS_ACT);
3515
3516 /* GSM 04.80 FACILITY message for a non-existing transaction */
3517 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
3518 tid := 1, /* An arbitrary transaction identifier */
3519 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3520 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3521 );
3522
3523 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
3524 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
3525 tid := 1, /* An arbitrary transaction identifier */
3526 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3527 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3528 );
3529
3530 /* Expected response from the network */
3531 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3532 tid := 1, /* Same as in the FACILITY message */
3533 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3534 facility := omit
3535 );
3536
3537 /* Send GSM 04.80 FACILITY for non-existing transaction */
3538 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
3539
3540 /* Expect GSM 04.80 RELEASE COMPLETE message */
3541 f_expect_mt_dtap_msg(mt_ss_rel);
3542 f_expect_clear();
3543
3544 /* Send another CM Service Request for SS/USSD */
3545 f_establish_fully(EST_TYPE_SS_ACT);
3546
3547 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
3548 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
3549
3550 /* Expect GSM 04.80 RELEASE COMPLETE message */
3551 f_expect_mt_dtap_msg(mt_ss_rel);
3552 f_expect_clear();
3553}
3554testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
3555 var BSC_ConnHdlr vc_conn;
3556 f_init();
3557 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
3558 vc_conn.done;
3559}
3560
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003561/* MT (network-originated) USSD for unknown session */
3562friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
3563runs on BSC_ConnHdlr {
3564 var OCT4 sid := '20000333'O;
3565
3566 f_init_handler(pars);
3567
3568 /* Perform location update */
3569 f_perform_lu();
3570
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003571 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003572 f_create_gsup_expect(hex2str(g_pars.imsi));
3573
3574 /* Request referencing a non-existing SS session */
3575 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3576 imsi := g_pars.imsi,
3577 sid := sid,
3578 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3579 ss := f_rnd_octstring(23)
3580 );
3581
3582 /* Error with some cause value */
3583 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3584 imsi := g_pars.imsi,
3585 sid := sid,
3586 state := OSMO_GSUP_SESSION_STATE_END,
3587 cause := ? /* FIXME: introduce an enumerated type! */
3588 );
3589
3590 /* Initiate a MT USSD notification */
3591 GSUP.send(gsup_req);
3592
3593 /* Expect GSUP PROC_SS_ERROR message */
3594 f_expect_gsup_msg(gsup_rsp);
3595}
3596testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
3597 var BSC_ConnHdlr vc_conn;
3598 f_init();
3599 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
3600 vc_conn.done;
3601}
3602
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003603/* MT (network-originated) USSD and no response to Paging Request */
3604friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
3605runs on BSC_ConnHdlr {
3606 timer TP := 2.0; /* Paging timer */
3607
3608 f_init_handler(pars);
3609
3610 /* Perform location update */
3611 f_perform_lu();
3612
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003613 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003614 f_create_gsup_expect(hex2str(g_pars.imsi));
3615
3616 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3617 imsi := g_pars.imsi,
3618 sid := '20000444'O,
3619 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3620 ss := f_rnd_octstring(23)
3621 );
3622
3623 /* Error with some cause value */
3624 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3625 imsi := g_pars.imsi,
3626 sid := '20000444'O,
3627 state := OSMO_GSUP_SESSION_STATE_END,
3628 cause := ? /* FIXME: introduce an enumerated type! */
3629 );
3630
3631 /* Initiate a MT USSD notification */
3632 GSUP.send(gsup_req);
3633
3634 /* Send it to MSC and expect Paging Request */
3635 TP.start;
3636 alt {
3637 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3638 setverdict(pass);
3639 }
3640 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
3641 setverdict(pass);
3642 }
3643 /* We don't expect anything else */
3644 [] as_unexp_gsup_or_bssap_msg();
3645 [] TP.timeout {
3646 setverdict(fail, "Timeout waiting for Paging Request");
3647 }
3648 }
3649
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07003650 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
3651 * OsmoMSC waits for Paging Response 10 seconds by default. */
3652 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003653}
3654testcase TC_proc_ss_paging_fail() runs on MTC_CT {
3655 var BSC_ConnHdlr vc_conn;
3656 f_init();
3657 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
3658 vc_conn.done;
3659}
3660
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07003661/* MT (network-originated) USSD followed by immediate abort */
3662friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
3663runs on BSC_ConnHdlr {
3664 var octetstring facility := f_rnd_octstring(23);
3665 var OCT4 sid := '20000555'O;
3666 timer TP := 2.0;
3667
3668 f_init_handler(pars);
3669
3670 /* Perform location update */
3671 f_perform_lu();
3672
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003673 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07003674 f_create_gsup_expect(hex2str(g_pars.imsi));
3675
3676 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
3677 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3678 imsi := g_pars.imsi, sid := sid,
3679 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3680 ss := facility
3681 );
3682
3683 /* On the MS side, we expect GSM 04.80 REGISTER message */
3684 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
3685 tid := 0, /* Most likely, it should be 0 */
3686 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3687 facility := facility
3688 );
3689
3690 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
3691 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
3692 imsi := g_pars.imsi, sid := sid,
3693 state := OSMO_GSUP_SESSION_STATE_END,
3694 cause := 0 /* FIXME: introduce an enumerated type! */
3695 );
3696
3697 /* On the MS side, we expect GSM 04.80 REGISTER message */
3698 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3699 tid := 0, /* Most likely, it should be 0 */
3700 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3701 cause := *, /* FIXME: expect some specific cause value */
3702 facility := omit
3703 );
3704
3705 /* Initiate a MT USSD with random payload */
3706 GSUP.send(gsup_req);
3707
3708 /* Expect Paging Request */
3709 TP.start;
3710 alt {
3711 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3712 setverdict(pass);
3713 }
3714 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
3715 setverdict(pass);
3716 }
3717 /* We don't expect anything else */
3718 [] as_unexp_gsup_or_bssap_msg();
3719 [] TP.timeout {
3720 setverdict(fail, "Timeout waiting for Paging Request");
3721 }
3722 }
3723
3724 /* Send Paging Response and establish connection */
3725 f_establish_fully(EST_TYPE_PAG_RESP);
3726 /* Expect MT REGISTER message with random facility */
3727 f_expect_mt_dtap_msg(dtap_reg);
3728
3729 /* HLR/EUSE decides to abort the session even
3730 * before getting any response from the MS */
3731 /* Initiate a MT USSD with random payload */
3732 GSUP.send(gsup_abort);
3733
3734 /* Expect RELEASE COMPLETE on ths MS side */
3735 f_expect_mt_dtap_msg(dtap_rel);
3736
3737 f_expect_clear();
3738}
3739testcase TC_proc_ss_abort() runs on MTC_CT {
3740 var BSC_ConnHdlr vc_conn;
3741 f_init();
3742 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
3743 vc_conn.done;
3744}
3745
Harald Weltee13cfb22019-04-23 16:52:02 +02003746
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003747/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
3748private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3749 pars.net.expect_auth := true;
3750 pars.net.expect_ciph := true;
3751 pars.net.kc_support := '02'O; /* A5/1 only */
3752 f_init_handler(pars);
3753
3754 g_pars.vec := f_gen_auth_vec_2g();
3755
3756 /* Can't use f_perform_lu() directly. Code below is based on it. */
3757
3758 /* tell GSUP dispatcher to send this IMSI to us */
3759 f_create_gsup_expect(hex2str(g_pars.imsi));
3760
3761 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3762 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02003763 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003764
3765 f_mm_auth();
3766
3767 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3768 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3769 alt {
3770 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3771 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
3772 }
3773 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3774 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3775 mtc.stop;
3776 }
3777 [] BSSAP.receive {
3778 setverdict(fail, "Unknown/unexpected BSSAP received");
3779 mtc.stop;
3780 }
3781 }
3782
3783 /* Expect LU reject from MSC. */
3784 alt {
3785 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3786 setverdict(pass);
3787 }
3788 [] BSSAP.receive {
3789 setverdict(fail, "Unknown/unexpected BSSAP received");
3790 mtc.stop;
3791 }
3792 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01003793 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003794}
3795
3796testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
3797 var BSC_ConnHdlr vc_conn;
3798 f_init();
3799 f_vty_config(MSCVTY, "network", "encryption a5 1");
3800
3801 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52);
3802 vc_conn.done;
3803}
3804
Harald Welteb2284bd2019-05-10 11:30:43 +02003805/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
3806friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3807 f_init_handler(pars);
3808
3809 /* tell GSUP dispatcher to send this IMSI to us */
3810 f_create_gsup_expect(hex2str(g_pars.imsi));
3811
3812 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
3813 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
3814
3815 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3816 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
3817 f_cl3_or_initial_ue(l3_lu);
3818
3819 /* Expect LU reject from MSC. */
3820 alt {
3821 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3822 setverdict(pass);
3823 }
3824 [] BSSAP.receive {
3825 setverdict(fail, "Unknown/unexpected BSSAP received");
3826 mtc.stop;
3827 }
3828 }
3829 f_expect_clear();
3830}
3831testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
3832 var BSC_ConnHdlr vc_conn;
3833 f_init();
3834 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
3835 vc_conn.done;
3836}
3837
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01003838private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
3839 pars.net.expect_auth := true;
3840 pars.net.expect_ciph := true;
3841 pars.net.kc_support := kc_support;
3842 f_init_handler(pars);
3843
3844 g_pars.vec := f_gen_auth_vec_2g();
3845
3846 /* Can't use f_perform_lu() directly. Code below is based on it. */
3847
3848 /* tell GSUP dispatcher to send this IMSI to us */
3849 f_create_gsup_expect(hex2str(g_pars.imsi));
3850
3851 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3852 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
3853 f_cl3_or_initial_ue(l3_lu);
3854
3855 f_mm_auth();
3856
3857 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3858 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3859 alt {
3860 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3861 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
3862 }
3863 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
3864 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
3865 repeat;
3866 }
3867 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3868 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3869 mtc.stop;
3870 }
3871 [] BSSAP.receive {
3872 setverdict(fail, "Unknown/unexpected BSSAP received");
3873 mtc.stop;
3874 }
3875 }
3876
3877 /* TODO: Verify MSC is using the best cipher available! How? */
3878
3879 f_msc_lu_hlr();
3880 f_accept_reject_lu();
3881 f_expect_clear();
3882 setverdict(pass);
3883}
3884
3885/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
3886private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3887 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
3888}
3889
3890/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
3891private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3892 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
3893}
3894
3895/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
3896private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3897 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
3898}
3899
3900testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
3901 var BSC_ConnHdlr vc_conn;
3902 f_init();
3903 f_vty_config(MSCVTY, "network", "encryption a5 1");
3904
3905 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
3906 vc_conn.done;
3907}
3908
3909testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
3910 var BSC_ConnHdlr vc_conn;
3911 f_init();
3912 f_vty_config(MSCVTY, "network", "encryption a5 3");
3913
3914 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
3915 vc_conn.done;
3916}
3917
3918testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
3919 var BSC_ConnHdlr vc_conn;
3920 f_init();
3921 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
3922
3923 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
3924 vc_conn.done;
3925}
Harald Welteb2284bd2019-05-10 11:30:43 +02003926
Harald Weltef640a012018-04-14 17:49:21 +02003927/* TODO (SMS):
3928 * different user data lengths
3929 * SMPP transaction mode with unsuccessful delivery
3930 * queued MT-SMS with no paging response + later delivery
3931 * different data coding schemes
3932 * multi-part SMS
3933 * user-data headers
3934 * TP-PID for SMS to SIM
3935 * behavior if SMS memory is full + RP-SMMA
3936 * delivery reports
3937 * SMPP osmocom extensions
3938 * more-messages-to-send
3939 * SMS during ongoing call (SACCH/SAPI3)
3940 */
3941
3942/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01003943 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
3944 * malformed messages (missing IE, invalid message type): properly rejected?
3945 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
3946 * 3G/2G auth permutations
3947 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01003948 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01003949 * too long L3 INFO in DTAP
3950 * too long / padded BSSAP
3951 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01003952 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01003953
Harald Weltee13cfb22019-04-23 16:52:02 +02003954/***********************************************************************
3955 * SGsAP Testing
3956 ***********************************************************************/
3957
Philipp Maier948747b2019-04-02 15:22:33 +02003958/* Check if a subscriber exists in the VLR */
3959private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
3960
3961 var CtrlValue active_subsribers;
3962 var integer rc;
3963 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
3964
3965 rc := f_strstr(active_subsribers, imsi_or_msisdn);
3966 if (rc < 0) {
3967 return false;
3968 }
3969
3970 return true;
3971}
3972
Harald Welte4263c522018-12-06 11:56:27 +01003973/* Perform a location updatye at the A-Interface and run some checks to confirm
3974 * that everything is back to normal. */
3975private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
3976 var SmsParameters spars := valueof(t_SmsPars);
3977
3978 /* Perform a location update, the SGs association is expected to fall
3979 * back to NULL */
3980 f_perform_lu();
3981 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3982
3983 /* Trigger a paging request and expect the paging on BSSMAP, this is
3984 * to make sure that pagings are sent throught the A-Interface again
3985 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02003986 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01003987 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3988
3989 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003990 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
3991 setverdict(pass);
3992 }
Harald Welte62113fc2019-05-09 13:04:02 +02003993 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01003994 setverdict(pass);
3995 }
3996 [] SGsAP.receive {
3997 setverdict(fail, "Received unexpected message on SGs");
3998 }
3999 }
4000
4001 /* Send an SMS to make sure that also payload messages are routed
4002 * throught the A-Interface again */
4003 f_establish_fully(EST_TYPE_MO_SMS);
4004 f_mo_sms(spars);
4005 f_expect_clear();
4006}
4007
4008private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4009 var charstring vlr_name;
4010 f_init_handler(pars);
4011
4012 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4013 log("VLR name: ", vlr_name);
4014 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004015 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004016}
4017
4018testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004019 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004020 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004021 f_init(1, true);
4022 pars := f_init_pars(11810, true);
4023 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004024 vc_conn.done;
4025}
4026
4027/* like f_mm_auth() but for SGs */
4028function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4029 if (g_pars.net.expect_auth) {
4030 g_pars.vec := f_gen_auth_vec_3g();
4031 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4032 g_pars.vec.sres,
4033 g_pars.vec.kc,
4034 g_pars.vec.ik,
4035 g_pars.vec.ck,
4036 g_pars.vec.autn,
4037 g_pars.vec.res));
4038 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4039 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4040 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4041 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4042 }
4043}
4044
4045/* like f_perform_lu(), but on SGs rather than BSSAP */
4046function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4047 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4048 var PDU_SGsAP lur;
4049 var PDU_SGsAP lua;
4050 var PDU_SGsAP mm_info;
4051 var octetstring mm_info_dtap;
4052
4053 /* tell GSUP dispatcher to send this IMSI to us */
4054 f_create_gsup_expect(hex2str(g_pars.imsi));
4055
4056 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4057 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4058 /* Old LAI, if MS sends it */
4059 /* TMSI status, if MS has no valid TMSI */
4060 /* IMEISV, if it supports "automatic device detection" */
4061 /* TAI, if available in MME */
4062 /* E-CGI, if available in MME */
4063 SGsAP.send(lur);
4064
4065 /* FIXME: is this really done over SGs? The Ue is already authenticated
4066 * via the MME ... */
4067 f_mm_auth_sgs();
4068
4069 /* Expect MSC to perform LU with HLR */
4070 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4071 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4072 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4073 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4074
4075 alt {
4076 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4077 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4078 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4079 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4080 }
4081 setverdict(pass);
4082 }
4083 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4084 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4085 }
4086 [] SGsAP.receive {
4087 setverdict(fail, "Received unexpected message on SGs");
4088 }
4089 }
4090
4091 /* Check MM information */
4092 if (mp_mm_info == true) {
4093 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4094 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4095 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4096 setverdict(fail, "Unexpected MM Information");
4097 }
4098 }
4099
4100 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4101}
4102
4103private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4104 f_init_handler(pars);
4105 f_sgs_perform_lu();
4106 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4107
4108 f_sgsap_bssmap_screening();
4109
4110 setverdict(pass);
4111}
4112testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004113 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004114 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004115 f_init(1, true);
4116 pars := f_init_pars(11811, true);
4117 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004118 vc_conn.done;
4119}
4120
4121/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4122private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4123 f_init_handler(pars);
4124 var PDU_SGsAP lur;
4125
4126 f_create_gsup_expect(hex2str(g_pars.imsi));
4127 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4128 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4129 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4130 SGsAP.send(lur);
4131
4132 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4133 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4134 alt {
4135 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4136 setverdict(pass);
4137 }
4138 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4139 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4140 mtc.stop;
4141 }
4142 [] SGsAP.receive {
4143 setverdict(fail, "Received unexpected message on SGs");
4144 }
4145 }
4146
4147 f_sgsap_bssmap_screening();
4148
4149 setverdict(pass);
4150}
4151testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004152 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004153 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004154 f_init(1, true);
4155 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004156
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004157 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004158 vc_conn.done;
4159}
4160
4161/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4162private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4163 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4164 var PDU_SGsAP lur;
4165
4166 f_init_handler(pars);
4167
4168 /* tell GSUP dispatcher to send this IMSI to us */
4169 f_create_gsup_expect(hex2str(g_pars.imsi));
4170
4171 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4172 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4173 /* Old LAI, if MS sends it */
4174 /* TMSI status, if MS has no valid TMSI */
4175 /* IMEISV, if it supports "automatic device detection" */
4176 /* TAI, if available in MME */
4177 /* E-CGI, if available in MME */
4178 SGsAP.send(lur);
4179
4180 /* FIXME: is this really done over SGs? The Ue is already authenticated
4181 * via the MME ... */
4182 f_mm_auth_sgs();
4183
4184 /* Expect MSC to perform LU with HLR */
4185 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4186 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4187 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4188 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4189
4190 alt {
4191 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4192 setverdict(pass);
4193 }
4194 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4195 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4196 }
4197 [] SGsAP.receive {
4198 setverdict(fail, "Received unexpected message on SGs");
4199 }
4200 }
4201
4202 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4203
4204 /* Wait until the VLR has abort the TMSI reallocation procedure */
4205 f_sleep(45.0);
4206
4207 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4208 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4209
4210 f_sgsap_bssmap_screening();
4211
4212 setverdict(pass);
4213}
4214testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004215 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004216 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004217 f_init(1, true);
4218 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004219
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004220 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004221 vc_conn.done;
4222}
4223
4224private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4225runs on BSC_ConnHdlr {
4226 f_init_handler(pars);
4227 f_sgs_perform_lu();
4228 f_sleep(3.0);
4229
4230 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4231 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4232 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4233 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4234
4235 f_sgsap_bssmap_screening();
4236
4237 setverdict(pass);
4238}
4239testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004240 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004241 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004242 f_init(1, true);
4243 pars := f_init_pars(11814, true);
4244 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004245 vc_conn.done;
4246}
4247
Philipp Maierfc19f172019-03-21 11:17:54 +01004248private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4249runs on BSC_ConnHdlr {
4250 f_init_handler(pars);
4251 f_sgs_perform_lu();
4252 f_sleep(3.0);
4253
4254 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4255 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4256 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4257 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4258
4259 f_sgsap_bssmap_screening();
4260
4261 setverdict(pass);
4262}
4263testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4264 var BSC_ConnHdlrPars pars;
4265 var BSC_ConnHdlr vc_conn;
4266 f_init(1, true);
4267 pars := f_init_pars(11814, true);
4268 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4269 vc_conn.done;
4270}
4271
Harald Welte4263c522018-12-06 11:56:27 +01004272private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4273runs on BSC_ConnHdlr {
4274 f_init_handler(pars);
4275 f_sgs_perform_lu();
4276 f_sleep(3.0);
4277
4278 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4279 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4280 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004281
4282 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4283 setverdict(fail, "subscriber not removed from VLR");
4284 }
Harald Welte4263c522018-12-06 11:56:27 +01004285
4286 f_sgsap_bssmap_screening();
4287
4288 setverdict(pass);
4289}
4290testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004291 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004292 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004293 f_init(1, true);
4294 pars := f_init_pars(11815, true);
4295 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004296 vc_conn.done;
4297}
4298
Philipp Maier5d812702019-03-21 10:51:26 +01004299private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4300runs on BSC_ConnHdlr {
4301 f_init_handler(pars);
4302 f_sgs_perform_lu();
4303 f_sleep(3.0);
4304
4305 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4306 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4307 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4308
4309 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4310 setverdict(fail, "subscriber not removed from VLR");
4311 }
4312
4313 f_sgsap_bssmap_screening();
4314
4315 setverdict(pass);
4316}
4317testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4318 var BSC_ConnHdlrPars pars;
4319 var BSC_ConnHdlr vc_conn;
4320 f_init(1, true);
4321 pars := f_init_pars(11815, true);
4322 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4323 vc_conn.done;
4324}
4325
Harald Welte4263c522018-12-06 11:56:27 +01004326/* Trigger a paging request via VTY and send a paging reject in response */
4327private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4328runs on BSC_ConnHdlr {
4329 f_init_handler(pars);
4330 f_sgs_perform_lu();
4331 f_sleep(1.0);
4332
4333 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4334 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4335 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4336 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4337
4338 /* Initiate paging via VTY */
4339 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4340 alt {
4341 [] SGsAP.receive(exp_resp) {
4342 setverdict(pass);
4343 }
4344 [] SGsAP.receive {
4345 setverdict(fail, "Received unexpected message on SGs");
4346 }
4347 }
4348
4349 /* Now reject the paging */
4350 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4351
4352 /* Wait for the states inside the MSC to settle and check the state
4353 * of the SGs Association */
4354 f_sleep(1.0);
4355 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4356
4357 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4358 * but we also need to cover tha case where the cause code indicates an
4359 * "IMSI detached for EPS services". In those cases the VLR is expected to
4360 * try paging on tha A/Iu interface. This will be another testcase similar to
4361 * this one, but extended with checks for the presence of the A/Iu paging
4362 * messages. */
4363
4364 f_sgsap_bssmap_screening();
4365
4366 setverdict(pass);
4367}
4368testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004369 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004370 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004371 f_init(1, true);
4372 pars := f_init_pars(11816, true);
4373 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004374 vc_conn.done;
4375}
4376
4377/* Trigger a paging request via VTY and send a paging reject that indicates
4378 * that the subscriber intentionally rejected the call. */
4379private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4380runs on BSC_ConnHdlr {
4381 f_init_handler(pars);
4382 f_sgs_perform_lu();
4383 f_sleep(1.0);
4384
4385 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4386 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4387 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4388 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4389
4390 /* Initiate paging via VTY */
4391 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4392 alt {
4393 [] SGsAP.receive(exp_resp) {
4394 setverdict(pass);
4395 }
4396 [] SGsAP.receive {
4397 setverdict(fail, "Received unexpected message on SGs");
4398 }
4399 }
4400
4401 /* Now reject the paging */
4402 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4403
4404 /* Wait for the states inside the MSC to settle and check the state
4405 * of the SGs Association */
4406 f_sleep(1.0);
4407 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4408
4409 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4410 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4411 * to check back how this works and how it can be tested */
4412
4413 f_sgsap_bssmap_screening();
4414
4415 setverdict(pass);
4416}
4417testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004418 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004419 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004420 f_init(1, true);
4421 pars := f_init_pars(11817, true);
4422 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004423 vc_conn.done;
4424}
4425
4426/* Trigger a paging request via VTY and send an UE unreacable messge in response */
4427private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
4428runs on BSC_ConnHdlr {
4429 f_init_handler(pars);
4430 f_sgs_perform_lu();
4431 f_sleep(1.0);
4432
4433 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4434 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4435 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4436 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4437
4438 /* Initiate paging via VTY */
4439 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4440 alt {
4441 [] SGsAP.receive(exp_resp) {
4442 setverdict(pass);
4443 }
4444 [] SGsAP.receive {
4445 setverdict(fail, "Received unexpected message on SGs");
4446 }
4447 }
4448
4449 /* Now pretend that the UE is unreachable */
4450 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
4451
4452 /* Wait for the states inside the MSC to settle and check the state
4453 * of the SGs Association. */
4454 f_sleep(1.0);
4455 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4456
4457 f_sgsap_bssmap_screening();
4458
4459 setverdict(pass);
4460}
4461testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004462 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004463 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004464 f_init(1, true);
4465 pars := f_init_pars(11818, true);
4466 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004467 vc_conn.done;
4468}
4469
4470/* Trigger a paging request via VTY but don't respond to it */
4471private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
4472runs on BSC_ConnHdlr {
4473 f_init_handler(pars);
4474 f_sgs_perform_lu();
4475 f_sleep(1.0);
4476
4477 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4478 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02004479 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01004480 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4481 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4482
4483 /* Initiate paging via VTY */
4484 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4485 alt {
4486 [] SGsAP.receive(exp_resp) {
4487 setverdict(pass);
4488 }
4489 [] SGsAP.receive {
4490 setverdict(fail, "Received unexpected message on SGs");
4491 }
4492 }
4493
Philipp Maier34218102019-09-24 09:15:49 +02004494 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
4495 * after some time */
4496 timer T := 10.0;
4497 T.start
4498 alt {
4499 [] SGsAP.receive(exp_serv_abrt)
4500 {
4501 setverdict(pass);
4502 }
4503 [] SGsAP.receive {
4504 setverdict(fail, "unexpected SGsAP message received");
4505 self.stop;
4506 }
4507 [] T.timeout {
4508 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
4509 self.stop;
4510 }
4511 }
4512
4513 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01004514 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4515
4516 f_sgsap_bssmap_screening();
4517
4518 setverdict(pass);
4519}
4520testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004521 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004522 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004523 f_init(1, true);
4524 pars := f_init_pars(11819, true);
4525 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004526 vc_conn.done;
4527}
4528
4529/* Trigger a paging request via VTY and slip in an LU */
4530private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4531runs on BSC_ConnHdlr {
4532 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4533 f_init_handler(pars);
4534
4535 /* First we prepar the situation, where the SGs association is in state
4536 * NULL and the confirmed by radio contact indicator is set to false
4537 * as well. This can be archived by performing an SGs LU and then
4538 * resetting the VLR */
4539 f_sgs_perform_lu();
4540 f_sgsap_reset_mme(mp_mme_name);
4541 f_sleep(1.0);
4542 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4543
4544 /* Perform a paging, expect the paging messages on the SGs interface */
4545 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4546 alt {
4547 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4548 setverdict(pass);
4549 }
4550 [] SGsAP.receive {
4551 setverdict(fail, "Received unexpected message on SGs");
4552 }
4553 }
4554
4555 /* Perform the LU as normal */
4556 f_sgs_perform_lu();
4557 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4558
4559 /* Expect a new paging request right after the LU */
4560 alt {
4561 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4562 setverdict(pass);
4563 }
4564 [] SGsAP.receive {
4565 setverdict(fail, "Received unexpected message on SGs");
4566 }
4567 }
4568
4569 /* Test is done now, lets round everything up by rejecting the paging
4570 * cleanly. */
4571 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4572 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4573
4574 f_sgsap_bssmap_screening();
4575
4576 setverdict(pass);
4577}
4578testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004579 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004580 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004581 f_init(1, true);
4582 pars := f_init_pars(11820, true);
4583 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004584 vc_conn.done;
4585}
4586
4587/* Send unexpected unit-data through the SGs interface */
4588private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4589 f_init_handler(pars);
4590 f_sleep(1.0);
4591
4592 /* This simulates what happens when a subscriber without SGs
4593 * association gets unitdata via the SGs interface. */
4594
4595 /* Make sure the subscriber exists and the SGs association
4596 * is in NULL state */
4597 f_perform_lu();
4598 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4599
4600 /* Send some random unit data, the MSC/VLR should send a release
4601 * immediately. */
4602 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4603 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
4604
4605 f_sgsap_bssmap_screening();
4606
4607 setverdict(pass);
4608}
4609testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004610 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004611 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004612 f_init(1, true);
4613 pars := f_init_pars(11821, true);
4614 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004615 vc_conn.done;
4616}
4617
4618/* Send unsolicited unit-data through the SGs interface */
4619private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4620 f_init_handler(pars);
4621 f_sleep(1.0);
4622
4623 /* This simulates what happens when the MME attempts to send unitdata
4624 * to a subscriber that is completely unknown to the VLR */
4625
4626 /* Send some random unit data, the MSC/VLR should send a release
4627 * immediately. */
4628 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4629 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
4630
4631 f_sgsap_bssmap_screening();
4632
4633 setverdict(pass);
4634}
4635testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004636 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004637 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004638 f_init(1, true);
4639 pars := f_init_pars(11822, true);
4640 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004641 vc_conn.done;
4642}
4643
4644private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
4645 /* FIXME: Match an actual payload (second questionmark), the type is
4646 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
4647 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
4648 setverdict(fail, "Unexpected SMS related PDU from MSC");
4649 mtc.stop;
4650 }
4651}
4652
4653/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
4654function f_mt_sms_sgs(inout SmsParameters spars)
4655runs on BSC_ConnHdlr {
4656 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4657 var template (value) RPDU_MS_SGSN rp_mo;
4658 var template (value) PDU_ML3_MS_NW l3_mo;
4659
4660 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4661 var template RPDU_SGSN_MS rp_mt;
4662 var template PDU_ML3_NW_MS l3_mt;
4663
4664 var PDU_ML3_NW_MS sgsap_l3_mt;
4665
4666 var default d := activate(as_other_sms_sgs());
4667
4668 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
4669 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09004670 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01004671 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
4672
4673 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
4674
4675 /* Extract relevant identifiers */
4676 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
4677 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
4678
4679 /* send CP-ACK for CP-DATA just received */
4680 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
4681
4682 SGsAP.send(l3_mo);
4683
4684 /* send RP-ACK for RP-DATA */
4685 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
4686 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
4687
4688 SGsAP.send(l3_mo);
4689
4690 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
4691 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
4692
4693 SGsAP.receive(l3_mt);
4694
4695 deactivate(d);
4696
4697 setverdict(pass);
4698}
4699
4700/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
4701function f_mo_sms_sgs(inout SmsParameters spars)
4702runs on BSC_ConnHdlr {
4703 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4704 var template (value) RPDU_MS_SGSN rp_mo;
4705 var template (value) PDU_ML3_MS_NW l3_mo;
4706
4707 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4708 var template RPDU_SGSN_MS rp_mt;
4709 var template PDU_ML3_NW_MS l3_mt;
4710
4711 var default d := activate(as_other_sms_sgs());
4712
4713 /* just in case this is routed to SMPP.. */
4714 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
4715
4716 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
4717 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09004718 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01004719 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
4720
4721 SGsAP.send(l3_mo);
4722
4723 /* receive CP-ACK for CP-DATA above */
4724 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
4725
4726 if (ispresent(spars.exp_rp_err)) {
4727 /* expect an RP-ERROR message from MSC with given cause */
4728 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
4729 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4730 SGsAP.receive(l3_mt);
4731 /* send CP-ACK for CP-DATA just received */
4732 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4733 SGsAP.send(l3_mo);
4734 } else {
4735 /* expect RP-ACK for RP-DATA */
4736 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
4737 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4738 SGsAP.receive(l3_mt);
4739 /* send CP-ACO for CP-DATA just received */
4740 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4741 SGsAP.send(l3_mo);
4742 }
4743
4744 deactivate(d);
4745
4746 setverdict(pass);
4747}
4748
4749private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
4750runs on BSC_ConnHdlr {
4751 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
4752}
4753
4754/* Send a MT SMS via SGs interface */
4755private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4756 f_init_handler(pars);
4757 f_sgs_perform_lu();
4758 f_sleep(1.0);
4759 var SmsParameters spars := valueof(t_SmsPars);
4760 spars.tp.ud := 'C8329BFD064D9B53'O;
4761
4762 /* Trigger SMS via VTY */
4763 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4764 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4765
4766 /* Expect a paging request and respond accordingly with a service request */
4767 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
4768 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
4769
4770 /* Connection is now live, receive the MT-SMS */
4771 f_mt_sms_sgs(spars);
4772
4773 /* Expect a concluding release from the MSC */
4774 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4775
4776 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4777 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4778
4779 f_sgsap_bssmap_screening();
4780
4781 setverdict(pass);
4782}
4783testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004784 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004785 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004786 f_init(1, true);
4787 pars := f_init_pars(11823, true);
4788 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004789 vc_conn.done;
4790}
4791
4792/* Send a MO SMS via SGs interface */
4793private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4794 f_init_handler(pars);
4795 f_sgs_perform_lu();
4796 f_sleep(1.0);
4797 var SmsParameters spars := valueof(t_SmsPars);
4798 spars.tp.ud := 'C8329BFD064D9B53'O;
4799
4800 /* Send the MO-SMS */
4801 f_mo_sms_sgs(spars);
4802
4803 /* Expect a concluding release from the MSC/VLR */
4804 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4805
4806 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4807 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4808
4809 setverdict(pass);
4810
4811 f_sgsap_bssmap_screening()
4812}
4813testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004814 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004815 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004816 f_init(1, true);
4817 pars := f_init_pars(11824, true);
4818 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004819 vc_conn.done;
4820}
4821
4822/* Trigger sending of an MT sms via VTY but never respond to anything */
4823private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4824 f_init_handler(pars, 170.0);
4825 f_sgs_perform_lu();
4826 f_sleep(1.0);
4827
4828 var SmsParameters spars := valueof(t_SmsPars);
4829 spars.tp.ud := 'C8329BFD064D9B53'O;
4830 var integer page_count := 0;
4831 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4832 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4833 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4834 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4835
4836 /* Trigger SMS via VTY */
4837 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4838
Neels Hofmeyr16237742019-03-06 15:34:01 +01004839 /* Expect the MSC/VLR to page exactly once */
4840 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01004841
4842 /* Wait some time to make sure the MSC is not delivering any further
4843 * paging messages or anything else that could be unexpected. */
4844 timer T := 20.0;
4845 T.start
4846 alt {
4847 [] SGsAP.receive(exp_pag_req)
4848 {
4849 setverdict(fail, "paging seems not to stop!");
4850 mtc.stop;
4851 }
4852 [] SGsAP.receive {
4853 setverdict(fail, "unexpected SGsAP message received");
4854 self.stop;
4855 }
4856 [] T.timeout {
4857 setverdict(pass);
4858 }
4859 }
4860
4861 /* Even on a failed paging the SGs Association should stay intact */
4862 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4863
Philipp Maier26bdb8c2019-09-24 09:21:12 +02004864 /* Make sure that the SMS we just inserted is cleared and the
4865 * subscriber is expired. This is necessary because otherwise the MSC
4866 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01004867
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01004868 f_vty_sms_clear(hex2str(g_pars.imsi));
4869
Harald Welte4263c522018-12-06 11:56:27 +01004870 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
4871
4872 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01004873
4874 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01004875}
4876testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004877 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004878 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004879 f_init(1, true);
4880 pars := f_init_pars(11825, true);
4881 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004882 vc_conn.done;
4883}
4884
4885/* Trigger sending of an MT sms via VTY but reject the paging immediately */
4886private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4887 f_init_handler(pars, 150.0);
4888 f_sgs_perform_lu();
4889 f_sleep(1.0);
4890
4891 var SmsParameters spars := valueof(t_SmsPars);
4892 spars.tp.ud := 'C8329BFD064D9B53'O;
4893 var integer page_count := 0;
4894 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4895 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4896 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4897 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4898
4899 /* Trigger SMS via VTY */
4900 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4901
4902 /* Expect a paging request and reject it immediately */
4903 SGsAP.receive(exp_pag_req);
4904 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4905
4906 /* The MSC/VLR should no longer try to page once the paging has been
4907 * rejected. Wait some time and check if there are no unexpected
4908 * messages on the SGs interface. */
4909 timer T := 20.0;
4910 T.start
4911 alt {
4912 [] SGsAP.receive(exp_pag_req)
4913 {
4914 setverdict(fail, "paging seems not to stop!");
4915 mtc.stop;
4916 }
4917 [] SGsAP.receive {
4918 setverdict(fail, "unexpected SGsAP message received");
4919 self.stop;
4920 }
4921 [] T.timeout {
4922 setverdict(pass);
4923 }
4924 }
4925
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01004926 f_vty_sms_clear(hex2str(g_pars.imsi));
4927
Harald Welte4263c522018-12-06 11:56:27 +01004928 /* A rejected paging with IMSI_unknown (see above) should always send
4929 * the SGs association to NULL. */
4930 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4931
4932 f_sgsap_bssmap_screening();
4933
Harald Welte4263c522018-12-06 11:56:27 +01004934 setverdict(pass);
4935}
4936testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004937 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004938 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004939 f_init(1, true);
4940 pars := f_init_pars(11826, true);
4941 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004942 vc_conn.done;
4943}
4944
4945/* Perform an MT CSDB call including LU */
4946private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
4947 f_init_handler(pars);
4948
4949 /* Be sure that the BSSMAP reset is done before we begin. */
4950 f_sleep(2.0);
4951
4952 /* Testcase variation: See what happens when we do a regular BSSMAP
4953 * LU first (this should not hurt in any way!) */
4954 if (bssmap_lu) {
4955 f_perform_lu();
4956 }
4957
4958 f_sgs_perform_lu();
4959 f_sleep(1.0);
4960
4961 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4962 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01004963
4964 /* Initiate a call via MNCC interface */
4965 f_mt_call_initate(cpars);
4966
4967 /* Expect a paging request and respond accordingly with a service request */
4968 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
4969 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
4970
4971 /* Complete the call, hold it for some time and then tear it down */
4972 f_mt_call_complete(cpars);
4973 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01004974 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01004975
4976 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4977 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4978
Harald Welte4263c522018-12-06 11:56:27 +01004979 /* Test for successful return by triggering a paging, when the paging
4980 * request is received via SGs, we can be sure that the MSC/VLR has
4981 * recognized that the UE is now back on 4G */
4982 f_sleep(1.0);
4983 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4984 alt {
4985 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4986 setverdict(pass);
4987 }
4988 [] SGsAP.receive {
4989 setverdict(fail, "Received unexpected message on SGs");
4990 }
4991 }
4992
4993 f_sgsap_bssmap_screening();
4994
4995 setverdict(pass);
4996}
4997
4998/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
4999private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5000 f_mt_lu_and_csfb_call(id, pars, true);
5001}
5002testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005003 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005004 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005005 f_init(1, true);
5006 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005007
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005008 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005009 vc_conn.done;
5010}
5011
5012
5013/* Perform a SGSAP LU and then make a CSFB call */
5014private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5015 f_mt_lu_and_csfb_call(id, pars, false);
5016}
5017testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005018 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005019 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005020 f_init(1, true);
5021 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005022
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005023 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005024 vc_conn.done;
5025}
5026
Philipp Maier628c0052019-04-09 17:36:57 +02005027/* Simulate an HLR/VLR failure */
5028private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5029 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5030 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5031
5032 var PDU_SGsAP lur;
5033
5034 f_init_handler(pars);
5035
5036 /* Attempt location update (which is expected to fail) */
5037 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5038 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5039 SGsAP.send(lur);
5040
5041 /* Respond to SGsAP-RESET-INDICATION from VLR */
5042 alt {
5043 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5044 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5045 setverdict(pass);
5046 }
5047 [] SGsAP.receive {
5048 setverdict(fail, "Received unexpected message on SGs");
5049 }
5050 }
5051
5052 f_sleep(1.0);
5053 setverdict(pass);
5054}
5055testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5056 var BSC_ConnHdlrPars pars;
5057 var BSC_ConnHdlr vc_conn;
5058 f_init(1, true, false);
5059 pars := f_init_pars(11811, true, false);
5060 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5061 vc_conn.done;
5062}
5063
Harald Welte4263c522018-12-06 11:56:27 +01005064/* SGs TODO:
5065 * LU attempt for IMSI without NAM_PS in HLR
5066 * LU attempt with AUTH FAIL due to invalid RES/SRES
5067 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5068 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5069 * implicit IMSI detach from EPS
5070 * implicit IMSI detach from non-EPS
5071 * MM INFO
5072 *
5073 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005074
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005075private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5076 f_init_handler(pars);
5077 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005078
5079 f_perform_lu();
5080 f_mo_call_establish(cpars);
5081
5082 f_sleep(1.0);
5083
5084 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5085 var BssmapCause cause := enum2int(cause_val);
5086
5087 var template BSSMAP_FIELD_CellIdentificationList cil;
5088 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5089
5090 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5091 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5092
5093 f_call_hangup(cpars, true);
5094}
5095testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5096 var BSC_ConnHdlr vc_conn;
5097 f_init();
5098
5099 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5100 vc_conn.done;
5101}
5102
5103private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5104 var MgcpCommand mgcp_cmd;
5105 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005106 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005107 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005108 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005109 { int2str(cpars.rtp_payload_type) },
5110 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5111 cpars.rtp_sdp_format)),
5112 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005113 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_2.mgcp_connection_id, sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005114 repeat;
5115 }
5116}
5117
5118private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5119 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005120
5121 f_init_handler(pars);
5122
5123 f_vty_transceive(MSCVTY, "configure terminal");
5124 f_vty_transceive(MSCVTY, "msc");
5125 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
5126 f_vty_transceive(MSCVTY, "neighbor a lac 5 ran-pc 0.24.2");
5127 f_vty_transceive(MSCVTY, "exit");
5128 f_vty_transceive(MSCVTY, "exit");
5129
5130 f_perform_lu();
5131 f_mo_call_establish(cpars);
5132
5133 f_sleep(1.0);
5134
5135 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5136
5137 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5138 var BssmapCause cause := enum2int(cause_val);
5139
5140 var template BSSMAP_FIELD_CellIdentificationList cil;
5141 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 5) } };
5142
5143 /* old BSS sends Handover Required */
5144 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5145
5146 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5147
5148 /* MSC forwards the RR Handover Command to old BSS */
5149 var PDU_BSSAP ho_command;
5150 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5151
5152 log("GOT HandoverCommand", ho_command);
5153
5154 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5155
5156 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5157 f_expect_clear();
5158
5159 log("FIRST inter-BSC Handover done");
5160
5161
5162 /* ------------------------ */
5163
5164 /* Ok, that went well, now the other BSC is handovering back here --
5165 * from now on this here is the new BSS. */
5166 f_create_bssmap_exp_handoverRequest(193);
5167
5168 var PDU_BSSAP ho_request;
5169 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5170
5171 /* new BSS composes a RR Handover Command */
5172 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5173 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5174 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5175 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5176 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5177
5178 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5179
5180 f_sleep(0.5);
5181
5182 /* Notify that the MS is now over here */
5183
5184 BSSAP.send(ts_BSSMAP_HandoverDetect);
5185 f_sleep(0.1);
5186 BSSAP.send(ts_BSSMAP_HandoverComplete);
5187
5188 f_sleep(3.0);
5189
5190 deactivate(ack_mdcx);
5191
5192 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5193
5194 /* blatant cheating */
5195 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5196 last_n_sd[0] := 3;
5197 f_bssmap_continue_after_n_sd(last_n_sd);
5198
5199 f_call_hangup(cpars, true);
5200 f_sleep(1.0);
5201 deactivate(ccrel);
5202
5203 setverdict(pass);
5204}
5205private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5206 f_init_handler(pars);
5207 f_create_bssmap_exp_handoverRequest(194);
5208
5209 var PDU_BSSAP ho_request;
5210 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5211
5212 /* new BSS composes a RR Handover Command */
5213 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5214 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5215 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5216 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5217 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5218
5219 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5220
5221 f_sleep(0.5);
5222
5223 /* Notify that the MS is now over here */
5224
5225 BSSAP.send(ts_BSSMAP_HandoverDetect);
5226 f_sleep(0.1);
5227 BSSAP.send(ts_BSSMAP_HandoverComplete);
5228
5229 f_sleep(3.0);
5230
5231 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5232 * ... handover back to the first BSC :P */
5233
5234 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5235 var BssmapCause cause := enum2int(cause_val);
5236
5237 var template BSSMAP_FIELD_CellIdentificationList cil;
5238 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('262'H, '42'H, 23) } };
5239
5240 /* old BSS sends Handover Required */
5241 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5242
5243 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5244
5245 /* MSC forwards the RR Handover Command to old BSS */
5246 var PDU_BSSAP ho_command;
5247 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5248
5249 log("GOT HandoverCommand", ho_command);
5250
5251 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5252
5253 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5254 f_expect_clear();
5255 setverdict(pass);
5256}
5257testcase TC_ho_inter_bsc() runs on MTC_CT {
5258 var BSC_ConnHdlr vc_conn0;
5259 var BSC_ConnHdlr vc_conn1;
5260 f_init(2);
5261
5262 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
5263 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
5264
5265 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0, 0);
5266 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1, 1);
5267 vc_conn0.done;
5268 vc_conn1.done;
5269}
5270
5271function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5272 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5273 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5274 log("MS_NW patched enc_l3: ", enc_l3);
5275}
5276
5277private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5278 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005279 var hexstring ho_number := f_gen_msisdn(99999);
5280
5281 f_init_handler(pars);
5282
5283 f_create_mncc_expect(hex2str(ho_number));
5284
5285 f_vty_transceive(MSCVTY, "configure terminal");
5286 f_vty_transceive(MSCVTY, "msc");
5287 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
5288 f_vty_transceive(MSCVTY, "exit");
5289 f_vty_transceive(MSCVTY, "exit");
5290
5291 f_perform_lu();
5292 f_mo_call_establish(cpars);
5293
5294 f_sleep(1.0);
5295
5296 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5297
5298 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5299 var BssmapCause cause := enum2int(cause_val);
5300
5301 var template BSSMAP_FIELD_CellIdentificationList cil;
5302 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('017'H, '017'H, 1) } };
5303
5304 /* old BSS sends Handover Required */
5305 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5306
5307 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
5308 * This MSC tries to reach the other MSC via GSUP. */
5309
5310 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
5311 var GSUP_PDU prep_ho_req;
5312 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
5313 pars.imsi, destination_name := remote_msc_name)) -> value prep_ho_req;
5314
5315 var GSUP_IeValue source_name_ie;
5316 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
5317 var octetstring local_msc_name := source_name_ie.source_name;
5318
5319 /* Remote MSC has figured out its BSC and signals success */
5320 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5321 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5322 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5323 aoIPTransportLayer := omit,
5324 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5325 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
5326 pars.imsi,
5327 ho_number,
5328 remote_msc_name, local_msc_name,
5329 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
5330
5331 /* MSC forwards the RR Handover Command to old BSS */
5332 BSSAP.receive(tr_BSSMAP_HandoverCommand);
5333
5334 /* The MS shows up at remote new BSS */
5335
5336 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5337 pars.imsi, remote_msc_name, local_msc_name,
5338 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5339 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
5340 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5341 f_sleep(0.1);
5342
5343 /* Save the MS sequence counters for use on the other connection */
5344 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5345
5346 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
5347 pars.imsi, remote_msc_name, local_msc_name,
5348 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5349 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
5350
5351 /* The local BSS conn clears, all communication goes via remote MSC now */
5352 f_expect_clear();
5353
5354 /**********************************/
5355 /* Play through some signalling across the inter-MSC link.
5356 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
5357
5358 if (false) {
5359 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
5360 invoke_id := 5, /* Phone may not start from 0 or 1 */
5361 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5362 ussd_string := "*#100#"
5363 );
5364
5365 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
5366 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
5367 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5368 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
5369 )
5370
5371 /* Compose a new SS/REGISTER message with request */
5372 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
5373 tid := 1, /* We just need a single transaction */
5374 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
5375 facility := valueof(facility_req)
5376 );
5377 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
5378
5379 /* Compose SS/RELEASE_COMPLETE template with expected response */
5380 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
5381 tid := 1, /* Response should arrive within the same transaction */
5382 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
5383 facility := valueof(facility_rsp)
5384 );
5385
5386 /* Compose expected MSC -> HLR message */
5387 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
5388 imsi := g_pars.imsi,
5389 state := OSMO_GSUP_SESSION_STATE_BEGIN,
5390 ss := valueof(facility_req)
5391 );
5392
5393 /* To be used for sending response with correct session ID */
5394 var GSUP_PDU gsup_req_complete;
5395
5396 /* Request own number */
5397 /* From remote MSC instead of BSSAP directly */
5398 /* Patch the correct N_SD value into the message. */
5399 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
5400 var RAN_Emulation.ConnectionData cd;
5401 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
5402 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5403 pars.imsi, remote_msc_name, local_msc_name,
5404 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5405 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
5406 ))
5407 ));
5408
5409 /* Expect GSUP message containing the SS payload */
5410 gsup_req_complete := f_expect_gsup_msg(gsup_req);
5411
5412 /* Compose the response from HLR using received session ID */
5413 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
5414 imsi := g_pars.imsi,
5415 sid := gsup_req_complete.ies[1].val.session_id,
5416 state := OSMO_GSUP_SESSION_STATE_END,
5417 ss := valueof(facility_rsp)
5418 );
5419
5420 /* Finally, HLR terminates the session */
5421 GSUP.send(gsup_rsp);
5422
5423 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
5424 var GSUP_PDU gsup_ussd_rsp;
5425 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5426 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
5427
5428 var GSUP_IeValue an_apdu;
5429 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
5430 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5431 mtc.stop;
5432 }
5433 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
5434 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
5435 log("Expecting", ussd_rsp);
5436 log("Got", dtap_mt);
5437 if (not match(dtap_mt, ussd_rsp)) {
5438 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5439 mtc.stop;
5440 }
5441 }
5442 /**********************************/
5443
5444
5445 /* inter-MSC handover back to the first MSC */
5446 f_create_bssmap_exp_handoverRequest(193);
5447 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
5448
5449 /* old BSS sends Handover Required, via inter-MSC E link: like
5450 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5451 * but via GSUP */
5452 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
5453 pars.imsi, remote_msc_name, local_msc_name,
5454 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5455 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
5456 ))
5457 ));
5458
5459 /* MSC asks local BSS to prepare Handover to it */
5460 BSSAP.receive(tr_BSSMAP_HandoverRequest);
5461
5462 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
5463 f_bssmap_continue_after_n_sd(last_n_sd);
5464
5465 /* new BSS composes a RR Handover Command */
5466 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5467 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5468 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5469 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5470 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5471
5472 /* HandoverCommand goes out via remote MSC-I */
5473 var GSUP_PDU prep_subsq_ho_res;
5474 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
5475 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
5476
5477 /* MS shows up at the local BSS */
5478 BSSAP.send(ts_BSSMAP_HandoverDetect);
5479 f_sleep(0.1);
5480 BSSAP.send(ts_BSSMAP_HandoverComplete);
5481
5482 /* Handover Succeeded message */
5483 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5484 pars.imsi, destination_name := remote_msc_name));
5485
5486 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
5487 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
5488 pars.imsi, destination_name := remote_msc_name));
5489
5490 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
5491
5492 f_sleep(1.0);
5493 deactivate(ack_mdcx);
5494
5495 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
5496 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
5497 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
5498 MNCC.clear;
5499
5500 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5501 f_call_hangup(cpars, true);
5502 f_sleep(1.0);
5503 deactivate(ccrel);
5504
5505 setverdict(pass);
5506}
5507testcase TC_ho_inter_msc_out() runs on MTC_CT {
5508 var BSC_ConnHdlr vc_conn;
5509 f_init(1);
5510
5511 var BSC_ConnHdlrPars pars := f_init_pars(54);
5512
5513 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5514 vc_conn.done;
5515}
5516
Oliver Smith1d118ff2019-07-03 10:57:35 +02005517private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5518 pars.net.expect_auth := true;
5519 pars.net.expect_imei := true;
5520 f_init_handler(pars);
5521 f_perform_lu();
5522}
5523testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
5524 var BSC_ConnHdlr vc_conn;
5525 f_init();
5526 f_vty_config(MSCVTY, "network", "authentication required");
5527 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5528
5529 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
5530 vc_conn.done;
5531}
5532
5533private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5534 pars.net.expect_auth := true;
5535 pars.use_umts_aka := true;
5536 pars.net.expect_imei := true;
5537 f_init_handler(pars);
5538 f_perform_lu();
5539}
5540testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
5541 var BSC_ConnHdlr vc_conn;
5542 f_init();
5543 f_vty_config(MSCVTY, "network", "authentication required");
5544 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5545
5546 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
5547 vc_conn.done;
5548}
5549
5550private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5551 pars.net.expect_imei := true;
5552 f_init_handler(pars);
5553 f_perform_lu();
5554}
5555testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
5556 var BSC_ConnHdlr vc_conn;
5557 f_init();
5558 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5559
5560 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
5561 vc_conn.done;
5562}
5563
5564private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5565 pars.net.expect_tmsi := false;
5566 pars.net.expect_imei := true;
5567 f_init_handler(pars);
5568 f_perform_lu();
5569}
5570testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
5571 var BSC_ConnHdlr vc_conn;
5572 f_init();
5573 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
5574 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5575
5576 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
5577 vc_conn.done;
5578}
5579
5580private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5581 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005582
5583 pars.net.expect_auth := true;
5584 pars.net.expect_imei := true;
5585 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
5586 f_init_handler(pars);
5587
5588 /* Cannot use f_perform_lu() as we expect a reject */
5589 l3_lu := f_build_lu_imsi(g_pars.imsi)
5590 f_create_gsup_expect(hex2str(g_pars.imsi));
5591 f_bssap_compl_l3(l3_lu);
5592 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5593
5594 f_mm_common();
5595 f_msc_lu_hlr();
5596 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005597 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005598 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005599}
5600testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
5601 var BSC_ConnHdlr vc_conn;
5602 f_init();
5603 f_vty_config(MSCVTY, "network", "authentication required");
5604 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5605
5606 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
5607 vc_conn.done;
5608}
5609
5610private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5611 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005612
5613 pars.net.expect_auth := true;
5614 pars.net.expect_imei := true;
5615 pars.net.check_imei_error := true;
5616 f_init_handler(pars);
5617
5618 /* Cannot use f_perform_lu() as we expect a reject */
5619 l3_lu := f_build_lu_imsi(g_pars.imsi)
5620 f_create_gsup_expect(hex2str(g_pars.imsi));
5621 f_bssap_compl_l3(l3_lu);
5622 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5623
5624 f_mm_common();
5625 f_msc_lu_hlr();
5626 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005627 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005628 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005629}
5630testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
5631 var BSC_ConnHdlr vc_conn;
5632 f_init();
5633 f_vty_config(MSCVTY, "network", "authentication required");
5634 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5635
5636 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
5637 vc_conn.done;
5638}
5639
5640private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5641 pars.net.expect_auth := true;
5642 pars.net.expect_imei_early := true;
5643 f_init_handler(pars);
5644 f_perform_lu();
5645}
5646testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
5647 var BSC_ConnHdlr vc_conn;
5648 f_init();
5649 f_vty_config(MSCVTY, "network", "authentication required");
5650 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5651
5652 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
5653 vc_conn.done;
5654}
5655
5656private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5657 pars.net.expect_auth := true;
5658 pars.use_umts_aka := true;
5659 pars.net.expect_imei_early := true;
5660 f_init_handler(pars);
5661 f_perform_lu();
5662}
5663testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
5664 var BSC_ConnHdlr vc_conn;
5665 f_init();
5666 f_vty_config(MSCVTY, "network", "authentication required");
5667 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5668
5669 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
5670 vc_conn.done;
5671}
5672
5673private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5674 pars.net.expect_imei_early := true;
5675 f_init_handler(pars);
5676 f_perform_lu();
5677}
5678testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
5679 var BSC_ConnHdlr vc_conn;
5680 f_init();
5681 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5682
5683 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
5684 vc_conn.done;
5685}
5686
5687private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5688 pars.net.expect_tmsi := false;
5689 pars.net.expect_imei_early := true;
5690 f_init_handler(pars);
5691 f_perform_lu();
5692}
5693testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
5694 var BSC_ConnHdlr vc_conn;
5695 f_init();
5696 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
5697 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5698
5699 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
5700 vc_conn.done;
5701}
5702
5703private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5704 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005705
5706 pars.net.expect_auth := true;
5707 pars.net.expect_imei_early := true;
5708 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
5709 f_init_handler(pars);
5710
5711 /* Cannot use f_perform_lu() as we expect a reject */
5712 l3_lu := f_build_lu_imsi(g_pars.imsi)
5713 f_create_gsup_expect(hex2str(g_pars.imsi));
5714 f_bssap_compl_l3(l3_lu);
5715 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5716
5717 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005718 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005719 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005720}
5721testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
5722 var BSC_ConnHdlr vc_conn;
5723 f_init();
5724 f_vty_config(MSCVTY, "network", "authentication required");
5725 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5726
5727 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
5728 vc_conn.done;
5729}
5730
5731private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5732 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005733
5734 pars.net.expect_auth := true;
5735 pars.net.expect_imei_early := true;
5736 pars.net.check_imei_error := true;
5737 f_init_handler(pars);
5738
5739 /* Cannot use f_perform_lu() as we expect a reject */
5740 l3_lu := f_build_lu_imsi(g_pars.imsi)
5741 f_create_gsup_expect(hex2str(g_pars.imsi));
5742 f_bssap_compl_l3(l3_lu);
5743 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5744
5745 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005746 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005747 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005748}
5749testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
5750 var BSC_ConnHdlr vc_conn;
5751 f_init();
5752 f_vty_config(MSCVTY, "network", "authentication required");
5753 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5754
5755 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
5756 vc_conn.done;
5757}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005758
Neels Hofmeyr8df69622019-11-02 19:16:03 +01005759friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5760 f_init_handler(pars);
5761 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
5762
5763 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
5764 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
5765 * will cause a use-after-free after that event dispatch. */
5766 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
5767 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
5768 cpars.rtp_sdp_format := "FOO/8000";
5769 cpars.expect_release := true;
5770
5771 f_perform_lu();
5772 f_mo_call_establish(cpars);
5773}
5774testcase TC_invalid_mgcp_crash() runs on MTC_CT {
5775 var BSC_ConnHdlr vc_conn;
5776 f_init();
5777
5778 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
5779 vc_conn.done;
5780}
5781
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01005782friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
5783runs on BSC_ConnHdlr {
5784 pars.tmsi := 'FFFFFFFF'O;
5785 f_init_handler(pars);
5786
5787 f_create_gsup_expect(hex2str(g_pars.imsi));
5788
5789 /* Initiate Location Updating using an unknown TMSI */
5790 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
5791
5792 /* Expect an Identity Request, send response with no identity */
5793 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
5794 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
5795 lengthIndicator := 1,
5796 mobileIdentityV := {
5797 typeOfIdentity := '000'B,
5798 oddEvenInd_identity := {
5799 no_identity := {
5800 oddevenIndicator := '0'B,
5801 fillerDigits := '00000'H
5802 }
5803 }
5804 }
5805 })));
5806
5807 f_expect_lu_reject();
5808 f_expect_clear();
5809}
5810testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
5811 var BSC_ConnHdlr vc_conn;
5812
5813 f_init();
5814
5815 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7);
5816 vc_conn.done;
5817}
5818
Harald Weltef6dd64d2017-11-19 12:09:51 +01005819control {
Philipp Maier328d1662018-03-07 10:40:27 +01005820 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01005821 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01005822 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01005823 execute( TC_lu_imsi_reject() );
5824 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01005825 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02005826 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01005827 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01005828 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01005829 execute( TC_lu_and_mo_call() );
Harald Welte071ed732018-01-23 19:53:52 +01005830 execute( TC_lu_auth_sai_timeout() );
5831 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01005832 execute( TC_lu_clear_request() );
5833 execute( TC_lu_disconnect() );
5834 execute( TC_lu_by_imei() );
5835 execute( TC_lu_by_tmsi_noauth_unknown() );
5836 execute( TC_imsi_detach_by_imsi() );
5837 execute( TC_imsi_detach_by_tmsi() );
5838 execute( TC_imsi_detach_by_imei() );
5839 execute( TC_emerg_call_imei_reject() );
5840 execute( TC_emerg_call_imsi() );
5841 execute( TC_cm_serv_req_vgcs_reject() );
5842 execute( TC_cm_serv_req_vbs_reject() );
5843 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01005844 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01005845 execute( TC_lu_auth_2G_fail() );
5846 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
5847 execute( TC_cl3_no_payload() );
5848 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01005849 execute( TC_establish_and_nothing() );
5850 execute( TC_mo_setup_and_nothing() );
5851 execute( TC_mo_crcx_ran_timeout() );
5852 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01005853 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01005854 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01005855 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01005856 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01005857 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
5858 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
5859 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01005860 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01005861 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
5862 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01005863 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01005864 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02005865 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01005866
5867 execute( TC_lu_and_mt_call() );
5868
Harald Weltef45efeb2018-04-09 18:19:24 +02005869 execute( TC_lu_and_mo_sms() );
5870 execute( TC_lu_and_mt_sms() );
Philipp Maier3983e702018-11-22 19:01:33 +01005871 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02005872 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02005873 execute( TC_smpp_mo_sms() );
5874 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02005875
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07005876 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07005877 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07005878 execute( TC_gsup_mt_sms_ack() );
5879 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07005880 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07005881 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07005882 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07005883
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07005884 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07005885 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07005886 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07005887 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07005888 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07005889 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07005890
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07005891 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07005892 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07005893 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07005894 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07005895 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07005896
Stefan Sperling89eb1f32018-12-17 15:06:20 +01005897 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01005898 execute( TC_cipher_complete_1_without_cipher() );
5899 execute( TC_cipher_complete_3_without_cipher() );
5900 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02005901 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01005902
Harald Welte4263c522018-12-06 11:56:27 +01005903 execute( TC_sgsap_reset() );
5904 execute( TC_sgsap_lu() );
5905 execute( TC_sgsap_lu_imsi_reject() );
5906 execute( TC_sgsap_lu_and_nothing() );
5907 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01005908 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01005909 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01005910 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01005911 execute( TC_sgsap_paging_rej() );
5912 execute( TC_sgsap_paging_subscr_rej() );
5913 execute( TC_sgsap_paging_ue_unr() );
5914 execute( TC_sgsap_paging_and_nothing() );
5915 execute( TC_sgsap_paging_and_lu() );
5916 execute( TC_sgsap_mt_sms() );
5917 execute( TC_sgsap_mo_sms() );
5918 execute( TC_sgsap_mt_sms_and_nothing() );
5919 execute( TC_sgsap_mt_sms_and_reject() );
5920 execute( TC_sgsap_unexp_ud() );
5921 execute( TC_sgsap_unsol_ud() );
5922 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
5923 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02005924 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01005925
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005926 execute( TC_ho_inter_bsc_unknown_cell() );
5927 execute( TC_ho_inter_bsc() );
5928
5929 execute( TC_ho_inter_msc_out() );
5930
Oliver Smith1d118ff2019-07-03 10:57:35 +02005931 execute( TC_lu_imsi_auth_tmsi_check_imei() );
5932 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
5933 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
5934 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
5935 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
5936 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
5937 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
5938 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
5939 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
5940 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
5941 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
5942 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
5943
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01005944 /* Run this last: at the time of writing this test crashes the MSC */
5945 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02005946 execute( TC_mo_cc_bssmap_clear() );
Pau Espin Pedrol690d6592019-05-31 17:56:32 +02005947 if (mp_enable_osmux_test) {
5948 execute( TC_lu_and_mt_call_osmux() );
5949 }
Neels Hofmeyr8df69622019-11-02 19:16:03 +01005950 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01005951 execute( TC_mm_id_resp_no_identity() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01005952}
5953
5954
5955}