blob: 1cacbd9811e529157fe275c337ec2f93095869da [file] [log] [blame]
Harald Welteb8a4ac82019-06-23 11:04:12 +02001/* MME (Mobility Management Engine) test suite in TTCN-3
2 * (C) 2019 Harald Welte <laforge@gnumonks.org>
3 * All rights reserved.
4 *
5 * Released under the terms of GNU General Public License, Version 2 or
6 * (at your option) any later version.
7 *
8 * SPDX-License-Identifier: GPL-2.0-or-later
9 */
10
11module MME_Tests {
12
Harald Welte95333a12019-07-11 22:51:45 +080013import from General_Types all;
Philipp Maier74d776a2023-07-12 14:04:14 +020014import from Native_Functions all;
15import from IPL4asp_Types all;
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +010016import from Misc_Helpers all;
Harald Welte95333a12019-07-11 22:51:45 +080017import from S1AP_Types all;
18import from S1AP_Templates all;
19import from S1AP_Emulation all;
20import from S1AP_PDU_Descriptions all;
21import from S1AP_IEs all;
Philipp Maiera9306202023-07-24 11:41:51 +020022import from S1AP_PDU_Contents all;
23import from S1AP_Constants all;
Harald Welte95333a12019-07-11 22:51:45 +080024
25import from NAS_EPS_Types all;
26import from NAS_Templates all;
27
Harald Welte6ec64392019-08-14 12:37:07 +020028import from DIAMETER_Types all;
29import from DIAMETER_Templates all;
Pau Espin Pedrol117a94f2023-12-21 16:10:12 +010030import from DIAMETER_ts29_272_Templates all;
Harald Welte6ec64392019-08-14 12:37:07 +020031import from DIAMETER_Emulation all;
32
Harald Welteb8a4ac82019-06-23 11:04:12 +020033import from SGsAP_Types all;
34import from SGsAP_Templates all;
35import from SGsAP_Emulation all;
36
Philipp Maier74d776a2023-07-12 14:04:14 +020037import from GTP_Emulation all;
38import from GTP_Templates all;
39import from GTP_CodecPort all;
40import from GTPC_Types all;
41
Harald Welte95333a12019-07-11 22:51:45 +080042import from LTE_CryptoFunctions all;
43
Harald Welteb8a4ac82019-06-23 11:04:12 +020044import from L3_Templates all;
45import from DNS_Helpers all;
Harald Welte95333a12019-07-11 22:51:45 +080046import from Osmocom_Types all;
Philipp Maiera9306202023-07-24 11:41:51 +020047import from Osmocom_Gb_Types all;
Harald Welteb8a4ac82019-06-23 11:04:12 +020048
Philipp Maier9abb8c92023-08-31 13:12:28 +020049import from GTPv2_Types all;
50import from GTPv2_Templates all;
51import from GTPv2_Emulation all;
52
Harald Welteb8a4ac82019-06-23 11:04:12 +020053friend module MME_Tests_SGsAP;
54
Harald Welte95333a12019-07-11 22:51:45 +080055/* (maximum) number of emulated eNBs */
56const integer NUM_ENB := 3;
57
58/* (maximum) number of emulated UEs */
59const integer NUM_UE := 3;
60
61/* parameters of emulated ENB */
62type record EnbParams {
63 Global_ENB_ID global_enb_id,
64 integer cell_identity,
65 SupportedTAs supported_tas
66}
67
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +010068type record BearerConfig {
69 /* EPS Bearer ID */
70 uint4_t ebi optional,
71 /* TEI (Data) local side, S11 (SGW) */
72 OCT4 s11_teid_local optional,
73 /* TEI (Data) remote side, S11 (SGW) */
74 OCT4 s11_teid_remote optional,
75 /* TEI (Data) local side, S5c (PGW) */
76 OCT4 s5c_teid_local optional,
77 /* TEI (Data) remote side, S5c (PGW) */
78 OCT4 s5c_teid_remote optional
79};
80
Harald Welte95333a12019-07-11 22:51:45 +080081/* parameters of emulated UE */
82type record UeParams {
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +010083 hexstring imsi,
84 charstring ue_ip,
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +010085 NAS_EPS_Types.GUTI guti optional,
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +010086 octetstring kasme optional,
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +010087
88 /* TEI (Control) local side, S11 (SGW) */
89 OCT4 s11_teic_local,
90 /* TEI (Control) remote side, S11 (SGW) */
91 OCT4 s11_teic_remote optional,
92 /* TEI (Control) local side, S5c (PGW) */
93 OCT4 s5c_teic_local,
94 /* TEI (Control) remote side, S5c (PGW) */
95 OCT4 s5c_teic_remote optional,
96
97 BearerConfig bearer optional
Harald Welte95333a12019-07-11 22:51:45 +080098}
99
Harald Welteb8a4ac82019-06-23 11:04:12 +0200100type component MTC_CT {
Harald Welte95333a12019-07-11 22:51:45 +0800101 /* S1 intreface of emulated ENBs */
102 var EnbParams g_enb_pars[NUM_ENB];
103 var S1AP_Emulation_CT vc_S1AP[NUM_ENB];
104 port S1AP_PT S1AP_UNIT[NUM_ENB];
105 port S1APEM_PROC_PT S1AP_PROC[NUM_ENB];
106
Harald Welte6ec64392019-08-14 12:37:07 +0200107 /* S6a/S6d interface of emulated HSS */
108 var DIAMETER_Emulation_CT vc_DIAMETER;
109 port DIAMETER_PT DIAMETER_UNIT;
110 port DIAMETEREM_PROC_PT DIAMETER_PROC;
111
Harald Welte95333a12019-07-11 22:51:45 +0800112 /* SGs interface of emulated MSC/VLR */
Harald Welteb8a4ac82019-06-23 11:04:12 +0200113 var SGsAP_Emulation_CT vc_SGsAP;
114 port SGsAP_PT SGsAP_UNIT;
115 port SGsAPEM_PROC_PT SGsAP_PROC;
Harald Welte95333a12019-07-11 22:51:45 +0800116
Philipp Maier74d776a2023-07-12 14:04:14 +0200117 /* Gn interface (GTPv1C) of emulated SGSN (Rel. 7) */
118 var GTP_Emulation_CT vc_GTP;
119
Philipp Maier9abb8c92023-08-31 13:12:28 +0200120 /* S11 interface (GTPv2C) of emulated SGW-C */
121 var GTPv2_Emulation_CT vc_GTP2;
122 port GTP2EM_PT TEID0;
123
Harald Welte95333a12019-07-11 22:51:45 +0800124 var UeParams g_ue_pars[NUM_UE];
Harald Welteb8a4ac82019-06-23 11:04:12 +0200125}
126
Philipp Maiera9306202023-07-24 11:41:51 +0200127/* Encode an S1AP Global-ENB-ID into an octetstring */
128private function enc_S1AP_Global_ENB_ID(Global_ENB_ID global_enb_id) return octetstring {
129
130 /* Due to the limitations of libfftranscode, we can not define encoders (or decoders) for individual
131 * information elements (in S1AP_Types.cc). Unfortuantely Global-ENB-ID also appears in BSSGP in its
132 * encoded form. (see also: GTP-C 3GPP TS 48.018, section 11.3.70). To encode a given Global-ENB-ID
133 * we craft a full S1AP PDU and encode it. Then we can cut out the encoded Global-ENB-ID from the
134 * generated octetstring. */
135
136 var SupportedTAs supported_tas_dummy := {{
137 tAC := '0000'O,
138 broadcastPLMNs := { '00f000'O },
139 iE_Extensions := omit
140 }};
141 var octetstring encoded;
142 var integer global_enb_id_len;
143
144 if (ispresent(global_enb_id.eNB_ID.macroENB_ID)) {
145 global_enb_id_len := 8;
146 } else {
147 /* All other ENB ID types fit into 8 byte (homeENB_ID, short_macroENB_ID, long_macroENB_ID) */
148 global_enb_id_len := 9;
149 }
150
151 encoded := enc_S1AP_PDU(valueof(ts_S1AP_SetupReq(global_enb_id, supported_tas_dummy, v32)));
152
153 return substr(encoded, 11, global_enb_id_len);
154}
155
Philipp Maier9abb8c92023-08-31 13:12:28 +0200156type component ConnHdlr extends S1AP_ConnHdlr, SGsAP_ConnHdlr, DIAMETER_ConnHdlr, GTP_ConnHdlr, GTP2_ConnHdlr {
Harald Welteb8a4ac82019-06-23 11:04:12 +0200157 var ConnHdlrPars g_pars;
158 timer g_Tguard := 30.0;
Philipp Maier74d776a2023-07-12 14:04:14 +0200159
Pau Espin Pedrolcc9b8042023-09-21 17:45:11 +0200160 var GtpPeer g_gn_iface_peer := { connId := 1, remName := mp_gn_remote_ip, remPort := mp_gn_remote_port };
Harald Welteb8a4ac82019-06-23 11:04:12 +0200161}
162
163type record ConnHdlrPars {
Harald Welte95333a12019-07-11 22:51:45 +0800164 /* copied over from MTC_CT on start of component */
165 EnbParams enb_pars[NUM_ENB],
166 /* copied over from MTC_CT on start of component */
167 UeParams ue_pars,
168 /* currently used MME (index into enb_pars, S1AP, ...) */
169 integer mme_idx
Harald Welteb8a4ac82019-06-23 11:04:12 +0200170}
171
172modulepar {
Harald Welte95333a12019-07-11 22:51:45 +0800173 /* S1 interface */
174 charstring mp_mme_ip := "127.0.0.1";
175 integer mp_mme_s1ap_port := 36412;
176 charstring mp_s1_local_ip := "127.0.0.1";
177 integer mp_s1_local_port := 50000;
178
Harald Welte6ec64392019-08-14 12:37:07 +0200179 /* S6 interface */
180 charstring mp_s6_local_ip := "127.0.0.4";
181 integer mp_s6_local_port := 3868;
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100182 charstring mp_s6_diam_realm := "localdomain";
183 charstring mp_s6_local_diam_host := "hss.localdomain";
184 charstring mp_s6_remote_diam_host := "mme.localdomain";
Harald Welte6ec64392019-08-14 12:37:07 +0200185
Harald Welte95333a12019-07-11 22:51:45 +0800186 /* SGs interface */
Harald Welteb8a4ac82019-06-23 11:04:12 +0200187 charstring mp_sgs_local_ip := "127.0.0.1";
188 integer mp_sgs_local_port := 29118;
189 charstring mp_vlr_name := "vlr.example.net";
190 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
Philipp Maier74d776a2023-07-12 14:04:14 +0200191
192 /* Gn interface (GTPv1C) */
193 charstring mp_gn_local_ip := "127.0.0.22";
194 integer mp_gn_local_port := 2123;
195 charstring mp_gn_remote_ip := "127.0.0.2";
Pau Espin Pedrol11625852023-12-22 14:20:42 +0100196 /* RAI+CI served from emulated peer SGSN: */
Pau Espin Pedrolcc9b8042023-09-21 17:45:11 +0200197 integer mp_gn_remote_port := 2123;
Pau Espin Pedrol11625852023-12-22 14:20:42 +0100198 hexstring mp_gn_local_mcc := '262'H;
199 hexstring mp_gn_local_mnc := 'f42'H;
Pau Espin Pedrol209d0a42023-12-22 14:22:40 +0100200 uint16_t mp_gn_local_lac := 39594;
Pau Espin Pedrol11625852023-12-22 14:20:42 +0100201 uint8_t mp_gn_local_rac := 187;
202 uint16_t mp_gn_local_ci := 1223;
Philipp Maier9abb8c92023-08-31 13:12:28 +0200203
204 /* S11 interface (GTPv2C, interface between MME and SGW) */
205 charstring mp_s11_local_ip := "127.0.0.3";
206 integer mp_s11_local_port := 2123;
207 charstring mp_s11_remote_ip := "127.0.0.2";
208 integer mp_s11_remote_port := 2123;
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100209
210 /* PGW information announced by SGWC. MME never really interacts with these. */
211 charstring mp_s5c_pgw_ip := "1.2.3.4";
Harald Welteb8a4ac82019-06-23 11:04:12 +0200212}
213
214/* send incoming unit data messages (like reset) to global SGsAP_UNIT port */
215friend function ForwardUnitdataCallback(PDU_SGsAP msg)
216runs on SGsAP_Emulation_CT return template PDU_SGsAP {
217 SGsAP_UNIT.send(msg);
218 return omit;
219}
220
221friend function f_init_sgsap(charstring id) runs on MTC_CT {
222 id := id & "-SGsAP";
223 var SGsAPOps ops := {
224 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
225 unitdata_cb := refers(ForwardUnitdataCallback)
226 }
227 var SGsAP_conn_parameters pars := {
228 remote_ip := "",
229 remote_sctp_port := -1,
230 local_ip := mp_sgs_local_ip,
231 local_sctp_port := mp_sgs_local_port
232 }
233
234 vc_SGsAP := SGsAP_Emulation_CT.create(id);
235 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
236 connect(vc_SGsAP:SGsAP_PROC, self:SGsAP_PROC);
237 connect(vc_SGsAP:SGsAP_UNIT, self:SGsAP_UNIT);
238 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
239}
240
Harald Welte95333a12019-07-11 22:51:45 +0800241/* send incoming unit data messages (like reset) to global S1AP_UNIT port */
242friend function S1apForwardUnitdataCallback(S1AP_PDU msg)
243runs on S1AP_Emulation_CT return template S1AP_PDU {
244 S1AP_UNIT.send(msg);
245 return omit;
246}
247
Harald Welte95333a12019-07-11 22:51:45 +0800248friend function f_init_one_enb(charstring id, integer num := 0) runs on MTC_CT {
249 id := id & "-S1AP" & int2str(num);
250 var S1APOps ops := {
Philipp Maier7147c922023-07-07 14:18:32 +0200251 create_cb := refers(S1AP_Emulation.ExpectedCreateCallback),
Harald Welte95333a12019-07-11 22:51:45 +0800252 unitdata_cb := refers(S1apForwardUnitdataCallback)
253 }
254 var S1AP_conn_parameters pars := {
255 remote_ip := mp_mme_ip,
256 remote_sctp_port := mp_mme_s1ap_port,
257 local_ip := mp_s1_local_ip,
258 local_sctp_port := mp_s1_local_port + num,
259 role := NAS_ROLE_UE
260 }
261 var PLMNidentity plmn_id := '00f110'O;
262 var EnbParams enb_pars := {
263 global_enb_id := {
264 pLMNidentity := plmn_id,
265 eNB_ID := {
266 macroENB_ID := int2bit(num, 20)
267 },
268 iE_Extensions := omit
269 },
270 cell_identity := num,
271 supported_tas := {
272 {
273 tAC := int2oct(12345, 2),
274 broadcastPLMNs := { plmn_id },
275 iE_Extensions := omit
276 }
277 }
278 };
279
280 g_enb_pars[num] := enb_pars;
281 vc_S1AP[num] := S1AP_Emulation_CT.create(id);
282 map(vc_S1AP[num]:S1AP, system:S1AP_CODEC_PT);
283 connect(vc_S1AP[num]:S1AP_PROC, self:S1AP_PROC[num]);
284 connect(vc_S1AP[num]:S1AP_UNIT, self:S1AP_UNIT[num]);
285 vc_S1AP[num].start(S1AP_Emulation.main(ops, pars, id));
286 S1AP_UNIT[num].receive(S1APEM_Event:{up_down:=S1APEM_EVENT_UP});
287}
288friend function f_init_one_ue(inout UeParams uep, integer imsi_suffix) {
289 uep := {
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100290 imsi := f_gen_imsi(imsi_suffix),
291 ue_ip := "192.168.123.50",
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +0100292 guti := omit,
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +0100293 kasme := omit,
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100294 s11_teic_local := '00000000'O,
295 s11_teic_remote := omit,
296 s5c_teic_local := '00000000'O,
297 s5c_teic_remote := omit,
298 bearer := {
299 ebi := omit,
300 s11_teid_local := omit,
301 s11_teid_remote := omit,
302 s5c_teid_local := omit,
303 s5c_teid_remote := omit
304 }
Harald Welte95333a12019-07-11 22:51:45 +0800305 }
306}
307friend function f_init_s1ap(charstring id, integer imsi_suffix) runs on MTC_CT {
308 var integer i;
309 for (i := 0; i < NUM_ENB; i := i+1) {
310 f_init_one_enb(id, i);
311 }
312 for (i := 0; i < NUM_UE; i := i+1) {
313 f_init_one_ue(g_ue_pars[i], i*1000 + imsi_suffix);
314 }
315}
316
Harald Welte6ec64392019-08-14 12:37:07 +0200317friend function DiameterForwardUnitdataCallback(PDU_DIAMETER msg)
318runs on DIAMETER_Emulation_CT return template PDU_DIAMETER {
319 DIAMETER_UNIT.send(msg);
320 return omit;
321}
322
323friend function f_init_diameter(charstring id) runs on MTC_CT {
324 var DIAMETEROps ops := {
325 create_cb := refers(DIAMETER_Emulation.ExpectedCreateCallback),
Vadim Yanitskiyb46f01e2021-12-06 03:23:13 +0300326 unitdata_cb := refers(DiameterForwardUnitdataCallback),
327 raw := false /* handler mode (IMSI based routing) */
Harald Welte6ec64392019-08-14 12:37:07 +0200328 };
329 var DIAMETER_conn_parameters pars := {
330 remote_ip := mp_mme_ip,
331 remote_sctp_port := -1,
332 local_ip := mp_s6_local_ip,
Harald Welte61f73d52020-04-26 21:41:12 +0200333 local_sctp_port := mp_s6_local_port,
334 origin_host := "hss.localdomain",
335 origin_realm := "localdomain",
Pau Espin Pedrol33b47492022-03-08 17:43:01 +0100336 auth_app_id := omit,
Harald Welte61f73d52020-04-26 21:41:12 +0200337 vendor_app_id := c_DIAMETER_3GPP_S6_AID
Harald Welte6ec64392019-08-14 12:37:07 +0200338 };
339 vc_DIAMETER := DIAMETER_Emulation_CT.create(id);
340 map(vc_DIAMETER:DIAMETER, system:DIAMETER_CODEC_PT);
341 connect(vc_DIAMETER:DIAMETER_UNIT, self:DIAMETER_UNIT);
342 connect(vc_DIAMETER:DIAMETER_PROC, self:DIAMETER_PROC);
343 vc_DIAMETER.start(DIAMETER_Emulation.main(ops, pars, id));
Harald Welted01b5d02020-04-26 22:05:53 +0200344
345 f_diameter_wait_capability(DIAMETER_UNIT);
Harald Welte6ec64392019-08-14 12:37:07 +0200346}
347
Philipp Maier74d776a2023-07-12 14:04:14 +0200348friend function f_init_gtp(charstring id) runs on MTC_CT {
349 id := id & "-GTP";
350
351 var GtpEmulationCfg gtp_cfg := {
352 gtpc_bind_ip := mp_gn_local_ip,
353 gtpc_bind_port := mp_gn_local_port,
354 gtpu_bind_ip := omit,
355 gtpu_bind_port := omit,
356 sgsn_role := true
357 };
358
359 vc_GTP := GTP_Emulation_CT.create(id);
360 vc_GTP.start(GTP_Emulation.main(gtp_cfg));
361}
362
Philipp Maier9abb8c92023-08-31 13:12:28 +0200363friend function f_init_gtpv2_s11(charstring id) runs on MTC_CT {
364 id := id & "-GTPV2";
365
366 var Gtp2EmulationCfg cfg := {
367 gtpc_bind_ip := mp_s11_local_ip,
368 gtpc_bind_port := mp_s11_local_port,
369 gtpc_remote_ip := mp_s11_remote_ip,
370 gtpc_remote_port := mp_s11_remote_port,
371 sgw_role := true,
372 use_gtpu_daemon := false
373 };
374
375 vc_GTP2 := GTPv2_Emulation_CT.create(id);
376 map(vc_GTP2:GTP2C, system:GTP2C);
377 connect(vc_GTP2:TEID0, self:TEID0);
378 vc_GTP2.start(GTPv2_Emulation.main(cfg));
379}
380
381friend template (value) S1AP_IEs.TAI ts_enb_S1AP_TAI(EnbParams enb) := {
Harald Welte95333a12019-07-11 22:51:45 +0800382 pLMNidentity := enb.global_enb_id.pLMNidentity,
383 tAC := enb.supported_tas[0].tAC,
384 iE_Extensions := omit
385}
386
387friend template (value) EUTRAN_CGI ts_enb_S1AP_CGI(EnbParams enb) := {
388 pLMNidentity := enb.global_enb_id.pLMNidentity,
389 cell_ID := int2bit(enb.cell_identity, 28),
390 iE_Extensions := omit
391}
392
393
Harald Welteb8a4ac82019-06-23 11:04:12 +0200394/* generate parameters for a connection handler */
Harald Welte95333a12019-07-11 22:51:45 +0800395friend function f_init_pars(integer ue_idx := 0)
Harald Welteb8a4ac82019-06-23 11:04:12 +0200396runs on MTC_CT return ConnHdlrPars {
397 var ConnHdlrPars pars := {
Harald Welte95333a12019-07-11 22:51:45 +0800398 enb_pars := g_enb_pars,
399 ue_pars := g_ue_pars[ue_idx],
400 mme_idx := 0
Harald Welteb8a4ac82019-06-23 11:04:12 +0200401 };
402 return pars;
403}
404
405type function void_fn(ConnHdlrPars pars) runs on ConnHdlr;
406
407/* start a connection handler with given parameters */
408friend function f_start_handler_with_pars(void_fn fn, ConnHdlrPars pars, integer s1ap_idx := 0)
409runs on MTC_CT return ConnHdlr {
410 var ConnHdlr vc_conn;
411 var charstring id := testcasename() & int2str(s1ap_idx);
412
413 vc_conn := ConnHdlr.create(id);
Harald Welte95333a12019-07-11 22:51:45 +0800414 /* S1AP part */
415 connect(vc_conn:S1AP, vc_S1AP[s1ap_idx]:S1AP_CLIENT);
416 connect(vc_conn:S1AP_PROC, vc_S1AP[s1ap_idx]:S1AP_PROC);
417 if (isbound(vc_SGsAP)) {
418 /* SGsAP part */
419 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
420 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
421 }
Harald Welte6ec64392019-08-14 12:37:07 +0200422 if (isbound(vc_DIAMETER)) {
423 connect(vc_conn:DIAMETER, vc_DIAMETER:DIAMETER_CLIENT);
424 connect(vc_conn:DIAMETER_PROC, vc_DIAMETER:DIAMETER_PROC);
425 }
Philipp Maier74d776a2023-07-12 14:04:14 +0200426 if (isbound(vc_GTP)) {
427 connect(vc_conn:GTP, vc_GTP:CLIENT);
428 connect(vc_conn:GTP_PROC, vc_GTP:CLIENT_PROC);
429 }
Philipp Maier9abb8c92023-08-31 13:12:28 +0200430 if (isbound(vc_GTP2)) {
431 connect(vc_conn:GTP2, vc_GTP2:CLIENT);
432 connect(vc_conn:GTP2_PROC, vc_GTP2:CLIENT_PROC);
433 }
Harald Welteb8a4ac82019-06-23 11:04:12 +0200434
435 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
436 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
437 vc_conn.start(derefers(fn)(pars));
438 return vc_conn;
439}
440
441/* altstep for the global guard timer */
442private altstep as_Tguard()runs on ConnHdlr {
443 [] g_Tguard.timeout {
444 setverdict(fail, "Tguard timeout");
445 mtc.stop;
446 }
447}
448
449friend function f_init_handler(ConnHdlrPars pars, float t_guard := 30.0) runs on ConnHdlr {
450 /* make parameters available via component variable */
451 g_pars := pars;
452 /* start guard timre and activate it as default */
453 g_Tguard.start(t_guard);
454 activate(as_Tguard());
Harald Welte6ec64392019-08-14 12:37:07 +0200455 if (DIAMETER_PROC.checkstate("Connected")) {
Pau Espin Pedroldb017f42023-08-25 19:22:25 +0200456 f_diameter_expect_imsi(g_pars.ue_pars.imsi);
Harald Welte6ec64392019-08-14 12:37:07 +0200457 }
Harald Welte95333a12019-07-11 22:51:45 +0800458 if (SGsAP_PROC.checkstate("Connected")) {
459 /* Route all SGsAP mesages for our IMSIto us */
460 f_create_sgsap_expect(pars.ue_pars.imsi);
461 }
462}
463
464
465
Philipp Maier9abb8c92023-08-31 13:12:28 +0200466friend function f_s1ap_setup(integer idx := 0, template S1AP_IEs.Cause cause := omit) runs on MTC_CT {
467 var template (present) S1AP_IEs.Cause exp_cause;
Harald Welte95333a12019-07-11 22:51:45 +0800468 var boolean exp_fail := false;
469 timer T := 5.0;
470 if (not istemplatekind(cause, "omit")) {
471 exp_fail := true;
472 exp_cause := cause;
473 }
474
475 S1AP_UNIT[idx].send(ts_S1AP_SetupReq(g_enb_pars[idx].global_enb_id,
476 g_enb_pars[idx].supported_tas, v32));
477 T.start;
478 alt {
479 [exp_fail] S1AP_UNIT[idx].receive(tr_S1AP_SetupFail(exp_cause)) {
480 setverdict(pass);
481 }
482 [not exp_fail] S1AP_UNIT[idx].receive(tr_S1AP_SetupResp) {
483 setverdict(pass);
484 }
485 [] S1AP_UNIT[idx].receive {
486 setverdict(fail, "Received unexpected S1AP");
487 }
488 [] T.timeout {
489 setverdict(fail, "Timeout waiting for S1AP Setup result");
490 }
491 }
492}
493
494/* Unsuccessful S1 Setup procedure to MME (wrong PLMN) */
495testcase TC_s1ap_setup_wrong_plmn() runs on MTC_CT {
496 var charstring id := testcasename();
497 f_init_s1ap(id, 1);
498 g_enb_pars[0].global_enb_id.pLMNidentity := '62F224'O;
499 f_s1ap_setup(0, {misc:=unknown_PLMN});
500}
501
502/* Unsuccessful S1 Setup procedure to MME (wrong PLMN) */
503testcase TC_s1ap_setup_wrong_tac() runs on MTC_CT {
504 var charstring id := testcasename();
505 f_init_s1ap(id, 2);
506 g_enb_pars[0].supported_tas[0].broadcastPLMNs[0] := '62F224'O;
507 f_s1ap_setup(0, {misc:=unknown_PLMN});
508}
509
510/* Successful S1 Setup procedure to MME */
511testcase TC_s1ap_setup() runs on MTC_CT {
512 var charstring id := testcasename();
513 f_init_s1ap(id, 3);
514 f_s1ap_setup(0);
515}
516
517private const EPS_QualityOfServiceV c_NAS_defaultQoS := {
518 qCI := '00'O,
519 maxBitRateUplink := omit,
520 maxBitRateDownlink := omit,
521 guaranteedBitRateUplink := omit,
522 guaranteedBitRateDownlink := omit,
523 maxBitRateUplinkExt := omit,
524 maxBitRateDownlinkExt := omit,
525 guaranteedBitRateUplinkExt := omit,
526 guaranteedBitRateDownlinkExt := omit,
527 maxBitRateUplinkExt2 := omit,
528 maxBitRateDownlinkExt2 := omit,
529 guaranteedBitRateUplinkExt2 := omit,
530 guaranteedBitRateDownlinkExt2 := omit
531};
532
533private const UENetworkCapabilityV c_NAS_defaultUeNetCap := {
534 eEA := '10000000'B,
535 eIA := '11000000'B,
536 uEA := omit,
537 uIA := omit,
538 uCS2 := omit,
539 nF := omit,
540 vCC := omit,
541 lCS := omit,
542 lPP := omit,
543 aCC_CSFB := omit,
544 h245_ASH := omit,
545 proSe := omit,
546 proSe_dd := omit,
547 proSe_dc := omit,
548 proSe_relay := omit,
549 cP_CIoT := omit,
550 uP_CIoT := omit,
551 s1_Udata := omit,
552 eRwoPDN := omit,
553 hC_CP_CIoT := omit,
554 ePCO := omit,
555 multipleDRB := omit,
556 v2XPC5 := omit,
557 restrictEC := omit,
558 cPbackoff := omit,
559 dCNR := omit,
560 n1Mode := omit,
561 sGC := omit,
562 spare1 := omit,
563 spare := omit
564};
565
566private const octetstring c_NAS_defaultAPN := '00'O;
567
568private altstep as_s1ap_handle_auth() runs on ConnHdlr {
569 var PDU_NAS_EPS rx_nas;
570 [] S1AP.receive(tr_NAS_AuthReq) -> value rx_nas {
571 /* static XRES result as we fixed the HSS RAND value and always have the following
572 RAND: 20080c3818183b522614162c07601d0d
573 AUTN: f11b89a2a8be00001f9c526f3d75d44c
574 IK: 11329aae8e8d2941bb226b2061137c58
575 CK: 740d62df9803eebde5120acf358433d0
576 RES: 6a91970e838fd079
577 SRES: e91e4777
578 Kc: 3b0f999e42198874
579 SQN: 32
580 IND: 0
581 */
582 /* KASME: 95AFAD9A0D29AFAA079A9451DF7161D7EE4CBF2AF9387F766D058BB6B44B905D */
583 const OCT16 ck := '740d62df9803eebde5120acf358433d0'O;
584 const OCT16 ik := '11329aae8e8d2941bb226b2061137c58'O;
585 const OCT16 autn := 'f11b89a2a8be00001f9c526f3d75d44c'O;
586 const OCT8 res := '6a91970e838fd079'O;
587 const OCT3 plmn_id := '00F110'O;
588 const OCT6 sqn := '000000000020'O;
589 const OCT6 ak := substr(autn, 0, 6) xor4b sqn;
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +0100590 g_pars.ue_pars.kasme := f_kdf_kasme(ck, ik, plmn_id, sqn, ak);
Harald Welte95333a12019-07-11 22:51:45 +0800591 var S1APEM_Config cfg := {
592 set_nas_keys := {
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +0100593 k_nas_int := f_kdf_nas_int(1, g_pars.ue_pars.kasme),
594 k_nas_enc := f_kdf_nas_enc(1, g_pars.ue_pars.kasme)
Harald Welte95333a12019-07-11 22:51:45 +0800595 }
596 };
597 S1AP.send(cfg);
598 S1AP.send(ts_NAS_AuthResp(res));
599 }
600}
601
602private altstep as_s1ap_handle_sec_mode() runs on ConnHdlr {
603 var PDU_NAS_EPS rx_nas;
604 var NAS_SecurityAlgorithmsV alg := {
605 typeOfIntegrityProtection := '001'B,
606 spare1 := '0'B,
607 typeOfCiphering := '000'B,
608 spare2 := '0'B
609 };
610 var NAS_KeySetIdentifierV kset_id := {
611 identifier := '000'B,
612 tSC := '0'B
613 };
614 [] S1AP.receive(tr_NAS_SecModeCmd(alg, kset_id, ?)) {
615 S1AP.send(ts_NAS_SecModeCmpl);
616 }
617}
618
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100619
Pau Espin Pedrol35618872024-01-15 15:25:18 +0100620private altstep as_s1ap_handle_IntialCtxSetupReq_Attach_Accept() runs on ConnHdlr {
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100621 var S1AP_PDU rx_msg;
622 var PDU_NAS_EPS rx_nas;
623 [] S1AP.receive(tr_S1AP_IntialCtxSetupReq) -> value rx_msg {
624 var template (omit) MME_UE_S1AP_ID mme_ue_id := f_S1AP_get_MME_UE_S1AP_ID(rx_msg);
625 var template (omit) ENB_UE_S1AP_ID enb_ue_id := f_S1AP_get_ENB_UE_S1AP_ID(rx_msg);
626 var template (value) E_RABSetupItemCtxtSURes rab_setup_it;
627 var template (value) E_RABSetupListCtxtSURes rab_setup_items;
628 var octetstring esm_enc;
629 var template (value) PDU_NAS_EPS nas;
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +0100630 var EPS_MobileIdentityTLV mi_tlv;
631
632 S1AP.receive(tr_NAS_AttachAccept()) -> value rx_nas;
633 mi_tlv := rx_nas.ePS_messages.ePS_MobilityManagement.pDU_NAS_EPS_AttachAccept.gUTI;
634 if (mi_tlv.ePS_MobileIdentity.ePS_MobileIdentity.typeOfIdentity != '110'B) {
635 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("Rx GUTI of unexpected MI type: ", mi_tlv));
636 }
637 g_pars.ue_pars.guti := mi_tlv.ePS_MobileIdentity.ePS_MobileIdentity.oddEvenInd_identity.guti
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100638
639 rab_setup_it := ts_S1AP_RABSetupItemCtxtSURes(rab_id := 5,
640 tla := oct2bit(f_inet_addr(mp_mme_ip)),
641 gtp_teid := '00000002'O);
642 rab_setup_items := ts_S1AP_RABSetupListCtxtSURes(rab_setup_it);
643 S1AP.send(ts_S1AP_InitialCtxSetupResp(valueof(mme_ue_id), valueof(enb_ue_id), rab_setup_items));
644
645 nas := ts_NAS_ActDefEpsBearCtxAck(int2bit(g_pars.ue_pars.bearer.ebi, 4), '00000000'B, omit);
646 esm_enc := enc_PDU_NAS_EPS(valueof(nas));
647 S1AP.send(ts_NAS_AttachComplete(esm_enc));
Pau Espin Pedrol278f5432023-12-21 19:21:28 +0100648
649 /* Optional from the network: */
650 S1AP.receive(tr_NAS_EMMInformation);
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100651 }
652 [] S1AP.receive(PDU_NAS_EPS:?) -> value rx_nas {
653 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("Rx Unexpected NAS PDU msg: ", rx_nas));
654 }
655}
656
Pau Espin Pedrol35618872024-01-15 15:25:18 +0100657private altstep as_s1ap_handle_IntialCtxSetupReq_TAU_Accept() runs on ConnHdlr {
658 var S1AP_PDU rx_msg;
659 var PDU_NAS_EPS rx_nas;
660 [] S1AP.receive(tr_S1AP_IntialCtxSetupReq) -> value rx_msg {
661 /* 3GPP TS 23.401 D.3.6 step 22: */
662 var template (omit) MME_UE_S1AP_ID mme_ue_id := f_S1AP_get_MME_UE_S1AP_ID(rx_msg);
663 var template (omit) ENB_UE_S1AP_ID enb_ue_id := f_S1AP_get_ENB_UE_S1AP_ID(rx_msg);
664 var template (value) E_RABSetupItemCtxtSURes rab_setup_it;
665 var template (value) E_RABSetupListCtxtSURes rab_setup_items;
666 var S1APEM_Config cfg;
667
668 S1AP.receive(tr_PDU_NAS_EPS_TrackingAreaUpdateAccept)-> value rx_nas;
669
670 /* Configure integrity protection: */
671 cfg := {
672 set_nas_alg_int := NAS_ALG_IP_EIA1
673 };
674 S1AP.send(cfg);
675
676 rab_setup_it := ts_S1AP_RABSetupItemCtxtSURes(rab_id := 5,
677 tla := oct2bit(f_inet_addr(mp_mme_ip)),
678 gtp_teid := '00000002'O);
679 rab_setup_items := ts_S1AP_RABSetupListCtxtSURes(rab_setup_it);
680 S1AP.send(ts_S1AP_InitialCtxSetupResp(valueof(mme_ue_id), valueof(enb_ue_id), rab_setup_items));
681
682 /* 3GPP TS 23.401 D.3.6 step 23: */
683 /* Integrity Protection: TS 24.301 Section 4.4.4.3*/
684 S1AP.send(ts_PDU_NAS_EPS_TrackingAreaUpdateComplete(c_EPS_SEC_IP));
685 }
686 [] S1AP.receive(PDU_NAS_EPS:?) -> value rx_nas {
687 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("Rx Unexpected NAS PDU msg: ", rx_nas));
688 }
689}
690
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100691private altstep as_s1ap_handle_UeContextReleaseCmd(template S1AP_IEs.Cause cause := ?) runs on ConnHdlr {
692 var S1AP_PDU rx_msg;
693 var PDU_NAS_EPS rx_nas;
694 [] S1AP.receive(tr_S1AP_UeContextReleaseCmd(?, cause)) -> value rx_msg {
695 var template MME_UE_S1AP_ID mme_ue_id;
696 var template ENB_UE_S1AP_ID enb_ue_id;
697 if (not ispresent(rx_msg.initiatingMessage.value_.uEContextReleaseCommand.protocolIEs[0].value_.uE_S1AP_IDs.uE_S1AP_ID_pair)) {
698 /* TODO: The UE CONTEXT RELEASE COMMAND (see also: 3GPP TS 36.413, section 9.1.4.6), may identify the
699 * context by either an uE_S1AP_ID_pair (MME_UE_S1AP_ID and ENB_UE_S1AP_ID) or an MME_UE_S1AP_ID alone.
700 * The latter case is not implemented here yet. */
701 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("complete implementation of UeContextReleaseCmd handling"));
702 return;
703 }
704
705 mme_ue_id := rx_msg.initiatingMessage.value_.uEContextReleaseCommand.protocolIEs[0].value_.uE_S1AP_IDs.uE_S1AP_ID_pair.mME_UE_S1AP_ID;
706 enb_ue_id := rx_msg.initiatingMessage.value_.uEContextReleaseCommand.protocolIEs[0].value_.uE_S1AP_IDs.uE_S1AP_ID_pair.eNB_UE_S1AP_ID;
707
708 S1AP.send(ts_S1AP_UeContextReleaseCompl(mme_ue_id, enb_ue_id));
709 }
710 [] S1AP.receive(PDU_NAS_EPS:?) -> value rx_nas {
711 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("Rx Unexpected NAS PDU msg: ", rx_nas));
712 }
713}
714
Harald Welte6ec64392019-08-14 12:37:07 +0200715/* Exepect AuthInfoReq (AIR) from HSS; respond with AuthInforAnswer (AIA) */
716private altstep as_DIA_AuthInfo() runs on ConnHdlr {
717 var PDU_DIAMETER rx_dia;
718 [] DIAMETER.receive(tr_DIA_AIR(g_pars.ue_pars.imsi)) -> value rx_dia {
719 var template (omit) AVP avp;
720 var octetstring sess_id;
721 var octetstring vplmn_id;
722 var hexstring imsi;
723 var template (value) AVP_list auth_info_content;
724
725 /* retrieve input data */
726 imsi := valueof(f_DIAMETER_get_imsi(rx_dia));
727 avp := f_DIAMETER_get_avp(rx_dia, c_AVP_Code_BASE_NONE_Session_Id);
728 sess_id := valueof(avp.avp_data.avp_BASE_NONE_Session_Id);
729 avp := f_DIAMETER_get_avp(rx_dia, c_AVP_Code_AAA_3GPP_Visited_PLMN_Id);
730 vplmn_id := valueof(avp.avp_data.avp_AAA_3GPP_Visited_PLMN_Id);
731
732 /* compute tuple */
733 auth_info_content := { ts_AVP_EutranVec(1, '20080c3818183b522614162c07601d0d'O, '6a91970e838fd079'O, 'f11b89a2a8be00001f9c526f3d75d44c'O, '95AFAD9A0D29AFAA079A9451DF7161D7EE4CBF2AF9387F766D058BB6B44B905D'O) };
734
Vadim Yanitskiy2dba4942021-12-11 15:46:30 +0300735 DIAMETER.send(ts_DIA_AIA(auth_info_content, sess_id,
736 hbh_id := rx_dia.hop_by_hop_id,
737 ete_id := rx_dia.end_to_end_id));
Harald Welte6ec64392019-08-14 12:37:07 +0200738 }
739}
740
741/* Expect UpdateLocationReq (ULR); respond with UpdateLocationAnswer (ULA) */
742private altstep as_DIA_UpdLoc() runs on ConnHdlr {
743 var PDU_DIAMETER rx_dia;
744 [] DIAMETER.receive(tr_DIA_ULR(g_pars.ue_pars.imsi)) -> value rx_dia {
745 var template (omit) AVP avp;
Harald Welte6ec64392019-08-14 12:37:07 +0200746 var hexstring imsi;
747 var template (value) AVP_list sub_data;
748
749 /* retrieve input data */
750 imsi := valueof(f_DIAMETER_get_imsi(rx_dia));
751 avp := f_DIAMETER_get_avp(rx_dia, c_AVP_Code_BASE_NONE_Session_Id);
Harald Welte6ec64392019-08-14 12:37:07 +0200752
753 sub_data := {
754 ts_AVP_3GPP_SubscriberStatus(SERVICE_GRANTED),
755 ts_AVP_3GPP_SubscrRauTauTmr(30),
756 ts_AVP_3GPP_AMBR(1000, 2000),
757 ts_AVP_3GPP_ApnConfigProfile({
758 ts_AVP_3GPP_ContextId(1),
759 ts_AVP_3GPP_AllApnConfigsIncl,
760 ts_AVP_3GPP_ApnConfig(1, IPv4, "*")
761 })
762 };
763
Vadim Yanitskiy0e8f5162021-12-15 05:00:32 +0300764 DIAMETER.send(ts_DIA_ULA(sub_data, avp.avp_data.avp_BASE_NONE_Session_Id,
765 hbh_id := rx_dia.hop_by_hop_id,
766 ete_id := rx_dia.end_to_end_id));
Harald Welte6ec64392019-08-14 12:37:07 +0200767 }
768}
769
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100770private function f_DIA_CancelLocation(integer idx := 0, template S1AP_IEs.Cause cause := omit) runs on ConnHdlr {
771
772 var UINT32 hbh_id := f_rnd_octstring(4);
773 var UINT32 ete_id := f_rnd_octstring(4);
774 var PDU_DIAMETER rx_dia;
775
776 /* Unlike CLR, CLA contains no IMSI. Register ete_id in DIAMETER_Emulation,
777 * so AIA is forwarded back to us in DIAMETER port instead of MTC_CT.DIAMETER_UNIT.
778 */
779 f_diameter_expect_eteid(ete_id);
780
781 DIAMETER.send(ts_DIA_CLR(g_pars.ue_pars.imsi, SGSN_UPDATE_PROCEDURE,
782 orig_host := mp_s6_local_diam_host,
783 orig_realm := mp_s6_diam_realm,
784 dest_host := mp_s6_remote_diam_host,
785 dest_realm := mp_s6_diam_realm,
786 hbh_id := hbh_id,
787 ete_id := ete_id));
788
789 alt {
790 [] DIAMETER.receive(tr_DIA_CLA) -> value rx_dia {}
791 [] DIAMETER.receive(PDU_DIAMETER:?) -> value rx_dia {
792 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("Unexpected Diameter S6b msg rx: ", rx_dia));
793 }
794 }
795}
796
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100797private altstep as_GTP2C_CreateSession_success() runs on ConnHdlr {
798 var PDU_GTPCv2 rx_msg;
799 var BearerContextIEs rx_bctx_ies;
800 var template (value) FullyQualifiedTEID s11_fteid_c_ie, s11_fteid_u_ie, s5c_fteid_c_ie, s5c_fteid_u_ie;
801 var template (value) PDN_AddressAllocation paa;
802 var template (value) BearerContextIEs bctx_ies;
Harald Welte6ec64392019-08-14 12:37:07 +0200803
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100804 [] GTP2.receive(tr_GTP2C_CreateSessionReq(g_pars.ue_pars.imsi)) -> value rx_msg {
805 /* Parse TEIC and Bearer EBI and TEID and store it in g_pars */
806 g_pars.ue_pars.s11_teic_remote := rx_msg.gtpcv2_pdu.createSessionRequest.fullyQualifiedTEID[0].tEID_GRE_Key;
807 g_pars.ue_pars.s5c_teic_remote := rx_msg.gtpcv2_pdu.createSessionRequest.fullyQualifiedTEID[1].tEID_GRE_Key;
808
809 rx_bctx_ies := rx_msg.gtpcv2_pdu.createSessionRequest.bearerContextGrouped[0].bearerContextIEs;
810 g_pars.ue_pars.bearer.ebi := rx_bctx_ies.ePS_Bearer_ID.ePS_Bearer_ID_Value;
811
812 /* allocate + register TEID-C on local side */
813 g_pars.ue_pars.s11_teic_local := f_gtp2_allocate_teid();
814 g_pars.ue_pars.bearer.s11_teid_local := g_pars.ue_pars.s11_teic_local;
815 g_pars.ue_pars.s5c_teic_local := f_gtp2_allocate_teid();
816 g_pars.ue_pars.bearer.s5c_teid_local := g_pars.ue_pars.s5c_teic_local;
817
818 s11_fteid_c_ie := ts_GTP2C_FTEID(FTEID_IF_S11_MME_GTPC, g_pars.ue_pars.s11_teic_local, 0,
819 f_inet_addr(mp_s11_local_ip), omit);
820 s5c_fteid_c_ie := ts_GTP2C_FTEID(FTEID_IF_S5S8_PGW_GTPC, g_pars.ue_pars.s5c_teic_local, 1,
821 f_inet_addr(mp_s5c_pgw_ip), omit);
822 s11_fteid_u_ie := ts_GTP2C_FTEID(FTEID_IF_S1U_SGW_GTPU, g_pars.ue_pars.bearer.s11_teid_local, 0,
823 f_inet_addr(mp_s11_local_ip), omit);
824 s5c_fteid_u_ie := ts_GTP2C_FTEID(FTEID_IF_S5S8_PGW_GTPU, g_pars.ue_pars.bearer.s5c_teid_local, 2,
825 f_inet_addr(mp_s5c_pgw_ip), omit);
826 paa := ts_GTP2C_PdnAddrAlloc_v4(f_inet_addr(g_pars.ue_pars.ue_ip));
827 bctx_ies := ts_GTP2C_BcContextIE(ebi := g_pars.ue_pars.bearer.ebi,
828 teid_list := { s11_fteid_u_ie, s5c_fteid_u_ie },
829 qos := ts_GTP2C_BearerQos('09'O, 0, 0, 0, 0),
830 charging_id := ts_GTP2C_ChargingID(g_pars.ue_pars.bearer.s11_teid_local));
831
832 GTP2.send(ts_GTP2C_CreateSessionResp(g_pars.ue_pars.s11_teic_remote,
833 rx_msg.sequenceNumber,
Pau Espin Pedrol7b2cc922024-02-28 16:14:15 +0100834 Request_accepted,
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100835 { s11_fteid_c_ie, s5c_fteid_c_ie },
836 paa, { ts_GTP2C_BcGrouped(bctx_ies) } ));
837 setverdict(pass);
838 }
839 [] GTP2.receive {
840 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
841 log2str("Unexpected GTPv2/S11 message from MME"));
842 }
843}
844
845private altstep as_GTP2C_ModifyBearer_success() runs on ConnHdlr {
846 var PDU_GTPCv2 rx_msg;
847 var BearerContextIEs rx_bctx_ies;
848 var template (value) FullyQualifiedTEID s11_fteid_c_ie, s11_fteid_u_ie, s5c_fteid_c_ie, s5c_fteid_u_ie;
849 var template (value) BearerContextIEs bctx_ies;
850
851 [] GTP2.receive(tr_GTP2C_ModifyBearerReq(g_pars.ue_pars.s11_teic_local)) -> value rx_msg {
852
853 rx_bctx_ies := rx_msg.gtpcv2_pdu.modifyBearerRequest.bearerContextGrouped[0].bearerContextIEs;
854
855 /* TODO: validate the S1-U fullyQualifiedTEID announces the IP address provided by the ENB in InitialCtxSetupResp */
856 // rx_bctx_ies.fullyQualifiedTEID[0]. == f_inet_addr(mp_mme_ip)
857
858 /* Update S11 TEID */
859 g_pars.ue_pars.bearer.s11_teid_remote := rx_bctx_ies.fullyQualifiedTEID[0].tEID_GRE_Key;
860
861 s11_fteid_u_ie := ts_GTP2C_FTEID(FTEID_IF_S1U_SGW_GTPU, g_pars.ue_pars.bearer.s11_teid_local, 0,
862 f_inet_addr(mp_s11_local_ip), omit);
863 bctx_ies := ts_GTP2C_BcContextIE(ebi := g_pars.ue_pars.bearer.ebi,
864 teid_list := { s11_fteid_u_ie },
865 qos := ts_GTP2C_BearerQos('09'O, 0, 0, 0, 0),
866 charging_id := ts_GTP2C_ChargingID(g_pars.ue_pars.bearer.s11_teid_local));
867
868 GTP2.send(ts_GTP2C_ModifyBearerResp(g_pars.ue_pars.s11_teic_remote,
869 rx_msg.sequenceNumber,
870 Request_accepted,
871 g_pars.ue_pars.bearer.ebi,
872 { ts_GTP2C_BcGrouped(bctx_ies) } ));
873 setverdict(pass);
874 }
875 [] GTP2.receive {
876 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
877 log2str("Unexpected GTPv2/S11 message from MME"));
878 }
879}
880
Pau Espin Pedrol78c5e412023-12-21 19:50:11 +0100881private altstep as_GTP2C_DeleteSession_success(template Indication ind_flags := *) runs on ConnHdlr {
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100882 var PDU_GTPCv2 rx_msg;
883
Pau Espin Pedrol78c5e412023-12-21 19:50:11 +0100884 [] GTP2.receive(tr_GTP2C_DeleteSessionReq(g_pars.ue_pars.s11_teic_local, indicationFlags := ind_flags)) -> value rx_msg {
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100885 GTP2.send(ts_GTP2C_DeleteSessionResp(g_pars.ue_pars.s11_teic_remote,
886 rx_msg.sequenceNumber,
887 Request_accepted));
888 setverdict(pass);
889 }
890 [] GTP2.receive {
891 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail,
892 log2str("Unexpected GTPv2/S11 message from MME"));
893 }
894}
895
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +0100896
897/* 3GPP TS 23.401 D.3.5, TS 23.003 2.8.2.1 */
898private function guti2rai_ptmsi(in NAS_EPS_Types.GUTI guti, in OCT2 truncated_nas_token, out RoutingAreaIdentity rai, out OCT4 ptmsi, out OCT3 ptmsi_sig) runs on ConnHdlr {
899 var bitstring mtmsi_bits := oct2bit(guti.mTMSI);
900 var bitstring ptmsi_bits;
901 var bitstring ptmsi_sig_bits;
902
903 rai := valueof(ts_RoutingAreaIdentity(guti.mccDigit1 & guti.mccDigit2 & guti.mccDigit3,
904 guti.mncDigit3 & guti.mncDigit1 & guti.mncDigit2,
905 guti.mMEGI, guti.mMEC));
906 /* 3GPP TS 23.003 2.8.2.0: "P-TMSI shall be of 32 bits length where the two topmost bits are
907 * reserved and always set to '11'. Hence, for a UE which may handover to GERAN/UTRAN (based on
908 * subscription and UE capabilities), the corresponding bits in the M-TMSI are set to '11'"
909 */
910 ptmsi_bits := '11'B & substr(mtmsi_bits, 2, 6) & oct2bit(guti.mMEC) & substr(mtmsi_bits, 16, 16);
911 ptmsi_sig_bits := substr(mtmsi_bits, 8, 8) & oct2bit(truncated_nas_token);
912 ptmsi := bit2oct(ptmsi_bits);
913 ptmsi_sig := bit2oct(ptmsi_sig_bits);
914 /* TODO: The UE shall fill the remaining 2 octets of the <P-TMSI signature> according to clauses 9.1.1, 9.4.1, 10.2.1, or
915 * 10.5.1 of 3GPP TS.33.401 [89] , as appropriate, for RAU/Attach procedures.*/
916}
917
918/* Test UE attached to EUTRAN reselecting a GERAN cell. In this scenario, the
919 * new SGSN will attempt to obtain information of the UE from the old SGSN (MME)
920 * through Gn interface using SGSN Context Request/Response procedure (OS#6294). */
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100921private function f_gtp_sgsn_context_4g_to_2g(OCT4 new_sgsn_local_teid := '12345678'O) runs on ConnHdlr {
922 var template (value) GTPC_PDUs SGSNContextReqPDU;
923 var RoutingAreaIdentity rai;
924 var OCT4 ptmsi;
925 var OCT3 ptmsi_sig;
926 var Gtp1cUnitdata gtpc_pdu;
927 var OCT4 old_mme_local_teid;
Pau Espin Pedrol20f35142024-01-15 18:47:05 +0100928 var uint16_t gtpc_seq_nr := f_rnd_int(65535);
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100929
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +0100930 /* Derive NAS Token (and post-increment ul_count): */
931 var OCT32 nas_token := f_s1apem_derive_nas_token(g_pars.ue_pars.kasme);
932 var OCT2 truncated_nas_token := substr(nas_token, 30, 2);
933
934 guti2rai_ptmsi(g_pars.ue_pars.guti, truncated_nas_token, rai, ptmsi, ptmsi_sig);
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100935
936 SGSNContextReqPDU := ts_SGSNContextReqPDU(rai, new_sgsn_local_teid, f_inet_addr(mp_gn_local_ip),
937 ptmsi := ts_PTMSI(ptmsi), ptmsi_sig := ts_PTMSI_sig(ptmsi_sig));
Pau Espin Pedrol20f35142024-01-15 18:47:05 +0100938 GTP.send(ts_GTPC_SGSNContextReq(g_gn_iface_peer, gtpc_seq_nr, SGSNContextReqPDU));
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100939
940 timer T := 5.0;
941 T.start;
942 alt {
943 [] GTP.receive(tr_GTPC_SGSNContextResp(g_gn_iface_peer, new_sgsn_local_teid,
944 tr_SGSNContextRespPDU(GTP_CAUSE_REQUEST_ACCEPTED,
945 g_pars.ue_pars.imsi))) -> value gtpc_pdu {
946 old_mme_local_teid := gtpc_pdu.gtpc.gtpc_pdu.sgsn_ContextResponse.teidControlPlane.teidControlPlane;
947 setverdict(pass);
948 }
949 [] GTP.receive {
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +0100950 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("unexpected GTPC message from MME"));
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100951 }
952 [] T.timeout {
Pau Espin Pedrol3be4d922024-01-15 15:21:57 +0100953 Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("no SGSN Context Response from MME"));
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +0100954 }
955 }
956
957 GTP.send(ts_GTPC_SGSNContextAck(g_gn_iface_peer, old_mme_local_teid,
958 oct2int(gtpc_pdu.gtpc.opt_part.sequenceNumber),
959 ts_SGSNContextAckPDU(GTP_CAUSE_REQUEST_ACCEPTED)));
960
961}
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +0100962
Pau Espin Pedrol35618872024-01-15 15:25:18 +0100963private altstep as_gtp_sgsn_context_2g_to_4g(OCT4 new_sgsn_teid := 'ABABABAB'O, GTP_Templates.GTP_RATType rat_type := GTP_RAT_TYPE_EUTRAN) runs on ConnHdlr {
964 var Gtp1cUnitdata gtpc_pdu;
965
966 [] GTP.receive(tr_GTPC_SGSNContextReq(g_gn_iface_peer, tr_SGSNContextReqPDU(rat_type := int2oct(enum2int(rat_type), 1)))) -> value gtpc_pdu {
967 var template (value) PDP_Context_GTPC pdp_ctx;
968 var template (value) GTPC_PDUs SGSNContextRespPDU;
969 var Gtp1cUnitdata gtpc_pdu_ack;
970 var OCT4 old_mme_remote_teid := gtpc_pdu.gtpc.gtpc_pdu.sgsn_ContextRequest.teidControlPlane.teidControlPlane;
971
972 const OCT16 ck := '740d62df9803eebde5120acf358433d0'O;
973 const OCT16 ik := '11329aae8e8d2941bb226b2061137c58'O;
974
975 pdp_ctx := ts_PDP_Context_GTPC(f_inet_addr(g_pars.ue_pars.ue_ip),
976 f_inet_addr(mp_gn_local_ip),
977 c_NAS_defaultAPN,
978 ggsn_teic := '12345678'O,
979 ggsn_teid := '87654321'O);
980 SGSNContextRespPDU := ts_SGSNContextRespPDU(GTP_CAUSE_REQUEST_ACCEPTED,
981 g_pars.ue_pars.imsi,
982 new_sgsn_teid,
983 f_inet_addr(mp_gn_local_ip),
984 ts_MM_ContextUMTS(ck, ik),
985 { pdp_ctx });
986 GTP.send(ts_GTPC_SGSNContextResp(g_gn_iface_peer,
987 old_mme_remote_teid,
988 oct2int(gtpc_pdu.gtpc.opt_part.sequenceNumber),
989 SGSNContextRespPDU));
990
991 GTP.receive(tr_GTPC_SGSNContextAck(g_gn_iface_peer, new_sgsn_teid,
992 tr_SGSNContextAckPDU(GTP_CAUSE_REQUEST_ACCEPTED))) -> value gtpc_pdu;
993 setverdict(pass);
994 }
995 [] GTP.receive {
996 setverdict(fail, "unexpected GTPC message from MME");
997 }
998}
999
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +01001000private function f_attach() runs on ConnHdlr {
1001 var template (value) EPS_MobileIdentityV mi := ts_NAS_MobileId_IMSI(g_pars.ue_pars.imsi);
Harald Welte95333a12019-07-11 22:51:45 +08001002 var template (value) PDU_NAS_EPS nas_esm, nas_emm;
Philipp Maierf74f3192023-09-01 17:24:36 +02001003 timer T := 5.0;
1004
Harald Welte95333a12019-07-11 22:51:45 +08001005 nas_esm := ts_NAS_PdnConnReq(bearer_id := '0000'B, proc_tid := int2bit(1,8),
1006 pdn_type := NAS_PDN_T_IPv4, req_type := '001'B);
1007 nas_emm := ts_NAS_AttachRequest(att_type := '000'B, kset_id := '000'B, mobile_id := mi,
1008 ue_net_cap := c_NAS_defaultUeNetCap,
1009 esm_enc := enc_PDU_NAS_EPS(valueof(nas_esm)));
1010 var template (value) S1AP_PDU tx;
1011 tx := ts_S1AP_InitialUE(p_eNB_value := 0, p_nasPdu := enc_PDU_NAS_EPS(valueof(nas_emm)),
1012 p_tAI := ts_enb_S1AP_TAI(g_pars.enb_pars[g_pars.mme_idx]),
1013 p_eUTRAN_CGI := ts_enb_S1AP_CGI(g_pars.enb_pars[g_pars.mme_idx]),
1014 p_rrcCause := mo_Signalling);
1015 S1AP.send(tx);
1016
Harald Welte6ec64392019-08-14 12:37:07 +02001017 as_DIA_AuthInfo();
Harald Welte95333a12019-07-11 22:51:45 +08001018 as_s1ap_handle_auth();
Harald Welte6ec64392019-08-14 12:37:07 +02001019 alt {
1020 [] as_DIA_UpdLoc() {
1021 as_s1ap_handle_sec_mode();
1022 }
1023 [] as_s1ap_handle_sec_mode() {
1024 as_DIA_UpdLoc();
1025 }
1026 }
Harald Welte95333a12019-07-11 22:51:45 +08001027
Philipp Maierf74f3192023-09-01 17:24:36 +02001028 /* We now expect the MME to send a Create Session Request to the SGW-C */
Philipp Maierf74f3192023-09-01 17:24:36 +02001029 f_gtp2_register_udmsg('20'O);
1030 T.start;
1031 alt {
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +01001032 [] as_GTP2C_CreateSession_success();
1033 [] T.timeout { Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("No message from MME")); }
Philipp Maierf74f3192023-09-01 17:24:36 +02001034 }
1035
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +01001036 T.start;
1037 alt {
Pau Espin Pedrol35618872024-01-15 15:25:18 +01001038 [] as_s1ap_handle_IntialCtxSetupReq_Attach_Accept();
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +01001039 [] T.timeout { Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("No message from MME")); }
1040 }
Philipp Maierf74f3192023-09-01 17:24:36 +02001041
Pau Espin Pedrolecfc7d62023-12-13 18:49:29 +01001042 /* We now expect the MME to send a Modify Bearer Request to the SGW-C */
1043 f_gtp2_register_udmsg('22'O);
1044 T.start;
1045 alt {
1046 [] as_GTP2C_ModifyBearer_success();
1047 [] T.timeout { Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("No message from MME")); }
1048 }
1049}
1050
1051private function f_TC_attach(ConnHdlrPars pars) runs on ConnHdlr {
1052 f_init_handler(pars);
1053 f_attach();
Harald Welte95333a12019-07-11 22:51:45 +08001054}
1055testcase TC_s1ap_attach() runs on MTC_CT {
1056 var charstring id := testcasename();
1057
Harald Welte6ec64392019-08-14 12:37:07 +02001058 f_init_diameter(id);
1059 f_sleep(10.0);
Harald Welte95333a12019-07-11 22:51:45 +08001060 f_init_s1ap(id, 4);
Philipp Maierf74f3192023-09-01 17:24:36 +02001061 f_init_gtpv2_s11(id);
Harald Welte95333a12019-07-11 22:51:45 +08001062 f_s1ap_setup(0);
1063
1064 var ConnHdlrPars pars := f_init_pars(ue_idx := 0);
1065 var ConnHdlr vc_conn;
1066 vc_conn := f_start_handler_with_pars(refers(f_TC_attach), pars);
1067 vc_conn.done;
1068}
1069
Philipp Maier74d776a2023-07-12 14:04:14 +02001070private function f_TC_gn_echo_request(ConnHdlrPars pars) runs on ConnHdlr {
1071 timer T := 5.0;
1072 f_init_handler(pars);
1073 f_gtp_register_teid('00000000'O);
1074
1075 GTP.send(ts_GTPC_PING(g_gn_iface_peer, 1));
1076 T.start;
1077 alt {
1078 [] GTP.receive(tr_GTPC_PONG(?)) {
1079 setverdict(pass);
1080 }
1081 [] GTP.receive {
1082 setverdict(fail, "unexpected GTPC message from MME");
1083 }
1084 [] T.timeout {
1085 setverdict(fail, "no GTPC ECHO RESPONSE from MME");
1086 }
1087 }
1088}
1089testcase TC_gn_echo_request() runs on MTC_CT {
1090 var charstring id := testcasename();
1091
1092 f_init_diameter(id);
Pau Espin Pedrolae747ac2023-12-20 20:55:32 +01001093 f_init_s1ap(id, 0);
Philipp Maier74d776a2023-07-12 14:04:14 +02001094 f_s1ap_setup(0);
1095 f_init_gtp(id);
1096
1097 var ConnHdlrPars pars := f_init_pars(ue_idx := 0);
1098 var ConnHdlr vc_conn;
1099 vc_conn := f_start_handler_with_pars(refers(f_TC_gn_echo_request), pars);
1100 vc_conn.done;
1101}
1102
Philipp Maiera9306202023-07-24 11:41:51 +02001103external function enc_PDU_GTPC_RAN_INF_REQ(in PDU_BSSGP_RAN_INFORMATION_REQUEST_GTPC gtpc_pdu) return octetstring
1104with { extension "prototype(convert)"
1105 extension "encode(RAW)"
1106 }
1107
1108external function enc_PDU_GTPC_RAN_INF(in PDU_BSSGP_RAN_INFORMATION_GTPC gtpc_pdu) return octetstring
1109with { extension "prototype(convert)"
1110 extension "encode(RAW)"
1111 }
1112
1113function f_convert_plmn(OCT3 pLMNidentity) return hexstring {
1114 var hexstring pLMNidentity_hex := oct2hex(pLMNidentity);
1115 var hexstring pLMNidentity_hex_swapped;
1116 pLMNidentity_hex_swapped[0] := pLMNidentity_hex[1];
1117 pLMNidentity_hex_swapped[1] := pLMNidentity_hex[0];
1118 pLMNidentity_hex_swapped[2] := pLMNidentity_hex[3];
1119 pLMNidentity_hex_swapped[3] := pLMNidentity_hex[2];
1120 pLMNidentity_hex_swapped[4] := pLMNidentity_hex[5];
1121 pLMNidentity_hex_swapped[5] := pLMNidentity_hex[4];
1122 return pLMNidentity_hex_swapped;
1123}
1124
1125/* Make a template for a GTPC BSSGP container that contains a RAN INFORMATION REQUEST. The template can be used to
1126 * craft the request for the S1AP/S1-MME interface and also to verfify the contents of the coresponding request on
1127 * the GTPC/Gn interface */
1128private function f_make_ts_GTPC_RAN_Information_Request(GTP_CellId geran_gtp_ci)
1129 runs on ConnHdlr return template (value) PDU_BSSGP_RAN_INFORMATION_REQUEST_GTPC {
1130 var template (value) RIM_Routing_Address_GTPC gtpc_dst_addr, gtpc_src_addr;
1131 var template (value) RAN_Information_Request_RIM_Container_GTPC gtpc_rim_req_cont;
1132 var template (value) PDU_BSSGP_RAN_INFORMATION_REQUEST_GTPC gtpc_bssgp_cont;
1133 var octetstring gnbid;
1134 var GTP_CellId eutran_gtp_ci;
1135 eutran_gtp_ci.ra_id.lai.mcc_mnc := f_convert_plmn(g_pars.enb_pars[g_pars.mme_idx].global_enb_id.pLMNidentity);
1136
1137 gnbid := enc_S1AP_Global_ENB_ID(g_pars.enb_pars[g_pars.mme_idx].global_enb_id);
1138 gtpc_dst_addr := t_GTPC_RIM_Routing_Address_cid(geran_gtp_ci);
1139 gtpc_src_addr := t_GTPC_RIM_Routing_Address_enbid(eutran_gtp_ci,
1140 oct2int(g_pars.enb_pars[g_pars.mme_idx].supported_tas[0].tAC),
1141 gnbid);
1142
1143 gtpc_rim_req_cont := ts_GTPC_RAN_Information_Request_RIM_Container(
1144 ts_GTPC_RIM_Application_Identity(RIM_APP_ID_NACC),
1145 ts_GTPC_RIM_Sequence_Number(1),
1146 ts_GTPC_RIM_PDU_Indications(false, RIM_PDU_TYPE_SING_REP),
1147 ts_GTPC_RIM_Protocol_Version_Number(1),
1148 tsu_GTPC_RAN_Information_Request_Application_Container_NACC(geran_gtp_ci),
1149 omit);
1150 gtpc_bssgp_cont := ts_GTPC_RAN_Information_Request(
1151 ts_GTPC_RIM_Routing_Information(RIM_ADDR_GERAN_CELL_ID, gtpc_dst_addr),
1152 ts_GTPC_RIM_Routing_Information(RIM_ADDR_EUTRAN_NODEB_ID, gtpc_src_addr),
1153 gtpc_rim_req_cont);
1154
1155 return gtpc_bssgp_cont;
1156}
1157
1158private function f_make_tr_GTPC_RAN_Information_Request(GTP_CellId geran_gtp_ci)
1159 runs on ConnHdlr return template (present) PDU_BSSGP_RAN_INFORMATION_REQUEST_GTPC {
1160 var template (present) RIM_Routing_Address_GTPC gtpc_dst_addr, gtpc_src_addr;
1161 var template (present) RAN_Information_Request_RIM_Container_GTPC gtpc_rim_req_cont;
1162 var template (present) PDU_BSSGP_RAN_INFORMATION_REQUEST_GTPC gtpc_bssgp_cont;
1163 var octetstring gnbid;
1164 var GTP_CellId eutran_gtp_ci;
1165 eutran_gtp_ci.ra_id.lai.mcc_mnc := f_convert_plmn(g_pars.enb_pars[g_pars.mme_idx].global_enb_id.pLMNidentity);
1166
1167 gnbid := enc_S1AP_Global_ENB_ID(g_pars.enb_pars[g_pars.mme_idx].global_enb_id);
1168 gtpc_dst_addr := t_GTPC_RIM_Routing_Address_cid(geran_gtp_ci);
1169 gtpc_src_addr := t_GTPC_RIM_Routing_Address_enbid(eutran_gtp_ci,
1170 oct2int(g_pars.enb_pars[g_pars.mme_idx].supported_tas[0].tAC),
1171 gnbid);
1172
1173 gtpc_rim_req_cont := tr_GTPC_RAN_Information_Request_RIM_Container(
1174 ts_GTPC_RIM_Application_Identity(RIM_APP_ID_NACC),
1175 ts_GTPC_RIM_Sequence_Number(1),
1176 ts_GTPC_RIM_PDU_Indications(false, RIM_PDU_TYPE_SING_REP),
1177 ts_GTPC_RIM_Protocol_Version_Number(1),
1178 tru_GTPC_RAN_Information_Request_Application_Container_NACC(geran_gtp_ci));
1179 gtpc_bssgp_cont := tr_GTPC_RAN_Information_Request(
1180 tr_GTPC_RIM_Routing_Information(RIM_ADDR_GERAN_CELL_ID, gtpc_dst_addr),
1181 tr_GTPC_RIM_Routing_Information(RIM_ADDR_EUTRAN_NODEB_ID, gtpc_src_addr),
1182 gtpc_rim_req_cont);
1183
1184 return gtpc_bssgp_cont;
1185}
1186
1187/* Make initial RAN INFORMATION REQUEST message that is sent on the S1AP/S1-MME interface */
1188private function f_make_ts_S1AP_eNBDirectInfTrans(GTP_CellId geran_gtp_ci)
1189 runs on ConnHdlr return template (value) S1AP_PDU {
1190 var template (value) Inter_SystemInformationTransferType inf;
1191
1192 inf.rIMTransfer.rIMInformation := enc_PDU_GTPC_RAN_INF_REQ(valueof(f_make_ts_GTPC_RAN_Information_Request(geran_gtp_ci)));
1193 inf.rIMTransfer.rIMRoutingAddress.gERAN_Cell_ID.lAI.pLMNidentity := hex2oct(f_convert_plmn(hex2oct(geran_gtp_ci.ra_id.lai.mcc_mnc)));
1194 inf.rIMTransfer.rIMRoutingAddress.gERAN_Cell_ID.lAI.lAC := int2oct(geran_gtp_ci.ra_id.lai.lac, 2);
1195 inf.rIMTransfer.rIMRoutingAddress.gERAN_Cell_ID.lAI.iE_Extensions := omit;
1196 inf.rIMTransfer.rIMRoutingAddress.gERAN_Cell_ID.rAC := int2oct(geran_gtp_ci.ra_id.rac, 1);
1197 inf.rIMTransfer.rIMRoutingAddress.gERAN_Cell_ID.cI := int2oct(geran_gtp_ci.cell_id, 2);
1198 inf.rIMTransfer.rIMRoutingAddress.gERAN_Cell_ID.iE_Extensions := omit;
1199 inf.rIMTransfer.iE_Extensions := omit;
1200
1201 return ts_S1AP_eNBDirectInfTrans(inf);
1202}
1203
1204/* Make RAN INFORMATION (response) message that is sent on the GTPC/Gn interface */
1205private function f_make_ts_GTPC_RANInfoRelay(template Gtp1cUnitdata req_gtpc_pdu,
1206 GTP_CellId geran_gtp_ci, octetstring geran_si)
1207 runs on ConnHdlr return template (value) Gtp1cUnitdata {
1208 var template Gtp1cUnitdata res_gtpc_pdu;
1209 var template RAN_Information_RIM_Container_GTPC gtpc_rim_res_cont;
1210 var template PDU_BSSGP_RAN_INFORMATION_GTPC gtpc_bssgp_rim_res_pdu;
1211 var template RIM_Routing_Information_GTPC gtpc_rim_dst_cell_id, gtpc_rim_src_cell_id;
1212 var template RIM_RoutingAddress gtpc_rim_ra;
1213 var template RIM_RoutingAddress_Discriminator gtpc_rim_ra_discr;
1214
1215 /* Assemble GTPC RAN Information */
1216 gtpc_rim_res_cont := ts_GTPC_RAN_Information_RIM_Container(ts_GTPC_RIM_Application_Identity(RIM_APP_ID_NACC),
1217 ts_GTPC_RIM_Sequence_Number(2),
1218 ts_GTPC_RIM_PDU_Indications(false, RIM_PDU_TYPE_SING_REP),
1219 ts_GTPC_RIM_Protocol_Version_Number(1),
1220 tsu_GTPC_ApplContainer_or_ApplErrContainer_NACC(tsu_GTPC_ApplContainer_NACC(geran_gtp_ci, false, 3, geran_si)),
1221 omit);
1222
1223 /* The source becomes the destination and vice versa */
1224 gtpc_rim_dst_cell_id := req_gtpc_pdu.gtpc.gtpc_pdu.ranInformationRelay.transparentContainer.
1225 rANTransparentContainerField.pDU_BSSGP_RAN_INFORMATION_REQUEST.source_Cell_Identifier
1226 gtpc_rim_src_cell_id := req_gtpc_pdu.gtpc.gtpc_pdu.ranInformationRelay.transparentContainer.
1227 rANTransparentContainerField.pDU_BSSGP_RAN_INFORMATION_REQUEST.destination_Cell_Identifier
1228 gtpc_bssgp_rim_res_pdu := ts_GTPC_RAN_Information(gtpc_rim_dst_cell_id,
1229 gtpc_rim_src_cell_id,
1230 gtpc_rim_res_cont);
1231
1232 /* Assemble RIM Routing Address (essentially a copy of the destination cell identifier)*/
1233 gtpc_rim_ra := ts_RIM_RoutingAddress(enc_RIM_Routing_Address_GTPC(valueof(gtpc_rim_dst_cell_id.rIM_Routing_Address)));
1234 gtpc_rim_ra_discr := ts_RIM_RoutingAddress_Discriminator(hex2bit(valueof(gtpc_rim_dst_cell_id.rIMRoutingAddressDiscriminator)));
1235
1236 res_gtpc_pdu := ts_GTPC_RANInfoRelay(g_gn_iface_peer,
1237 ts_RANTransparentContainer_RAN_INFO(gtpc_bssgp_rim_res_pdu),
1238 gtpc_rim_ra, gtpc_rim_ra_discr);
1239
1240 return res_gtpc_pdu;
1241}
1242
1243/* Make template to verify the RAN INFORMATION REQUEST as it appears on the GTPC/Gn interface */
1244private function f_make_tr_GTPC_MsgType(GTP_CellId geran_gtp_ci)
1245 runs on ConnHdlr return template (present) Gtp1cUnitdata {
1246 var template Gtp1cUnitdata msg;
1247 var template GTPC_PDUs pdus;
1248 var template RANTransparentContainer ran_transp_cont;
1249
1250 ran_transp_cont := tr_RANTransparentContainer_RAN_INFO_REQ(
1251 f_make_tr_GTPC_RAN_Information_Request(geran_gtp_ci));
1252 pdus := tr_RANInfoRelay(ran_transp_cont);
1253 msg := tr_GTPC_MsgType(g_gn_iface_peer, rANInformationRelay, '00000000'O, pdus);
1254
1255 return msg;
1256}
1257
1258/* Make template to verify the RAN INFORMATION (response) as it appears on the S1AP/S1-MME interface */
1259private function f_make_tr_S1AP_MMEDirectInfTrans(Gtp1cUnitdata ran_information_gtpc_pdu)
1260 runs on ConnHdlr return template (present) S1AP_PDU {
1261 var template S1AP_PDU msg;
1262 var template Inter_SystemInformationTransferType inf;
1263
1264 inf.rIMTransfer.rIMInformation := enc_PDU_GTPC_RAN_INF(
1265 ran_information_gtpc_pdu.gtpc.gtpc_pdu.ranInformationRelay.
1266 transparentContainer.rANTransparentContainerField.
1267 pDU_BSSGP_RAN_INFORMATION);
1268 inf.rIMTransfer.rIMRoutingAddress := omit;
1269 inf.rIMTransfer.iE_Extensions := omit;
1270 msg := tr_S1AP_MMEDirectInfTrans(inf);
1271
1272 return msg;
1273}
1274
1275private function f_TC_RIM_RAN_INF(ConnHdlrPars pars) runs on ConnHdlr {
1276 timer T := 5.0;
1277 f_init_handler(pars);
1278 f_gtp_register_teid('00000000'O);
1279 var Gtp1cUnitdata req_gtpc_pdu;
1280 var Gtp1cUnitdata resp_gtpc_pdu;
1281 var GTP_CellId geran_gtp_ci;
1282
1283 /* Assemble data of a fictitiously GERAN cell */
Pau Espin Pedrol11625852023-12-22 14:20:42 +01001284 geran_gtp_ci.ra_id.rac := mp_gn_local_rac;
1285 geran_gtp_ci.ra_id.lai.mcc_mnc := mp_gn_local_mcc & mp_gn_local_mnc;
1286 geran_gtp_ci.ra_id.lai.lac := mp_gn_local_lac;
1287 geran_gtp_ci.cell_id := mp_gn_local_ci;
Philipp Maiera9306202023-07-24 11:41:51 +02001288 const octetstring geran_si1 := '198fb100000000000000000000000000007900002b'O;
1289 const octetstring geran_si3 := '1b753000f110236ec9033c2747407900003c0b2b2b'O;
1290 const octetstring geran_si13 := '009000185a6fc9e08410ab2b2b2b2b2b2b2b2b2b2b'O;
1291 const octetstring geran_si := geran_si1 & geran_si3 & geran_si13;
1292
1293 /* Send initial RAN information request via S1AP to MME and expect the MME to forward the request on GTP-C
1294 * (eNB -> MME -> SGSN) */
1295 S1AP.send(f_make_ts_S1AP_eNBDirectInfTrans(geran_gtp_ci));
1296 T.start;
1297 alt {
1298 [] GTP.receive(f_make_tr_GTPC_MsgType(geran_gtp_ci)) -> value req_gtpc_pdu {
1299 setverdict(pass);
1300 }
1301 [] GTP.receive {
1302 setverdict(fail, "unexpected GTPC message from MME");
1303 }
1304 [] T.timeout {
1305 setverdict(fail, "no GTPC RAN INFORMATION REQUEST from MME");
1306 }
1307 }
1308
1309 /* Send RAN information response via GTP-C to MME and expect the MME to forward the respnse on S1AP
1310 * (SGSN -> MME -> eNB) */
1311 f_create_s1ap_expect_proc(id_MMEDirectInformationTransfer, self);
1312 resp_gtpc_pdu := valueof(f_make_ts_GTPC_RANInfoRelay(req_gtpc_pdu, geran_gtp_ci, geran_si));
1313 GTP.send(resp_gtpc_pdu);
1314 T.start;
1315 alt {
1316 [] S1AP.receive(f_make_tr_S1AP_MMEDirectInfTrans(resp_gtpc_pdu)) {
1317 setverdict(pass);
1318 }
1319 [] S1AP.receive {
1320 setverdict(fail, "unexpected S1AP message from MME");
1321 }
1322 [] T.timeout {
1323 setverdict(fail, "no S1AP RAN INFORMATION from MME");
1324 }
1325 }
1326
1327 setverdict(pass);
1328}
1329
1330testcase TC_RIM_RAN_INF() runs on MTC_CT {
1331 var charstring id := testcasename();
1332
1333 f_init_diameter(id);
Pau Espin Pedrolae747ac2023-12-20 20:55:32 +01001334 f_init_s1ap(id, 0);
Philipp Maiera9306202023-07-24 11:41:51 +02001335 f_s1ap_setup(0);
1336 f_init_gtp(id);
1337
Philipp Maiera9306202023-07-24 11:41:51 +02001338 var ConnHdlrPars pars := f_init_pars(ue_idx := 0);
1339 var ConnHdlr vc_conn;
1340 vc_conn := f_start_handler_with_pars(refers(f_TC_RIM_RAN_INF), pars);
1341
1342 vc_conn.done;
1343}
1344
Philipp Maier46059f02023-08-16 14:45:27 +02001345/* Successful RESET procedure from eNB to MME */
1346testcase TC_s1ap_reset() runs on MTC_CT {
1347 var charstring id := testcasename();
Pau Espin Pedrolae747ac2023-12-20 20:55:32 +01001348 f_init_s1ap(id, 0);
Philipp Maier46059f02023-08-16 14:45:27 +02001349 f_s1ap_setup(0);
1350
Philipp Maier9abb8c92023-08-31 13:12:28 +02001351 var template (value) S1AP_IEs.Cause reset_cause := {misc := om_intervention};
Philipp Maier46059f02023-08-16 14:45:27 +02001352 var template (value) ResetType reset_type := {s1_Interface := reset_all};
1353 timer T := 5.0;
1354
1355 S1AP_UNIT[0].send(ts_S1AP_Reset(reset_cause, reset_type));
1356 T.start;
1357 alt {
1358 [] S1AP_UNIT[0].receive(tr_S1AP_ResetAck_any) {
1359 setverdict(pass);
1360 }
1361 [] S1AP_UNIT[0].receive {
1362 setverdict(fail, "Received unexpected S1AP");
1363 }
1364 [] T.timeout {
1365 setverdict(fail, "Timeout waiting for S1AP Setup result");
1366 }
1367 }
1368}
1369
Philipp Maier26a09f32023-09-01 14:18:33 +02001370/* Tracking area update with a GUTI (TMSI) that is unknown to the MME. The MME is expected to reject this TAU
1371 * request. */
1372private function f_TC_tau_unknown_guti(ConnHdlrPars pars) runs on ConnHdlr {
1373
1374 f_init_handler(pars);
1375 var template (value) EPS_MobileIdentityV mi := ts_NAS_MobileId_IMSI(pars.ue_pars.imsi);
1376 var template (value) S1AP_PDU tx;
1377 var template (value) PDU_NAS_EPS nas_tau;
1378 timer T := 5.0;
1379
1380 var hexstring mcc_mnc := f_convert_plmn(g_pars.enb_pars[g_pars.mme_idx].global_enb_id.pLMNidentity);
1381 var EPS_MobileIdentityLV old_guti := valueof(ts_EPS_MobileId_GUTI(mcc_mnc, '0001'O, '01'O, 'AABBCCDD'O));
1382 nas_tau := ts_PDU_NAS_EPS_TrackingAreaUpdateRequest(old_guti);
1383
1384 tx := ts_S1AP_InitialUE(p_eNB_value := 0, p_nasPdu := enc_PDU_NAS_EPS(valueof(nas_tau)),
1385 p_tAI := ts_enb_S1AP_TAI(g_pars.enb_pars[g_pars.mme_idx]),
1386 p_eUTRAN_CGI := ts_enb_S1AP_CGI(g_pars.enb_pars[g_pars.mme_idx]),
1387 p_rrcCause := mo_Signalling);
1388
1389 S1AP.send(tx);
1390
1391 T.start;
1392 alt {
1393 [] S1AP.receive(tr_PDU_NAS_EPS_TrackingAreaUpdateReject) {
1394 setverdict(pass);
1395 }
1396 [] S1AP.receive {
1397 setverdict(fail, "unexpected S1AP message from MME");
1398 }
1399 [] T.timeout {
1400 setverdict(fail, "no message from MME");
1401 }
1402 }
1403
Pau Espin Pedrola88e51d2024-01-08 15:44:36 +01001404 as_s1ap_handle_UeContextReleaseCmd();
Philipp Maier26a09f32023-09-01 14:18:33 +02001405}
1406testcase TC_s1ap_tau_unknown_guti() runs on MTC_CT {
1407 var charstring id := testcasename();
1408
1409 f_init_diameter(id);
Pau Espin Pedrolae747ac2023-12-20 20:55:32 +01001410 f_init_s1ap(id, 5);
Philipp Maier26a09f32023-09-01 14:18:33 +02001411 f_s1ap_setup(0);
1412
1413 var ConnHdlrPars pars := f_init_pars(ue_idx := 0);
1414 var ConnHdlr vc_conn;
1415 vc_conn := f_start_handler_with_pars(refers(f_TC_tau_unknown_guti), pars);
1416 vc_conn.done;
1417}
1418
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001419private function f_TC_ue_cell_reselect_eutran_to_geran(ConnHdlrPars pars) runs on ConnHdlr {
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001420 f_init_handler(pars);
1421 f_gtp_register_imsi(g_pars.ue_pars.imsi);
1422 f_attach();
1423
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +01001424 /* TS 23.401 Figure D.3.5-1 Steps 1,2,3,4: */
1425 f_gtp_sgsn_context_4g_to_2g();
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001426
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +01001427 /* TS 23.401 Figure D.3.5-1 Step 8: */
1428 f_DIA_CancelLocation();
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001429
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +01001430 /* TS 23.401 Figure D.3.5-1 Step 13:
1431 * Upon rx of SGSN Context Acknowledge, MME released the ENB/UE context:
1432 */
1433 as_s1ap_handle_UeContextReleaseCmd();
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001434
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +01001435 /* TS 23.401 Figure D.3.5-1 Step 13:
Pau Espin Pedrol78c5e412023-12-21 19:50:11 +01001436 * After Gn timer triggers, the SGW session is deleted.
1437 * Make sure Operation Indication is set to 0, to tell the SGW to keep the Session up at the PGW.
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +01001438 */
Pau Espin Pedrol78c5e412023-12-21 19:50:11 +01001439 as_GTP2C_DeleteSession_success(tr_GTP2C_Indication(oI := '0'B));
Pau Espin Pedrol35c0cc22023-12-21 19:23:48 +01001440 /* Let MME some time to handle the Create Session Response: */
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001441 f_sleep(3.0);
1442}
1443testcase TC_ue_cell_reselect_eutran_to_geran() runs on MTC_CT {
1444 var charstring id := testcasename();
1445
1446 f_init_diameter(id);
Pau Espin Pedrolae747ac2023-12-20 20:55:32 +01001447 f_init_s1ap(id, 6);
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001448 f_init_gtpv2_s11(id);
1449 f_s1ap_setup(0);
1450 f_init_gtp(id);
1451
1452 var ConnHdlrPars pars := f_init_pars(ue_idx := 0);
1453 var ConnHdlr vc_conn;
1454 vc_conn := f_start_handler_with_pars(refers(f_TC_ue_cell_reselect_eutran_to_geran), pars);
1455 vc_conn.done;
1456}
1457
Pau Espin Pedrol35618872024-01-15 15:25:18 +01001458/* 3GPP TS 23.401 D.3.6, TS 23.003 2.8.2.2 */
1459private function rai_ptmsi2_guti(in RoutingAreaIdentity rai, in OCT4 ptmsi, in OCT3 ptmsi_sig, out NAS_EPS_Types.GUTI guti) runs on ConnHdlr {
1460
1461
1462 var bitstring ptmsi_bits := oct2bit(ptmsi);
1463 var bitstring ptmsi_sig_bits := oct2bit(ptmsi_sig);
1464 var bitstring mtmsi_bits := '11'B &
1465 substr(ptmsi_bits, 2, 6) &
1466 substr(ptmsi_sig_bits, 0, 8) &
1467 substr(ptmsi_bits, 16, 16);
1468 guti := valueof(ts_NAS_GUTI(mcc_mnc := rai.mcc_digits & rai.mnc_digits,
1469 mmegi := rai.lac,
1470 mmec := rai.rac,
1471 tmsi := bit2oct(mtmsi_bits)));
1472}
1473/* Test UE attached to GERAN reselecting a EUTRAN cell. In this scenario, the
1474 * new MME will attempt to obtain information of the UE from the old SGSN
1475 * through Gn interface using SGSN Context Request/Response procedure (OS#6294). */
1476/* 3GPP TS 23.401 D.3.6, TS 23.003 2.8.2.1 */
1477private function f_TC_ue_cell_reselect_geran_to_eutran(ConnHdlrPars pars) runs on ConnHdlr {
1478 f_init_handler(pars);
1479 f_gtp_register_imsi(g_pars.ue_pars.imsi);
1480 f_gtp2_register_imsi(g_pars.ue_pars.imsi);
1481 /* SGSN Context Req doesn't necessarily contain IMSI, hence expect it through TEID=0 */
1482 f_gtp_register_teid('00000000'O);
1483 /* passed in SGSN Context Resp to MME, will be used by MME when answering with SGSN Context Ack: */
1484 const OCT4 new_sgsn_teid := 'ABABABAB'O;
1485 f_gtp_register_teid(new_sgsn_teid);
1486
1487 var template (value) EPS_MobileIdentityV mi := ts_NAS_MobileId_IMSI(pars.ue_pars.imsi);
1488 var template (value) S1AP_PDU tx;
1489 var template (value) PDU_NAS_EPS nas_tau;
1490 var RoutingAreaIdentity rai;
1491 var OCT4 ptmsi := f_gen_tmsi(suffix := 0, nri_v := 0, nri_bitlen := 8);
1492 var OCT3 ptmsi_sig := f_rnd_octstring(3);
1493 var NAS_EPS_Types.GUTI guti_val;
1494 var template (value) EPS_MobileIdentityLV old_guti;
1495 var S1APEM_Config cfg;
1496 timer T := 5.0;
1497
1498 rai := valueof(ts_RoutingAreaIdentity(mp_gn_local_mcc, mp_gn_local_mnc,
1499 int2oct(mp_gn_local_lac, 2), int2oct(mp_gn_local_rac, 1)));
1500 rai_ptmsi2_guti(rai, ptmsi, ptmsi_sig, guti_val);
1501 old_guti := ts_EPS_MobileId_GUTI_(guti_val);
1502
1503 nas_tau := ts_PDU_NAS_EPS_TrackingAreaUpdateRequest(old_guti,
1504 ts_PTMSI_SignatureTV(ptmsi_sig),
1505 ts_GUTI_TypeTV(GUTI_TYPE_MAPPED),
1506 ts_NonceTV('12345678'O),
1507 ts_CipheringKeySequenceNumberTV('000'B));
1508 tx := ts_S1AP_InitialUE(p_eNB_value := 0, p_nasPdu := enc_PDU_NAS_EPS(valueof(nas_tau)),
1509 p_tAI := ts_enb_S1AP_TAI(g_pars.enb_pars[g_pars.mme_idx]),
1510 p_eUTRAN_CGI := ts_enb_S1AP_CGI(g_pars.enb_pars[g_pars.mme_idx]),
1511 p_rrcCause := mo_Signalling);
1512
1513 S1AP.send(tx);
1514
1515 /* NAS counts are reset to zero when a mapped security context is created. */
1516 cfg := {
1517 reset_nas_counts := {}
1518 };
1519 S1AP.send(cfg);
1520
1521 as_gtp_sgsn_context_2g_to_4g(new_sgsn_teid);
1522
1523 /* We now expect the MME to send a Create Session Request to the SGW-C */
1524 T.start;
1525 alt {
1526 [] as_GTP2C_CreateSession_success();
1527 [] T.timeout { Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("No message from MME")); }
1528 }
1529
1530 /* 3GPP TS 23.401 D.3.6 steps 14-21: */
1531 as_DIA_UpdLoc();
1532
1533 /* 3GPP TS 23.401 D.3.6 step 22, 23: */
1534 as_s1ap_handle_IntialCtxSetupReq_TAU_Accept();
1535
1536 /* We now expect the MME to send a Modify Bearer Request to the SGW-C */
1537 T.start;
1538 alt {
1539 [] as_GTP2C_ModifyBearer_success();
1540 [] T.timeout { Misc_Helpers.f_shutdown(__BFILE__, __LINE__, fail, log2str("No message from MME")); }
1541 }
1542
1543 /* Leave some time for MME to handle Modify Bearer Response: */
1544 f_sleep(1.0);
1545}
1546testcase TC_ue_cell_reselect_geran_to_eutran() runs on MTC_CT {
1547 var charstring id := testcasename();
1548
1549 f_init_diameter(id);
1550 f_init_s1ap(id, 7);
1551 f_init_gtpv2_s11(id);
1552 f_s1ap_setup(0);
1553 f_init_gtp(id);
1554
1555 var ConnHdlrPars pars := f_init_pars(ue_idx := 0);
1556 var ConnHdlr vc_conn;
1557 vc_conn := f_start_handler_with_pars(refers(f_TC_ue_cell_reselect_geran_to_eutran), pars);
1558 vc_conn.done;
1559}
1560
Harald Welte95333a12019-07-11 22:51:45 +08001561control {
1562 execute( TC_s1ap_setup_wrong_plmn() );
1563 execute( TC_s1ap_setup_wrong_tac() );
1564 execute( TC_s1ap_setup() );
Harald Welte6ec64392019-08-14 12:37:07 +02001565 execute( TC_s1ap_attach() );
Philipp Maier26a09f32023-09-01 14:18:33 +02001566 execute( TC_s1ap_tau_unknown_guti() );
Philipp Maier74d776a2023-07-12 14:04:14 +02001567 execute( TC_gn_echo_request() );
Philipp Maiera9306202023-07-24 11:41:51 +02001568 execute( TC_RIM_RAN_INF() );
Philipp Maier46059f02023-08-16 14:45:27 +02001569 execute( TC_s1ap_reset() );
Pau Espin Pedrol408e0ae2023-12-15 18:56:31 +01001570 execute( TC_ue_cell_reselect_eutran_to_geran() );
Pau Espin Pedrol35618872024-01-15 15:25:18 +01001571 execute( TC_ue_cell_reselect_geran_to_eutran() );
Harald Welteb8a4ac82019-06-23 11:04:12 +02001572}
1573
Philipp Maier46059f02023-08-16 14:45:27 +02001574
Harald Welteb8a4ac82019-06-23 11:04:12 +02001575}