blob: 31a7401cd754340d6cc3034817de29fa90d037dc [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
3import from General_Types all;
4import from Osmocom_Types all;
5
6import from M3UA_Types all;
7import from M3UA_Emulation all;
8
9import from MTP3asp_Types all;
10import from MTP3asp_PortType all;
11
12import from SCCPasp_Types all;
13import from SCCP_Types all;
14import from SCCP_Emulation all;
15
16import from SCTPasp_Types all;
17import from SCTPasp_PortType all;
18
Harald Weltea49e36e2018-01-21 19:29:33 +010019import from Osmocom_CTRL_Functions all;
20import from Osmocom_CTRL_Types all;
21import from Osmocom_CTRL_Adapter all;
22
Harald Welte3ca1c902018-01-24 18:51:27 +010023import from TELNETasp_PortType all;
24import from Osmocom_VTY_Functions all;
25
Harald Weltea49e36e2018-01-21 19:29:33 +010026import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010027import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010028
Harald Welte4aa970c2018-01-26 10:38:09 +010029import from MGCP_Emulation all;
30import from MGCP_Types all;
31import from MGCP_Templates all;
32import from SDP_Types all;
33
Harald Weltea49e36e2018-01-21 19:29:33 +010034import from GSUP_Emulation all;
35import from GSUP_Types all;
36import from IPA_Emulation all;
37
Harald Weltef6dd64d2017-11-19 12:09:51 +010038import from BSSAP_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010039import from BSSAP_Adapter all;
40import from BSSAP_CodecPort all;
41import from BSSMAP_Templates all;
42import from BSSMAP_Emulation all;
43import from BSC_ConnectionHandler all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010044
Harald Welte4263c522018-12-06 11:56:27 +010045import from SGsAP_Templates all;
46import from SGsAP_Types all;
47import from SGsAP_Emulation all;
48
Harald Weltea49e36e2018-01-21 19:29:33 +010049import from MobileL3_Types all;
50import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070051import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010052import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010053import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010054
Harald Weltef640a012018-04-14 17:49:21 +020055import from SMPP_Types all;
56import from SMPP_Templates all;
57import from SMPP_Emulation all;
58
Stefan Sperlingc307e682018-06-14 15:15:46 +020059import from SCCP_Templates all;
60
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070061import from SS_Types all;
62import from SS_Templates all;
63import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010064import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070065
Philipp Maier75932982018-03-27 14:52:35 +020066const integer NUM_BSC := 2;
67type record of BSSAP_Configuration BSSAP_Configurations;
Harald Weltef6dd64d2017-11-19 12:09:51 +010068
Harald Welte4263c522018-12-06 11:56:27 +010069/* Needed for SGsAP SMS */
70import from MobileL3_SMS_Types all;
71
Harald Weltea4ca4462018-02-09 00:17:14 +010072type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010073 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010074
Philipp Maier75932982018-03-27 14:52:35 +020075 var BSSAP_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010076
Harald Weltea49e36e2018-01-21 19:29:33 +010077 /* no 'adapter_CT' for MNCC or GSUP */
78 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010079 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010080 var GSUP_Emulation_CT vc_GSUP;
81 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020082 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +010083 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +010084
85 /* only to get events from IPA underneath GSUP */
86 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +010087 /* VTY to MSC */
88 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +010089
90 /* A port to directly send BSSAP messages. This port is used for
91 * tests that require low level access to sen arbitrary BSSAP
92 * messages. Run f_init_bssap_direct() to connect and initialize */
93 port BSSAP_CODEC_PT BSSAP_DIRECT;
94
95 /* When BSSAP messages are directly sent, then the connection
96 * handler is not active, which means that also no guard timer is
97 * set up. The following timer will serve as a replacement */
98 timer Tguard_direct := 60.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +010099}
100
101modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100102 /* remote parameters of IUT */
103 charstring mp_msc_ip := "127.0.0.1";
104 integer mp_msc_ctrl_port := 4255;
105 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100106
Harald Weltea49e36e2018-01-21 19:29:33 +0100107 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100108 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100109 charstring mp_hlr_ip := "127.0.0.1";
110 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100111 charstring mp_mgw_ip := "127.0.0.1";
112 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100113
Harald Weltea49e36e2018-01-21 19:29:33 +0100114 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100115
Harald Weltef640a012018-04-14 17:49:21 +0200116 integer mp_msc_smpp_port := 2775;
117 charstring mp_smpp_system_id := "msc_tester";
118 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100119 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
120 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200121
Philipp Maier75932982018-03-27 14:52:35 +0200122 BSSAP_Configurations mp_bssap_cfg := {
123 {
124 sccp_service_type := "mtp3_itu",
125 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
126 own_pc := 185,
127 own_ssn := 254,
128 peer_pc := 187,
129 peer_ssn := 254,
130 sio := '83'O,
131 rctx := 0
132 },
133 {
134 sccp_service_type := "mtp3_itu",
135 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
136 own_pc := 186,
137 own_ssn := 254,
138 peer_pc := 187,
139 peer_ssn := 254,
140 sio := '83'O,
141 rctx := 1
142 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100143 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100144}
145
Philipp Maier328d1662018-03-07 10:40:27 +0100146/* altstep for the global guard timer (only used when BSSAP_DIRECT
147 * is used for communication */
148private altstep as_Tguard_direct() runs on MTC_CT {
149 [] Tguard_direct.timeout {
150 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200151 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100152 }
153}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100154
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100155private altstep as_optional_cc_rel(CallParameters cpars) runs on BSC_ConnHdlr {
156 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) { repeat; };
157}
158
Harald Weltef640a012018-04-14 17:49:21 +0200159function f_init_smpp(charstring id) runs on MTC_CT {
160 id := id & "-SMPP";
161 var EsmePars pars := {
162 mode := MODE_TRANSCEIVER,
163 bind := {
164 system_id := mp_smpp_system_id,
165 password := mp_smpp_password,
166 system_type := "MSC_Tests",
167 interface_version := hex2int('34'H),
168 addr_ton := unknown,
169 addr_npi := unknown,
170 address_range := ""
171 },
172 esme_role := true
173 }
174
175 vc_SMPP := SMPP_Emulation_CT.create(id);
176 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
177 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", -1));
178}
179
180
Harald Weltea49e36e2018-01-21 19:29:33 +0100181function f_init_mncc(charstring id) runs on MTC_CT {
182 id := id & "-MNCC";
183 var MnccOps ops := {
184 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
185 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
186 }
187
188 vc_MNCC := MNCC_Emulation_CT.create(id);
189 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
190 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100191}
192
Harald Welte4aa970c2018-01-26 10:38:09 +0100193function f_init_mgcp(charstring id) runs on MTC_CT {
194 id := id & "-MGCP";
195 var MGCPOps ops := {
196 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
197 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
198 }
199 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100200 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100201 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100202 mgw_ip := mp_mgw_ip,
203 mgw_udp_port := mp_mgw_port
Harald Welte4aa970c2018-01-26 10:38:09 +0100204 }
205
206 vc_MGCP := MGCP_Emulation_CT.create(id);
207 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
208 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
209}
210
Harald Welte4263c522018-12-06 11:56:27 +0100211function f_init_sgsap(charstring id) runs on MTC_CT {
212 id := id & "-SGsAP";
213 var SGsAPOps ops := {
214 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
215 unitdata_cb := refers(SGsAP_Emulation.DummyUnitdataCallback)
216 }
217 var SGsAP_conn_parameters pars := {
218 remote_ip := mp_msc_ip,
219 remote_sctp_port := 29118,
220 local_ip := "",
221 local_sctp_port := -1
222 }
223
224 vc_SGsAP := SGsAP_Emulation_CT.create(id);
225 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
226 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
227}
228
229
Harald Weltea49e36e2018-01-21 19:29:33 +0100230function f_init_gsup(charstring id) runs on MTC_CT {
231 id := id & "-GSUP";
232 var GsupOps ops := {
233 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
234 }
235
236 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
237 vc_GSUP := GSUP_Emulation_CT.create(id);
238
239 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
240 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
241 /* we use this hack to get events like ASP_IPA_EVENT_UP */
242 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
243
244 vc_GSUP.start(GSUP_Emulation.main(ops, id));
245 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
246
247 /* wait for incoming connection to GSUP port before proceeding */
248 timer T := 10.0;
249 T.start;
250 alt {
251 [] GSUP_IPA_EVENT.receive(t_ASP_IPA_EVT_UD(ASP_IPA_EVENT_UP)) { }
252 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100253 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200254 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100255 }
256 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100257}
258
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100259function f_init(integer num_bsc := 1, boolean sgsap := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100260
261 if (g_initialized == true) {
262 return;
263 }
264 g_initialized := true;
265
Philipp Maier75932982018-03-27 14:52:35 +0200266 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200267 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200268 }
269
270 for (var integer i := 0; i < num_bsc; i := i + 1) {
271 if (isbound(mp_bssap_cfg[i])) {
Philipp Maierdefd9482018-05-16 16:44:37 +0200272 f_bssap_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), BSC_BssmapOps);
Harald Welted5833a82018-05-27 16:52:56 +0200273 f_bssap_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200274 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200275 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200276 }
277 }
278
Harald Weltea49e36e2018-01-21 19:29:33 +0100279 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
280 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100281 f_init_mgcp("MSC_Test");
Harald Weltea49e36e2018-01-21 19:29:33 +0100282 f_init_gsup("MSC_Test");
Harald Weltef640a012018-04-14 17:49:21 +0200283 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100284
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100285 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100286 f_init_sgsap("MSC_Test");
287 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100288
289 map(self:MSCVTY, system:MSCVTY);
290 f_vty_set_prompts(MSCVTY);
291 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100292
293 /* set some defaults */
294 f_vty_config(MSCVTY, "network", "authentication optional");
295 f_vty_config(MSCVTY, "msc", "assign-tmsi");
296 f_vty_config(MSCVTY, "network", "encryption a5 0");
Harald Weltef6dd64d2017-11-19 12:09:51 +0100297}
298
Philipp Maier328d1662018-03-07 10:40:27 +0100299/* Initialize for a direct connection to BSSAP. This function is an alternative
300 * to f_init() when the high level functions of the BSC_ConnectionHandler are
301 * not needed. */
302function f_init_bssap_direct() runs on MTC_CT {
Philipp Maier75932982018-03-27 14:52:35 +0200303 f_bssap_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
304 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100305
306 /* Start guard timer and activate it as default */
307 Tguard_direct.start
308 activate(as_Tguard_direct());
309}
310
Harald Weltef6dd64d2017-11-19 12:09:51 +0100311template PDU_BSSAP ts_BSSAP_BSSMAP := {
312 discriminator := '0'B,
313 spare := '0000000'B,
314 dlci := omit,
315 lengthIndicator := 0, /* overwritten by codec */
316 pdu := ?
317}
318
319template PDU_BSSAP tr_BSSAP_BSSMAP := {
320 discriminator := '0'B,
321 spare := '0000000'B,
322 dlci := omit,
323 lengthIndicator := ?,
324 pdu := {
325 bssmap := ?
326 }
327}
328
329
330type integer BssmapCause;
331
332template (value) BSSMAP_IE_Cause ts_BSSMAP_IE_Cause(BssmapCause val) := {
333 elementIdentifier := '04'O,
334 lengthIndicator := 0,
335 causeValue := int2bit(val, 7),
336 extensionCauseValue := '0'B,
337 spare1 := omit
338}
339
340template (value) PDU_BSSAP ts_BSSMAP_Reset(BssmapCause cause) modifies ts_BSSAP_BSSMAP := {
341 pdu := {
342 bssmap := {
343 reset := {
344 messageType := '30'O,
345 cause := ts_BSSMAP_IE_Cause(cause),
346 a_InterfaceSelectorForReset := omit
347 }
348 }
349 }
350}
351
352template (value) PDU_BSSAP ts_BSSMAP_ResetAck modifies ts_BSSAP_BSSMAP := {
353 pdu := {
354 bssmap := {
355 resetAck := {
356 messageType := '31'O,
357 a_InterfaceSelectorForReset := omit
358 }
359 }
360 }
361}
362
363template PDU_BSSAP tr_BSSMAP_ResetAck modifies tr_BSSAP_BSSMAP := {
364 pdu := {
365 bssmap := {
366 resetAck := {
367 messageType := '31'O,
368 a_InterfaceSelectorForReset := *
369 }
370 }
371 }
372}
373
374template BSSMAP_IE_CellIdentifier ts_BSSMAP_IE_CellID := {
375 elementIdentifier := '05'O,
376 lengthIndicator := 0,
377 cellIdentifierDiscriminator := '0000'B,
378 spare1_4 := '0000'B,
379 cellIdentification := ?
380}
381
382type uint16_t BssmapLAC;
383type uint16_t BssmapCI;
384
385/*
386template BSSMAP_IE_CellIdentifier ts_CellId_CGI(mcc, mnc, lac, ci)
387modifies ts_BSSMAP_IE_CellID := {
388 cellIdentification := {
389 cI_LAC_CGI := {
390 mnc_mcc := FIXME,
391 lac := int2oct(lac, 2),
392 ci := int2oct(ci, 2)
393 }
394 }
395}
396*/
397
398template BSSMAP_IE_CellIdentifier ts_CellID_LAC_CI(BssmapLAC lac, BssmapCI ci)
399modifies ts_BSSMAP_IE_CellID := {
400 cellIdentification := {
401 cI_LAC_CI := {
402 lac := int2oct(lac, 2),
403 ci := int2oct(ci, 2)
404 }
405 }
406}
407
408template BSSMAP_IE_CellIdentifier ts_CellId_CI(BssmapCI ci)
409modifies ts_BSSMAP_IE_CellID := {
410 cellIdentification := {
411 cI_CI := int2oct(ci, 2)
412 }
413}
414
415template BSSMAP_IE_CellIdentifier ts_CellId_none
416modifies ts_BSSMAP_IE_CellID := {
417 cellIdentification := {
418 cI_noCell := ''O
419 }
420}
421
422
423template BSSMAP_IE_Layer3Information ts_BSSMAP_IE_L3Info(octetstring l3info) := {
424 elementIdentifier := '17'O,
425 lengthIndicator := 0,
426 layer3info := l3info
427}
428
429template PDU_BSSAP ts_BSSMAP_ComplL3(BSSMAP_IE_CellIdentifier cell_id, octetstring l3_info)
430modifies ts_BSSAP_BSSMAP := {
431 pdu := {
432 bssmap := {
433 completeLayer3Information := {
434 messageType := '57'O,
435 cellIdentifier := cell_id,
436 layer3Information := ts_BSSMAP_IE_L3Info(l3_info),
437 chosenChannel := omit,
438 lSAIdentifier := omit,
439 aPDU := omit,
440 codecList := omit,
441 redirectAttemptFlag := omit,
442 sendSequenceNumber := omit,
443 iMSI := omit
444 }
445 }
446 }
447}
448
449template PDU_BSSAP ts_BSSMAP_HandoReq(BssmapCause cause, BSSMAP_IE_CellIdentifierList cid_list)
450modifies ts_BSSAP_BSSMAP := {
451 pdu := {
452 bssmap := {
453 handoverRequired := {
454 messageType := '11'O,
455 cause := ts_BSSMAP_IE_Cause(cause),
456 responseRequest := omit,
457 cellIdentifierList := cid_list,
458 circuitPoolList := omit,
459 currentChannelType1 := omit,
460 speechVersion := omit,
461 queueingIndicator := omit,
462 oldToNewBSSInfo := omit,
463 sourceToTargetRNCTransparentInfo := omit,
464 sourceToTargetRNCTransparentInfoCDMA := omit,
465 gERANClassmark := omit,
466 talkerPriority := omit,
467 speechCodec := omit,
468 cSG_Identifier := omit
469 }
470 }
471 }
472}
473
Harald Weltea49e36e2018-01-21 19:29:33 +0100474type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100475
Harald Weltea49e36e2018-01-21 19:29:33 +0100476/* FIXME: move into BSC_ConnectionHandler? */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100477function f_init_pars(integer imsi_suffix, boolean sgsap := false) runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100478 var BSC_ConnHdlrNetworkPars net_pars := {
479 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
480 expect_tmsi := true,
481 expect_auth := false,
482 expect_ciph := false
483 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100484 var BSC_ConnHdlrPars pars := {
Philipp Maier75932982018-03-27 14:52:35 +0200485 sccp_addr_own := g_bssap[0].sccp_addr_own,
486 sccp_addr_peer := g_bssap[0].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100487 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100488 imei := f_gen_imei(imsi_suffix),
489 imsi := f_gen_imsi(imsi_suffix),
490 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100491 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100492 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100493 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100494 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100495 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100496 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100497 send_early_cm := true,
498 ipa_ctrl_ip := mp_msc_ip,
499 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100500 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100501 mm_info := mp_mm_info,
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100502 sgsap_enable := sgsap
Harald Weltea49e36e2018-01-21 19:29:33 +0100503 };
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100504 return pars;
505}
506
507function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
508 var BSC_ConnHdlr vc_conn;
509 var charstring id := testcasename();
Harald Weltea49e36e2018-01-21 19:29:33 +0100510
511 vc_conn := BSC_ConnHdlr.create(id);
512 /* BSSMAP part / A interface */
Philipp Maier75932982018-03-27 14:52:35 +0200513 connect(vc_conn:BSSAP, g_bssap[0].vc_BSSMAP:CLIENT);
514 connect(vc_conn:BSSAP_PROC, g_bssap[0].vc_BSSMAP:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100515 /* MNCC part */
516 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
517 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100518 /* MGCP part */
519 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
520 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100521 /* GSUP part */
522 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
523 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
Harald Weltef640a012018-04-14 17:49:21 +0200524 /* SMPP part */
525 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
526 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100527 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100528 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100529 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
530 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
531 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100532
Harald Weltea10db902018-01-27 12:44:49 +0100533 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
534 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100535 vc_conn.start(derefers(fn)(id, pars));
536 return vc_conn;
537}
538
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100539function f_start_handler(void_fn fn, integer imsi_suffix) runs on MTC_CT return BSC_ConnHdlr {
540 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix));
541}
542
Harald Weltea49e36e2018-01-21 19:29:33 +0100543private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100544 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100545 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100546}
Harald Weltea49e36e2018-01-21 19:29:33 +0100547testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
548 var BSC_ConnHdlr vc_conn;
549 f_init();
550
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100551 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100552 vc_conn.done;
553}
554
555private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100556 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100557 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100558 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100559}
Harald Weltea49e36e2018-01-21 19:29:33 +0100560testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
561 var BSC_ConnHdlr vc_conn;
562 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100563 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100564
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100565 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100566 vc_conn.done;
567}
568
569/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
570private function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100571 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100572 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
573
574 f_create_gsup_expect(hex2str(g_pars.imsi));
575 f_bssap_compl_l3(l3_lu);
576 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
577 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
578 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100579 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
580 f_expect_clear();
581 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100582 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
583 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200584 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100585 }
586 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100587}
588testcase TC_lu_imsi_reject() runs on MTC_CT {
589 var BSC_ConnHdlr vc_conn;
590 f_init();
591
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100592 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3);
Harald Weltea49e36e2018-01-21 19:29:33 +0100593 vc_conn.done;
594}
595
596/* Do LU by IMSI, timeout on GSUP */
597private function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100598 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100599 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
600
601 f_create_gsup_expect(hex2str(g_pars.imsi));
602 f_bssap_compl_l3(l3_lu);
603 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
604 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
605 alt {
606 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100607 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
608 f_expect_clear();
609 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100610 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
611 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200612 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100613 }
614 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100615}
616testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
617 var BSC_ConnHdlr vc_conn;
618 f_init();
619
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100620 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4);
Harald Weltea49e36e2018-01-21 19:29:33 +0100621 vc_conn.done;
622}
623
Harald Welte7b1b2812018-01-22 21:23:06 +0100624private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100625 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100626 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100627 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100628}
629testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
630 var BSC_ConnHdlr vc_conn;
631 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100632 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100633
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100634 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100635 vc_conn.done;
636}
637
Harald Weltea49e36e2018-01-21 19:29:33 +0100638
639/* Send CM SERVICE REQ for IMSI that has never performed LU before */
640private function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
641runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100642 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100643
644 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100645 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100646 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100647
648 f_create_gsup_expect(hex2str(g_pars.imsi));
649
650 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
651 f_bssap_compl_l3(l3_info);
652
653 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100654 T.start;
655 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100656 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
657 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200658 [] BSSAP.receive {
659 setverdict(fail, "Received unexpected BSSAP");
660 mtc.stop;
661 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100662 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
663 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200664 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100665 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200666 [] T.timeout {
667 setverdict(fail, "Timeout waiting for CM SERV REQ");
668 mtc.stop;
669 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100670 }
671
Harald Welte1ddc7162018-01-27 14:25:46 +0100672 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100673}
Harald Weltea49e36e2018-01-21 19:29:33 +0100674testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
675 var BSC_ConnHdlr vc_conn;
676 f_init();
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100677 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6);
Harald Weltea49e36e2018-01-21 19:29:33 +0100678 vc_conn.done;
679}
680
Harald Welte2bb825f2018-01-22 11:31:18 +0100681private function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100682 f_init_handler(pars);
Harald Welteb71901a2018-01-26 19:16:05 +0100683 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
684 cpars.bss_rtp_port := 1110;
685 cpars.mgcp_connection_id_bss := '22222'H;
686 cpars.mgcp_connection_id_mss := '33333'H;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100687 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte2bb825f2018-01-22 11:31:18 +0100688
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100689 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100690 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100691}
692testcase TC_lu_and_mo_call() runs on MTC_CT {
693 var BSC_ConnHdlr vc_conn;
694 f_init();
695
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100696 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100697 vc_conn.done;
698}
699
700/* Test LU (with authentication enabled), where HLR times out sending SAI response */
701private function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100702 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100703
704 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
705 var PDU_DTAP_MT dtap_mt;
706
707 /* tell GSUP dispatcher to send this IMSI to us */
708 f_create_gsup_expect(hex2str(g_pars.imsi));
709
710 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
711 f_bssap_compl_l3(l3_lu);
712
713 /* Send Early Classmark, just for the fun of it */
714 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
715
716 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
717 /* The HLR would normally return an auth vector here, but we fail to do so. */
718
719 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100720 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100721}
722testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
723 var BSC_ConnHdlr vc_conn;
724 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100725 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100726
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100727 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8);
Harald Welte071ed732018-01-23 19:53:52 +0100728 vc_conn.done;
729}
730
731/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
732private function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100733 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100734
735 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
736 var PDU_DTAP_MT dtap_mt;
737
738 /* tell GSUP dispatcher to send this IMSI to us */
739 f_create_gsup_expect(hex2str(g_pars.imsi));
740
741 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
742 f_bssap_compl_l3(l3_lu);
743
744 /* Send Early Classmark, just for the fun of it */
745 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
746
747 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
748 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
749
750 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100751 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100752}
753testcase TC_lu_auth_sai_err() runs on MTC_CT {
754 var BSC_ConnHdlr vc_conn;
755 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100756 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100757
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100758 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9);
Harald Welte2bb825f2018-01-22 11:31:18 +0100759 vc_conn.done;
760}
Harald Weltea49e36e2018-01-21 19:29:33 +0100761
Harald Weltebc881782018-01-23 20:09:15 +0100762/* Test LU but BSC will send a clear request in the middle */
763private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100764 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100765
766 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
767 var PDU_DTAP_MT dtap_mt;
768
769 /* tell GSUP dispatcher to send this IMSI to us */
770 f_create_gsup_expect(hex2str(g_pars.imsi));
771
772 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
773 f_bssap_compl_l3(l3_lu);
774
775 /* Send Early Classmark, just for the fun of it */
776 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
777
778 f_sleep(1.0);
779 /* send clear request in the middle of the LU */
780 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200781 alt {
782 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
783 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
784 }
Harald Weltebc881782018-01-23 20:09:15 +0100785 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100786 alt {
787 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200788 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
789 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200790 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200791 repeat;
792 }
Harald Welte89a32492018-01-27 19:07:28 +0100793 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
794 }
Harald Weltebc881782018-01-23 20:09:15 +0100795 setverdict(pass);
796}
797testcase TC_lu_clear_request() runs on MTC_CT {
798 var BSC_ConnHdlr vc_conn;
799 f_init();
800
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100801 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100802 vc_conn.done;
803}
804
Harald Welte66af9e62018-01-24 17:28:21 +0100805/* Test LU but BSC will send a clear request in the middle */
806private function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100807 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100808
809 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
810 var PDU_DTAP_MT dtap_mt;
811
812 /* tell GSUP dispatcher to send this IMSI to us */
813 f_create_gsup_expect(hex2str(g_pars.imsi));
814
815 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
816 f_bssap_compl_l3(l3_lu);
817
818 /* Send Early Classmark, just for the fun of it */
819 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
820
821 f_sleep(1.0);
822 /* send clear request in the middle of the LU */
823 BSSAP.send(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
824 setverdict(pass);
825}
826testcase TC_lu_disconnect() runs on MTC_CT {
827 var BSC_ConnHdlr vc_conn;
828 f_init();
829
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100830 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100831 vc_conn.done;
832}
833
834
Harald Welteba7b6d92018-01-23 21:32:34 +0100835/* Test LU but with illegal mobile identity type = IMEI */
836private function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100837 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100838
Harald Welte256571e2018-01-24 18:47:19 +0100839 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100840 var PDU_DTAP_MT dtap_mt;
841
842 /* tell GSUP dispatcher to send this IMSI to us */
843 f_create_gsup_expect(hex2str(g_pars.imsi));
844
845 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
846 f_bssap_compl_l3(l3_lu);
847
848 /* Send Early Classmark, just for the fun of it */
849 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
850 /* wait for LU reject, ignore any ID REQ */
851 alt {
852 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
853 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
854 }
855 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100856 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100857}
858testcase TC_lu_by_imei() runs on MTC_CT {
859 var BSC_ConnHdlr vc_conn;
860 f_init();
861
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100862 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12);
Harald Welteba7b6d92018-01-23 21:32:34 +0100863 vc_conn.done;
864}
865
866/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
867private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200868 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
869 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100870 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100871
872 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
873 var PDU_DTAP_MT dtap_mt;
874
875 /* tell GSUP dispatcher to send this IMSI to us */
876 f_create_gsup_expect(hex2str(g_pars.imsi));
877
878 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
879 f_bssap_compl_l3(l3_lu);
880
881 /* Send Early Classmark, just for the fun of it */
882 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
883
884 /* Wait for + respond to ID REQ (IMSI) */
885 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req('001'B)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200886 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100887 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
888
889 /* Expect MSC to do UpdateLocation to HLR; respond to it */
890 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
891 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
892 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
893 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
894
895 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100896 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
897 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
898 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100899 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
900 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200901 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +0100902 }
903 }
904
Philipp Maier9b690e42018-12-21 11:50:03 +0100905 /* Wait for MM-Information (if enabled) */
906 f_expect_mm_info();
907
Harald Welteba7b6d92018-01-23 21:32:34 +0100908 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100909 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100910}
911testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
912 var BSC_ConnHdlr vc_conn;
913 f_init();
914
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100915 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100916 vc_conn.done;
917}
918
919
Harald Welte45164da2018-01-24 12:51:27 +0100920/* Test IMSI DETACH (MI=IMSI) */
921private function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100922 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100923
924 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
925
926 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
927 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
928
929 /* Send Early Classmark, just for the fun of it? */
930 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
931
932 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100933 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100934}
935testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
936 var BSC_ConnHdlr vc_conn;
937 f_init();
938
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100939 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14);
Harald Welte45164da2018-01-24 12:51:27 +0100940 vc_conn.done;
941}
942
943/* Test IMSI DETACH (MI=TMSI) */
944private function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100945 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100946
947 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
948
949 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
950 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
951
952 /* Send Early Classmark, just for the fun of it? */
953 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
954
955 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100956 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100957}
958testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
959 var BSC_ConnHdlr vc_conn;
960 f_init();
961
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100962 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15);
Harald Welte45164da2018-01-24 12:51:27 +0100963 vc_conn.done;
964}
965
966/* Test IMSI DETACH (MI=IMEI), which is illegal */
967private function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100968 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100969
Harald Welte256571e2018-01-24 18:47:19 +0100970 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +0100971
972 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
973 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
974
975 /* Send Early Classmark, just for the fun of it? */
976 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
977
978 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100979 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100980}
981testcase TC_imsi_detach_by_imei() runs on MTC_CT {
982 var BSC_ConnHdlr vc_conn;
983 f_init();
984
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100985 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16);
Harald Welte45164da2018-01-24 12:51:27 +0100986 vc_conn.done;
987}
988
989
990/* helper function for an emergency call. caller passes in mobile identity to use */
991private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +0100992 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
993 cpars.emergency := true;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100994 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte45164da2018-01-24 12:51:27 +0100995
Harald Welte0bef21e2018-02-10 09:48:23 +0100996 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +0100997}
998
999/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
1000private function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001001 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001002
Harald Welte256571e2018-01-24 18:47:19 +01001003 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001004 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001005 f_bssap_compl_l3(l3_info);
1006 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001007 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001008}
1009testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1010 var BSC_ConnHdlr vc_conn;
1011 f_init();
1012
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001013 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17);
Harald Welte45164da2018-01-24 12:51:27 +01001014 vc_conn.done;
1015}
1016
Harald Welted5b91402018-01-24 18:48:16 +01001017/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Welte45164da2018-01-24 12:51:27 +01001018private function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001019 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001020 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001021 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001022 /* Then issue emergency call identified by IMSI */
1023 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1024}
1025testcase TC_emerg_call_imsi() runs on MTC_CT {
1026 var BSC_ConnHdlr vc_conn;
1027 f_init();
1028
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001029 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001030 vc_conn.done;
1031}
1032
1033/* CM Service Request for VGCS -> reject */
1034private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001035 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001036
1037 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001038 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001039
1040 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001041 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001042 f_bssap_compl_l3(l3_info);
1043 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001044 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001045}
1046testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1047 var BSC_ConnHdlr vc_conn;
1048 f_init();
1049
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001050 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001051 vc_conn.done;
1052}
1053
1054/* CM Service Request for VBS -> reject */
1055private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001056 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001057
1058 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001059 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001060
1061 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001062 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001063 f_bssap_compl_l3(l3_info);
1064 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001065 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001066}
1067testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1068 var BSC_ConnHdlr vc_conn;
1069 f_init();
1070
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001071 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001072 vc_conn.done;
1073}
1074
1075/* CM Service Request for LCS -> reject */
1076private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001077 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001078
1079 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001080 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001081
1082 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001083 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001084 f_bssap_compl_l3(l3_info);
1085 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001086 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001087}
1088testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1089 var BSC_ConnHdlr vc_conn;
1090 f_init();
1091
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001092 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001093 vc_conn.done;
1094}
1095
Harald Welte0195ab12018-01-24 21:50:20 +01001096/* CM Re-Establishment Request */
1097private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001098 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001099
1100 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001101 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001102
1103 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1104 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
1105 f_bssap_compl_l3(l3_info);
1106 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001107 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001108}
1109testcase TC_cm_reest_req_reject() runs on MTC_CT {
1110 var BSC_ConnHdlr vc_conn;
1111 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001112
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001113 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001114 vc_conn.done;
1115}
1116
Harald Weltec638f4d2018-01-24 22:00:36 +01001117/* Test LU (with authentication enabled), with wrong response from MS */
1118private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001119 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001120
1121 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1122
1123 /* tell GSUP dispatcher to send this IMSI to us */
1124 f_create_gsup_expect(hex2str(g_pars.imsi));
1125
1126 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1127 f_bssap_compl_l3(l3_lu);
1128
1129 /* Send Early Classmark, just for the fun of it */
1130 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1131
1132 var AuthVector vec := f_gen_auth_vec_2g();
1133 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1134 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1135 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1136
1137 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1138 /* Send back wrong auth response */
1139 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1140
1141 /* Expect GSUP AUTH FAIL REP to HLR */
1142 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1143
1144 /* Expect LU REJECT with Cause == Illegal MS */
1145 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001146 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001147}
1148testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1149 var BSC_ConnHdlr vc_conn;
1150 f_init();
1151 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001152
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001153 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23);
Harald Weltec638f4d2018-01-24 22:00:36 +01001154 vc_conn.done;
1155}
1156
Harald Weltede371492018-01-27 23:44:41 +01001157/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001158private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001159 pars.net.expect_auth := true;
1160 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001161 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001162 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001163}
1164testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1165 var BSC_ConnHdlr vc_conn;
1166 f_init();
1167 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001168 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1169
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001170 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001171 vc_conn.done;
1172}
1173
Harald Welte1af6ea82018-01-25 18:33:15 +01001174/* Test Complete L3 without payload */
1175private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001176 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001177
1178 /* Send Complete L3 Info with empty L3 frame */
1179 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1180 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1181
Harald Weltef466eb42018-01-27 14:26:54 +01001182 timer T := 5.0;
1183 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001184 alt {
1185 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
1186 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001187 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
1188 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001189 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001190 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001191 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001192 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001193 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001194 }
1195 setverdict(pass);
1196}
1197testcase TC_cl3_no_payload() runs on MTC_CT {
1198 var BSC_ConnHdlr vc_conn;
1199 f_init();
1200
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001201 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001202 vc_conn.done;
1203}
1204
1205/* Test Complete L3 with random payload */
1206private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001207 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001208
Daniel Willmannaa14a382018-07-26 08:29:45 +02001209 /* length is limited by PDU_BSSAP length field which includes some
1210 * other fields beside l3info payload. So payl can only be 240 bytes
1211 * Since rnd() returns values < 1 multiply with 241
1212 */
1213 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001214 var octetstring payl := f_rnd_octstring(len);
1215
1216 /* Send Complete L3 Info with empty L3 frame */
1217 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1218 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1219
Harald Weltef466eb42018-01-27 14:26:54 +01001220 timer T := 5.0;
1221 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001222 alt {
1223 /* Immediate disconnect */
1224 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001225 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Weltebdb3c452018-03-18 22:43:06 +01001226 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001227 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001228 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001229 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001230 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001231 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001232 }
1233 setverdict(pass);
1234}
1235testcase TC_cl3_rnd_payload() runs on MTC_CT {
1236 var BSC_ConnHdlr vc_conn;
1237 f_init();
1238
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001239 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001240 vc_conn.done;
1241}
1242
Harald Welte116e4332018-01-26 22:17:48 +01001243/* Test Complete L3 with random payload */
1244private function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001245 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001246
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001247 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001248
Harald Welteb9e86fa2018-04-09 18:18:31 +02001249 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001250 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001251}
1252testcase TC_establish_and_nothing() runs on MTC_CT {
1253 var BSC_ConnHdlr vc_conn;
1254 f_init();
1255
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001256 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001257 vc_conn.done;
1258}
1259
Harald Welte12510c52018-01-26 22:26:24 +01001260/* Test MO Call SETUP with no response from MNCC */
1261private function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001262 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001263
Harald Welte12510c52018-01-26 22:26:24 +01001264 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1265
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001266 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001267
Harald Welteb9e86fa2018-04-09 18:18:31 +02001268 f_establish_fully();
Harald Welte12510c52018-01-26 22:26:24 +01001269 f_create_mncc_expect(hex2str(cpars.called_party));
1270 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1271
1272 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1273
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001274 var default ccrel := activate(as_optional_cc_rel(cpars));
1275
Philipp Maier109e6aa2018-10-17 10:53:32 +02001276 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001277
1278 deactivate(ccrel);
1279
1280 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001281}
1282testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1283 var BSC_ConnHdlr vc_conn;
1284 f_init();
1285
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001286 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001287 vc_conn.done;
1288}
1289
Harald Welte3ab88002018-01-26 22:37:25 +01001290/* Test MO Call with no response to RAN-side CRCX */
1291private function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001292 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001293 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1294 var MNCC_PDU mncc;
1295 var MgcpCommand mgcp_cmd;
1296
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001297 f_perform_lu();
Harald Welte3ab88002018-01-26 22:37:25 +01001298
Harald Welteb9e86fa2018-04-09 18:18:31 +02001299 f_establish_fully();
Harald Welte3ab88002018-01-26 22:37:25 +01001300 f_create_mncc_expect(hex2str(cpars.called_party));
1301 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1302
1303 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1304 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1305 cpars.mncc_callref := mncc.u.signal.callref;
1306 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1307 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1308
1309 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Harald Welte1852a842018-01-26 22:53:36 +01001310 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1311 cpars.mgcp_ep := mgcp_cmd.line.ep;
Harald Welte3ab88002018-01-26 22:37:25 +01001312 /* never respond to this */
1313
Philipp Maier8e58f592018-03-14 11:10:56 +01001314 /* When the connection with the MGW fails, the MSC will first request
1315 * a release via call control. We will answer this request normally. */
1316 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1317 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1318
Harald Welte1ddc7162018-01-27 14:25:46 +01001319 f_expect_clear(30.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001320}
1321testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1322 var BSC_ConnHdlr vc_conn;
1323 f_init();
1324
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001325 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001326 vc_conn.done;
1327}
1328
Harald Welte0cc82d92018-01-26 22:52:34 +01001329/* Test MO Call with reject to RAN-side CRCX */
1330private function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001331 f_init_handler(pars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001332 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1333 var MNCC_PDU mncc;
1334 var MgcpCommand mgcp_cmd;
1335
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001336 f_perform_lu();
Harald Welte0cc82d92018-01-26 22:52:34 +01001337
Harald Welteb9e86fa2018-04-09 18:18:31 +02001338 f_establish_fully();
Harald Welte0cc82d92018-01-26 22:52:34 +01001339 f_create_mncc_expect(hex2str(cpars.called_party));
1340 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1341
1342 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1343 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1344 cpars.mncc_callref := mncc.u.signal.callref;
1345 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1346 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1347
1348 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001349
1350 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1351 * set an endpoint name that fits the pattern. If not, just use the
1352 * endpoint name from the request */
1353 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1354 cpars.mgcp_ep := "rtpbridge/1@mgw";
1355 } else {
1356 cpars.mgcp_ep := mgcp_cmd.line.ep;
1357 }
1358
Harald Welte0cc82d92018-01-26 22:52:34 +01001359 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001360
Harald Welte0cc82d92018-01-26 22:52:34 +01001361 /* Respond to CRCX with error */
1362 var MgcpResponse mgcp_rsp := {
1363 line := {
1364 code := "542",
1365 trans_id := mgcp_cmd.line.trans_id,
1366 string := "FORCED_FAIL"
1367 },
Harald Welte0cc82d92018-01-26 22:52:34 +01001368 sdp := omit
1369 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001370 var MgcpParameter mgcp_rsp_param := {
1371 code := "Z",
1372 val := cpars.mgcp_ep
1373 };
1374 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte0cc82d92018-01-26 22:52:34 +01001375 MGCP.send(mgcp_rsp);
1376
1377 timer T := 30.0;
1378 T.start;
1379 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001380 [] T.timeout {
1381 setverdict(fail, "Timeout waiting for channel release");
1382 mtc.stop;
1383 }
Daniel Willmann5868e622018-02-15 17:42:59 +01001384 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
1385 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1386 repeat;
1387 }
Harald Welte0cc82d92018-01-26 22:52:34 +01001388 [] MNCC.receive { repeat; }
1389 [] GSUP.receive { repeat; }
Philipp Maierc6e06f72018-04-11 18:12:23 +02001390 /* Note: As we did not respond properly to the CRCX from the MSC we
1391 * expect the MSC to omit any further MGCP operation (At least in the
1392 * the current implementation, there is no recovery mechanism implemented
1393 * and a DLCX can not be performed as the MSC does not know a specific
1394 * endpoint yet. */
Daniel Willmannafce8662018-07-06 23:11:32 +02001395 [] MGCP.receive {
1396 setverdict(fail, "Unexpected MGCP message");
1397 mtc.stop;
1398 }
Harald Welte5946b332018-03-18 23:32:21 +01001399 [] as_clear_cmd_compl_disc();
Harald Welte0cc82d92018-01-26 22:52:34 +01001400 }
1401}
1402testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1403 var BSC_ConnHdlr vc_conn;
1404 f_init();
1405
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001406 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001407 vc_conn.done;
1408}
1409
Harald Welte3ab88002018-01-26 22:37:25 +01001410
Harald Welte812f7a42018-01-27 00:49:18 +01001411/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1412private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1413 var MNCC_PDU mncc;
1414 var MgcpCommand mgcp_cmd;
1415 var OCT4 tmsi;
1416
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001417 f_perform_lu();
Harald Welte812f7a42018-01-27 00:49:18 +01001418 if (isvalue(g_pars.tmsi)) {
1419 tmsi := g_pars.tmsi;
1420 } else {
1421 tmsi := 'FFFFFFFF'O;
1422 }
1423 f_bssmap_register_imsi(g_pars.imsi, tmsi);
1424
1425 /* Allocate call reference and send SETUP via MNCC to MSC */
1426 cpars.mncc_callref := f_rnd_int(2147483648);
1427 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1428 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1429
1430 /* MSC->BSC: expect PAGING from MSC */
1431 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
1432 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001433 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001434
1435 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1436
1437 /* MSC->MS: SETUP */
1438 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1439}
1440
1441/* Test MT Call */
1442private function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001443 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001444 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1445 var MNCC_PDU mncc;
1446 var MgcpCommand mgcp_cmd;
1447
1448 f_mt_call_start(cpars);
1449
1450 /* MS->MSC: CALL CONFIRMED */
1451 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1452
1453 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1454
1455 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1456 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001457
1458 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1459 * set an endpoint name that fits the pattern. If not, just use the
1460 * endpoint name from the request */
1461 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1462 cpars.mgcp_ep := "rtpbridge/1@mgw";
1463 } else {
1464 cpars.mgcp_ep := mgcp_cmd.line.ep;
1465 }
1466
Harald Welte812f7a42018-01-27 00:49:18 +01001467 /* Respond to CRCX with error */
1468 var MgcpResponse mgcp_rsp := {
1469 line := {
1470 code := "542",
1471 trans_id := mgcp_cmd.line.trans_id,
1472 string := "FORCED_FAIL"
1473 },
Harald Welte812f7a42018-01-27 00:49:18 +01001474 sdp := omit
1475 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001476 var MgcpParameter mgcp_rsp_param := {
1477 code := "Z",
1478 val := cpars.mgcp_ep
1479 };
1480 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001481 MGCP.send(mgcp_rsp);
1482
1483 timer T := 30.0;
1484 T.start;
1485 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001486 [] T.timeout {
1487 setverdict(fail, "Timeout waiting for channel release");
1488 mtc.stop;
1489 }
Harald Welte812f7a42018-01-27 00:49:18 +01001490 [] MNCC.receive { repeat; }
1491 [] GSUP.receive { repeat; }
1492 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1493 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1494 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1495 repeat;
1496 }
1497 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001498 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001499 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001500 }
1501}
1502testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1503 var BSC_ConnHdlr vc_conn;
1504 f_init();
1505
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001506 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001507 vc_conn.done;
1508}
1509
1510
1511/* Test MT Call T310 timer */
1512private function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001513 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001514 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1515 var MNCC_PDU mncc;
1516 var MgcpCommand mgcp_cmd;
1517
1518 f_mt_call_start(cpars);
1519
1520 /* MS->MSC: CALL CONFIRMED */
1521 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1522 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1523
1524 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1525 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1526 cpars.mgcp_ep := mgcp_cmd.line.ep;
1527 /* FIXME: Respond to CRCX */
1528
1529 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1530 timer T := 190.0;
1531 T.start;
1532 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001533 [] T.timeout {
1534 setverdict(fail, "Timeout waiting for T310");
1535 mtc.stop;
1536 }
Harald Welte812f7a42018-01-27 00:49:18 +01001537 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1538 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1539 }
1540 }
1541 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1542 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1543 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1544 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1545
1546 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001547 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1548 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1549 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1550 repeat;
1551 }
Harald Welte5946b332018-03-18 23:32:21 +01001552 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001553 }
1554}
1555testcase TC_mt_t310() runs on MTC_CT {
1556 var BSC_ConnHdlr vc_conn;
1557 f_init();
1558
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001559 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001560 vc_conn.done;
1561}
1562
Harald Welte167458a2018-01-27 15:58:16 +01001563/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
1564private function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1565 f_init_handler(pars);
1566 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1567 cpars.bss_rtp_port := 1110;
1568 cpars.mgcp_connection_id_bss := '22222'H;
1569 cpars.mgcp_connection_id_mss := '33333'H;
Daniel Willmann9b0235b2018-07-24 12:13:34 +02001570 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte167458a2018-01-27 15:58:16 +01001571
1572 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001573 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001574
1575 /* First MO call should succeed */
1576 f_mo_call(cpars);
1577
1578 /* Cancel the subscriber in the VLR */
1579 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1580 alt {
1581 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1582 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1583 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001584 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001585 }
1586 }
1587
1588 /* Follow-up transactions should fail */
1589 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1590 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
1591 f_bssap_compl_l3(l3_info);
1592 alt {
1593 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1594 [] BSSAP.receive {
1595 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001596 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001597 }
1598 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001599
1600 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001601 setverdict(pass);
1602}
1603testcase TC_gsup_cancel() runs on MTC_CT {
1604 var BSC_ConnHdlr vc_conn;
1605 f_init();
1606
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001607 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33);
Harald Welte167458a2018-01-27 15:58:16 +01001608 vc_conn.done;
1609}
1610
Harald Welte9de84792018-01-28 01:06:35 +01001611/* A5/1 only permitted on network side, and MS capable to do it */
1612private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1613 pars.net.expect_auth := true;
1614 pars.net.expect_ciph := true;
1615 pars.net.kc_support := '02'O; /* A5/1 only */
1616 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001617 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001618}
1619testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1620 var BSC_ConnHdlr vc_conn;
1621 f_init();
1622 f_vty_config(MSCVTY, "network", "authentication required");
1623 f_vty_config(MSCVTY, "network", "encryption a5 1");
1624
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001625 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001626 vc_conn.done;
1627}
1628
1629/* A5/3 only permitted on network side, and MS capable to do it */
1630private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1631 pars.net.expect_auth := true;
1632 pars.net.expect_ciph := true;
1633 pars.net.kc_support := '08'O; /* A5/3 only */
1634 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001635 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001636}
1637testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1638 var BSC_ConnHdlr vc_conn;
1639 f_init();
1640 f_vty_config(MSCVTY, "network", "authentication required");
1641 f_vty_config(MSCVTY, "network", "encryption a5 3");
1642
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001643 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001644 vc_conn.done;
1645}
1646
1647/* A5/3 only permitted on network side, and MS with only A5/1 support */
1648private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1649 pars.net.expect_auth := true;
1650 pars.net.expect_ciph := true;
1651 pars.net.kc_support := '08'O; /* A5/3 only */
1652 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1653 f_init_handler(pars, 15.0);
1654
1655 /* cannot use f_perform_lu() as we expect a reject */
1656 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1657 f_create_gsup_expect(hex2str(g_pars.imsi));
1658 f_bssap_compl_l3(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001659 if (pars.send_early_cm) {
1660 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1661 } else {
1662 pars.cm1.esind := '0'B;
1663 }
Harald Welte9de84792018-01-28 01:06:35 +01001664 f_mm_auth();
1665 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001666 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1667 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1668 repeat;
1669 }
Harald Welte5946b332018-03-18 23:32:21 +01001670 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1671 f_expect_clear();
1672 }
Harald Welte9de84792018-01-28 01:06:35 +01001673 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1674 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001675 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001676 }
1677 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001678 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001679 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001680 }
1681 }
1682 setverdict(pass);
1683}
1684testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1685 var BSC_ConnHdlr vc_conn;
1686 f_init();
1687 f_vty_config(MSCVTY, "network", "authentication required");
1688 f_vty_config(MSCVTY, "network", "encryption a5 3");
1689
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001690 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360);
1691 vc_conn.done;
1692}
1693testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1694 var BSC_ConnHdlrPars pars;
1695 var BSC_ConnHdlr vc_conn;
1696 f_init();
1697 f_vty_config(MSCVTY, "network", "authentication required");
1698 f_vty_config(MSCVTY, "network", "encryption a5 3");
1699
1700 pars := f_init_pars(361);
1701 pars.send_early_cm := false;
1702 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001703 vc_conn.done;
1704}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001705testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1706 var BSC_ConnHdlr vc_conn;
1707 f_init();
1708 f_vty_config(MSCVTY, "network", "authentication required");
1709 f_vty_config(MSCVTY, "network", "encryption a5 3");
1710
1711 /* Make sure the MSC category is on DEBUG level to trigger the log
1712 * message that is reported in OS#2947 to trigger the segfault */
1713 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1714
1715 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362);
1716 vc_conn.done;
1717}
Harald Welte9de84792018-01-28 01:06:35 +01001718
1719/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1720private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1721 pars.net.expect_auth := true;
1722 pars.net.expect_ciph := true;
1723 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1724 pars.cm1.a5_1 := '1'B;
1725 pars.cm2.a5_1 := '1'B;
1726 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1727 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1728 f_init_handler(pars, 15.0);
1729
1730 /* cannot use f_perform_lu() as we expect a reject */
1731 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1732 f_create_gsup_expect(hex2str(g_pars.imsi));
1733 f_bssap_compl_l3(l3_lu);
1734 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1735 f_mm_auth();
1736 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001737 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1738 f_expect_clear();
1739 }
Harald Welte9de84792018-01-28 01:06:35 +01001740 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1741 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001742 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001743 }
1744 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001745 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001746 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001747 }
1748 }
1749 setverdict(pass);
1750}
1751testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1752 var BSC_ConnHdlr vc_conn;
1753 f_init();
1754 f_vty_config(MSCVTY, "network", "authentication required");
1755 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1756
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001757 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37);
Harald Welte9de84792018-01-28 01:06:35 +01001758 vc_conn.done;
1759}
1760
1761/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1762private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1763 pars.net.expect_auth := true;
1764 pars.net.expect_ciph := true;
1765 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1766 pars.cm1.a5_1 := '1'B;
1767 pars.cm2.a5_1 := '1'B;
1768 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1769 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1770 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001771 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001772}
1773testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1774 var BSC_ConnHdlr vc_conn;
1775 f_init();
1776 f_vty_config(MSCVTY, "network", "authentication required");
1777 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1778
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001779 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001780 vc_conn.done;
1781}
1782
Harald Welte33ec09b2018-02-10 15:34:46 +01001783/* LU followed by MT call (including paging) */
1784private function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1785 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001786 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte33ec09b2018-02-10 15:34:46 +01001787 cpars.bss_rtp_port := 1110;
1788 cpars.mgcp_connection_id_bss := '10004'H;
1789 cpars.mgcp_connection_id_mss := '10005'H;
1790
Philipp Maier4b2692d2018-03-14 16:37:48 +01001791 /* Note: This is an optional parameter. When the call-agent (MSC) does
1792 * supply a full endpoint name this setting will be overwritten. */
1793 cpars.mgcp_ep := "rtpbridge/1@mgw";
1794
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001795 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001796 f_mt_call(cpars);
1797}
1798testcase TC_lu_and_mt_call() runs on MTC_CT {
1799 var BSC_ConnHdlr vc_conn;
1800 f_init();
1801
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001802 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001803 vc_conn.done;
1804}
1805
Daniel Willmann8b084372018-02-04 13:35:26 +01001806/* Test MO Call SETUP with DTMF */
1807private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1808 f_init_handler(pars);
1809 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1810 cpars.bss_rtp_port := 1110;
1811 cpars.mgcp_connection_id_bss := '22222'H;
1812 cpars.mgcp_connection_id_mss := '33333'H;
1813
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001814 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001815 f_mo_seq_dtmf_dup(cpars);
1816}
1817testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1818 var BSC_ConnHdlr vc_conn;
1819 f_init();
1820
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001821 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001822 vc_conn.done;
1823}
Harald Welte9de84792018-01-28 01:06:35 +01001824
Philipp Maier328d1662018-03-07 10:40:27 +01001825testcase TC_cr_before_reset() runs on MTC_CT {
1826 timer T := 4.0;
1827 var boolean reset_ack_seen := false;
1828 f_init_bssap_direct();
1829
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02001830 f_bssap_start(g_bssap[0]);
1831
Daniel Willmanne8018962018-08-21 14:18:00 +02001832 f_sleep(3.0);
1833
Philipp Maier328d1662018-03-07 10:40:27 +01001834 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001835 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001836
1837 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001838 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001839 T.start
1840 alt {
1841 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1842 reset_ack_seen := true;
1843 repeat;
1844 }
1845
1846 /* Acknowledge MSC sided reset requests */
1847 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001848 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001849 repeat;
1850 }
1851
1852 /* Ignore all other messages (e.g CR from the connection request) */
1853 [] BSSAP_DIRECT.receive { repeat }
1854
1855 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1856 * deadlock situation. The MSC is then unable to respond to any
1857 * further BSSMAP RESET or any other sort of traffic. */
1858 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1859 [reset_ack_seen == false] T.timeout {
1860 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02001861 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01001862 }
1863 }
1864}
Harald Welte9de84792018-01-28 01:06:35 +01001865
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001866/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
1867private function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1868 f_init_handler(pars);
1869 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1870 var MNCC_PDU mncc;
1871 var MgcpCommand mgcp_cmd;
1872
1873 f_perform_lu();
1874
Harald Welteb9e86fa2018-04-09 18:18:31 +02001875 f_establish_fully();
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001876 f_create_mncc_expect(hex2str(cpars.called_party));
1877 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1878
1879 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1880 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1881 cpars.mncc_callref := mncc.u.signal.callref;
1882 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1883 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1884
1885 /* Drop CRCX */
1886 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1887
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001888 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001889
1890 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001891
1892 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001893}
1894testcase TC_mo_release_timeout() runs on MTC_CT {
1895 var BSC_ConnHdlr vc_conn;
1896 f_init();
1897
1898 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1899 vc_conn.done;
1900}
1901
Harald Welte12510c52018-01-26 22:26:24 +01001902
Philipp Maier2a98a732018-03-19 16:06:12 +01001903/* LU followed by MT call (including paging) */
1904private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1905 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001906 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01001907 cpars.bss_rtp_port := 1110;
1908 cpars.mgcp_connection_id_bss := '10004'H;
1909 cpars.mgcp_connection_id_mss := '10005'H;
1910
1911 /* Note: This is an optional parameter. When the call-agent (MSC) does
1912 * supply a full endpoint name this setting will be overwritten. */
1913 cpars.mgcp_ep := "rtpbridge/1@mgw";
1914
1915 /* Intentionally disable the CRCX response */
1916 cpars.mgw_drop_dlcx := true;
1917
1918 /* Perform location update and call */
1919 f_perform_lu();
1920 f_mt_call(cpars);
1921}
1922testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
1923 var BSC_ConnHdlr vc_conn;
1924 f_init();
1925
1926 /* Perform an almost normal looking locationupdate + mt-call, but do
1927 * not respond to the DLCX at the end of the call */
1928 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
1929 vc_conn.done;
1930
1931 /* Wait a guard period until the MGCP layer in the MSC times out,
1932 * if the MSC is vulnerable to the use-after-free situation that is
1933 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
1934 * segfault now */
1935 f_sleep(6.0);
1936
1937 /* Run the init procedures once more. If the MSC has crashed, this
1938 * this will fail */
1939 f_init();
1940}
Harald Welte45164da2018-01-24 12:51:27 +01001941
Philipp Maier75932982018-03-27 14:52:35 +02001942/* Two BSSMAP resets from two different BSCs */
1943testcase TC_reset_two() runs on MTC_CT {
1944 var BSC_ConnHdlr vc_conn;
1945 f_init(2);
1946 f_sleep(2.0);
1947 setverdict(pass);
1948}
1949
Harald Weltef640a012018-04-14 17:49:21 +02001950/***********************************************************************
1951 * SMS Testing
1952 ***********************************************************************/
1953
Harald Weltef45efeb2018-04-09 18:19:24 +02001954/* LU followed by MO SMS */
1955private function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1956 var SmsParameters spars := valueof(t_SmsPars);
1957
1958 f_init_handler(pars);
1959
1960 /* Perform location update and call */
1961 f_perform_lu();
1962
1963 f_establish_fully(EST_TYPE_MO_SMS);
1964
1965 //spars.exp_rp_err := 96; /* invalid mandatory information */
1966 f_mo_sms(spars);
1967
1968 f_expect_clear();
1969}
1970testcase TC_lu_and_mo_sms() runs on MTC_CT {
1971 var BSC_ConnHdlr vc_conn;
1972 f_init();
1973 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
1974 vc_conn.done;
1975}
1976
1977private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01001978runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02001979 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
1980}
1981
1982/* LU followed by MT SMS */
1983private function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1984 var SmsParameters spars := valueof(t_SmsPars);
1985 var OCT4 tmsi;
1986
1987 f_init_handler(pars);
1988
1989 /* Perform location update and call */
1990 f_perform_lu();
1991
1992 /* register an 'expect' for given IMSI (+TMSI) */
1993 if (isvalue(g_pars.tmsi)) {
1994 tmsi := g_pars.tmsi;
1995 } else {
1996 tmsi := 'FFFFFFFF'O;
1997 }
1998 f_bssmap_register_imsi(g_pars.imsi, tmsi);
1999
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002000 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002001
2002 /* MSC->BSC: expect PAGING from MSC */
2003 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2004 /* Establish DTAP / BSSAP / SCCP connection */
2005 f_establish_fully(EST_TYPE_PAG_RESP);
2006
2007 spars.tp.ud := 'C8329BFD064D9B53'O;
2008 f_mt_sms(spars);
2009
2010 f_expect_clear();
2011}
2012testcase TC_lu_and_mt_sms() runs on MTC_CT {
2013 var BSC_ConnHdlrPars pars;
2014 var BSC_ConnHdlr vc_conn;
2015 f_init();
2016 pars := f_init_pars(43);
2017 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002018 vc_conn.done;
2019}
2020
Philipp Maier3983e702018-11-22 19:01:33 +01002021/* Paging for MT SMS but no response */
2022private function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2023 var SmsParameters spars := valueof(t_SmsPars);
2024 var OCT4 tmsi;
2025 var integer page_count := 0;
2026 f_init_handler(pars, 150.0);
2027
2028 /* Perform location update */
2029 f_perform_lu();
2030
2031 /* register an 'expect' for given IMSI (+TMSI) */
2032 if (isvalue(g_pars.tmsi)) {
2033 tmsi := g_pars.tmsi;
2034 } else {
2035 tmsi := 'FFFFFFFF'O;
2036 }
2037 f_bssmap_register_imsi(g_pars.imsi, tmsi);
2038
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002039 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2040
Philipp Maier3983e702018-11-22 19:01:33 +01002041 /* Expect the MSC to page exactly 10 times before giving up */
2042 alt {
2043 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi))
2044 {
2045 page_count := page_count + 1;
2046
2047 if (page_count < 10) {
2048 repeat;
2049 }
2050 }
2051 [] BSSAP.receive {
2052 setverdict(fail, "unexpected BSSAP message received");
2053 self.stop;
2054 }
2055 }
2056
2057 /* Wait some time to make sure the MSC is not delivering any further
2058 * paging messages or anything else that could be unexpected. */
2059 timer T := 20.0;
2060 T.start
2061 alt {
2062 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi))
2063 {
2064 setverdict(fail, "paging seems not to stop!");
2065 mtc.stop;
2066 }
2067 [] BSSAP.receive {
2068 setverdict(fail, "unexpected BSSAP message received");
2069 self.stop;
2070 }
2071 [] T.timeout {
2072 setverdict(pass);
2073 }
2074 }
2075
2076 setverdict(pass);
2077}
2078testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2079 var BSC_ConnHdlrPars pars;
2080 var BSC_ConnHdlr vc_conn;
2081 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002082 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002083 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002084 vc_conn.done;
2085}
2086
Harald Weltef640a012018-04-14 17:49:21 +02002087/* mobile originated SMS from MS/BTS/BSC side to SMPP */
2088private function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2089 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002090
Harald Weltef640a012018-04-14 17:49:21 +02002091 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002092
Harald Weltef640a012018-04-14 17:49:21 +02002093 /* Perform location update so IMSI is known + registered in MSC/VLR */
2094 f_perform_lu();
2095 f_establish_fully(EST_TYPE_MO_SMS);
2096
2097 f_mo_sms(spars);
2098
2099 var SMPP_PDU smpp;
2100 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2101 tr_smpp.body.deliver_sm := {
2102 service_type := "CMT",
2103 source_addr_ton := network_specific,
2104 source_addr_npi := isdn,
2105 source_addr := hex2str(pars.msisdn),
2106 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2107 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2108 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2109 esm_class := '00000001'B,
2110 protocol_id := 0,
2111 priority_flag := 0,
2112 schedule_delivery_time := "",
2113 replace_if_present := 0,
2114 data_coding := '00000001'B,
2115 sm_default_msg_id := 0,
2116 sm_length := ?,
2117 short_message := spars.tp.ud,
2118 opt_pars := {
2119 {
2120 tag := user_message_reference,
2121 len := 2,
2122 opt_value := {
2123 int2_val := oct2int(spars.tp.msg_ref)
2124 }
2125 }
2126 }
2127 };
2128 alt {
2129 [] SMPP.receive(tr_smpp) -> value smpp {
2130 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2131 }
2132 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2133 }
2134
2135 f_expect_clear();
2136}
2137testcase TC_smpp_mo_sms() runs on MTC_CT {
2138 var BSC_ConnHdlr vc_conn;
2139 f_init();
2140 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2141 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2142 vc_conn.done;
2143 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2144}
2145
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002146/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
2147private function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
2148runs on BSC_ConnHdlr {
2149 var SmsParameters spars := valueof(t_SmsPars);
2150 var GSUP_PDU gsup_msg_rx;
2151 var octetstring sm_tpdu;
2152
2153 f_init_handler(pars);
2154
2155 /* We need to inspect GSUP activity */
2156 f_create_gsup_expect(hex2str(g_pars.imsi));
2157
2158 /* Perform location update */
2159 f_perform_lu();
2160
2161 /* Send CM Service Request for SMS */
2162 f_establish_fully(EST_TYPE_MO_SMS);
2163
2164 /* Prepare expected SM-RP-UI (SM TPDU) */
2165 enc_TPDU_RP_DATA_MS_SGSN_fast(
2166 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2167 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2168 spars.tp.udl, spars.tp.ud)),
2169 sm_tpdu);
2170
2171 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2172 imsi := g_pars.imsi,
2173 sm_rp_mr := spars.rp.msg_ref,
2174 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2175 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(?),
2176 /* FIXME: MSISDN coding troubles */
2177 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(?),
2178 /* TODO: can we use decmatch here? */
2179 sm_rp_ui := sm_tpdu
2180 );
2181
2182 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2183 f_mo_sms_submit(spars);
2184 alt {
2185 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
2186 log("RX MO-forwardSM-Req");
2187 log(gsup_msg_rx);
2188 setverdict(pass);
2189 }
2190 [] GSUP.receive {
2191 log("RX unexpected GSUP message");
2192 setverdict(fail);
2193 mtc.stop;
2194 }
2195 }
2196
2197 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2198 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2199 imsi := g_pars.imsi,
2200 sm_rp_mr := spars.rp.msg_ref)));
2201 /* Expect RP-ACK on DTAP */
2202 f_mo_sms_wait_rp_ack(spars);
2203
2204 f_expect_clear();
2205}
2206testcase TC_gsup_mo_sms() runs on MTC_CT {
2207 var BSC_ConnHdlr vc_conn;
2208 f_init();
2209 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2210 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2211 vc_conn.done;
2212 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2213}
2214
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002215/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
2216private function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
2217runs on BSC_ConnHdlr {
2218 var SmsParameters spars := valueof(t_SmsPars);
2219 var GSUP_PDU gsup_msg_rx;
2220
2221 f_init_handler(pars);
2222
2223 /* We need to inspect GSUP activity */
2224 f_create_gsup_expect(hex2str(g_pars.imsi));
2225
2226 /* Perform location update */
2227 f_perform_lu();
2228
2229 /* Send CM Service Request for SMS */
2230 f_establish_fully(EST_TYPE_MO_SMS);
2231
2232 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2233 imsi := g_pars.imsi,
2234 sm_rp_mr := spars.rp.msg_ref,
2235 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2236 );
2237
2238 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2239 f_mo_smma(spars);
2240 alt {
2241 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
2242 log("RX MO-ReadyForSM-Req");
2243 log(gsup_msg_rx);
2244 setverdict(pass);
2245 }
2246 [] GSUP.receive {
2247 log("RX unexpected GSUP message");
2248 setverdict(fail);
2249 mtc.stop;
2250 }
2251 }
2252
2253 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2254 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2255 imsi := g_pars.imsi,
2256 sm_rp_mr := spars.rp.msg_ref)));
2257 /* Expect RP-ACK on DTAP */
2258 f_mo_sms_wait_rp_ack(spars);
2259
2260 f_expect_clear();
2261}
2262testcase TC_gsup_mo_smma() runs on MTC_CT {
2263 var BSC_ConnHdlr vc_conn;
2264 f_init();
2265 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2266 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2267 vc_conn.done;
2268 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2269}
2270
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002271/* Helper for sending MT SMS over GSUP */
2272private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2273runs on BSC_ConnHdlr {
2274 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2275 imsi := g_pars.imsi,
2276 /* NOTE: MSC should assign RP-MR itself */
2277 sm_rp_mr := 'FF'O,
2278 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2279 /* TODO: fix encoding of ts_GSUP_SM_RP_DA_IMSI */
2280 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(g_pars.msisdn)),
2281 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(g_pars.msisdn)),
2282 /* Encoded SMS TPDU (taken from Wireshark)
2283 * FIXME: we should encode spars somehow */
2284 sm_rp_ui := '00068021436500008111328130858200'O,
2285 sm_rp_mms := mms
2286 ));
2287}
2288
2289/* Test successful MT-SMS (RP-ACK) over GSUP */
2290private function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
2291runs on BSC_ConnHdlr {
2292 var SmsParameters spars := valueof(t_SmsPars);
2293
2294 f_init_handler(pars);
2295
2296 /* We need to inspect GSUP activity */
2297 f_create_gsup_expect(hex2str(g_pars.imsi));
2298
2299 /* Perform location update */
2300 f_perform_lu();
2301
2302 /* Register an 'expect' for given IMSI (+TMSI) */
2303 if (isvalue(g_pars.tmsi)) {
2304 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2305 } else {
2306 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2307 }
2308
2309 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2310 imsi := g_pars.imsi,
2311 /* NOTE: MSC should assign RP-MR itself */
2312 sm_rp_mr := ?
2313 );
2314
2315 /* Submit a MT SMS on GSUP */
2316 f_gsup_forwardSM_req(spars);
2317
2318 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
2319 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2320 f_establish_fully(EST_TYPE_PAG_RESP);
2321
2322 /* Wait for MT SMS on DTAP */
2323 f_mt_sms_expect(spars);
2324
2325 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2326 f_mt_sms_send_rp_ack(spars);
2327 alt {
2328 [] GSUP.receive(mt_forwardSM_res) {
2329 log("RX MT-forwardSM-Res (RP-ACK)");
2330 setverdict(pass);
2331 }
2332 [] GSUP.receive {
2333 log("RX unexpected GSUP message");
2334 setverdict(fail);
2335 mtc.stop;
2336 }
2337 }
2338
2339 f_expect_clear();
2340}
2341testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2342 var BSC_ConnHdlrPars pars;
2343 var BSC_ConnHdlr vc_conn;
2344 f_init();
2345 pars := f_init_pars(90);
2346 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2347 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2348 vc_conn.done;
2349 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2350}
2351
2352/* Test rejected MT-SMS (RP-ERROR) over GSUP */
2353private function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
2354runs on BSC_ConnHdlr {
2355 var SmsParameters spars := valueof(t_SmsPars);
2356 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2357
2358 f_init_handler(pars);
2359
2360 /* We need to inspect GSUP activity */
2361 f_create_gsup_expect(hex2str(g_pars.imsi));
2362
2363 /* Perform location update */
2364 f_perform_lu();
2365
2366 /* Register an 'expect' for given IMSI (+TMSI) */
2367 if (isvalue(g_pars.tmsi)) {
2368 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2369 } else {
2370 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2371 }
2372
2373 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2374 imsi := g_pars.imsi,
2375 /* NOTE: MSC should assign RP-MR itself */
2376 sm_rp_mr := ?,
2377 sm_rp_cause := sm_rp_cause
2378 );
2379
2380 /* Submit a MT SMS on GSUP */
2381 f_gsup_forwardSM_req(spars);
2382
2383 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
2384 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2385 f_establish_fully(EST_TYPE_PAG_RESP);
2386
2387 /* Wait for MT SMS on DTAP */
2388 f_mt_sms_expect(spars);
2389
2390 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2391 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2392 alt {
2393 [] GSUP.receive(mt_forwardSM_err) {
2394 log("RX MT-forwardSM-Err (RP-ERROR)");
2395 setverdict(pass);
2396 mtc.stop;
2397 }
2398 [] GSUP.receive {
2399 log("RX unexpected GSUP message");
2400 setverdict(fail);
2401 mtc.stop;
2402 }
2403 }
2404
2405 f_expect_clear();
2406}
2407testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2408 var BSC_ConnHdlrPars pars;
2409 var BSC_ConnHdlr vc_conn;
2410 f_init();
2411 pars := f_init_pars(91);
2412 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2413 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2414 vc_conn.done;
2415 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2416}
2417
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002418/* Test SM-RP-MR assignment for MT-SMS over GSUP */
2419private function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
2420runs on BSC_ConnHdlr {
2421 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2422 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2423
2424 f_init_handler(pars);
2425
2426 /* We need to inspect GSUP activity */
2427 f_create_gsup_expect(hex2str(g_pars.imsi));
2428
2429 /* Perform location update */
2430 f_perform_lu();
2431
2432 /* Register an 'expect' for given IMSI (+TMSI) */
2433 if (isvalue(g_pars.tmsi)) {
2434 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2435 } else {
2436 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2437 }
2438
2439 /* Submit the 1st MT SMS on GSUP */
2440 log("TX MT-forwardSM-Req for the 1st SMS");
2441 f_gsup_forwardSM_req(spars1);
2442
2443 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
2444 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2445 f_establish_fully(EST_TYPE_PAG_RESP);
2446
2447 /* Wait for 1st MT SMS on DTAP */
2448 f_mt_sms_expect(spars1);
2449 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2450 ", SM-RP-MR is ", spars1.rp.msg_ref);
2451
2452 /* Submit the 2nd MT SMS on GSUP */
2453 log("TX MT-forwardSM-Req for the 2nd SMS");
2454 f_gsup_forwardSM_req(spars2);
2455
2456 /* Wait for 2nd MT SMS on DTAP */
2457 f_mt_sms_expect(spars2);
2458 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2459 ", SM-RP-MR is ", spars2.rp.msg_ref);
2460
2461 /* Both transaction IDs shall be different */
2462 if (spars1.tid == spars2.tid) {
2463 log("Both DTAP transaction IDs shall be different");
2464 setverdict(fail);
2465 }
2466
2467 /* Both SM-RP-MR values shall be different */
2468 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2469 log("Both SM-RP-MR values shall be different");
2470 setverdict(fail);
2471 }
2472
2473 /* Both SM-RP-MR values shall be assigned */
2474 if (spars1.rp.msg_ref == 'FF'O) {
2475 log("Unassigned SM-RP-MR value for the 1st SMS");
2476 setverdict(fail);
2477 }
2478 if (spars2.rp.msg_ref == 'FF'O) {
2479 log("Unassigned SM-RP-MR value for the 2nd SMS");
2480 setverdict(fail);
2481 }
2482
2483 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2484 f_mt_sms_send_rp_ack(spars1);
2485 alt {
2486 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2487 imsi := g_pars.imsi,
2488 sm_rp_mr := spars1.rp.msg_ref
2489 )) {
2490 log("RX MT-forwardSM-Res (RP-ACK)");
2491 setverdict(pass);
2492 }
2493 [] GSUP.receive {
2494 log("RX unexpected GSUP message");
2495 setverdict(fail);
2496 mtc.stop;
2497 }
2498 }
2499
2500 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2501 f_mt_sms_send_rp_ack(spars2);
2502 alt {
2503 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2504 imsi := g_pars.imsi,
2505 sm_rp_mr := spars2.rp.msg_ref
2506 )) {
2507 log("RX MT-forwardSM-Res (RP-ACK)");
2508 setverdict(pass);
2509 }
2510 [] GSUP.receive {
2511 log("RX unexpected GSUP message");
2512 setverdict(fail);
2513 mtc.stop;
2514 }
2515 }
2516
2517 f_expect_clear();
2518}
2519testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2520 var BSC_ConnHdlrPars pars;
2521 var BSC_ConnHdlr vc_conn;
2522 f_init();
2523 pars := f_init_pars(92);
2524 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2525 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2526 vc_conn.done;
2527 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2528}
2529
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002530/* Test SM-RP-MR assignment for MT-SMS over GSUP */
2531private function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
2532runs on BSC_ConnHdlr {
2533 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2534 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2535
2536 f_init_handler(pars);
2537
2538 /* We need to inspect GSUP activity */
2539 f_create_gsup_expect(hex2str(g_pars.imsi));
2540
2541 /* Perform location update */
2542 f_perform_lu();
2543
2544 /* Register an 'expect' for given IMSI (+TMSI) */
2545 if (isvalue(g_pars.tmsi)) {
2546 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2547 } else {
2548 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2549 }
2550
2551 /* Send CM Service Request for MO SMMA */
2552 f_establish_fully(EST_TYPE_MO_SMS);
2553
2554 /* Submit MO SMMA on DTAP */
2555 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2556 spars_mo.rp.msg_ref := '00'O;
2557 f_mo_smma(spars_mo);
2558
2559 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2560 alt {
2561 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2562 imsi := g_pars.imsi,
2563 sm_rp_mr := spars_mo.rp.msg_ref,
2564 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2565 )) {
2566 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2567 setverdict(pass);
2568 }
2569 [] GSUP.receive {
2570 log("RX unexpected GSUP message");
2571 setverdict(fail);
2572 mtc.stop;
2573 }
2574 }
2575
2576 /* Submit MT SMS on GSUP */
2577 log("TX MT-forwardSM-Req for the MT SMS");
2578 f_gsup_forwardSM_req(spars_mt);
2579
2580 /* Wait for MT SMS on DTAP */
2581 f_mt_sms_expect(spars_mt);
2582 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2583 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2584
2585 /* Both SM-RP-MR values shall be different */
2586 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2587 log("Both SM-RP-MR values shall be different");
2588 setverdict(fail);
2589 }
2590
2591 /* SM-RP-MR value for MT SMS shall be assigned */
2592 if (spars_mt.rp.msg_ref == 'FF'O) {
2593 log("Unassigned SM-RP-MR value for the MT SMS");
2594 setverdict(fail);
2595 }
2596
2597 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2598 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2599 imsi := g_pars.imsi,
2600 sm_rp_mr := spars_mo.rp.msg_ref)));
2601 /* Expect RP-ACK for MO SMMA on DTAP */
2602 f_mo_sms_wait_rp_ack(spars_mo);
2603
2604 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2605 f_mt_sms_send_rp_ack(spars_mt);
2606 alt {
2607 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2608 imsi := g_pars.imsi,
2609 sm_rp_mr := spars_mt.rp.msg_ref
2610 )) {
2611 log("RX MT-forwardSM-Res (RP-ACK)");
2612 setverdict(pass);
2613 }
2614 [] GSUP.receive {
2615 log("RX unexpected GSUP message");
2616 setverdict(fail);
2617 mtc.stop;
2618 }
2619 }
2620
2621 f_expect_clear();
2622}
2623testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
2624 var BSC_ConnHdlrPars pars;
2625 var BSC_ConnHdlr vc_conn;
2626 f_init();
2627 pars := f_init_pars(93);
2628 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2629 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
2630 vc_conn.done;
2631 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2632}
2633
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002634/* Test multi-part MT-SMS over GSUP */
2635private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
2636runs on BSC_ConnHdlr {
2637 var SmsParameters spars := valueof(t_SmsPars);
2638
2639 f_init_handler(pars);
2640
2641 /* We need to inspect GSUP activity */
2642 f_create_gsup_expect(hex2str(g_pars.imsi));
2643
2644 /* Perform location update */
2645 f_perform_lu();
2646
2647 /* Register an 'expect' for given IMSI (+TMSI) */
2648 if (isvalue(g_pars.tmsi)) {
2649 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2650 } else {
2651 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2652 }
2653
2654 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2655 imsi := g_pars.imsi,
2656 /* NOTE: MSC should assign RP-MR itself */
2657 sm_rp_mr := ?
2658 );
2659
2660 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
2661 for (var integer i := 3; i >= 0; i := i-1) {
2662 /* Submit a MT SMS on GSUP (MMS is decremented) */
2663 f_gsup_forwardSM_req(spars, int2oct(i, 1));
2664
2665 /* Expect Paging Request and Establish connection */
2666 if (i == 3) { /* ... only once! */
2667 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2668 f_establish_fully(EST_TYPE_PAG_RESP);
2669 }
2670
2671 /* Wait for MT SMS on DTAP */
2672 f_mt_sms_expect(spars);
2673
2674 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2675 f_mt_sms_send_rp_ack(spars);
2676 alt {
2677 [] GSUP.receive(mt_forwardSM_res) {
2678 log("RX MT-forwardSM-Res (RP-ACK)");
2679 setverdict(pass);
2680 }
2681 [] GSUP.receive {
2682 log("RX unexpected GSUP message");
2683 setverdict(fail);
2684 mtc.stop;
2685 }
2686 }
2687
2688 /* Keep some 'distance' between transmissions */
2689 f_sleep(1.5);
2690 }
2691
2692 f_expect_clear();
2693}
2694testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
2695 var BSC_ConnHdlrPars pars;
2696 var BSC_ConnHdlr vc_conn;
2697 f_init();
2698 pars := f_init_pars(91);
2699 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2700 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
2701 vc_conn.done;
2702 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2703}
2704
Harald Weltef640a012018-04-14 17:49:21 +02002705/* convert GSM L3 TON to SMPP_TON enum */
2706function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
2707 select (ton) {
2708 case ('000'B) { return unknown; }
2709 case ('001'B) { return international; }
2710 case ('010'B) { return national; }
2711 case ('011'B) { return network_specific; }
2712 case ('100'B) { return subscriber_number; }
2713 case ('101'B) { return alphanumeric; }
2714 case ('110'B) { return abbreviated; }
2715 }
2716 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02002717 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002718}
2719/* convert GSM L3 NPI to SMPP_NPI enum */
2720function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2721 select (npi) {
2722 case ('0000'B) { return unknown; }
2723 case ('0001'B) { return isdn; }
2724 case ('0011'B) { return data; }
2725 case ('0100'B) { return telex; }
2726 case ('0110'B) { return land_mobile; }
2727 case ('1000'B) { return national; }
2728 case ('1001'B) { return private_; }
2729 case ('1010'B) { return ermes; }
2730 }
2731 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02002732 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002733}
2734
2735/* build a SMPP_SM from SmsParameters */
2736function f_mt_sm_from_spars(SmsParameters spars)
2737runs on BSC_ConnHdlr return SMPP_SM {
2738 var SMPP_SM sm := {
2739 service_type := "CMT",
2740 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2741 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2742 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2743 dest_addr_ton := international,
2744 dest_addr_npi := isdn,
2745 destination_addr := hex2str(g_pars.msisdn),
2746 esm_class := '00000001'B,
2747 protocol_id := 0,
2748 priority_flag := 0,
2749 schedule_delivery_time := "",
2750 validity_period := "",
2751 registered_delivery := '00000000'B,
2752 replace_if_present := 0,
2753 data_coding := '00000001'B,
2754 sm_default_msg_id := 0,
2755 sm_length := spars.tp.udl,
2756 short_message := spars.tp.ud,
2757 opt_pars := {}
2758 };
2759 return sm;
2760}
2761
2762/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2763private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2764 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2765 if (trans_mode) {
2766 sm.esm_class := '00000010'B;
2767 }
2768
2769 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2770 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2771 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2772 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2773 * before we expect the SMS delivery on the BSC/radio side */
2774 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2775 }
2776
2777 /* MSC->BSC: expect PAGING from MSC */
2778 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2779 /* Establish DTAP / BSSAP / SCCP connection */
2780 f_establish_fully(EST_TYPE_PAG_RESP);
2781 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2782
2783 f_mt_sms(spars);
2784
2785 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2786 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2787 }
2788 f_expect_clear();
2789}
2790
2791/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2792private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2793 f_init_handler(pars);
2794
2795 /* Perform location update so IMSI is known + registered in MSC/VLR */
2796 f_perform_lu();
2797 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2798
2799 /* register an 'expect' for given IMSI (+TMSI) */
2800 var OCT4 tmsi;
2801 if (isvalue(g_pars.tmsi)) {
2802 tmsi := g_pars.tmsi;
2803 } else {
2804 tmsi := 'FFFFFFFF'O;
2805 }
2806 f_bssmap_register_imsi(g_pars.imsi, tmsi);
2807
2808 var SmsParameters spars := valueof(t_SmsPars);
2809 /* TODO: test with more intelligent user data; test different coding schemes */
2810 spars.tp.ud := '00'O;
2811 spars.tp.udl := 1;
2812
2813 /* first test the non-transaction store+forward mode */
2814 f_smpp_mt_sms(spars, false);
2815
2816 /* then test the transaction mode */
2817 f_smpp_mt_sms(spars, true);
2818}
2819testcase TC_smpp_mt_sms() runs on MTC_CT {
2820 var BSC_ConnHdlr vc_conn;
2821 f_init();
2822 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
2823 vc_conn.done;
2824}
2825
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002826/***********************************************************************
2827 * USSD Testing
2828 ***********************************************************************/
2829
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002830private altstep as_unexp_gsup_or_bssap_msg()
2831runs on BSC_ConnHdlr {
2832 [] GSUP.receive {
2833 setverdict(fail, "Unknown/unexpected GSUP received");
2834 self.stop;
2835 }
2836 [] BSSAP.receive {
2837 setverdict(fail, "Unknown/unexpected BSSAP message received");
2838 self.stop;
2839 }
2840}
2841
2842private function f_expect_gsup_msg(template GSUP_PDU msg)
2843runs on BSC_ConnHdlr return GSUP_PDU {
2844 var GSUP_PDU gsup_msg_complete;
2845
2846 alt {
2847 [] GSUP.receive(msg) -> value gsup_msg_complete {
2848 setverdict(pass);
2849 }
2850 /* We don't expect anything else */
2851 [] as_unexp_gsup_or_bssap_msg();
2852 }
2853
2854 return gsup_msg_complete;
2855}
2856
2857private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg)
2858runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
2859 var PDU_DTAP_MT bssap_msg_complete;
2860
2861 alt {
2862 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
2863 setverdict(pass);
2864 }
2865 /* We don't expect anything else */
2866 [] as_unexp_gsup_or_bssap_msg();
2867 }
2868
2869 return bssap_msg_complete.dtap;
2870}
2871
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002872/* LU followed by MO USSD request */
2873private function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002874runs on BSC_ConnHdlr {
2875 f_init_handler(pars);
2876
2877 /* Perform location update */
2878 f_perform_lu();
2879
2880 /* Send CM Service Request for SS/USSD */
2881 f_establish_fully(EST_TYPE_SS_ACT);
2882
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002883 /* We need to inspect GSUP activity */
2884 f_create_gsup_expect(hex2str(g_pars.imsi));
2885
2886 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2887 invoke_id := 5, /* Phone may not start from 0 or 1 */
2888 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2889 ussd_string := "*#100#"
2890 );
2891
2892 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
2893 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
2894 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2895 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
2896 )
2897
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002898 /* Compose a new SS/REGISTER message with request */
2899 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
2900 tid := 1, /* We just need a single transaction */
2901 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002902 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002903 );
2904
2905 /* Compose SS/RELEASE_COMPLETE template with expected response */
2906 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
2907 tid := 1, /* Response should arrive within the same transaction */
2908 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002909 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002910 );
2911
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002912 /* Compose expected MSC -> HLR message */
2913 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
2914 imsi := g_pars.imsi,
2915 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2916 ss := valueof(facility_req)
2917 );
2918
2919 /* To be used for sending response with correct session ID */
2920 var GSUP_PDU gsup_req_complete;
2921
2922 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002923 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002924 /* Expect GSUP message containing the SS payload */
2925 gsup_req_complete := f_expect_gsup_msg(gsup_req);
2926
2927 /* Compose the response from HLR using received session ID */
2928 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
2929 imsi := g_pars.imsi,
2930 sid := gsup_req_complete.ies[1].val.session_id,
2931 state := OSMO_GSUP_SESSION_STATE_END,
2932 ss := valueof(facility_rsp)
2933 );
2934
2935 /* Finally, HLR terminates the session */
2936 GSUP.send(gsup_rsp);
2937 /* Expect RELEASE_COMPLETE message with the response */
2938 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002939
2940 f_expect_clear();
2941}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002942testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002943 var BSC_ConnHdlr vc_conn;
2944 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002945 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002946 vc_conn.done;
2947}
2948
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002949/* LU followed by MT USSD notification */
2950private function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
2951runs on BSC_ConnHdlr {
2952 f_init_handler(pars);
2953
2954 /* Perform location update */
2955 f_perform_lu();
2956
2957 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2958
2959 /* We need to inspect GSUP activity */
2960 f_create_gsup_expect(hex2str(g_pars.imsi));
2961
2962 /* Facility IE with network-originated USSD notification */
2963 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2964 op_code := SS_OP_CODE_USS_NOTIFY,
2965 ussd_string := "Mahlzeit!"
2966 );
2967
2968 /* Facility IE with acknowledgment to the USSD notification */
2969 var template OCTN facility_rsp := enc_SS_FacilityInformation(
2970 /* In case of USSD notification, Return Result is empty */
2971 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
2972 );
2973
2974 /* Compose a new MT SS/REGISTER message with USSD notification */
2975 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
2976 tid := 0, /* FIXME: most likely, it should be 0 */
2977 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
2978 facility := valueof(facility_req)
2979 );
2980
2981 /* Compose HLR -> MSC GSUP message */
2982 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
2983 imsi := g_pars.imsi,
2984 sid := '20000101'O,
2985 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2986 ss := valueof(facility_req)
2987 );
2988
2989 /* Send it to MSC and expect Paging Request */
2990 GSUP.send(gsup_req);
2991 alt {
2992 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2993 setverdict(pass);
2994 }
2995 /* We don't expect anything else */
2996 [] as_unexp_gsup_or_bssap_msg();
2997 }
2998
2999 /* Send Paging Response and expect USSD notification */
3000 f_establish_fully(EST_TYPE_PAG_RESP);
3001 /* Expect MT REGISTER message with USSD notification */
3002 f_expect_mt_dtap_msg(ussd_ntf);
3003
3004 /* Compose a new MO SS/FACILITY message with empty response */
3005 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3006 tid := 0, /* FIXME: it shall match the request tid */
3007 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3008 facility := valueof(facility_rsp)
3009 );
3010
3011 /* Compose expected MSC -> HLR GSUP message */
3012 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3013 imsi := g_pars.imsi,
3014 sid := '20000101'O,
3015 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3016 ss := valueof(facility_rsp)
3017 );
3018
3019 /* MS sends response to the notification */
3020 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3021 /* Expect GSUP message containing the SS payload */
3022 f_expect_gsup_msg(gsup_rsp);
3023
3024 /* Compose expected MT SS/RELEASE COMPLETE message */
3025 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3026 tid := 0, /* FIXME: it shall match the request tid */
3027 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3028 facility := omit
3029 );
3030
3031 /* Compose MSC -> HLR GSUP message */
3032 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3033 imsi := g_pars.imsi,
3034 sid := '20000101'O,
3035 state := OSMO_GSUP_SESSION_STATE_END
3036 );
3037
3038 /* Finally, HLR terminates the session */
3039 GSUP.send(gsup_term)
3040 /* Expect MT RELEASE COMPLETE without Facility IE */
3041 f_expect_mt_dtap_msg(ussd_term);
3042
3043 f_expect_clear();
3044}
3045testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3046 var BSC_ConnHdlr vc_conn;
3047 f_init();
3048 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3049 vc_conn.done;
3050}
3051
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003052/* LU followed by MT call and MO USSD request during this call */
3053private function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003054runs on BSC_ConnHdlr {
3055 f_init_handler(pars);
3056
3057 /* Call parameters taken from f_tc_lu_and_mt_call */
3058 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3059 cpars.mgcp_connection_id_bss := '10004'H;
3060 cpars.mgcp_connection_id_mss := '10005'H;
3061 cpars.mgcp_ep := "rtpbridge/1@mgw";
3062 cpars.bss_rtp_port := 1110;
3063
3064 /* Perform location update */
3065 f_perform_lu();
3066
3067 /* Establish a MT call */
3068 f_mt_call_establish(cpars);
3069
3070 /* Hold the call for some time */
3071 f_sleep(1.0);
3072
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003073 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3074 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3075 ussd_string := "*#100#"
3076 );
3077
3078 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3079 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3080 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3081 )
3082
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003083 /* Compose a new SS/REGISTER message with request */
3084 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3085 tid := 1, /* We just need a single transaction */
3086 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003087 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003088 );
3089
3090 /* Compose SS/RELEASE_COMPLETE template with expected response */
3091 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3092 tid := 1, /* Response should arrive within the same transaction */
3093 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003094 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003095 );
3096
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003097 /* Compose expected MSC -> HLR message */
3098 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3099 imsi := g_pars.imsi,
3100 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3101 ss := valueof(facility_req)
3102 );
3103
3104 /* To be used for sending response with correct session ID */
3105 var GSUP_PDU gsup_req_complete;
3106
3107 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003108 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003109 /* Expect GSUP message containing the SS payload */
3110 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3111
3112 /* Compose the response from HLR using received session ID */
3113 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3114 imsi := g_pars.imsi,
3115 sid := gsup_req_complete.ies[1].val.session_id,
3116 state := OSMO_GSUP_SESSION_STATE_END,
3117 ss := valueof(facility_rsp)
3118 );
3119
3120 /* Finally, HLR terminates the session */
3121 GSUP.send(gsup_rsp);
3122 /* Expect RELEASE_COMPLETE message with the response */
3123 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003124
3125 /* Hold the call for some time */
3126 f_sleep(1.0);
3127
3128 /* Release the call (does Clear Complete itself) */
3129 f_call_hangup(cpars, true);
3130}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003131testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003132 var BSC_ConnHdlr vc_conn;
3133 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003134 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003135 vc_conn.done;
3136}
3137
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003138/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
3139private function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3140 f_init_handler(pars);
3141 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
3142 var MNCC_PDU mncc;
3143 var MgcpCommand mgcp_cmd;
3144
3145 f_perform_lu();
3146
3147 f_establish_fully();
3148 f_create_mncc_expect(hex2str(cpars.called_party));
3149 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
3150
3151 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
3152 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
3153 cpars.mncc_callref := mncc.u.signal.callref;
3154 log("mncc_callref=", cpars.mncc_callref);
3155 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
3156 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
3157
3158 MNCC.send(ts_MNCC_ALERT_req(cpars.mncc_callref));
3159 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_ALERTING(cpars.transaction_id)));
3160 MGCP.receive(tr_CRCX);
3161
3162 f_sleep(1.0);
3163 BSSAP.send(ts_BSSMAP_ClearRequest(0));
3164
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003165 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003166
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003167 interleave {
3168 [] MNCC.receive(tr_MNCC_REL_ind(?, ?)) { };
3169 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
3170 BSSAP.send(ts_BSSMAP_ClearComplete);
3171 };
3172 }
3173
3174 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003175
3176 f_sleep(1.0);
3177}
3178testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3179 var BSC_ConnHdlr vc_conn;
3180 f_init();
3181
3182 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3183 vc_conn.done;
3184}
3185
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003186/* LU followed by MT call and MT USSD request during this call */
3187private function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
3188runs on BSC_ConnHdlr {
3189 f_init_handler(pars);
3190
3191 /* Call parameters taken from f_tc_lu_and_mt_call */
3192 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3193 cpars.mgcp_connection_id_bss := '10004'H;
3194 cpars.mgcp_connection_id_mss := '10005'H;
3195 cpars.mgcp_ep := "rtpbridge/1@mgw";
3196 cpars.bss_rtp_port := 1110;
3197
3198 /* Perform location update */
3199 f_perform_lu();
3200
3201 /* Establish a MT call */
3202 f_mt_call_establish(cpars);
3203
3204 /* Hold the call for some time */
3205 f_sleep(1.0);
3206
3207 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3208 op_code := SS_OP_CODE_USS_REQUEST,
3209 ussd_string := "Please type anything..."
3210 );
3211
3212 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3213 op_code := SS_OP_CODE_USS_REQUEST,
3214 ussd_string := "Nope."
3215 )
3216
3217 /* Compose MT SS/REGISTER message with network-originated request */
3218 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3219 tid := 0, /* FIXME: most likely, it should be 0 */
3220 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3221 facility := valueof(facility_req)
3222 );
3223
3224 /* Compose HLR -> MSC GSUP message */
3225 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3226 imsi := g_pars.imsi,
3227 sid := '20000101'O,
3228 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3229 ss := valueof(facility_req)
3230 );
3231
3232 /* Send it to MSC */
3233 GSUP.send(gsup_req);
3234 /* Expect MT REGISTER message with USSD request */
3235 f_expect_mt_dtap_msg(ussd_req);
3236
3237 /* Compose a new MO SS/FACILITY message with response */
3238 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3239 tid := 0, /* FIXME: it shall match the request tid */
3240 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3241 facility := valueof(facility_rsp)
3242 );
3243
3244 /* Compose expected MSC -> HLR GSUP message */
3245 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3246 imsi := g_pars.imsi,
3247 sid := '20000101'O,
3248 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3249 ss := valueof(facility_rsp)
3250 );
3251
3252 /* MS sends response */
3253 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3254 f_expect_gsup_msg(gsup_rsp);
3255
3256 /* Compose expected MT SS/RELEASE COMPLETE message */
3257 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3258 tid := 0, /* FIXME: it shall match the request tid */
3259 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3260 facility := omit
3261 );
3262
3263 /* Compose MSC -> HLR GSUP message */
3264 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3265 imsi := g_pars.imsi,
3266 sid := '20000101'O,
3267 state := OSMO_GSUP_SESSION_STATE_END
3268 );
3269
3270 /* Finally, HLR terminates the session */
3271 GSUP.send(gsup_term);
3272 /* Expect MT RELEASE COMPLETE without Facility IE */
3273 f_expect_mt_dtap_msg(ussd_term);
3274
3275 /* Hold the call for some time */
3276 f_sleep(1.0);
3277
3278 /* Release the call (does Clear Complete itself) */
3279 f_call_hangup(cpars, true);
3280}
3281testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3282 var BSC_ConnHdlr vc_conn;
3283 f_init();
3284 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3285 vc_conn.done;
3286}
3287
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003288/* LU followed by MO USSD request and MO Release during transaction */
3289private function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
3290runs on BSC_ConnHdlr {
3291 f_init_handler(pars);
3292
3293 /* Perform location update */
3294 f_perform_lu();
3295
3296 /* Send CM Service Request for SS/USSD */
3297 f_establish_fully(EST_TYPE_SS_ACT);
3298
3299 /* We need to inspect GSUP activity */
3300 f_create_gsup_expect(hex2str(g_pars.imsi));
3301
3302 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3303 invoke_id := 1, /* Initial request */
3304 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3305 ussd_string := "*6766*266#"
3306 );
3307
3308 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3309 invoke_id := 2, /* Counter request */
3310 op_code := SS_OP_CODE_USS_REQUEST,
3311 ussd_string := "Password?!?"
3312 )
3313
3314 /* Compose MO SS/REGISTER message with request */
3315 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3316 tid := 1, /* We just need a single transaction */
3317 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3318 facility := valueof(facility_ms_req)
3319 );
3320
3321 /* Compose expected MSC -> HLR message */
3322 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3323 imsi := g_pars.imsi,
3324 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3325 ss := valueof(facility_ms_req)
3326 );
3327
3328 /* To be used for sending response with correct session ID */
3329 var GSUP_PDU gsup_ms_req_complete;
3330
3331 /* Initiate a new transaction */
3332 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3333 /* Expect GSUP request with original Facility IE */
3334 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3335
3336 /* Compose the response from HLR using received session ID */
3337 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3338 imsi := g_pars.imsi,
3339 sid := gsup_ms_req_complete.ies[1].val.session_id,
3340 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3341 ss := valueof(facility_net_req)
3342 );
3343
3344 /* Compose expected MT SS/FACILITY template with counter request */
3345 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3346 tid := 1, /* Response should arrive within the same transaction */
3347 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3348 facility := valueof(facility_net_req)
3349 );
3350
3351 /* Send response over GSUP */
3352 GSUP.send(gsup_net_req);
3353 /* Expect MT SS/FACILITY message with counter request */
3354 f_expect_mt_dtap_msg(ussd_net_req);
3355
3356 /* Compose MO SS/RELEASE COMPLETE */
3357 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3358 tid := 1, /* Response should arrive within the same transaction */
3359 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3360 facility := omit
3361 /* TODO: cause? */
3362 );
3363
3364 /* Compose expected HLR -> MSC abort message */
3365 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3366 imsi := g_pars.imsi,
3367 sid := gsup_ms_req_complete.ies[1].val.session_id,
3368 state := OSMO_GSUP_SESSION_STATE_END
3369 );
3370
3371 /* Abort transaction */
3372 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3373 /* Expect GSUP message indicating abort */
3374 f_expect_gsup_msg(gsup_abort);
3375
3376 f_expect_clear();
3377}
3378testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3379 var BSC_ConnHdlr vc_conn;
3380 f_init();
3381 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3382 vc_conn.done;
3383}
3384
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003385/* LU followed by MO USSD request and MT Release due to timeout */
3386private function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
3387runs on BSC_ConnHdlr {
3388 f_init_handler(pars);
3389
3390 /* Perform location update */
3391 f_perform_lu();
3392
3393 /* Send CM Service Request for SS/USSD */
3394 f_establish_fully(EST_TYPE_SS_ACT);
3395
3396 /* We need to inspect GSUP activity */
3397 f_create_gsup_expect(hex2str(g_pars.imsi));
3398
3399 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3400 invoke_id := 1,
3401 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3402 ussd_string := "#release_me");
3403
3404 /* Compose MO SS/REGISTER message with request */
3405 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3406 tid := 1, /* An arbitrary transaction identifier */
3407 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3408 facility := valueof(facility_ms_req));
3409
3410 /* Compose expected MSC -> HLR message */
3411 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3412 imsi := g_pars.imsi,
3413 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3414 ss := valueof(facility_ms_req));
3415
3416 /* To be used for sending response with correct session ID */
3417 var GSUP_PDU gsup_ms_req_complete;
3418
3419 /* Initiate a new SS transaction */
3420 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3421 /* Expect GSUP request with original Facility IE */
3422 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3423
3424 /* Don't respond, wait for timeout */
3425 f_sleep(3.0);
3426
3427 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3428 tid := 1, /* Should match the request's tid */
3429 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3430 cause := *, /* TODO: expect some specific value */
3431 facility := omit);
3432
3433 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3434 imsi := g_pars.imsi,
3435 sid := gsup_ms_req_complete.ies[1].val.session_id,
3436 state := OSMO_GSUP_SESSION_STATE_END,
3437 cause := ?); /* TODO: expect some specific value */
3438
3439 /* Expect release on both interfaces */
3440 interleave {
3441 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3442 [] GSUP.receive(gsup_rel) { };
3443 }
3444
3445 f_expect_clear();
3446 setverdict(pass);
3447}
3448testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3449 var BSC_ConnHdlr vc_conn;
3450 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003451 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003452 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3453 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003454 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003455}
3456
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003457/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
3458private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3459 pars.net.expect_auth := true;
3460 pars.net.expect_ciph := true;
3461 pars.net.kc_support := '02'O; /* A5/1 only */
3462 f_init_handler(pars);
3463
3464 g_pars.vec := f_gen_auth_vec_2g();
3465
3466 /* Can't use f_perform_lu() directly. Code below is based on it. */
3467
3468 /* tell GSUP dispatcher to send this IMSI to us */
3469 f_create_gsup_expect(hex2str(g_pars.imsi));
3470
3471 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3472 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
3473 f_bssap_compl_l3(l3_lu);
3474
3475 f_mm_auth();
3476
3477 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3478 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3479 alt {
3480 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3481 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
3482 }
3483 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3484 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3485 mtc.stop;
3486 }
3487 [] BSSAP.receive {
3488 setverdict(fail, "Unknown/unexpected BSSAP received");
3489 mtc.stop;
3490 }
3491 }
3492
3493 /* Expect LU reject from MSC. */
3494 alt {
3495 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3496 setverdict(pass);
3497 }
3498 [] BSSAP.receive {
3499 setverdict(fail, "Unknown/unexpected BSSAP received");
3500 mtc.stop;
3501 }
3502 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01003503 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003504}
3505
3506testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
3507 var BSC_ConnHdlr vc_conn;
3508 f_init();
3509 f_vty_config(MSCVTY, "network", "encryption a5 1");
3510
3511 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52);
3512 vc_conn.done;
3513}
3514
Harald Weltef640a012018-04-14 17:49:21 +02003515/* TODO (SMS):
3516 * different user data lengths
3517 * SMPP transaction mode with unsuccessful delivery
3518 * queued MT-SMS with no paging response + later delivery
3519 * different data coding schemes
3520 * multi-part SMS
3521 * user-data headers
3522 * TP-PID for SMS to SIM
3523 * behavior if SMS memory is full + RP-SMMA
3524 * delivery reports
3525 * SMPP osmocom extensions
3526 * more-messages-to-send
3527 * SMS during ongoing call (SACCH/SAPI3)
3528 */
3529
3530/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01003531 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
3532 * malformed messages (missing IE, invalid message type): properly rejected?
3533 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
3534 * 3G/2G auth permutations
3535 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01003536 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01003537 * too long L3 INFO in DTAP
3538 * too long / padded BSSAP
3539 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01003540 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01003541
Harald Welte4263c522018-12-06 11:56:27 +01003542/* Perform a location updatye at the A-Interface and run some checks to confirm
3543 * that everything is back to normal. */
3544private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
3545 var SmsParameters spars := valueof(t_SmsPars);
3546
3547 /* Perform a location update, the SGs association is expected to fall
3548 * back to NULL */
3549 f_perform_lu();
3550 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3551
3552 /* Trigger a paging request and expect the paging on BSSMAP, this is
3553 * to make sure that pagings are sent throught the A-Interface again
3554 * and not throught the SGs interface.*/
3555 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
3556 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3557
3558 alt {
3559 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
3560 setverdict(pass);
3561 }
3562 [] SGsAP.receive {
3563 setverdict(fail, "Received unexpected message on SGs");
3564 }
3565 }
3566
3567 /* Send an SMS to make sure that also payload messages are routed
3568 * throught the A-Interface again */
3569 f_establish_fully(EST_TYPE_MO_SMS);
3570 f_mo_sms(spars);
3571 f_expect_clear();
3572}
3573
3574private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3575 var charstring vlr_name;
3576 f_init_handler(pars);
3577
3578 vlr_name := f_sgsap_reset_mme(mp_mme_name);
3579 log("VLR name: ", vlr_name);
3580 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01003581 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01003582}
3583
3584testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003585 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003586 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003587 f_init(1, true);
3588 pars := f_init_pars(11810, true);
3589 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003590 vc_conn.done;
3591}
3592
3593/* like f_mm_auth() but for SGs */
3594function f_mm_auth_sgs() runs on BSC_ConnHdlr {
3595 if (g_pars.net.expect_auth) {
3596 g_pars.vec := f_gen_auth_vec_3g();
3597 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
3598 g_pars.vec.sres,
3599 g_pars.vec.kc,
3600 g_pars.vec.ik,
3601 g_pars.vec.ck,
3602 g_pars.vec.autn,
3603 g_pars.vec.res));
3604 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
3605 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
3606 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
3607 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
3608 }
3609}
3610
3611/* like f_perform_lu(), but on SGs rather than BSSAP */
3612function f_sgs_perform_lu() runs on BSC_ConnHdlr {
3613 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3614 var PDU_SGsAP lur;
3615 var PDU_SGsAP lua;
3616 var PDU_SGsAP mm_info;
3617 var octetstring mm_info_dtap;
3618
3619 /* tell GSUP dispatcher to send this IMSI to us */
3620 f_create_gsup_expect(hex2str(g_pars.imsi));
3621
3622 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3623 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3624 /* Old LAI, if MS sends it */
3625 /* TMSI status, if MS has no valid TMSI */
3626 /* IMEISV, if it supports "automatic device detection" */
3627 /* TAI, if available in MME */
3628 /* E-CGI, if available in MME */
3629 SGsAP.send(lur);
3630
3631 /* FIXME: is this really done over SGs? The Ue is already authenticated
3632 * via the MME ... */
3633 f_mm_auth_sgs();
3634
3635 /* Expect MSC to perform LU with HLR */
3636 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3637 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
3638 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
3639 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
3640
3641 alt {
3642 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
3643 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
3644 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
3645 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
3646 }
3647 setverdict(pass);
3648 }
3649 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3650 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
3651 }
3652 [] SGsAP.receive {
3653 setverdict(fail, "Received unexpected message on SGs");
3654 }
3655 }
3656
3657 /* Check MM information */
3658 if (mp_mm_info == true) {
3659 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
3660 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
3661 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
3662 setverdict(fail, "Unexpected MM Information");
3663 }
3664 }
3665
3666 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3667}
3668
3669private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3670 f_init_handler(pars);
3671 f_sgs_perform_lu();
3672 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3673
3674 f_sgsap_bssmap_screening();
3675
3676 setverdict(pass);
3677}
3678testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003679 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003680 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003681 f_init(1, true);
3682 pars := f_init_pars(11811, true);
3683 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003684 vc_conn.done;
3685}
3686
3687/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
3688private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3689 f_init_handler(pars);
3690 var PDU_SGsAP lur;
3691
3692 f_create_gsup_expect(hex2str(g_pars.imsi));
3693 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3694 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3695 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3696 SGsAP.send(lur);
3697
3698 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3699 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
3700 alt {
3701 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3702 setverdict(pass);
3703 }
3704 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
3705 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
3706 mtc.stop;
3707 }
3708 [] SGsAP.receive {
3709 setverdict(fail, "Received unexpected message on SGs");
3710 }
3711 }
3712
3713 f_sgsap_bssmap_screening();
3714
3715 setverdict(pass);
3716}
3717testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003718 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003719 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003720 f_init(1, true);
3721 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01003722
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003723 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003724 vc_conn.done;
3725}
3726
3727/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
3728private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3729 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3730 var PDU_SGsAP lur;
3731
3732 f_init_handler(pars);
3733
3734 /* tell GSUP dispatcher to send this IMSI to us */
3735 f_create_gsup_expect(hex2str(g_pars.imsi));
3736
3737 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3738 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3739 /* Old LAI, if MS sends it */
3740 /* TMSI status, if MS has no valid TMSI */
3741 /* IMEISV, if it supports "automatic device detection" */
3742 /* TAI, if available in MME */
3743 /* E-CGI, if available in MME */
3744 SGsAP.send(lur);
3745
3746 /* FIXME: is this really done over SGs? The Ue is already authenticated
3747 * via the MME ... */
3748 f_mm_auth_sgs();
3749
3750 /* Expect MSC to perform LU with HLR */
3751 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3752 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
3753 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
3754 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
3755
3756 alt {
3757 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
3758 setverdict(pass);
3759 }
3760 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3761 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
3762 }
3763 [] SGsAP.receive {
3764 setverdict(fail, "Received unexpected message on SGs");
3765 }
3766 }
3767
3768 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3769
3770 /* Wait until the VLR has abort the TMSI reallocation procedure */
3771 f_sleep(45.0);
3772
3773 /* The outcome does not change the SGs state, see also 5.2.3.4 */
3774 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3775
3776 f_sgsap_bssmap_screening();
3777
3778 setverdict(pass);
3779}
3780testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003781 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003782 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003783 f_init(1, true);
3784 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01003785
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003786 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003787 vc_conn.done;
3788}
3789
3790private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
3791runs on BSC_ConnHdlr {
3792 f_init_handler(pars);
3793 f_sgs_perform_lu();
3794 f_sleep(3.0);
3795
3796 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3797 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
3798 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
3799 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3800
3801 f_sgsap_bssmap_screening();
3802
3803 setverdict(pass);
3804}
3805testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003806 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003807 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003808 f_init(1, true);
3809 pars := f_init_pars(11814, true);
3810 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003811 vc_conn.done;
3812}
3813
3814private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
3815runs on BSC_ConnHdlr {
3816 f_init_handler(pars);
3817 f_sgs_perform_lu();
3818 f_sleep(3.0);
3819
3820 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3821 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
3822 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
3823 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3824 /* FIXME: How to verify that VLR has removed MM context? */
3825
3826 f_sgsap_bssmap_screening();
3827
3828 setverdict(pass);
3829}
3830testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003831 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003832 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003833 f_init(1, true);
3834 pars := f_init_pars(11815, true);
3835 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003836 vc_conn.done;
3837}
3838
3839/* Trigger a paging request via VTY and send a paging reject in response */
3840private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
3841runs on BSC_ConnHdlr {
3842 f_init_handler(pars);
3843 f_sgs_perform_lu();
3844 f_sleep(1.0);
3845
3846 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3847 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3848 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3849 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3850
3851 /* Initiate paging via VTY */
3852 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3853 alt {
3854 [] SGsAP.receive(exp_resp) {
3855 setverdict(pass);
3856 }
3857 [] SGsAP.receive {
3858 setverdict(fail, "Received unexpected message on SGs");
3859 }
3860 }
3861
3862 /* Now reject the paging */
3863 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
3864
3865 /* Wait for the states inside the MSC to settle and check the state
3866 * of the SGs Association */
3867 f_sleep(1.0);
3868 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3869
3870 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
3871 * but we also need to cover tha case where the cause code indicates an
3872 * "IMSI detached for EPS services". In those cases the VLR is expected to
3873 * try paging on tha A/Iu interface. This will be another testcase similar to
3874 * this one, but extended with checks for the presence of the A/Iu paging
3875 * messages. */
3876
3877 f_sgsap_bssmap_screening();
3878
3879 setverdict(pass);
3880}
3881testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003882 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003883 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003884 f_init(1, true);
3885 pars := f_init_pars(11816, true);
3886 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003887 vc_conn.done;
3888}
3889
3890/* Trigger a paging request via VTY and send a paging reject that indicates
3891 * that the subscriber intentionally rejected the call. */
3892private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
3893runs on BSC_ConnHdlr {
3894 f_init_handler(pars);
3895 f_sgs_perform_lu();
3896 f_sleep(1.0);
3897
3898 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3899 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3900 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3901 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3902
3903 /* Initiate paging via VTY */
3904 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3905 alt {
3906 [] SGsAP.receive(exp_resp) {
3907 setverdict(pass);
3908 }
3909 [] SGsAP.receive {
3910 setverdict(fail, "Received unexpected message on SGs");
3911 }
3912 }
3913
3914 /* Now reject the paging */
3915 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
3916
3917 /* Wait for the states inside the MSC to settle and check the state
3918 * of the SGs Association */
3919 f_sleep(1.0);
3920 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3921
3922 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
3923 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
3924 * to check back how this works and how it can be tested */
3925
3926 f_sgsap_bssmap_screening();
3927
3928 setverdict(pass);
3929}
3930testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003931 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003932 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003933 f_init(1, true);
3934 pars := f_init_pars(11817, true);
3935 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003936 vc_conn.done;
3937}
3938
3939/* Trigger a paging request via VTY and send an UE unreacable messge in response */
3940private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
3941runs on BSC_ConnHdlr {
3942 f_init_handler(pars);
3943 f_sgs_perform_lu();
3944 f_sleep(1.0);
3945
3946 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3947 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3948 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3949 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3950
3951 /* Initiate paging via VTY */
3952 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3953 alt {
3954 [] SGsAP.receive(exp_resp) {
3955 setverdict(pass);
3956 }
3957 [] SGsAP.receive {
3958 setverdict(fail, "Received unexpected message on SGs");
3959 }
3960 }
3961
3962 /* Now pretend that the UE is unreachable */
3963 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
3964
3965 /* Wait for the states inside the MSC to settle and check the state
3966 * of the SGs Association. */
3967 f_sleep(1.0);
3968 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3969
3970 f_sgsap_bssmap_screening();
3971
3972 setverdict(pass);
3973}
3974testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003975 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003976 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003977 f_init(1, true);
3978 pars := f_init_pars(11818, true);
3979 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003980 vc_conn.done;
3981}
3982
3983/* Trigger a paging request via VTY but don't respond to it */
3984private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
3985runs on BSC_ConnHdlr {
3986 f_init_handler(pars);
3987 f_sgs_perform_lu();
3988 f_sleep(1.0);
3989
3990 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3991 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3992 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3993 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3994
3995 /* Initiate paging via VTY */
3996 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3997 alt {
3998 [] SGsAP.receive(exp_resp) {
3999 setverdict(pass);
4000 }
4001 [] SGsAP.receive {
4002 setverdict(fail, "Received unexpected message on SGs");
4003 }
4004 }
4005
4006 /* Now do nothing, the MSC/VLR should fail silently to page after a
4007 * few seconds, The SGs association must remain unchanged. */
4008 f_sleep(15.0);
4009 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4010
4011 f_sgsap_bssmap_screening();
4012
4013 setverdict(pass);
4014}
4015testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004016 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004017 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004018 f_init(1, true);
4019 pars := f_init_pars(11819, true);
4020 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004021 vc_conn.done;
4022}
4023
4024/* Trigger a paging request via VTY and slip in an LU */
4025private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4026runs on BSC_ConnHdlr {
4027 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4028 f_init_handler(pars);
4029
4030 /* First we prepar the situation, where the SGs association is in state
4031 * NULL and the confirmed by radio contact indicator is set to false
4032 * as well. This can be archived by performing an SGs LU and then
4033 * resetting the VLR */
4034 f_sgs_perform_lu();
4035 f_sgsap_reset_mme(mp_mme_name);
4036 f_sleep(1.0);
4037 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4038
4039 /* Perform a paging, expect the paging messages on the SGs interface */
4040 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4041 alt {
4042 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4043 setverdict(pass);
4044 }
4045 [] SGsAP.receive {
4046 setverdict(fail, "Received unexpected message on SGs");
4047 }
4048 }
4049
4050 /* Perform the LU as normal */
4051 f_sgs_perform_lu();
4052 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4053
4054 /* Expect a new paging request right after the LU */
4055 alt {
4056 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4057 setverdict(pass);
4058 }
4059 [] SGsAP.receive {
4060 setverdict(fail, "Received unexpected message on SGs");
4061 }
4062 }
4063
4064 /* Test is done now, lets round everything up by rejecting the paging
4065 * cleanly. */
4066 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4067 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4068
4069 f_sgsap_bssmap_screening();
4070
4071 setverdict(pass);
4072}
4073testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004074 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004075 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004076 f_init(1, true);
4077 pars := f_init_pars(11820, true);
4078 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004079 vc_conn.done;
4080}
4081
4082/* Send unexpected unit-data through the SGs interface */
4083private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4084 f_init_handler(pars);
4085 f_sleep(1.0);
4086
4087 /* This simulates what happens when a subscriber without SGs
4088 * association gets unitdata via the SGs interface. */
4089
4090 /* Make sure the subscriber exists and the SGs association
4091 * is in NULL state */
4092 f_perform_lu();
4093 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4094
4095 /* Send some random unit data, the MSC/VLR should send a release
4096 * immediately. */
4097 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4098 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
4099
4100 f_sgsap_bssmap_screening();
4101
4102 setverdict(pass);
4103}
4104testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004105 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004106 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004107 f_init(1, true);
4108 pars := f_init_pars(11821, true);
4109 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004110 vc_conn.done;
4111}
4112
4113/* Send unsolicited unit-data through the SGs interface */
4114private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4115 f_init_handler(pars);
4116 f_sleep(1.0);
4117
4118 /* This simulates what happens when the MME attempts to send unitdata
4119 * to a subscriber that is completely unknown to the VLR */
4120
4121 /* Send some random unit data, the MSC/VLR should send a release
4122 * immediately. */
4123 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4124 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
4125
4126 f_sgsap_bssmap_screening();
4127
4128 setverdict(pass);
4129}
4130testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004131 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004132 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004133 f_init(1, true);
4134 pars := f_init_pars(11822, true);
4135 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004136 vc_conn.done;
4137}
4138
4139private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
4140 /* FIXME: Match an actual payload (second questionmark), the type is
4141 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
4142 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
4143 setverdict(fail, "Unexpected SMS related PDU from MSC");
4144 mtc.stop;
4145 }
4146}
4147
4148/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
4149function f_mt_sms_sgs(inout SmsParameters spars)
4150runs on BSC_ConnHdlr {
4151 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4152 var template (value) RPDU_MS_SGSN rp_mo;
4153 var template (value) PDU_ML3_MS_NW l3_mo;
4154
4155 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4156 var template RPDU_SGSN_MS rp_mt;
4157 var template PDU_ML3_NW_MS l3_mt;
4158
4159 var PDU_ML3_NW_MS sgsap_l3_mt;
4160
4161 var default d := activate(as_other_sms_sgs());
4162
4163 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
4164 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
4165 rp_mt := tr_RP_DATA_MT(?, ?, omit, tp_mt);
4166 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
4167
4168 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
4169
4170 /* Extract relevant identifiers */
4171 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
4172 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
4173
4174 /* send CP-ACK for CP-DATA just received */
4175 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
4176
4177 SGsAP.send(l3_mo);
4178
4179 /* send RP-ACK for RP-DATA */
4180 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
4181 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
4182
4183 SGsAP.send(l3_mo);
4184
4185 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
4186 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
4187
4188 SGsAP.receive(l3_mt);
4189
4190 deactivate(d);
4191
4192 setverdict(pass);
4193}
4194
4195/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
4196function f_mo_sms_sgs(inout SmsParameters spars)
4197runs on BSC_ConnHdlr {
4198 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4199 var template (value) RPDU_MS_SGSN rp_mo;
4200 var template (value) PDU_ML3_MS_NW l3_mo;
4201
4202 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4203 var template RPDU_SGSN_MS rp_mt;
4204 var template PDU_ML3_NW_MS l3_mt;
4205
4206 var default d := activate(as_other_sms_sgs());
4207
4208 /* just in case this is routed to SMPP.. */
4209 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
4210
4211 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
4212 spars.tp.udl, spars.tp.ud);
4213 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, spars.rp.orig, spars.rp.dest, tp_mo);
4214 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
4215
4216 SGsAP.send(l3_mo);
4217
4218 /* receive CP-ACK for CP-DATA above */
4219 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
4220
4221 if (ispresent(spars.exp_rp_err)) {
4222 /* expect an RP-ERROR message from MSC with given cause */
4223 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
4224 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4225 SGsAP.receive(l3_mt);
4226 /* send CP-ACK for CP-DATA just received */
4227 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4228 SGsAP.send(l3_mo);
4229 } else {
4230 /* expect RP-ACK for RP-DATA */
4231 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
4232 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4233 SGsAP.receive(l3_mt);
4234 /* send CP-ACO for CP-DATA just received */
4235 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4236 SGsAP.send(l3_mo);
4237 }
4238
4239 deactivate(d);
4240
4241 setverdict(pass);
4242}
4243
4244private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
4245runs on BSC_ConnHdlr {
4246 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
4247}
4248
4249/* Send a MT SMS via SGs interface */
4250private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4251 f_init_handler(pars);
4252 f_sgs_perform_lu();
4253 f_sleep(1.0);
4254 var SmsParameters spars := valueof(t_SmsPars);
4255 spars.tp.ud := 'C8329BFD064D9B53'O;
4256
4257 /* Trigger SMS via VTY */
4258 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4259 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4260
4261 /* Expect a paging request and respond accordingly with a service request */
4262 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
4263 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
4264
4265 /* Connection is now live, receive the MT-SMS */
4266 f_mt_sms_sgs(spars);
4267
4268 /* Expect a concluding release from the MSC */
4269 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4270
4271 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4272 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4273
4274 f_sgsap_bssmap_screening();
4275
4276 setverdict(pass);
4277}
4278testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004279 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004280 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004281 f_init(1, true);
4282 pars := f_init_pars(11823, true);
4283 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004284 vc_conn.done;
4285}
4286
4287/* Send a MO SMS via SGs interface */
4288private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4289 f_init_handler(pars);
4290 f_sgs_perform_lu();
4291 f_sleep(1.0);
4292 var SmsParameters spars := valueof(t_SmsPars);
4293 spars.tp.ud := 'C8329BFD064D9B53'O;
4294
4295 /* Send the MO-SMS */
4296 f_mo_sms_sgs(spars);
4297
4298 /* Expect a concluding release from the MSC/VLR */
4299 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4300
4301 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4302 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4303
4304 setverdict(pass);
4305
4306 f_sgsap_bssmap_screening()
4307}
4308testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004309 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004310 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004311 f_init(1, true);
4312 pars := f_init_pars(11824, true);
4313 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004314 vc_conn.done;
4315}
4316
4317/* Trigger sending of an MT sms via VTY but never respond to anything */
4318private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4319 f_init_handler(pars, 170.0);
4320 f_sgs_perform_lu();
4321 f_sleep(1.0);
4322
4323 var SmsParameters spars := valueof(t_SmsPars);
4324 spars.tp.ud := 'C8329BFD064D9B53'O;
4325 var integer page_count := 0;
4326 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4327 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4328 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4329 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4330
4331 /* Trigger SMS via VTY */
4332 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4333
4334 /* Expect the MSC/VLR to page exactly 10 times before giving up */
4335 alt {
4336 [] SGsAP.receive(exp_pag_req)
4337 {
4338 page_count := page_count + 1;
4339
4340 if (page_count < 10) {
4341 repeat;
4342 }
4343 }
4344 [] SGsAP.receive {
4345 setverdict(fail, "unexpected SGsAP message received");
4346 self.stop;
4347 }
4348 }
4349
4350 /* Wait some time to make sure the MSC is not delivering any further
4351 * paging messages or anything else that could be unexpected. */
4352 timer T := 20.0;
4353 T.start
4354 alt {
4355 [] SGsAP.receive(exp_pag_req)
4356 {
4357 setverdict(fail, "paging seems not to stop!");
4358 mtc.stop;
4359 }
4360 [] SGsAP.receive {
4361 setverdict(fail, "unexpected SGsAP message received");
4362 self.stop;
4363 }
4364 [] T.timeout {
4365 setverdict(pass);
4366 }
4367 }
4368
4369 /* Even on a failed paging the SGs Association should stay intact */
4370 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4371
4372 /* Note: We do not execute f_sgsap_bssmap_screening() here since the
4373 * MSC/VLR would re-try to deliver the test SMS trigered above and
4374 * so the screening would fail. */
4375
4376 /* Expire the subscriber now to avoid that the MSC will try the SMS
4377 * delivery at some later point. */
4378 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
4379
4380 setverdict(pass);
4381}
4382testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004383 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004384 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004385 f_init(1, true);
4386 pars := f_init_pars(11825, true);
4387 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004388 vc_conn.done;
4389}
4390
4391/* Trigger sending of an MT sms via VTY but reject the paging immediately */
4392private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4393 f_init_handler(pars, 150.0);
4394 f_sgs_perform_lu();
4395 f_sleep(1.0);
4396
4397 var SmsParameters spars := valueof(t_SmsPars);
4398 spars.tp.ud := 'C8329BFD064D9B53'O;
4399 var integer page_count := 0;
4400 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4401 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4402 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4403 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4404
4405 /* Trigger SMS via VTY */
4406 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4407
4408 /* Expect a paging request and reject it immediately */
4409 SGsAP.receive(exp_pag_req);
4410 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4411
4412 /* The MSC/VLR should no longer try to page once the paging has been
4413 * rejected. Wait some time and check if there are no unexpected
4414 * messages on the SGs interface. */
4415 timer T := 20.0;
4416 T.start
4417 alt {
4418 [] SGsAP.receive(exp_pag_req)
4419 {
4420 setverdict(fail, "paging seems not to stop!");
4421 mtc.stop;
4422 }
4423 [] SGsAP.receive {
4424 setverdict(fail, "unexpected SGsAP message received");
4425 self.stop;
4426 }
4427 [] T.timeout {
4428 setverdict(pass);
4429 }
4430 }
4431
4432 /* A rejected paging with IMSI_unknown (see above) should always send
4433 * the SGs association to NULL. */
4434 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4435
4436 f_sgsap_bssmap_screening();
4437
4438 /* Expire the subscriber now to avoid that the MSC will try the SMS
4439 * delivery at some later point. */
4440 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
4441
4442 setverdict(pass);
4443}
4444testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004445 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004446 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004447 f_init(1, true);
4448 pars := f_init_pars(11826, true);
4449 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004450 vc_conn.done;
4451}
4452
4453/* Perform an MT CSDB call including LU */
4454private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
4455 f_init_handler(pars);
4456
4457 /* Be sure that the BSSMAP reset is done before we begin. */
4458 f_sleep(2.0);
4459
4460 /* Testcase variation: See what happens when we do a regular BSSMAP
4461 * LU first (this should not hurt in any way!) */
4462 if (bssmap_lu) {
4463 f_perform_lu();
4464 }
4465
4466 f_sgs_perform_lu();
4467 f_sleep(1.0);
4468
4469 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4470 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
4471 cpars.bss_rtp_port := 1110;
4472 cpars.mgcp_connection_id_bss := '10004'H;
4473 cpars.mgcp_connection_id_mss := '10005'H;
4474
4475 /* Note: This is an optional parameter. When the call-agent (MSC) does
4476 * supply a full endpoint name this setting will be overwritten. */
4477 cpars.mgcp_ep := "rtpbridge/1@mgw";
4478
4479 /* Initiate a call via MNCC interface */
4480 f_mt_call_initate(cpars);
4481
4482 /* Expect a paging request and respond accordingly with a service request */
4483 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
4484 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
4485
4486 /* Complete the call, hold it for some time and then tear it down */
4487 f_mt_call_complete(cpars);
4488 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01004489 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01004490
4491 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4492 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4493
4494 /* Finally simulate the return of the UE to the 4G network */
4495 SGsAP.send(ts_SGsAP_MO_CSFB_IND(pars.imsi));
4496
4497 /* Test for successful return by triggering a paging, when the paging
4498 * request is received via SGs, we can be sure that the MSC/VLR has
4499 * recognized that the UE is now back on 4G */
4500 f_sleep(1.0);
4501 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4502 alt {
4503 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4504 setverdict(pass);
4505 }
4506 [] SGsAP.receive {
4507 setverdict(fail, "Received unexpected message on SGs");
4508 }
4509 }
4510
4511 f_sgsap_bssmap_screening();
4512
4513 setverdict(pass);
4514}
4515
4516/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
4517private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4518 f_mt_lu_and_csfb_call(id, pars, true);
4519}
4520testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004521 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004522 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004523 f_init(1, true);
4524 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01004525
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004526 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004527 vc_conn.done;
4528}
4529
4530
4531/* Perform a SGSAP LU and then make a CSFB call */
4532private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4533 f_mt_lu_and_csfb_call(id, pars, false);
4534}
4535testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004536 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004537 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004538 f_init(1, true);
4539 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01004540
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004541 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004542 vc_conn.done;
4543}
4544
4545/* SGs TODO:
4546 * LU attempt for IMSI without NAM_PS in HLR
4547 * LU attempt with AUTH FAIL due to invalid RES/SRES
4548 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
4549 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
4550 * implicit IMSI detach from EPS
4551 * implicit IMSI detach from non-EPS
4552 * MM INFO
4553 *
4554 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004555
4556control {
Philipp Maier328d1662018-03-07 10:40:27 +01004557 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01004558 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01004559 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01004560 execute( TC_lu_imsi_reject() );
4561 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01004562 execute( TC_lu_imsi_auth_tmsi() );
4563 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01004564 execute( TC_lu_and_mo_call() );
Harald Welte071ed732018-01-23 19:53:52 +01004565 execute( TC_lu_auth_sai_timeout() );
4566 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01004567 execute( TC_lu_clear_request() );
4568 execute( TC_lu_disconnect() );
4569 execute( TC_lu_by_imei() );
4570 execute( TC_lu_by_tmsi_noauth_unknown() );
4571 execute( TC_imsi_detach_by_imsi() );
4572 execute( TC_imsi_detach_by_tmsi() );
4573 execute( TC_imsi_detach_by_imei() );
4574 execute( TC_emerg_call_imei_reject() );
4575 execute( TC_emerg_call_imsi() );
4576 execute( TC_cm_serv_req_vgcs_reject() );
4577 execute( TC_cm_serv_req_vbs_reject() );
4578 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01004579 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01004580 execute( TC_lu_auth_2G_fail() );
4581 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
4582 execute( TC_cl3_no_payload() );
4583 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01004584 execute( TC_establish_and_nothing() );
4585 execute( TC_mo_setup_and_nothing() );
4586 execute( TC_mo_crcx_ran_timeout() );
4587 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01004588 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01004589 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01004590 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01004591 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01004592 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
4593 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
4594 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01004595 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01004596 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
4597 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01004598 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01004599 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02004600 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01004601
4602 execute( TC_lu_and_mt_call() );
4603
Harald Weltef45efeb2018-04-09 18:19:24 +02004604 execute( TC_lu_and_mo_sms() );
4605 execute( TC_lu_and_mt_sms() );
Philipp Maier3983e702018-11-22 19:01:33 +01004606 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Harald Weltef640a012018-04-14 17:49:21 +02004607 execute( TC_smpp_mo_sms() );
4608 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02004609
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07004610 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07004611 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07004612 execute( TC_gsup_mt_sms_ack() );
4613 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07004614 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07004615 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07004616
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07004617 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07004618 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07004619 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07004620 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07004621 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07004622 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07004623
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004624 execute( TC_cipher_complete_with_invalid_cipher() );
4625
Harald Welte4263c522018-12-06 11:56:27 +01004626 execute( TC_sgsap_reset() );
4627 execute( TC_sgsap_lu() );
4628 execute( TC_sgsap_lu_imsi_reject() );
4629 execute( TC_sgsap_lu_and_nothing() );
4630 execute( TC_sgsap_expl_imsi_det_eps() );
4631 execute( TC_sgsap_expl_imsi_det_noneps() );
4632 execute( TC_sgsap_paging_rej() );
4633 execute( TC_sgsap_paging_subscr_rej() );
4634 execute( TC_sgsap_paging_ue_unr() );
4635 execute( TC_sgsap_paging_and_nothing() );
4636 execute( TC_sgsap_paging_and_lu() );
4637 execute( TC_sgsap_mt_sms() );
4638 execute( TC_sgsap_mo_sms() );
4639 execute( TC_sgsap_mt_sms_and_nothing() );
4640 execute( TC_sgsap_mt_sms_and_reject() );
4641 execute( TC_sgsap_unexp_ud() );
4642 execute( TC_sgsap_unsol_ud() );
4643 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
4644 execute( TC_sgsap_lu_and_mt_call() );
4645
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01004646 /* Run this last: at the time of writing this test crashes the MSC */
4647 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Philipp Maierdb7fb8d2019-02-11 10:50:13 +01004648 execute( TC_gsup_mt_multi_part_sms() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02004649 execute( TC_mo_cc_bssmap_clear() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01004650}
4651
4652
4653}