blob: 00f9bec19c11837e640e6d1923551248cce5c44e [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
3import from General_Types all;
4import from Osmocom_Types all;
5
6import from M3UA_Types all;
7import from M3UA_Emulation all;
8
9import from MTP3asp_Types all;
10import from MTP3asp_PortType all;
11
12import from SCCPasp_Types all;
13import from SCCP_Types all;
14import from SCCP_Emulation all;
15
16import from SCTPasp_Types all;
17import from SCTPasp_PortType all;
18
Harald Weltea49e36e2018-01-21 19:29:33 +010019import from Osmocom_CTRL_Functions all;
20import from Osmocom_CTRL_Types all;
21import from Osmocom_CTRL_Adapter all;
22
Harald Welte3ca1c902018-01-24 18:51:27 +010023import from TELNETasp_PortType all;
24import from Osmocom_VTY_Functions all;
25
Harald Weltea49e36e2018-01-21 19:29:33 +010026import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010027import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010028
Harald Welte4aa970c2018-01-26 10:38:09 +010029import from MGCP_Emulation all;
30import from MGCP_Types all;
31import from MGCP_Templates all;
32import from SDP_Types all;
33
Harald Weltea49e36e2018-01-21 19:29:33 +010034import from GSUP_Emulation all;
35import from GSUP_Types all;
36import from IPA_Emulation all;
37
Harald Weltef6dd64d2017-11-19 12:09:51 +010038import from BSSAP_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010039import from BSSAP_Adapter all;
40import from BSSAP_CodecPort all;
41import from BSSMAP_Templates all;
42import from BSSMAP_Emulation all;
43import from BSC_ConnectionHandler all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010044
Harald Welte4263c522018-12-06 11:56:27 +010045import from SGsAP_Templates all;
46import from SGsAP_Types all;
47import from SGsAP_Emulation all;
48
Harald Weltea49e36e2018-01-21 19:29:33 +010049import from MobileL3_Types all;
50import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070051import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010052import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010053import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010054
Harald Weltef640a012018-04-14 17:49:21 +020055import from SMPP_Types all;
56import from SMPP_Templates all;
57import from SMPP_Emulation all;
58
Stefan Sperlingc307e682018-06-14 15:15:46 +020059import from SCCP_Templates all;
60
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070061import from SS_Types all;
62import from SS_Templates all;
63import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010064import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070065
Philipp Maier75932982018-03-27 14:52:35 +020066const integer NUM_BSC := 2;
67type record of BSSAP_Configuration BSSAP_Configurations;
Harald Weltef6dd64d2017-11-19 12:09:51 +010068
Harald Welte4263c522018-12-06 11:56:27 +010069/* Needed for SGsAP SMS */
70import from MobileL3_SMS_Types all;
71
Harald Weltea4ca4462018-02-09 00:17:14 +010072type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010073 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010074
Philipp Maier75932982018-03-27 14:52:35 +020075 var BSSAP_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010076
Harald Weltea49e36e2018-01-21 19:29:33 +010077 /* no 'adapter_CT' for MNCC or GSUP */
78 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010079 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010080 var GSUP_Emulation_CT vc_GSUP;
81 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020082 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +010083 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +010084
85 /* only to get events from IPA underneath GSUP */
86 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +010087 /* VTY to MSC */
88 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +010089
90 /* A port to directly send BSSAP messages. This port is used for
91 * tests that require low level access to sen arbitrary BSSAP
92 * messages. Run f_init_bssap_direct() to connect and initialize */
93 port BSSAP_CODEC_PT BSSAP_DIRECT;
94
95 /* When BSSAP messages are directly sent, then the connection
96 * handler is not active, which means that also no guard timer is
97 * set up. The following timer will serve as a replacement */
98 timer Tguard_direct := 60.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +010099}
100
101modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100102 /* remote parameters of IUT */
103 charstring mp_msc_ip := "127.0.0.1";
104 integer mp_msc_ctrl_port := 4255;
105 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100106
Harald Weltea49e36e2018-01-21 19:29:33 +0100107 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100108 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100109 charstring mp_hlr_ip := "127.0.0.1";
110 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100111 charstring mp_mgw_ip := "127.0.0.1";
112 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100113
Harald Weltea49e36e2018-01-21 19:29:33 +0100114 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100115
Harald Weltef640a012018-04-14 17:49:21 +0200116 integer mp_msc_smpp_port := 2775;
117 charstring mp_smpp_system_id := "msc_tester";
118 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100119 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
120 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200121
Philipp Maier75932982018-03-27 14:52:35 +0200122 BSSAP_Configurations mp_bssap_cfg := {
123 {
124 sccp_service_type := "mtp3_itu",
125 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
126 own_pc := 185,
127 own_ssn := 254,
128 peer_pc := 187,
129 peer_ssn := 254,
130 sio := '83'O,
131 rctx := 0
132 },
133 {
134 sccp_service_type := "mtp3_itu",
135 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
136 own_pc := 186,
137 own_ssn := 254,
138 peer_pc := 187,
139 peer_ssn := 254,
140 sio := '83'O,
141 rctx := 1
142 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100143 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100144}
145
Philipp Maier328d1662018-03-07 10:40:27 +0100146/* altstep for the global guard timer (only used when BSSAP_DIRECT
147 * is used for communication */
148private altstep as_Tguard_direct() runs on MTC_CT {
149 [] Tguard_direct.timeout {
150 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200151 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100152 }
153}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100154
Harald Weltef640a012018-04-14 17:49:21 +0200155function f_init_smpp(charstring id) runs on MTC_CT {
156 id := id & "-SMPP";
157 var EsmePars pars := {
158 mode := MODE_TRANSCEIVER,
159 bind := {
160 system_id := mp_smpp_system_id,
161 password := mp_smpp_password,
162 system_type := "MSC_Tests",
163 interface_version := hex2int('34'H),
164 addr_ton := unknown,
165 addr_npi := unknown,
166 address_range := ""
167 },
168 esme_role := true
169 }
170
171 vc_SMPP := SMPP_Emulation_CT.create(id);
172 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
173 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", -1));
174}
175
176
Harald Weltea49e36e2018-01-21 19:29:33 +0100177function f_init_mncc(charstring id) runs on MTC_CT {
178 id := id & "-MNCC";
179 var MnccOps ops := {
180 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
181 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
182 }
183
184 vc_MNCC := MNCC_Emulation_CT.create(id);
185 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
186 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100187}
188
Harald Welte4aa970c2018-01-26 10:38:09 +0100189function f_init_mgcp(charstring id) runs on MTC_CT {
190 id := id & "-MGCP";
191 var MGCPOps ops := {
192 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
193 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
194 }
195 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100196 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100197 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100198 mgw_ip := mp_mgw_ip,
199 mgw_udp_port := mp_mgw_port
Harald Welte4aa970c2018-01-26 10:38:09 +0100200 }
201
202 vc_MGCP := MGCP_Emulation_CT.create(id);
203 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
204 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
205}
206
Harald Welte4263c522018-12-06 11:56:27 +0100207function f_init_sgsap(charstring id) runs on MTC_CT {
208 id := id & "-SGsAP";
209 var SGsAPOps ops := {
210 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
211 unitdata_cb := refers(SGsAP_Emulation.DummyUnitdataCallback)
212 }
213 var SGsAP_conn_parameters pars := {
214 remote_ip := mp_msc_ip,
215 remote_sctp_port := 29118,
216 local_ip := "",
217 local_sctp_port := -1
218 }
219
220 vc_SGsAP := SGsAP_Emulation_CT.create(id);
221 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
222 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
223}
224
225
Harald Weltea49e36e2018-01-21 19:29:33 +0100226function f_init_gsup(charstring id) runs on MTC_CT {
227 id := id & "-GSUP";
228 var GsupOps ops := {
229 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
230 }
231
232 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
233 vc_GSUP := GSUP_Emulation_CT.create(id);
234
235 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
236 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
237 /* we use this hack to get events like ASP_IPA_EVENT_UP */
238 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
239
240 vc_GSUP.start(GSUP_Emulation.main(ops, id));
241 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
242
243 /* wait for incoming connection to GSUP port before proceeding */
244 timer T := 10.0;
245 T.start;
246 alt {
247 [] GSUP_IPA_EVENT.receive(t_ASP_IPA_EVT_UD(ASP_IPA_EVENT_UP)) { }
248 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100249 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200250 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100251 }
252 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100253}
254
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100255function f_init(integer num_bsc := 1, boolean sgsap := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100256
257 if (g_initialized == true) {
258 return;
259 }
260 g_initialized := true;
261
Philipp Maier75932982018-03-27 14:52:35 +0200262 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200263 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200264 }
265
266 for (var integer i := 0; i < num_bsc; i := i + 1) {
267 if (isbound(mp_bssap_cfg[i])) {
Philipp Maierdefd9482018-05-16 16:44:37 +0200268 f_bssap_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), BSC_BssmapOps);
Harald Welted5833a82018-05-27 16:52:56 +0200269 f_bssap_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200270 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200271 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200272 }
273 }
274
Harald Weltea49e36e2018-01-21 19:29:33 +0100275 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
276 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100277 f_init_mgcp("MSC_Test");
Harald Weltea49e36e2018-01-21 19:29:33 +0100278 f_init_gsup("MSC_Test");
Harald Weltef640a012018-04-14 17:49:21 +0200279 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100280
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100281 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100282 f_init_sgsap("MSC_Test");
283 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100284
285 map(self:MSCVTY, system:MSCVTY);
286 f_vty_set_prompts(MSCVTY);
287 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100288
289 /* set some defaults */
290 f_vty_config(MSCVTY, "network", "authentication optional");
291 f_vty_config(MSCVTY, "msc", "assign-tmsi");
292 f_vty_config(MSCVTY, "network", "encryption a5 0");
Harald Weltef6dd64d2017-11-19 12:09:51 +0100293}
294
Philipp Maier328d1662018-03-07 10:40:27 +0100295/* Initialize for a direct connection to BSSAP. This function is an alternative
296 * to f_init() when the high level functions of the BSC_ConnectionHandler are
297 * not needed. */
298function f_init_bssap_direct() runs on MTC_CT {
Philipp Maier75932982018-03-27 14:52:35 +0200299 f_bssap_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
300 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100301
302 /* Start guard timer and activate it as default */
303 Tguard_direct.start
304 activate(as_Tguard_direct());
305}
306
Harald Weltef6dd64d2017-11-19 12:09:51 +0100307template PDU_BSSAP ts_BSSAP_BSSMAP := {
308 discriminator := '0'B,
309 spare := '0000000'B,
310 dlci := omit,
311 lengthIndicator := 0, /* overwritten by codec */
312 pdu := ?
313}
314
315template PDU_BSSAP tr_BSSAP_BSSMAP := {
316 discriminator := '0'B,
317 spare := '0000000'B,
318 dlci := omit,
319 lengthIndicator := ?,
320 pdu := {
321 bssmap := ?
322 }
323}
324
325
326type integer BssmapCause;
327
328template (value) BSSMAP_IE_Cause ts_BSSMAP_IE_Cause(BssmapCause val) := {
329 elementIdentifier := '04'O,
330 lengthIndicator := 0,
331 causeValue := int2bit(val, 7),
332 extensionCauseValue := '0'B,
333 spare1 := omit
334}
335
336template (value) PDU_BSSAP ts_BSSMAP_Reset(BssmapCause cause) modifies ts_BSSAP_BSSMAP := {
337 pdu := {
338 bssmap := {
339 reset := {
340 messageType := '30'O,
341 cause := ts_BSSMAP_IE_Cause(cause),
342 a_InterfaceSelectorForReset := omit
343 }
344 }
345 }
346}
347
348template (value) PDU_BSSAP ts_BSSMAP_ResetAck modifies ts_BSSAP_BSSMAP := {
349 pdu := {
350 bssmap := {
351 resetAck := {
352 messageType := '31'O,
353 a_InterfaceSelectorForReset := omit
354 }
355 }
356 }
357}
358
359template PDU_BSSAP tr_BSSMAP_ResetAck modifies tr_BSSAP_BSSMAP := {
360 pdu := {
361 bssmap := {
362 resetAck := {
363 messageType := '31'O,
364 a_InterfaceSelectorForReset := *
365 }
366 }
367 }
368}
369
370template BSSMAP_IE_CellIdentifier ts_BSSMAP_IE_CellID := {
371 elementIdentifier := '05'O,
372 lengthIndicator := 0,
373 cellIdentifierDiscriminator := '0000'B,
374 spare1_4 := '0000'B,
375 cellIdentification := ?
376}
377
378type uint16_t BssmapLAC;
379type uint16_t BssmapCI;
380
381/*
382template BSSMAP_IE_CellIdentifier ts_CellId_CGI(mcc, mnc, lac, ci)
383modifies ts_BSSMAP_IE_CellID := {
384 cellIdentification := {
385 cI_LAC_CGI := {
386 mnc_mcc := FIXME,
387 lac := int2oct(lac, 2),
388 ci := int2oct(ci, 2)
389 }
390 }
391}
392*/
393
394template BSSMAP_IE_CellIdentifier ts_CellID_LAC_CI(BssmapLAC lac, BssmapCI ci)
395modifies ts_BSSMAP_IE_CellID := {
396 cellIdentification := {
397 cI_LAC_CI := {
398 lac := int2oct(lac, 2),
399 ci := int2oct(ci, 2)
400 }
401 }
402}
403
404template BSSMAP_IE_CellIdentifier ts_CellId_CI(BssmapCI ci)
405modifies ts_BSSMAP_IE_CellID := {
406 cellIdentification := {
407 cI_CI := int2oct(ci, 2)
408 }
409}
410
411template BSSMAP_IE_CellIdentifier ts_CellId_none
412modifies ts_BSSMAP_IE_CellID := {
413 cellIdentification := {
414 cI_noCell := ''O
415 }
416}
417
418
419template BSSMAP_IE_Layer3Information ts_BSSMAP_IE_L3Info(octetstring l3info) := {
420 elementIdentifier := '17'O,
421 lengthIndicator := 0,
422 layer3info := l3info
423}
424
425template PDU_BSSAP ts_BSSMAP_ComplL3(BSSMAP_IE_CellIdentifier cell_id, octetstring l3_info)
426modifies ts_BSSAP_BSSMAP := {
427 pdu := {
428 bssmap := {
429 completeLayer3Information := {
430 messageType := '57'O,
431 cellIdentifier := cell_id,
432 layer3Information := ts_BSSMAP_IE_L3Info(l3_info),
433 chosenChannel := omit,
434 lSAIdentifier := omit,
435 aPDU := omit,
436 codecList := omit,
437 redirectAttemptFlag := omit,
438 sendSequenceNumber := omit,
439 iMSI := omit
440 }
441 }
442 }
443}
444
445template PDU_BSSAP ts_BSSMAP_HandoReq(BssmapCause cause, BSSMAP_IE_CellIdentifierList cid_list)
446modifies ts_BSSAP_BSSMAP := {
447 pdu := {
448 bssmap := {
449 handoverRequired := {
450 messageType := '11'O,
451 cause := ts_BSSMAP_IE_Cause(cause),
452 responseRequest := omit,
453 cellIdentifierList := cid_list,
454 circuitPoolList := omit,
455 currentChannelType1 := omit,
456 speechVersion := omit,
457 queueingIndicator := omit,
458 oldToNewBSSInfo := omit,
459 sourceToTargetRNCTransparentInfo := omit,
460 sourceToTargetRNCTransparentInfoCDMA := omit,
461 gERANClassmark := omit,
462 talkerPriority := omit,
463 speechCodec := omit,
464 cSG_Identifier := omit
465 }
466 }
467 }
468}
469
Harald Weltea49e36e2018-01-21 19:29:33 +0100470type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100471
Harald Weltea49e36e2018-01-21 19:29:33 +0100472/* FIXME: move into BSC_ConnectionHandler? */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100473function f_init_pars(integer imsi_suffix, boolean sgsap := false) runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100474 var BSC_ConnHdlrNetworkPars net_pars := {
475 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
476 expect_tmsi := true,
477 expect_auth := false,
478 expect_ciph := false
479 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100480 var BSC_ConnHdlrPars pars := {
Philipp Maier75932982018-03-27 14:52:35 +0200481 sccp_addr_own := g_bssap[0].sccp_addr_own,
482 sccp_addr_peer := g_bssap[0].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100483 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100484 imei := f_gen_imei(imsi_suffix),
485 imsi := f_gen_imsi(imsi_suffix),
486 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100487 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100488 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100489 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100490 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100491 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100492 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100493 send_early_cm := true,
494 ipa_ctrl_ip := mp_msc_ip,
495 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100496 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100497 mm_info := mp_mm_info,
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100498 sgsap_enable := sgsap
Harald Weltea49e36e2018-01-21 19:29:33 +0100499 };
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100500 return pars;
501}
502
503function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
504 var BSC_ConnHdlr vc_conn;
505 var charstring id := testcasename();
Harald Weltea49e36e2018-01-21 19:29:33 +0100506
507 vc_conn := BSC_ConnHdlr.create(id);
508 /* BSSMAP part / A interface */
Philipp Maier75932982018-03-27 14:52:35 +0200509 connect(vc_conn:BSSAP, g_bssap[0].vc_BSSMAP:CLIENT);
510 connect(vc_conn:BSSAP_PROC, g_bssap[0].vc_BSSMAP:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100511 /* MNCC part */
512 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
513 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100514 /* MGCP part */
515 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
516 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100517 /* GSUP part */
518 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
519 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
Harald Weltef640a012018-04-14 17:49:21 +0200520 /* SMPP part */
521 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
522 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100523 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100524 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100525 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
526 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
527 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100528
Harald Weltea10db902018-01-27 12:44:49 +0100529 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
530 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100531 vc_conn.start(derefers(fn)(id, pars));
532 return vc_conn;
533}
534
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100535function f_start_handler(void_fn fn, integer imsi_suffix) runs on MTC_CT return BSC_ConnHdlr {
536 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix));
537}
538
Harald Weltea49e36e2018-01-21 19:29:33 +0100539private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100540 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100541 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100542}
Harald Weltea49e36e2018-01-21 19:29:33 +0100543testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
544 var BSC_ConnHdlr vc_conn;
545 f_init();
546
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100547 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100548 vc_conn.done;
549}
550
551private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100552 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100553 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100554 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100555}
Harald Weltea49e36e2018-01-21 19:29:33 +0100556testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
557 var BSC_ConnHdlr vc_conn;
558 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100559 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100560
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100561 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100562 vc_conn.done;
563}
564
565/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
566private function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100567 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100568 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
569
570 f_create_gsup_expect(hex2str(g_pars.imsi));
571 f_bssap_compl_l3(l3_lu);
572 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
573 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
574 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100575 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
576 f_expect_clear();
577 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100578 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
579 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200580 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100581 }
582 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100583}
584testcase TC_lu_imsi_reject() runs on MTC_CT {
585 var BSC_ConnHdlr vc_conn;
586 f_init();
587
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100588 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3);
Harald Weltea49e36e2018-01-21 19:29:33 +0100589 vc_conn.done;
590}
591
592/* Do LU by IMSI, timeout on GSUP */
593private function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100594 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100595 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
596
597 f_create_gsup_expect(hex2str(g_pars.imsi));
598 f_bssap_compl_l3(l3_lu);
599 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
600 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
601 alt {
602 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100603 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
604 f_expect_clear();
605 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100606 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
607 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200608 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100609 }
610 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100611}
612testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
613 var BSC_ConnHdlr vc_conn;
614 f_init();
615
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100616 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4);
Harald Weltea49e36e2018-01-21 19:29:33 +0100617 vc_conn.done;
618}
619
Harald Welte7b1b2812018-01-22 21:23:06 +0100620private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100621 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100622 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100623 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100624}
625testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
626 var BSC_ConnHdlr vc_conn;
627 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100628 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100629
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100630 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100631 vc_conn.done;
632}
633
Harald Weltea49e36e2018-01-21 19:29:33 +0100634
635/* Send CM SERVICE REQ for IMSI that has never performed LU before */
636private function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
637runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100638 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100639
640 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100641 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100642 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100643
644 f_create_gsup_expect(hex2str(g_pars.imsi));
645
646 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
647 f_bssap_compl_l3(l3_info);
648
649 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100650 T.start;
651 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100652 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
653 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200654 [] BSSAP.receive {
655 setverdict(fail, "Received unexpected BSSAP");
656 mtc.stop;
657 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100658 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
659 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200660 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100661 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200662 [] T.timeout {
663 setverdict(fail, "Timeout waiting for CM SERV REQ");
664 mtc.stop;
665 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100666 }
667
Harald Welte1ddc7162018-01-27 14:25:46 +0100668 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100669}
Harald Weltea49e36e2018-01-21 19:29:33 +0100670testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
671 var BSC_ConnHdlr vc_conn;
672 f_init();
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100673 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6);
Harald Weltea49e36e2018-01-21 19:29:33 +0100674 vc_conn.done;
675}
676
Harald Welte2bb825f2018-01-22 11:31:18 +0100677private function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100678 f_init_handler(pars);
Harald Welteb71901a2018-01-26 19:16:05 +0100679 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
680 cpars.bss_rtp_port := 1110;
681 cpars.mgcp_connection_id_bss := '22222'H;
682 cpars.mgcp_connection_id_mss := '33333'H;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100683 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte2bb825f2018-01-22 11:31:18 +0100684
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100685 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100686 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100687}
688testcase TC_lu_and_mo_call() runs on MTC_CT {
689 var BSC_ConnHdlr vc_conn;
690 f_init();
691
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100692 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100693 vc_conn.done;
694}
695
696/* Test LU (with authentication enabled), where HLR times out sending SAI response */
697private function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100698 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100699
700 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
701 var PDU_DTAP_MT dtap_mt;
702
703 /* tell GSUP dispatcher to send this IMSI to us */
704 f_create_gsup_expect(hex2str(g_pars.imsi));
705
706 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
707 f_bssap_compl_l3(l3_lu);
708
709 /* Send Early Classmark, just for the fun of it */
710 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
711
712 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
713 /* The HLR would normally return an auth vector here, but we fail to do so. */
714
715 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100716 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100717}
718testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
719 var BSC_ConnHdlr vc_conn;
720 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100721 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100722
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100723 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8);
Harald Welte071ed732018-01-23 19:53:52 +0100724 vc_conn.done;
725}
726
727/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
728private function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100729 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100730
731 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
732 var PDU_DTAP_MT dtap_mt;
733
734 /* tell GSUP dispatcher to send this IMSI to us */
735 f_create_gsup_expect(hex2str(g_pars.imsi));
736
737 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
738 f_bssap_compl_l3(l3_lu);
739
740 /* Send Early Classmark, just for the fun of it */
741 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
742
743 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
744 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
745
746 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100747 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100748}
749testcase TC_lu_auth_sai_err() runs on MTC_CT {
750 var BSC_ConnHdlr vc_conn;
751 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100752 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100753
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100754 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9);
Harald Welte2bb825f2018-01-22 11:31:18 +0100755 vc_conn.done;
756}
Harald Weltea49e36e2018-01-21 19:29:33 +0100757
Harald Weltebc881782018-01-23 20:09:15 +0100758/* Test LU but BSC will send a clear request in the middle */
759private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100760 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100761
762 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
763 var PDU_DTAP_MT dtap_mt;
764
765 /* tell GSUP dispatcher to send this IMSI to us */
766 f_create_gsup_expect(hex2str(g_pars.imsi));
767
768 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
769 f_bssap_compl_l3(l3_lu);
770
771 /* Send Early Classmark, just for the fun of it */
772 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
773
774 f_sleep(1.0);
775 /* send clear request in the middle of the LU */
776 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200777 alt {
778 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
779 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
780 }
Harald Weltebc881782018-01-23 20:09:15 +0100781 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100782 alt {
783 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200784 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
785 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200786 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200787 repeat;
788 }
Harald Welte89a32492018-01-27 19:07:28 +0100789 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
790 }
Harald Weltebc881782018-01-23 20:09:15 +0100791 setverdict(pass);
792}
793testcase TC_lu_clear_request() runs on MTC_CT {
794 var BSC_ConnHdlr vc_conn;
795 f_init();
796
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100797 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100798 vc_conn.done;
799}
800
Harald Welte66af9e62018-01-24 17:28:21 +0100801/* Test LU but BSC will send a clear request in the middle */
802private function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100803 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100804
805 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
806 var PDU_DTAP_MT dtap_mt;
807
808 /* tell GSUP dispatcher to send this IMSI to us */
809 f_create_gsup_expect(hex2str(g_pars.imsi));
810
811 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
812 f_bssap_compl_l3(l3_lu);
813
814 /* Send Early Classmark, just for the fun of it */
815 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
816
817 f_sleep(1.0);
818 /* send clear request in the middle of the LU */
819 BSSAP.send(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
820 setverdict(pass);
821}
822testcase TC_lu_disconnect() runs on MTC_CT {
823 var BSC_ConnHdlr vc_conn;
824 f_init();
825
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100826 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100827 vc_conn.done;
828}
829
830
Harald Welteba7b6d92018-01-23 21:32:34 +0100831/* Test LU but with illegal mobile identity type = IMEI */
832private function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100833 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100834
Harald Welte256571e2018-01-24 18:47:19 +0100835 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100836 var PDU_DTAP_MT dtap_mt;
837
838 /* tell GSUP dispatcher to send this IMSI to us */
839 f_create_gsup_expect(hex2str(g_pars.imsi));
840
841 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
842 f_bssap_compl_l3(l3_lu);
843
844 /* Send Early Classmark, just for the fun of it */
845 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
846 /* wait for LU reject, ignore any ID REQ */
847 alt {
848 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
849 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
850 }
851 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100852 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100853}
854testcase TC_lu_by_imei() runs on MTC_CT {
855 var BSC_ConnHdlr vc_conn;
856 f_init();
857
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100858 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12);
Harald Welteba7b6d92018-01-23 21:32:34 +0100859 vc_conn.done;
860}
861
862/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
863private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200864 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
865 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100866 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100867
868 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
869 var PDU_DTAP_MT dtap_mt;
870
871 /* tell GSUP dispatcher to send this IMSI to us */
872 f_create_gsup_expect(hex2str(g_pars.imsi));
873
874 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
875 f_bssap_compl_l3(l3_lu);
876
877 /* Send Early Classmark, just for the fun of it */
878 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
879
880 /* Wait for + respond to ID REQ (IMSI) */
881 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req('001'B)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200882 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100883 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
884
885 /* Expect MSC to do UpdateLocation to HLR; respond to it */
886 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
887 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
888 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
889 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
890
891 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100892 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
893 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
894 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100895 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
896 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200897 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +0100898 }
899 }
900
Philipp Maier9b690e42018-12-21 11:50:03 +0100901 /* Wait for MM-Information (if enabled) */
902 f_expect_mm_info();
903
Harald Welteba7b6d92018-01-23 21:32:34 +0100904 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100905 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100906}
907testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
908 var BSC_ConnHdlr vc_conn;
909 f_init();
910
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100911 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100912 vc_conn.done;
913}
914
915
Harald Welte45164da2018-01-24 12:51:27 +0100916/* Test IMSI DETACH (MI=IMSI) */
917private function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100918 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100919
920 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
921
922 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
923 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
924
925 /* Send Early Classmark, just for the fun of it? */
926 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
927
928 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100929 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100930}
931testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
932 var BSC_ConnHdlr vc_conn;
933 f_init();
934
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100935 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14);
Harald Welte45164da2018-01-24 12:51:27 +0100936 vc_conn.done;
937}
938
939/* Test IMSI DETACH (MI=TMSI) */
940private function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100941 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100942
943 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
944
945 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
946 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
947
948 /* Send Early Classmark, just for the fun of it? */
949 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
950
951 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100952 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100953}
954testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
955 var BSC_ConnHdlr vc_conn;
956 f_init();
957
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100958 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15);
Harald Welte45164da2018-01-24 12:51:27 +0100959 vc_conn.done;
960}
961
962/* Test IMSI DETACH (MI=IMEI), which is illegal */
963private function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100964 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100965
Harald Welte256571e2018-01-24 18:47:19 +0100966 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +0100967
968 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
969 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
970
971 /* Send Early Classmark, just for the fun of it? */
972 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
973
974 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100975 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100976}
977testcase TC_imsi_detach_by_imei() runs on MTC_CT {
978 var BSC_ConnHdlr vc_conn;
979 f_init();
980
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100981 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16);
Harald Welte45164da2018-01-24 12:51:27 +0100982 vc_conn.done;
983}
984
985
986/* helper function for an emergency call. caller passes in mobile identity to use */
987private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +0100988 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
989 cpars.emergency := true;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100990 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte45164da2018-01-24 12:51:27 +0100991
Harald Welte0bef21e2018-02-10 09:48:23 +0100992 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +0100993}
994
995/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
996private function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100997 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100998
Harald Welte256571e2018-01-24 18:47:19 +0100999 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001000 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001001 f_bssap_compl_l3(l3_info);
1002 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001003 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001004}
1005testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1006 var BSC_ConnHdlr vc_conn;
1007 f_init();
1008
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001009 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17);
Harald Welte45164da2018-01-24 12:51:27 +01001010 vc_conn.done;
1011}
1012
Harald Welted5b91402018-01-24 18:48:16 +01001013/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Welte45164da2018-01-24 12:51:27 +01001014private function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001015 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001016 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001017 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001018 /* Then issue emergency call identified by IMSI */
1019 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1020}
1021testcase TC_emerg_call_imsi() runs on MTC_CT {
1022 var BSC_ConnHdlr vc_conn;
1023 f_init();
1024
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001025 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001026 vc_conn.done;
1027}
1028
1029/* CM Service Request for VGCS -> reject */
1030private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001031 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001032
1033 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001034 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001035
1036 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001037 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001038 f_bssap_compl_l3(l3_info);
1039 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001040 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001041}
1042testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1043 var BSC_ConnHdlr vc_conn;
1044 f_init();
1045
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001046 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001047 vc_conn.done;
1048}
1049
1050/* CM Service Request for VBS -> reject */
1051private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001052 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001053
1054 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001055 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001056
1057 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001058 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001059 f_bssap_compl_l3(l3_info);
1060 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001061 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001062}
1063testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1064 var BSC_ConnHdlr vc_conn;
1065 f_init();
1066
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001067 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001068 vc_conn.done;
1069}
1070
1071/* CM Service Request for LCS -> reject */
1072private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001073 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001074
1075 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001076 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001077
1078 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001079 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001080 f_bssap_compl_l3(l3_info);
1081 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001082 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001083}
1084testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1085 var BSC_ConnHdlr vc_conn;
1086 f_init();
1087
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001088 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001089 vc_conn.done;
1090}
1091
Harald Welte0195ab12018-01-24 21:50:20 +01001092/* CM Re-Establishment Request */
1093private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001094 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001095
1096 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001097 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001098
1099 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1100 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
1101 f_bssap_compl_l3(l3_info);
1102 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001103 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001104}
1105testcase TC_cm_reest_req_reject() runs on MTC_CT {
1106 var BSC_ConnHdlr vc_conn;
1107 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001108
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001109 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001110 vc_conn.done;
1111}
1112
Harald Weltec638f4d2018-01-24 22:00:36 +01001113/* Test LU (with authentication enabled), with wrong response from MS */
1114private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001115 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001116
1117 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1118
1119 /* tell GSUP dispatcher to send this IMSI to us */
1120 f_create_gsup_expect(hex2str(g_pars.imsi));
1121
1122 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1123 f_bssap_compl_l3(l3_lu);
1124
1125 /* Send Early Classmark, just for the fun of it */
1126 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1127
1128 var AuthVector vec := f_gen_auth_vec_2g();
1129 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1130 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1131 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1132
1133 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1134 /* Send back wrong auth response */
1135 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1136
1137 /* Expect GSUP AUTH FAIL REP to HLR */
1138 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1139
1140 /* Expect LU REJECT with Cause == Illegal MS */
1141 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001142 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001143}
1144testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1145 var BSC_ConnHdlr vc_conn;
1146 f_init();
1147 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001148
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001149 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23);
Harald Weltec638f4d2018-01-24 22:00:36 +01001150 vc_conn.done;
1151}
1152
Harald Weltede371492018-01-27 23:44:41 +01001153/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001154private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001155 pars.net.expect_auth := true;
1156 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001157 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001158 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001159}
1160testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1161 var BSC_ConnHdlr vc_conn;
1162 f_init();
1163 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001164 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1165
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001166 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001167 vc_conn.done;
1168}
1169
Harald Welte1af6ea82018-01-25 18:33:15 +01001170/* Test Complete L3 without payload */
1171private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001172 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001173
1174 /* Send Complete L3 Info with empty L3 frame */
1175 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1176 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1177
Harald Weltef466eb42018-01-27 14:26:54 +01001178 timer T := 5.0;
1179 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001180 alt {
1181 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
1182 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001183 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
1184 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001185 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001186 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001187 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001188 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001189 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001190 }
1191 setverdict(pass);
1192}
1193testcase TC_cl3_no_payload() runs on MTC_CT {
1194 var BSC_ConnHdlr vc_conn;
1195 f_init();
1196
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001197 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001198 vc_conn.done;
1199}
1200
1201/* Test Complete L3 with random payload */
1202private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001203 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001204
Daniel Willmannaa14a382018-07-26 08:29:45 +02001205 /* length is limited by PDU_BSSAP length field which includes some
1206 * other fields beside l3info payload. So payl can only be 240 bytes
1207 * Since rnd() returns values < 1 multiply with 241
1208 */
1209 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001210 var octetstring payl := f_rnd_octstring(len);
1211
1212 /* Send Complete L3 Info with empty L3 frame */
1213 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1214 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1215
Harald Weltef466eb42018-01-27 14:26:54 +01001216 timer T := 5.0;
1217 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001218 alt {
1219 /* Immediate disconnect */
1220 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001221 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Weltebdb3c452018-03-18 22:43:06 +01001222 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001223 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001224 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001225 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001226 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001227 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001228 }
1229 setverdict(pass);
1230}
1231testcase TC_cl3_rnd_payload() runs on MTC_CT {
1232 var BSC_ConnHdlr vc_conn;
1233 f_init();
1234
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001235 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001236 vc_conn.done;
1237}
1238
Harald Welte116e4332018-01-26 22:17:48 +01001239/* Test Complete L3 with random payload */
1240private function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001241 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001242
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001243 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001244
Harald Welteb9e86fa2018-04-09 18:18:31 +02001245 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001246 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001247}
1248testcase TC_establish_and_nothing() runs on MTC_CT {
1249 var BSC_ConnHdlr vc_conn;
1250 f_init();
1251
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001252 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001253 vc_conn.done;
1254}
1255
Harald Welte12510c52018-01-26 22:26:24 +01001256/* Test MO Call SETUP with no response from MNCC */
1257private function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001258 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001259
Harald Welte12510c52018-01-26 22:26:24 +01001260 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1261
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001262 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001263
Harald Welteb9e86fa2018-04-09 18:18:31 +02001264 f_establish_fully();
Harald Welte12510c52018-01-26 22:26:24 +01001265 f_create_mncc_expect(hex2str(cpars.called_party));
1266 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1267
1268 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1269
Philipp Maier109e6aa2018-10-17 10:53:32 +02001270 f_expect_clear(185.0);
Harald Welte12510c52018-01-26 22:26:24 +01001271}
1272testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1273 var BSC_ConnHdlr vc_conn;
1274 f_init();
1275
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001276 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001277 vc_conn.done;
1278}
1279
Harald Welte3ab88002018-01-26 22:37:25 +01001280/* Test MO Call with no response to RAN-side CRCX */
1281private function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001282 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001283 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1284 var MNCC_PDU mncc;
1285 var MgcpCommand mgcp_cmd;
1286
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001287 f_perform_lu();
Harald Welte3ab88002018-01-26 22:37:25 +01001288
Harald Welteb9e86fa2018-04-09 18:18:31 +02001289 f_establish_fully();
Harald Welte3ab88002018-01-26 22:37:25 +01001290 f_create_mncc_expect(hex2str(cpars.called_party));
1291 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1292
1293 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1294 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1295 cpars.mncc_callref := mncc.u.signal.callref;
1296 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1297 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1298
1299 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Harald Welte1852a842018-01-26 22:53:36 +01001300 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1301 cpars.mgcp_ep := mgcp_cmd.line.ep;
Harald Welte3ab88002018-01-26 22:37:25 +01001302 /* never respond to this */
1303
Philipp Maier8e58f592018-03-14 11:10:56 +01001304 /* When the connection with the MGW fails, the MSC will first request
1305 * a release via call control. We will answer this request normally. */
1306 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1307 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1308
Harald Welte1ddc7162018-01-27 14:25:46 +01001309 f_expect_clear(30.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001310}
1311testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1312 var BSC_ConnHdlr vc_conn;
1313 f_init();
1314
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001315 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001316 vc_conn.done;
1317}
1318
Harald Welte0cc82d92018-01-26 22:52:34 +01001319/* Test MO Call with reject to RAN-side CRCX */
1320private function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001321 f_init_handler(pars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001322 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1323 var MNCC_PDU mncc;
1324 var MgcpCommand mgcp_cmd;
1325
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001326 f_perform_lu();
Harald Welte0cc82d92018-01-26 22:52:34 +01001327
Harald Welteb9e86fa2018-04-09 18:18:31 +02001328 f_establish_fully();
Harald Welte0cc82d92018-01-26 22:52:34 +01001329 f_create_mncc_expect(hex2str(cpars.called_party));
1330 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1331
1332 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1333 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1334 cpars.mncc_callref := mncc.u.signal.callref;
1335 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1336 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1337
1338 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001339
1340 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1341 * set an endpoint name that fits the pattern. If not, just use the
1342 * endpoint name from the request */
1343 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1344 cpars.mgcp_ep := "rtpbridge/1@mgw";
1345 } else {
1346 cpars.mgcp_ep := mgcp_cmd.line.ep;
1347 }
1348
Harald Welte0cc82d92018-01-26 22:52:34 +01001349 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001350
Harald Welte0cc82d92018-01-26 22:52:34 +01001351 /* Respond to CRCX with error */
1352 var MgcpResponse mgcp_rsp := {
1353 line := {
1354 code := "542",
1355 trans_id := mgcp_cmd.line.trans_id,
1356 string := "FORCED_FAIL"
1357 },
Harald Welte0cc82d92018-01-26 22:52:34 +01001358 sdp := omit
1359 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001360 var MgcpParameter mgcp_rsp_param := {
1361 code := "Z",
1362 val := cpars.mgcp_ep
1363 };
1364 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte0cc82d92018-01-26 22:52:34 +01001365 MGCP.send(mgcp_rsp);
1366
1367 timer T := 30.0;
1368 T.start;
1369 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001370 [] T.timeout {
1371 setverdict(fail, "Timeout waiting for channel release");
1372 mtc.stop;
1373 }
Daniel Willmann5868e622018-02-15 17:42:59 +01001374 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
1375 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1376 repeat;
1377 }
Harald Welte0cc82d92018-01-26 22:52:34 +01001378 [] MNCC.receive { repeat; }
1379 [] GSUP.receive { repeat; }
Philipp Maierc6e06f72018-04-11 18:12:23 +02001380 /* Note: As we did not respond properly to the CRCX from the MSC we
1381 * expect the MSC to omit any further MGCP operation (At least in the
1382 * the current implementation, there is no recovery mechanism implemented
1383 * and a DLCX can not be performed as the MSC does not know a specific
1384 * endpoint yet. */
Daniel Willmannafce8662018-07-06 23:11:32 +02001385 [] MGCP.receive {
1386 setverdict(fail, "Unexpected MGCP message");
1387 mtc.stop;
1388 }
Harald Welte5946b332018-03-18 23:32:21 +01001389 [] as_clear_cmd_compl_disc();
Harald Welte0cc82d92018-01-26 22:52:34 +01001390 }
1391}
1392testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1393 var BSC_ConnHdlr vc_conn;
1394 f_init();
1395
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001396 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001397 vc_conn.done;
1398}
1399
Harald Welte3ab88002018-01-26 22:37:25 +01001400
Harald Welte812f7a42018-01-27 00:49:18 +01001401/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1402private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1403 var MNCC_PDU mncc;
1404 var MgcpCommand mgcp_cmd;
1405 var OCT4 tmsi;
1406
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001407 f_perform_lu();
Harald Welte812f7a42018-01-27 00:49:18 +01001408 if (isvalue(g_pars.tmsi)) {
1409 tmsi := g_pars.tmsi;
1410 } else {
1411 tmsi := 'FFFFFFFF'O;
1412 }
1413 f_bssmap_register_imsi(g_pars.imsi, tmsi);
1414
1415 /* Allocate call reference and send SETUP via MNCC to MSC */
1416 cpars.mncc_callref := f_rnd_int(2147483648);
1417 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1418 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1419
1420 /* MSC->BSC: expect PAGING from MSC */
1421 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
1422 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001423 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001424
1425 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1426
1427 /* MSC->MS: SETUP */
1428 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1429}
1430
1431/* Test MT Call */
1432private function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001433 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001434 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1435 var MNCC_PDU mncc;
1436 var MgcpCommand mgcp_cmd;
1437
1438 f_mt_call_start(cpars);
1439
1440 /* MS->MSC: CALL CONFIRMED */
1441 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1442
1443 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1444
1445 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1446 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001447
1448 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1449 * set an endpoint name that fits the pattern. If not, just use the
1450 * endpoint name from the request */
1451 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1452 cpars.mgcp_ep := "rtpbridge/1@mgw";
1453 } else {
1454 cpars.mgcp_ep := mgcp_cmd.line.ep;
1455 }
1456
Harald Welte812f7a42018-01-27 00:49:18 +01001457 /* Respond to CRCX with error */
1458 var MgcpResponse mgcp_rsp := {
1459 line := {
1460 code := "542",
1461 trans_id := mgcp_cmd.line.trans_id,
1462 string := "FORCED_FAIL"
1463 },
Harald Welte812f7a42018-01-27 00:49:18 +01001464 sdp := omit
1465 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001466 var MgcpParameter mgcp_rsp_param := {
1467 code := "Z",
1468 val := cpars.mgcp_ep
1469 };
1470 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001471 MGCP.send(mgcp_rsp);
1472
1473 timer T := 30.0;
1474 T.start;
1475 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001476 [] T.timeout {
1477 setverdict(fail, "Timeout waiting for channel release");
1478 mtc.stop;
1479 }
Harald Welte812f7a42018-01-27 00:49:18 +01001480 [] BSSAP.receive { repeat; }
1481 [] MNCC.receive { repeat; }
1482 [] GSUP.receive { repeat; }
1483 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1484 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1485 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1486 repeat;
1487 }
1488 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001489 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001490 }
1491}
1492testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1493 var BSC_ConnHdlr vc_conn;
1494 f_init();
1495
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001496 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001497 vc_conn.done;
1498}
1499
1500
1501/* Test MT Call T310 timer */
1502private function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001503 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001504 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1505 var MNCC_PDU mncc;
1506 var MgcpCommand mgcp_cmd;
1507
1508 f_mt_call_start(cpars);
1509
1510 /* MS->MSC: CALL CONFIRMED */
1511 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1512 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1513
1514 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1515 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1516 cpars.mgcp_ep := mgcp_cmd.line.ep;
1517 /* FIXME: Respond to CRCX */
1518
1519 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1520 timer T := 190.0;
1521 T.start;
1522 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001523 [] T.timeout {
1524 setverdict(fail, "Timeout waiting for T310");
1525 mtc.stop;
1526 }
Harald Welte812f7a42018-01-27 00:49:18 +01001527 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1528 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1529 }
1530 }
1531 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1532 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1533 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1534 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1535
1536 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001537 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1538 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1539 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1540 repeat;
1541 }
Harald Welte5946b332018-03-18 23:32:21 +01001542 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001543 }
1544}
1545testcase TC_mt_t310() runs on MTC_CT {
1546 var BSC_ConnHdlr vc_conn;
1547 f_init();
1548
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001549 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001550 vc_conn.done;
1551}
1552
Harald Welte167458a2018-01-27 15:58:16 +01001553/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
1554private function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1555 f_init_handler(pars);
1556 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1557 cpars.bss_rtp_port := 1110;
1558 cpars.mgcp_connection_id_bss := '22222'H;
1559 cpars.mgcp_connection_id_mss := '33333'H;
Daniel Willmann9b0235b2018-07-24 12:13:34 +02001560 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte167458a2018-01-27 15:58:16 +01001561
1562 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001563 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001564
1565 /* First MO call should succeed */
1566 f_mo_call(cpars);
1567
1568 /* Cancel the subscriber in the VLR */
1569 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1570 alt {
1571 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1572 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1573 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001574 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001575 }
1576 }
1577
1578 /* Follow-up transactions should fail */
1579 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1580 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
1581 f_bssap_compl_l3(l3_info);
1582 alt {
1583 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1584 [] BSSAP.receive {
1585 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001586 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001587 }
1588 }
1589 setverdict(pass);
1590}
1591testcase TC_gsup_cancel() runs on MTC_CT {
1592 var BSC_ConnHdlr vc_conn;
1593 f_init();
1594
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001595 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33);
Harald Welte167458a2018-01-27 15:58:16 +01001596 vc_conn.done;
1597}
1598
Harald Welte9de84792018-01-28 01:06:35 +01001599/* A5/1 only permitted on network side, and MS capable to do it */
1600private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1601 pars.net.expect_auth := true;
1602 pars.net.expect_ciph := true;
1603 pars.net.kc_support := '02'O; /* A5/1 only */
1604 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001605 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001606}
1607testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1608 var BSC_ConnHdlr vc_conn;
1609 f_init();
1610 f_vty_config(MSCVTY, "network", "authentication required");
1611 f_vty_config(MSCVTY, "network", "encryption a5 1");
1612
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001613 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001614 vc_conn.done;
1615}
1616
1617/* A5/3 only permitted on network side, and MS capable to do it */
1618private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1619 pars.net.expect_auth := true;
1620 pars.net.expect_ciph := true;
1621 pars.net.kc_support := '08'O; /* A5/3 only */
1622 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001623 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001624}
1625testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1626 var BSC_ConnHdlr vc_conn;
1627 f_init();
1628 f_vty_config(MSCVTY, "network", "authentication required");
1629 f_vty_config(MSCVTY, "network", "encryption a5 3");
1630
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001631 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001632 vc_conn.done;
1633}
1634
1635/* A5/3 only permitted on network side, and MS with only A5/1 support */
1636private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1637 pars.net.expect_auth := true;
1638 pars.net.expect_ciph := true;
1639 pars.net.kc_support := '08'O; /* A5/3 only */
1640 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1641 f_init_handler(pars, 15.0);
1642
1643 /* cannot use f_perform_lu() as we expect a reject */
1644 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1645 f_create_gsup_expect(hex2str(g_pars.imsi));
1646 f_bssap_compl_l3(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001647 if (pars.send_early_cm) {
1648 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1649 } else {
1650 pars.cm1.esind := '0'B;
1651 }
Harald Welte9de84792018-01-28 01:06:35 +01001652 f_mm_auth();
1653 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001654 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1655 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1656 repeat;
1657 }
Harald Welte5946b332018-03-18 23:32:21 +01001658 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1659 f_expect_clear();
1660 }
Harald Welte9de84792018-01-28 01:06:35 +01001661 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1662 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001663 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001664 }
1665 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001666 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001667 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001668 }
1669 }
1670 setverdict(pass);
1671}
1672testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1673 var BSC_ConnHdlr vc_conn;
1674 f_init();
1675 f_vty_config(MSCVTY, "network", "authentication required");
1676 f_vty_config(MSCVTY, "network", "encryption a5 3");
1677
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001678 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360);
1679 vc_conn.done;
1680}
1681testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1682 var BSC_ConnHdlrPars pars;
1683 var BSC_ConnHdlr vc_conn;
1684 f_init();
1685 f_vty_config(MSCVTY, "network", "authentication required");
1686 f_vty_config(MSCVTY, "network", "encryption a5 3");
1687
1688 pars := f_init_pars(361);
1689 pars.send_early_cm := false;
1690 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001691 vc_conn.done;
1692}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001693testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1694 var BSC_ConnHdlr vc_conn;
1695 f_init();
1696 f_vty_config(MSCVTY, "network", "authentication required");
1697 f_vty_config(MSCVTY, "network", "encryption a5 3");
1698
1699 /* Make sure the MSC category is on DEBUG level to trigger the log
1700 * message that is reported in OS#2947 to trigger the segfault */
1701 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1702
1703 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362);
1704 vc_conn.done;
1705}
Harald Welte9de84792018-01-28 01:06:35 +01001706
1707/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1708private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1709 pars.net.expect_auth := true;
1710 pars.net.expect_ciph := true;
1711 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1712 pars.cm1.a5_1 := '1'B;
1713 pars.cm2.a5_1 := '1'B;
1714 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1715 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1716 f_init_handler(pars, 15.0);
1717
1718 /* cannot use f_perform_lu() as we expect a reject */
1719 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1720 f_create_gsup_expect(hex2str(g_pars.imsi));
1721 f_bssap_compl_l3(l3_lu);
1722 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1723 f_mm_auth();
1724 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001725 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1726 f_expect_clear();
1727 }
Harald Welte9de84792018-01-28 01:06:35 +01001728 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1729 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001730 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001731 }
1732 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001733 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001734 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001735 }
1736 }
1737 setverdict(pass);
1738}
1739testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1740 var BSC_ConnHdlr vc_conn;
1741 f_init();
1742 f_vty_config(MSCVTY, "network", "authentication required");
1743 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1744
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001745 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37);
Harald Welte9de84792018-01-28 01:06:35 +01001746 vc_conn.done;
1747}
1748
1749/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1750private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1751 pars.net.expect_auth := true;
1752 pars.net.expect_ciph := true;
1753 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1754 pars.cm1.a5_1 := '1'B;
1755 pars.cm2.a5_1 := '1'B;
1756 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1757 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1758 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001759 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001760}
1761testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1762 var BSC_ConnHdlr vc_conn;
1763 f_init();
1764 f_vty_config(MSCVTY, "network", "authentication required");
1765 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1766
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001767 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001768 vc_conn.done;
1769}
1770
Harald Welte33ec09b2018-02-10 15:34:46 +01001771/* LU followed by MT call (including paging) */
1772private function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1773 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001774 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte33ec09b2018-02-10 15:34:46 +01001775 cpars.bss_rtp_port := 1110;
1776 cpars.mgcp_connection_id_bss := '10004'H;
1777 cpars.mgcp_connection_id_mss := '10005'H;
1778
Philipp Maier4b2692d2018-03-14 16:37:48 +01001779 /* Note: This is an optional parameter. When the call-agent (MSC) does
1780 * supply a full endpoint name this setting will be overwritten. */
1781 cpars.mgcp_ep := "rtpbridge/1@mgw";
1782
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001783 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001784 f_mt_call(cpars);
1785}
1786testcase TC_lu_and_mt_call() runs on MTC_CT {
1787 var BSC_ConnHdlr vc_conn;
1788 f_init();
1789
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001790 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001791 vc_conn.done;
1792}
1793
Daniel Willmann8b084372018-02-04 13:35:26 +01001794/* Test MO Call SETUP with DTMF */
1795private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1796 f_init_handler(pars);
1797 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1798 cpars.bss_rtp_port := 1110;
1799 cpars.mgcp_connection_id_bss := '22222'H;
1800 cpars.mgcp_connection_id_mss := '33333'H;
1801
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001802 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001803 f_mo_seq_dtmf_dup(cpars);
1804}
1805testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1806 var BSC_ConnHdlr vc_conn;
1807 f_init();
1808
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001809 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001810 vc_conn.done;
1811}
Harald Welte9de84792018-01-28 01:06:35 +01001812
Philipp Maier328d1662018-03-07 10:40:27 +01001813testcase TC_cr_before_reset() runs on MTC_CT {
1814 timer T := 4.0;
1815 var boolean reset_ack_seen := false;
1816 f_init_bssap_direct();
1817
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02001818 f_bssap_start(g_bssap[0]);
1819
Daniel Willmanne8018962018-08-21 14:18:00 +02001820 f_sleep(3.0);
1821
Philipp Maier328d1662018-03-07 10:40:27 +01001822 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001823 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001824
1825 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001826 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001827 T.start
1828 alt {
1829 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1830 reset_ack_seen := true;
1831 repeat;
1832 }
1833
1834 /* Acknowledge MSC sided reset requests */
1835 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001836 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001837 repeat;
1838 }
1839
1840 /* Ignore all other messages (e.g CR from the connection request) */
1841 [] BSSAP_DIRECT.receive { repeat }
1842
1843 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1844 * deadlock situation. The MSC is then unable to respond to any
1845 * further BSSMAP RESET or any other sort of traffic. */
1846 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1847 [reset_ack_seen == false] T.timeout {
1848 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02001849 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01001850 }
1851 }
1852}
Harald Welte9de84792018-01-28 01:06:35 +01001853
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001854/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
1855private function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1856 f_init_handler(pars);
1857 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1858 var MNCC_PDU mncc;
1859 var MgcpCommand mgcp_cmd;
1860
1861 f_perform_lu();
1862
Harald Welteb9e86fa2018-04-09 18:18:31 +02001863 f_establish_fully();
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001864 f_create_mncc_expect(hex2str(cpars.called_party));
1865 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1866
1867 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1868 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1869 cpars.mncc_callref := mncc.u.signal.callref;
1870 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1871 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1872
1873 /* Drop CRCX */
1874 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1875
1876 /* Drop DTAP Release */
1877 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1878
1879 /* Drop resent DTAP Release */
1880 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1881
1882 f_expect_clear(60.0);
1883}
1884testcase TC_mo_release_timeout() runs on MTC_CT {
1885 var BSC_ConnHdlr vc_conn;
1886 f_init();
1887
1888 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1889 vc_conn.done;
1890}
1891
Harald Welte12510c52018-01-26 22:26:24 +01001892
Philipp Maier2a98a732018-03-19 16:06:12 +01001893/* LU followed by MT call (including paging) */
1894private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1895 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001896 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01001897 cpars.bss_rtp_port := 1110;
1898 cpars.mgcp_connection_id_bss := '10004'H;
1899 cpars.mgcp_connection_id_mss := '10005'H;
1900
1901 /* Note: This is an optional parameter. When the call-agent (MSC) does
1902 * supply a full endpoint name this setting will be overwritten. */
1903 cpars.mgcp_ep := "rtpbridge/1@mgw";
1904
1905 /* Intentionally disable the CRCX response */
1906 cpars.mgw_drop_dlcx := true;
1907
1908 /* Perform location update and call */
1909 f_perform_lu();
1910 f_mt_call(cpars);
1911}
1912testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
1913 var BSC_ConnHdlr vc_conn;
1914 f_init();
1915
1916 /* Perform an almost normal looking locationupdate + mt-call, but do
1917 * not respond to the DLCX at the end of the call */
1918 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
1919 vc_conn.done;
1920
1921 /* Wait a guard period until the MGCP layer in the MSC times out,
1922 * if the MSC is vulnerable to the use-after-free situation that is
1923 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
1924 * segfault now */
1925 f_sleep(6.0);
1926
1927 /* Run the init procedures once more. If the MSC has crashed, this
1928 * this will fail */
1929 f_init();
1930}
Harald Welte45164da2018-01-24 12:51:27 +01001931
Philipp Maier75932982018-03-27 14:52:35 +02001932/* Two BSSMAP resets from two different BSCs */
1933testcase TC_reset_two() runs on MTC_CT {
1934 var BSC_ConnHdlr vc_conn;
1935 f_init(2);
1936 f_sleep(2.0);
1937 setverdict(pass);
1938}
1939
Harald Weltef640a012018-04-14 17:49:21 +02001940/***********************************************************************
1941 * SMS Testing
1942 ***********************************************************************/
1943
Harald Weltef45efeb2018-04-09 18:19:24 +02001944/* LU followed by MO SMS */
1945private function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1946 var SmsParameters spars := valueof(t_SmsPars);
1947
1948 f_init_handler(pars);
1949
1950 /* Perform location update and call */
1951 f_perform_lu();
1952
1953 f_establish_fully(EST_TYPE_MO_SMS);
1954
1955 //spars.exp_rp_err := 96; /* invalid mandatory information */
1956 f_mo_sms(spars);
1957
1958 f_expect_clear();
1959}
1960testcase TC_lu_and_mo_sms() runs on MTC_CT {
1961 var BSC_ConnHdlr vc_conn;
1962 f_init();
1963 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
1964 vc_conn.done;
1965}
1966
1967private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
1968runs on MTC_CT {
1969 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
1970}
1971
1972/* LU followed by MT SMS */
1973private function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1974 var SmsParameters spars := valueof(t_SmsPars);
1975 var OCT4 tmsi;
1976
1977 f_init_handler(pars);
1978
1979 /* Perform location update and call */
1980 f_perform_lu();
1981
1982 /* register an 'expect' for given IMSI (+TMSI) */
1983 if (isvalue(g_pars.tmsi)) {
1984 tmsi := g_pars.tmsi;
1985 } else {
1986 tmsi := 'FFFFFFFF'O;
1987 }
1988 f_bssmap_register_imsi(g_pars.imsi, tmsi);
1989
1990 /* FIXME: actually cause MSC to send a SMS via VTY or SMPP */
1991
1992 /* MSC->BSC: expect PAGING from MSC */
1993 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
1994 /* Establish DTAP / BSSAP / SCCP connection */
1995 f_establish_fully(EST_TYPE_PAG_RESP);
1996
1997 spars.tp.ud := 'C8329BFD064D9B53'O;
1998 f_mt_sms(spars);
1999
2000 f_expect_clear();
2001}
2002testcase TC_lu_and_mt_sms() runs on MTC_CT {
2003 var BSC_ConnHdlrPars pars;
2004 var BSC_ConnHdlr vc_conn;
2005 f_init();
2006 pars := f_init_pars(43);
2007 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
2008 f_sleep(2.0);
2009 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2010 vc_conn.done;
2011}
2012
Philipp Maier3983e702018-11-22 19:01:33 +01002013/* Paging for MT SMS but no response */
2014private function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2015 var SmsParameters spars := valueof(t_SmsPars);
2016 var OCT4 tmsi;
2017 var integer page_count := 0;
2018 f_init_handler(pars, 150.0);
2019
2020 /* Perform location update */
2021 f_perform_lu();
2022
2023 /* register an 'expect' for given IMSI (+TMSI) */
2024 if (isvalue(g_pars.tmsi)) {
2025 tmsi := g_pars.tmsi;
2026 } else {
2027 tmsi := 'FFFFFFFF'O;
2028 }
2029 f_bssmap_register_imsi(g_pars.imsi, tmsi);
2030
2031 /* Expect the MSC to page exactly 10 times before giving up */
2032 alt {
2033 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi))
2034 {
2035 page_count := page_count + 1;
2036
2037 if (page_count < 10) {
2038 repeat;
2039 }
2040 }
2041 [] BSSAP.receive {
2042 setverdict(fail, "unexpected BSSAP message received");
2043 self.stop;
2044 }
2045 }
2046
2047 /* Wait some time to make sure the MSC is not delivering any further
2048 * paging messages or anything else that could be unexpected. */
2049 timer T := 20.0;
2050 T.start
2051 alt {
2052 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi))
2053 {
2054 setverdict(fail, "paging seems not to stop!");
2055 mtc.stop;
2056 }
2057 [] BSSAP.receive {
2058 setverdict(fail, "unexpected BSSAP message received");
2059 self.stop;
2060 }
2061 [] T.timeout {
2062 setverdict(pass);
2063 }
2064 }
2065
2066 setverdict(pass);
2067}
2068testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2069 var BSC_ConnHdlrPars pars;
2070 var BSC_ConnHdlr vc_conn;
2071 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002072 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002073 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
2074 f_sleep(2.0);
2075 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2076 vc_conn.done;
2077}
2078
Harald Weltef640a012018-04-14 17:49:21 +02002079/* mobile originated SMS from MS/BTS/BSC side to SMPP */
2080private function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2081 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002082
Harald Weltef640a012018-04-14 17:49:21 +02002083 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002084
Harald Weltef640a012018-04-14 17:49:21 +02002085 /* Perform location update so IMSI is known + registered in MSC/VLR */
2086 f_perform_lu();
2087 f_establish_fully(EST_TYPE_MO_SMS);
2088
2089 f_mo_sms(spars);
2090
2091 var SMPP_PDU smpp;
2092 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2093 tr_smpp.body.deliver_sm := {
2094 service_type := "CMT",
2095 source_addr_ton := network_specific,
2096 source_addr_npi := isdn,
2097 source_addr := hex2str(pars.msisdn),
2098 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2099 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2100 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2101 esm_class := '00000001'B,
2102 protocol_id := 0,
2103 priority_flag := 0,
2104 schedule_delivery_time := "",
2105 replace_if_present := 0,
2106 data_coding := '00000001'B,
2107 sm_default_msg_id := 0,
2108 sm_length := ?,
2109 short_message := spars.tp.ud,
2110 opt_pars := {
2111 {
2112 tag := user_message_reference,
2113 len := 2,
2114 opt_value := {
2115 int2_val := oct2int(spars.tp.msg_ref)
2116 }
2117 }
2118 }
2119 };
2120 alt {
2121 [] SMPP.receive(tr_smpp) -> value smpp {
2122 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2123 }
2124 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2125 }
2126
2127 f_expect_clear();
2128}
2129testcase TC_smpp_mo_sms() runs on MTC_CT {
2130 var BSC_ConnHdlr vc_conn;
2131 f_init();
2132 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2133 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2134 vc_conn.done;
2135 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2136}
2137
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002138/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
2139private function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
2140runs on BSC_ConnHdlr {
2141 var SmsParameters spars := valueof(t_SmsPars);
2142 var GSUP_PDU gsup_msg_rx;
2143 var octetstring sm_tpdu;
2144
2145 f_init_handler(pars);
2146
2147 /* We need to inspect GSUP activity */
2148 f_create_gsup_expect(hex2str(g_pars.imsi));
2149
2150 /* Perform location update */
2151 f_perform_lu();
2152
2153 /* Send CM Service Request for SMS */
2154 f_establish_fully(EST_TYPE_MO_SMS);
2155
2156 /* Prepare expected SM-RP-UI (SM TPDU) */
2157 enc_TPDU_RP_DATA_MS_SGSN_fast(
2158 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2159 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2160 spars.tp.udl, spars.tp.ud)),
2161 sm_tpdu);
2162
2163 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2164 imsi := g_pars.imsi,
2165 sm_rp_mr := spars.rp.msg_ref,
2166 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2167 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(?),
2168 /* FIXME: MSISDN coding troubles */
2169 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(?),
2170 /* TODO: can we use decmatch here? */
2171 sm_rp_ui := sm_tpdu
2172 );
2173
2174 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2175 f_mo_sms_submit(spars);
2176 alt {
2177 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
2178 log("RX MO-forwardSM-Req");
2179 log(gsup_msg_rx);
2180 setverdict(pass);
2181 }
2182 [] GSUP.receive {
2183 log("RX unexpected GSUP message");
2184 setverdict(fail);
2185 mtc.stop;
2186 }
2187 }
2188
2189 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2190 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2191 imsi := g_pars.imsi,
2192 sm_rp_mr := spars.rp.msg_ref)));
2193 /* Expect RP-ACK on DTAP */
2194 f_mo_sms_wait_rp_ack(spars);
2195
2196 f_expect_clear();
2197}
2198testcase TC_gsup_mo_sms() runs on MTC_CT {
2199 var BSC_ConnHdlr vc_conn;
2200 f_init();
2201 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2202 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2203 vc_conn.done;
2204 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2205}
2206
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002207/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
2208private function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
2209runs on BSC_ConnHdlr {
2210 var SmsParameters spars := valueof(t_SmsPars);
2211 var GSUP_PDU gsup_msg_rx;
2212
2213 f_init_handler(pars);
2214
2215 /* We need to inspect GSUP activity */
2216 f_create_gsup_expect(hex2str(g_pars.imsi));
2217
2218 /* Perform location update */
2219 f_perform_lu();
2220
2221 /* Send CM Service Request for SMS */
2222 f_establish_fully(EST_TYPE_MO_SMS);
2223
2224 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2225 imsi := g_pars.imsi,
2226 sm_rp_mr := spars.rp.msg_ref,
2227 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2228 );
2229
2230 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2231 f_mo_smma(spars);
2232 alt {
2233 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
2234 log("RX MO-ReadyForSM-Req");
2235 log(gsup_msg_rx);
2236 setverdict(pass);
2237 }
2238 [] GSUP.receive {
2239 log("RX unexpected GSUP message");
2240 setverdict(fail);
2241 mtc.stop;
2242 }
2243 }
2244
2245 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2246 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2247 imsi := g_pars.imsi,
2248 sm_rp_mr := spars.rp.msg_ref)));
2249 /* Expect RP-ACK on DTAP */
2250 f_mo_sms_wait_rp_ack(spars);
2251
2252 f_expect_clear();
2253}
2254testcase TC_gsup_mo_smma() runs on MTC_CT {
2255 var BSC_ConnHdlr vc_conn;
2256 f_init();
2257 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2258 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2259 vc_conn.done;
2260 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2261}
2262
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002263/* Helper for sending MT SMS over GSUP */
2264private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2265runs on BSC_ConnHdlr {
2266 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2267 imsi := g_pars.imsi,
2268 /* NOTE: MSC should assign RP-MR itself */
2269 sm_rp_mr := 'FF'O,
2270 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2271 /* TODO: fix encoding of ts_GSUP_SM_RP_DA_IMSI */
2272 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(g_pars.msisdn)),
2273 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(g_pars.msisdn)),
2274 /* Encoded SMS TPDU (taken from Wireshark)
2275 * FIXME: we should encode spars somehow */
2276 sm_rp_ui := '00068021436500008111328130858200'O,
2277 sm_rp_mms := mms
2278 ));
2279}
2280
2281/* Test successful MT-SMS (RP-ACK) over GSUP */
2282private function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
2283runs on BSC_ConnHdlr {
2284 var SmsParameters spars := valueof(t_SmsPars);
2285
2286 f_init_handler(pars);
2287
2288 /* We need to inspect GSUP activity */
2289 f_create_gsup_expect(hex2str(g_pars.imsi));
2290
2291 /* Perform location update */
2292 f_perform_lu();
2293
2294 /* Register an 'expect' for given IMSI (+TMSI) */
2295 if (isvalue(g_pars.tmsi)) {
2296 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2297 } else {
2298 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2299 }
2300
2301 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2302 imsi := g_pars.imsi,
2303 /* NOTE: MSC should assign RP-MR itself */
2304 sm_rp_mr := ?
2305 );
2306
2307 /* Submit a MT SMS on GSUP */
2308 f_gsup_forwardSM_req(spars);
2309
2310 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
2311 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2312 f_establish_fully(EST_TYPE_PAG_RESP);
2313
2314 /* Wait for MT SMS on DTAP */
2315 f_mt_sms_expect(spars);
2316
2317 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2318 f_mt_sms_send_rp_ack(spars);
2319 alt {
2320 [] GSUP.receive(mt_forwardSM_res) {
2321 log("RX MT-forwardSM-Res (RP-ACK)");
2322 setverdict(pass);
2323 }
2324 [] GSUP.receive {
2325 log("RX unexpected GSUP message");
2326 setverdict(fail);
2327 mtc.stop;
2328 }
2329 }
2330
2331 f_expect_clear();
2332}
2333testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2334 var BSC_ConnHdlrPars pars;
2335 var BSC_ConnHdlr vc_conn;
2336 f_init();
2337 pars := f_init_pars(90);
2338 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2339 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2340 vc_conn.done;
2341 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2342}
2343
2344/* Test rejected MT-SMS (RP-ERROR) over GSUP */
2345private function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
2346runs on BSC_ConnHdlr {
2347 var SmsParameters spars := valueof(t_SmsPars);
2348 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2349
2350 f_init_handler(pars);
2351
2352 /* We need to inspect GSUP activity */
2353 f_create_gsup_expect(hex2str(g_pars.imsi));
2354
2355 /* Perform location update */
2356 f_perform_lu();
2357
2358 /* Register an 'expect' for given IMSI (+TMSI) */
2359 if (isvalue(g_pars.tmsi)) {
2360 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2361 } else {
2362 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2363 }
2364
2365 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2366 imsi := g_pars.imsi,
2367 /* NOTE: MSC should assign RP-MR itself */
2368 sm_rp_mr := ?,
2369 sm_rp_cause := sm_rp_cause
2370 );
2371
2372 /* Submit a MT SMS on GSUP */
2373 f_gsup_forwardSM_req(spars);
2374
2375 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
2376 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2377 f_establish_fully(EST_TYPE_PAG_RESP);
2378
2379 /* Wait for MT SMS on DTAP */
2380 f_mt_sms_expect(spars);
2381
2382 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2383 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2384 alt {
2385 [] GSUP.receive(mt_forwardSM_err) {
2386 log("RX MT-forwardSM-Err (RP-ERROR)");
2387 setverdict(pass);
2388 mtc.stop;
2389 }
2390 [] GSUP.receive {
2391 log("RX unexpected GSUP message");
2392 setverdict(fail);
2393 mtc.stop;
2394 }
2395 }
2396
2397 f_expect_clear();
2398}
2399testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2400 var BSC_ConnHdlrPars pars;
2401 var BSC_ConnHdlr vc_conn;
2402 f_init();
2403 pars := f_init_pars(91);
2404 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2405 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2406 vc_conn.done;
2407 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2408}
2409
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002410/* Test SM-RP-MR assignment for MT-SMS over GSUP */
2411private function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
2412runs on BSC_ConnHdlr {
2413 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2414 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2415
2416 f_init_handler(pars);
2417
2418 /* We need to inspect GSUP activity */
2419 f_create_gsup_expect(hex2str(g_pars.imsi));
2420
2421 /* Perform location update */
2422 f_perform_lu();
2423
2424 /* Register an 'expect' for given IMSI (+TMSI) */
2425 if (isvalue(g_pars.tmsi)) {
2426 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2427 } else {
2428 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2429 }
2430
2431 /* Submit the 1st MT SMS on GSUP */
2432 log("TX MT-forwardSM-Req for the 1st SMS");
2433 f_gsup_forwardSM_req(spars1);
2434
2435 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
2436 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2437 f_establish_fully(EST_TYPE_PAG_RESP);
2438
2439 /* Wait for 1st MT SMS on DTAP */
2440 f_mt_sms_expect(spars1);
2441 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2442 ", SM-RP-MR is ", spars1.rp.msg_ref);
2443
2444 /* Submit the 2nd MT SMS on GSUP */
2445 log("TX MT-forwardSM-Req for the 2nd SMS");
2446 f_gsup_forwardSM_req(spars2);
2447
2448 /* Wait for 2nd MT SMS on DTAP */
2449 f_mt_sms_expect(spars2);
2450 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2451 ", SM-RP-MR is ", spars2.rp.msg_ref);
2452
2453 /* Both transaction IDs shall be different */
2454 if (spars1.tid == spars2.tid) {
2455 log("Both DTAP transaction IDs shall be different");
2456 setverdict(fail);
2457 }
2458
2459 /* Both SM-RP-MR values shall be different */
2460 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2461 log("Both SM-RP-MR values shall be different");
2462 setverdict(fail);
2463 }
2464
2465 /* Both SM-RP-MR values shall be assigned */
2466 if (spars1.rp.msg_ref == 'FF'O) {
2467 log("Unassigned SM-RP-MR value for the 1st SMS");
2468 setverdict(fail);
2469 }
2470 if (spars2.rp.msg_ref == 'FF'O) {
2471 log("Unassigned SM-RP-MR value for the 2nd SMS");
2472 setverdict(fail);
2473 }
2474
2475 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2476 f_mt_sms_send_rp_ack(spars1);
2477 alt {
2478 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2479 imsi := g_pars.imsi,
2480 sm_rp_mr := spars1.rp.msg_ref
2481 )) {
2482 log("RX MT-forwardSM-Res (RP-ACK)");
2483 setverdict(pass);
2484 }
2485 [] GSUP.receive {
2486 log("RX unexpected GSUP message");
2487 setverdict(fail);
2488 mtc.stop;
2489 }
2490 }
2491
2492 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2493 f_mt_sms_send_rp_ack(spars2);
2494 alt {
2495 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2496 imsi := g_pars.imsi,
2497 sm_rp_mr := spars2.rp.msg_ref
2498 )) {
2499 log("RX MT-forwardSM-Res (RP-ACK)");
2500 setverdict(pass);
2501 }
2502 [] GSUP.receive {
2503 log("RX unexpected GSUP message");
2504 setverdict(fail);
2505 mtc.stop;
2506 }
2507 }
2508
2509 f_expect_clear();
2510}
2511testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2512 var BSC_ConnHdlrPars pars;
2513 var BSC_ConnHdlr vc_conn;
2514 f_init();
2515 pars := f_init_pars(92);
2516 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2517 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2518 vc_conn.done;
2519 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2520}
2521
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002522/* Test SM-RP-MR assignment for MT-SMS over GSUP */
2523private function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
2524runs on BSC_ConnHdlr {
2525 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2526 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2527
2528 f_init_handler(pars);
2529
2530 /* We need to inspect GSUP activity */
2531 f_create_gsup_expect(hex2str(g_pars.imsi));
2532
2533 /* Perform location update */
2534 f_perform_lu();
2535
2536 /* Register an 'expect' for given IMSI (+TMSI) */
2537 if (isvalue(g_pars.tmsi)) {
2538 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2539 } else {
2540 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2541 }
2542
2543 /* Send CM Service Request for MO SMMA */
2544 f_establish_fully(EST_TYPE_MO_SMS);
2545
2546 /* Submit MO SMMA on DTAP */
2547 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2548 spars_mo.rp.msg_ref := '00'O;
2549 f_mo_smma(spars_mo);
2550
2551 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2552 alt {
2553 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2554 imsi := g_pars.imsi,
2555 sm_rp_mr := spars_mo.rp.msg_ref,
2556 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2557 )) {
2558 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2559 setverdict(pass);
2560 }
2561 [] GSUP.receive {
2562 log("RX unexpected GSUP message");
2563 setverdict(fail);
2564 mtc.stop;
2565 }
2566 }
2567
2568 /* Submit MT SMS on GSUP */
2569 log("TX MT-forwardSM-Req for the MT SMS");
2570 f_gsup_forwardSM_req(spars_mt);
2571
2572 /* Wait for MT SMS on DTAP */
2573 f_mt_sms_expect(spars_mt);
2574 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2575 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2576
2577 /* Both SM-RP-MR values shall be different */
2578 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2579 log("Both SM-RP-MR values shall be different");
2580 setverdict(fail);
2581 }
2582
2583 /* SM-RP-MR value for MT SMS shall be assigned */
2584 if (spars_mt.rp.msg_ref == 'FF'O) {
2585 log("Unassigned SM-RP-MR value for the MT SMS");
2586 setverdict(fail);
2587 }
2588
2589 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2590 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2591 imsi := g_pars.imsi,
2592 sm_rp_mr := spars_mo.rp.msg_ref)));
2593 /* Expect RP-ACK for MO SMMA on DTAP */
2594 f_mo_sms_wait_rp_ack(spars_mo);
2595
2596 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2597 f_mt_sms_send_rp_ack(spars_mt);
2598 alt {
2599 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2600 imsi := g_pars.imsi,
2601 sm_rp_mr := spars_mt.rp.msg_ref
2602 )) {
2603 log("RX MT-forwardSM-Res (RP-ACK)");
2604 setverdict(pass);
2605 }
2606 [] GSUP.receive {
2607 log("RX unexpected GSUP message");
2608 setverdict(fail);
2609 mtc.stop;
2610 }
2611 }
2612
2613 f_expect_clear();
2614}
2615testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
2616 var BSC_ConnHdlrPars pars;
2617 var BSC_ConnHdlr vc_conn;
2618 f_init();
2619 pars := f_init_pars(93);
2620 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2621 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
2622 vc_conn.done;
2623 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2624}
2625
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002626/* Test multi-part MT-SMS over GSUP */
2627private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
2628runs on BSC_ConnHdlr {
2629 var SmsParameters spars := valueof(t_SmsPars);
2630
2631 f_init_handler(pars);
2632
2633 /* We need to inspect GSUP activity */
2634 f_create_gsup_expect(hex2str(g_pars.imsi));
2635
2636 /* Perform location update */
2637 f_perform_lu();
2638
2639 /* Register an 'expect' for given IMSI (+TMSI) */
2640 if (isvalue(g_pars.tmsi)) {
2641 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2642 } else {
2643 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2644 }
2645
2646 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2647 imsi := g_pars.imsi,
2648 /* NOTE: MSC should assign RP-MR itself */
2649 sm_rp_mr := ?
2650 );
2651
2652 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
2653 for (var integer i := 3; i >= 0; i := i-1) {
2654 /* Submit a MT SMS on GSUP (MMS is decremented) */
2655 f_gsup_forwardSM_req(spars, int2oct(i, 1));
2656
2657 /* Expect Paging Request and Establish connection */
2658 if (i == 3) { /* ... only once! */
2659 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2660 f_establish_fully(EST_TYPE_PAG_RESP);
2661 }
2662
2663 /* Wait for MT SMS on DTAP */
2664 f_mt_sms_expect(spars);
2665
2666 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2667 f_mt_sms_send_rp_ack(spars);
2668 alt {
2669 [] GSUP.receive(mt_forwardSM_res) {
2670 log("RX MT-forwardSM-Res (RP-ACK)");
2671 setverdict(pass);
2672 }
2673 [] GSUP.receive {
2674 log("RX unexpected GSUP message");
2675 setverdict(fail);
2676 mtc.stop;
2677 }
2678 }
2679
2680 /* Keep some 'distance' between transmissions */
2681 f_sleep(1.5);
2682 }
2683
2684 f_expect_clear();
2685}
2686testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
2687 var BSC_ConnHdlrPars pars;
2688 var BSC_ConnHdlr vc_conn;
2689 f_init();
2690 pars := f_init_pars(91);
2691 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2692 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
2693 vc_conn.done;
2694 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2695}
2696
Harald Weltef640a012018-04-14 17:49:21 +02002697/* convert GSM L3 TON to SMPP_TON enum */
2698function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
2699 select (ton) {
2700 case ('000'B) { return unknown; }
2701 case ('001'B) { return international; }
2702 case ('010'B) { return national; }
2703 case ('011'B) { return network_specific; }
2704 case ('100'B) { return subscriber_number; }
2705 case ('101'B) { return alphanumeric; }
2706 case ('110'B) { return abbreviated; }
2707 }
2708 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02002709 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002710}
2711/* convert GSM L3 NPI to SMPP_NPI enum */
2712function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2713 select (npi) {
2714 case ('0000'B) { return unknown; }
2715 case ('0001'B) { return isdn; }
2716 case ('0011'B) { return data; }
2717 case ('0100'B) { return telex; }
2718 case ('0110'B) { return land_mobile; }
2719 case ('1000'B) { return national; }
2720 case ('1001'B) { return private_; }
2721 case ('1010'B) { return ermes; }
2722 }
2723 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02002724 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002725}
2726
2727/* build a SMPP_SM from SmsParameters */
2728function f_mt_sm_from_spars(SmsParameters spars)
2729runs on BSC_ConnHdlr return SMPP_SM {
2730 var SMPP_SM sm := {
2731 service_type := "CMT",
2732 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2733 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2734 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2735 dest_addr_ton := international,
2736 dest_addr_npi := isdn,
2737 destination_addr := hex2str(g_pars.msisdn),
2738 esm_class := '00000001'B,
2739 protocol_id := 0,
2740 priority_flag := 0,
2741 schedule_delivery_time := "",
2742 validity_period := "",
2743 registered_delivery := '00000000'B,
2744 replace_if_present := 0,
2745 data_coding := '00000001'B,
2746 sm_default_msg_id := 0,
2747 sm_length := spars.tp.udl,
2748 short_message := spars.tp.ud,
2749 opt_pars := {}
2750 };
2751 return sm;
2752}
2753
2754/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2755private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2756 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2757 if (trans_mode) {
2758 sm.esm_class := '00000010'B;
2759 }
2760
2761 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2762 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2763 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2764 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2765 * before we expect the SMS delivery on the BSC/radio side */
2766 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2767 }
2768
2769 /* MSC->BSC: expect PAGING from MSC */
2770 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2771 /* Establish DTAP / BSSAP / SCCP connection */
2772 f_establish_fully(EST_TYPE_PAG_RESP);
2773 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2774
2775 f_mt_sms(spars);
2776
2777 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2778 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2779 }
2780 f_expect_clear();
2781}
2782
2783/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2784private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2785 f_init_handler(pars);
2786
2787 /* Perform location update so IMSI is known + registered in MSC/VLR */
2788 f_perform_lu();
2789 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2790
2791 /* register an 'expect' for given IMSI (+TMSI) */
2792 var OCT4 tmsi;
2793 if (isvalue(g_pars.tmsi)) {
2794 tmsi := g_pars.tmsi;
2795 } else {
2796 tmsi := 'FFFFFFFF'O;
2797 }
2798 f_bssmap_register_imsi(g_pars.imsi, tmsi);
2799
2800 var SmsParameters spars := valueof(t_SmsPars);
2801 /* TODO: test with more intelligent user data; test different coding schemes */
2802 spars.tp.ud := '00'O;
2803 spars.tp.udl := 1;
2804
2805 /* first test the non-transaction store+forward mode */
2806 f_smpp_mt_sms(spars, false);
2807
2808 /* then test the transaction mode */
2809 f_smpp_mt_sms(spars, true);
2810}
2811testcase TC_smpp_mt_sms() runs on MTC_CT {
2812 var BSC_ConnHdlr vc_conn;
2813 f_init();
2814 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
2815 vc_conn.done;
2816}
2817
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002818/***********************************************************************
2819 * USSD Testing
2820 ***********************************************************************/
2821
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002822private altstep as_unexp_gsup_or_bssap_msg()
2823runs on BSC_ConnHdlr {
2824 [] GSUP.receive {
2825 setverdict(fail, "Unknown/unexpected GSUP received");
2826 self.stop;
2827 }
2828 [] BSSAP.receive {
2829 setverdict(fail, "Unknown/unexpected BSSAP message received");
2830 self.stop;
2831 }
2832}
2833
2834private function f_expect_gsup_msg(template GSUP_PDU msg)
2835runs on BSC_ConnHdlr return GSUP_PDU {
2836 var GSUP_PDU gsup_msg_complete;
2837
2838 alt {
2839 [] GSUP.receive(msg) -> value gsup_msg_complete {
2840 setverdict(pass);
2841 }
2842 /* We don't expect anything else */
2843 [] as_unexp_gsup_or_bssap_msg();
2844 }
2845
2846 return gsup_msg_complete;
2847}
2848
2849private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg)
2850runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
2851 var PDU_DTAP_MT bssap_msg_complete;
2852
2853 alt {
2854 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
2855 setverdict(pass);
2856 }
2857 /* We don't expect anything else */
2858 [] as_unexp_gsup_or_bssap_msg();
2859 }
2860
2861 return bssap_msg_complete.dtap;
2862}
2863
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002864/* LU followed by MO USSD request */
2865private function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002866runs on BSC_ConnHdlr {
2867 f_init_handler(pars);
2868
2869 /* Perform location update */
2870 f_perform_lu();
2871
2872 /* Send CM Service Request for SS/USSD */
2873 f_establish_fully(EST_TYPE_SS_ACT);
2874
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002875 /* We need to inspect GSUP activity */
2876 f_create_gsup_expect(hex2str(g_pars.imsi));
2877
2878 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2879 invoke_id := 5, /* Phone may not start from 0 or 1 */
2880 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2881 ussd_string := "*#100#"
2882 );
2883
2884 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
2885 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
2886 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2887 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
2888 )
2889
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002890 /* Compose a new SS/REGISTER message with request */
2891 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
2892 tid := 1, /* We just need a single transaction */
2893 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002894 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002895 );
2896
2897 /* Compose SS/RELEASE_COMPLETE template with expected response */
2898 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
2899 tid := 1, /* Response should arrive within the same transaction */
2900 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002901 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002902 );
2903
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002904 /* Compose expected MSC -> HLR message */
2905 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
2906 imsi := g_pars.imsi,
2907 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2908 ss := valueof(facility_req)
2909 );
2910
2911 /* To be used for sending response with correct session ID */
2912 var GSUP_PDU gsup_req_complete;
2913
2914 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002915 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002916 /* Expect GSUP message containing the SS payload */
2917 gsup_req_complete := f_expect_gsup_msg(gsup_req);
2918
2919 /* Compose the response from HLR using received session ID */
2920 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
2921 imsi := g_pars.imsi,
2922 sid := gsup_req_complete.ies[1].val.session_id,
2923 state := OSMO_GSUP_SESSION_STATE_END,
2924 ss := valueof(facility_rsp)
2925 );
2926
2927 /* Finally, HLR terminates the session */
2928 GSUP.send(gsup_rsp);
2929 /* Expect RELEASE_COMPLETE message with the response */
2930 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002931
2932 f_expect_clear();
2933}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002934testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002935 var BSC_ConnHdlr vc_conn;
2936 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002937 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002938 vc_conn.done;
2939}
2940
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002941/* LU followed by MT USSD notification */
2942private function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
2943runs on BSC_ConnHdlr {
2944 f_init_handler(pars);
2945
2946 /* Perform location update */
2947 f_perform_lu();
2948
2949 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2950
2951 /* We need to inspect GSUP activity */
2952 f_create_gsup_expect(hex2str(g_pars.imsi));
2953
2954 /* Facility IE with network-originated USSD notification */
2955 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2956 op_code := SS_OP_CODE_USS_NOTIFY,
2957 ussd_string := "Mahlzeit!"
2958 );
2959
2960 /* Facility IE with acknowledgment to the USSD notification */
2961 var template OCTN facility_rsp := enc_SS_FacilityInformation(
2962 /* In case of USSD notification, Return Result is empty */
2963 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
2964 );
2965
2966 /* Compose a new MT SS/REGISTER message with USSD notification */
2967 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
2968 tid := 0, /* FIXME: most likely, it should be 0 */
2969 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
2970 facility := valueof(facility_req)
2971 );
2972
2973 /* Compose HLR -> MSC GSUP message */
2974 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
2975 imsi := g_pars.imsi,
2976 sid := '20000101'O,
2977 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2978 ss := valueof(facility_req)
2979 );
2980
2981 /* Send it to MSC and expect Paging Request */
2982 GSUP.send(gsup_req);
2983 alt {
2984 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2985 setverdict(pass);
2986 }
2987 /* We don't expect anything else */
2988 [] as_unexp_gsup_or_bssap_msg();
2989 }
2990
2991 /* Send Paging Response and expect USSD notification */
2992 f_establish_fully(EST_TYPE_PAG_RESP);
2993 /* Expect MT REGISTER message with USSD notification */
2994 f_expect_mt_dtap_msg(ussd_ntf);
2995
2996 /* Compose a new MO SS/FACILITY message with empty response */
2997 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
2998 tid := 0, /* FIXME: it shall match the request tid */
2999 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3000 facility := valueof(facility_rsp)
3001 );
3002
3003 /* Compose expected MSC -> HLR GSUP message */
3004 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3005 imsi := g_pars.imsi,
3006 sid := '20000101'O,
3007 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3008 ss := valueof(facility_rsp)
3009 );
3010
3011 /* MS sends response to the notification */
3012 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3013 /* Expect GSUP message containing the SS payload */
3014 f_expect_gsup_msg(gsup_rsp);
3015
3016 /* Compose expected MT SS/RELEASE COMPLETE message */
3017 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3018 tid := 0, /* FIXME: it shall match the request tid */
3019 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3020 facility := omit
3021 );
3022
3023 /* Compose MSC -> HLR GSUP message */
3024 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3025 imsi := g_pars.imsi,
3026 sid := '20000101'O,
3027 state := OSMO_GSUP_SESSION_STATE_END
3028 );
3029
3030 /* Finally, HLR terminates the session */
3031 GSUP.send(gsup_term)
3032 /* Expect MT RELEASE COMPLETE without Facility IE */
3033 f_expect_mt_dtap_msg(ussd_term);
3034
3035 f_expect_clear();
3036}
3037testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3038 var BSC_ConnHdlr vc_conn;
3039 f_init();
3040 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3041 vc_conn.done;
3042}
3043
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003044/* LU followed by MT call and MO USSD request during this call */
3045private function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003046runs on BSC_ConnHdlr {
3047 f_init_handler(pars);
3048
3049 /* Call parameters taken from f_tc_lu_and_mt_call */
3050 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3051 cpars.mgcp_connection_id_bss := '10004'H;
3052 cpars.mgcp_connection_id_mss := '10005'H;
3053 cpars.mgcp_ep := "rtpbridge/1@mgw";
3054 cpars.bss_rtp_port := 1110;
3055
3056 /* Perform location update */
3057 f_perform_lu();
3058
3059 /* Establish a MT call */
3060 f_mt_call_establish(cpars);
3061
3062 /* Hold the call for some time */
3063 f_sleep(1.0);
3064
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003065 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3066 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3067 ussd_string := "*#100#"
3068 );
3069
3070 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3071 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3072 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3073 )
3074
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003075 /* Compose a new SS/REGISTER message with request */
3076 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3077 tid := 1, /* We just need a single transaction */
3078 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003079 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003080 );
3081
3082 /* Compose SS/RELEASE_COMPLETE template with expected response */
3083 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3084 tid := 1, /* Response should arrive within the same transaction */
3085 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003086 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003087 );
3088
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003089 /* Compose expected MSC -> HLR message */
3090 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3091 imsi := g_pars.imsi,
3092 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3093 ss := valueof(facility_req)
3094 );
3095
3096 /* To be used for sending response with correct session ID */
3097 var GSUP_PDU gsup_req_complete;
3098
3099 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003100 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003101 /* Expect GSUP message containing the SS payload */
3102 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3103
3104 /* Compose the response from HLR using received session ID */
3105 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3106 imsi := g_pars.imsi,
3107 sid := gsup_req_complete.ies[1].val.session_id,
3108 state := OSMO_GSUP_SESSION_STATE_END,
3109 ss := valueof(facility_rsp)
3110 );
3111
3112 /* Finally, HLR terminates the session */
3113 GSUP.send(gsup_rsp);
3114 /* Expect RELEASE_COMPLETE message with the response */
3115 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003116
3117 /* Hold the call for some time */
3118 f_sleep(1.0);
3119
3120 /* Release the call (does Clear Complete itself) */
3121 f_call_hangup(cpars, true);
3122}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003123testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003124 var BSC_ConnHdlr vc_conn;
3125 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003126 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003127 vc_conn.done;
3128}
3129
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003130/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
3131private function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3132 f_init_handler(pars);
3133 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
3134 var MNCC_PDU mncc;
3135 var MgcpCommand mgcp_cmd;
3136
3137 f_perform_lu();
3138
3139 f_establish_fully();
3140 f_create_mncc_expect(hex2str(cpars.called_party));
3141 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
3142
3143 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
3144 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
3145 cpars.mncc_callref := mncc.u.signal.callref;
3146 log("mncc_callref=", cpars.mncc_callref);
3147 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
3148 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
3149
3150 MNCC.send(ts_MNCC_ALERT_req(cpars.mncc_callref));
3151 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_ALERTING(cpars.transaction_id)));
3152 MGCP.receive(tr_CRCX);
3153
3154 f_sleep(1.0);
3155 BSSAP.send(ts_BSSMAP_ClearRequest(0));
3156
3157 MNCC.receive(tr_MNCC_REL_ind(?, ?)) -> value mncc;
3158
3159 BSSAP.receive(tr_BSSMAP_ClearCommand);
3160 BSSAP.send(ts_BSSMAP_ClearComplete);
3161
3162 f_sleep(1.0);
3163}
3164testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3165 var BSC_ConnHdlr vc_conn;
3166 f_init();
3167
3168 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3169 vc_conn.done;
3170}
3171
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003172/* LU followed by MT call and MT USSD request during this call */
3173private function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
3174runs on BSC_ConnHdlr {
3175 f_init_handler(pars);
3176
3177 /* Call parameters taken from f_tc_lu_and_mt_call */
3178 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3179 cpars.mgcp_connection_id_bss := '10004'H;
3180 cpars.mgcp_connection_id_mss := '10005'H;
3181 cpars.mgcp_ep := "rtpbridge/1@mgw";
3182 cpars.bss_rtp_port := 1110;
3183
3184 /* Perform location update */
3185 f_perform_lu();
3186
3187 /* Establish a MT call */
3188 f_mt_call_establish(cpars);
3189
3190 /* Hold the call for some time */
3191 f_sleep(1.0);
3192
3193 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3194 op_code := SS_OP_CODE_USS_REQUEST,
3195 ussd_string := "Please type anything..."
3196 );
3197
3198 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3199 op_code := SS_OP_CODE_USS_REQUEST,
3200 ussd_string := "Nope."
3201 )
3202
3203 /* Compose MT SS/REGISTER message with network-originated request */
3204 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3205 tid := 0, /* FIXME: most likely, it should be 0 */
3206 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3207 facility := valueof(facility_req)
3208 );
3209
3210 /* Compose HLR -> MSC GSUP message */
3211 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3212 imsi := g_pars.imsi,
3213 sid := '20000101'O,
3214 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3215 ss := valueof(facility_req)
3216 );
3217
3218 /* Send it to MSC */
3219 GSUP.send(gsup_req);
3220 /* Expect MT REGISTER message with USSD request */
3221 f_expect_mt_dtap_msg(ussd_req);
3222
3223 /* Compose a new MO SS/FACILITY message with response */
3224 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3225 tid := 0, /* FIXME: it shall match the request tid */
3226 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3227 facility := valueof(facility_rsp)
3228 );
3229
3230 /* Compose expected MSC -> HLR GSUP message */
3231 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3232 imsi := g_pars.imsi,
3233 sid := '20000101'O,
3234 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3235 ss := valueof(facility_rsp)
3236 );
3237
3238 /* MS sends response */
3239 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3240 f_expect_gsup_msg(gsup_rsp);
3241
3242 /* Compose expected MT SS/RELEASE COMPLETE message */
3243 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3244 tid := 0, /* FIXME: it shall match the request tid */
3245 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3246 facility := omit
3247 );
3248
3249 /* Compose MSC -> HLR GSUP message */
3250 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3251 imsi := g_pars.imsi,
3252 sid := '20000101'O,
3253 state := OSMO_GSUP_SESSION_STATE_END
3254 );
3255
3256 /* Finally, HLR terminates the session */
3257 GSUP.send(gsup_term);
3258 /* Expect MT RELEASE COMPLETE without Facility IE */
3259 f_expect_mt_dtap_msg(ussd_term);
3260
3261 /* Hold the call for some time */
3262 f_sleep(1.0);
3263
3264 /* Release the call (does Clear Complete itself) */
3265 f_call_hangup(cpars, true);
3266}
3267testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3268 var BSC_ConnHdlr vc_conn;
3269 f_init();
3270 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3271 vc_conn.done;
3272}
3273
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003274/* LU followed by MO USSD request and MO Release during transaction */
3275private function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
3276runs on BSC_ConnHdlr {
3277 f_init_handler(pars);
3278
3279 /* Perform location update */
3280 f_perform_lu();
3281
3282 /* Send CM Service Request for SS/USSD */
3283 f_establish_fully(EST_TYPE_SS_ACT);
3284
3285 /* We need to inspect GSUP activity */
3286 f_create_gsup_expect(hex2str(g_pars.imsi));
3287
3288 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3289 invoke_id := 1, /* Initial request */
3290 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3291 ussd_string := "*6766*266#"
3292 );
3293
3294 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3295 invoke_id := 2, /* Counter request */
3296 op_code := SS_OP_CODE_USS_REQUEST,
3297 ussd_string := "Password?!?"
3298 )
3299
3300 /* Compose MO SS/REGISTER message with request */
3301 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3302 tid := 1, /* We just need a single transaction */
3303 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3304 facility := valueof(facility_ms_req)
3305 );
3306
3307 /* Compose expected MSC -> HLR message */
3308 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3309 imsi := g_pars.imsi,
3310 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3311 ss := valueof(facility_ms_req)
3312 );
3313
3314 /* To be used for sending response with correct session ID */
3315 var GSUP_PDU gsup_ms_req_complete;
3316
3317 /* Initiate a new transaction */
3318 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3319 /* Expect GSUP request with original Facility IE */
3320 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3321
3322 /* Compose the response from HLR using received session ID */
3323 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3324 imsi := g_pars.imsi,
3325 sid := gsup_ms_req_complete.ies[1].val.session_id,
3326 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3327 ss := valueof(facility_net_req)
3328 );
3329
3330 /* Compose expected MT SS/FACILITY template with counter request */
3331 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3332 tid := 1, /* Response should arrive within the same transaction */
3333 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3334 facility := valueof(facility_net_req)
3335 );
3336
3337 /* Send response over GSUP */
3338 GSUP.send(gsup_net_req);
3339 /* Expect MT SS/FACILITY message with counter request */
3340 f_expect_mt_dtap_msg(ussd_net_req);
3341
3342 /* Compose MO SS/RELEASE COMPLETE */
3343 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3344 tid := 1, /* Response should arrive within the same transaction */
3345 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3346 facility := omit
3347 /* TODO: cause? */
3348 );
3349
3350 /* Compose expected HLR -> MSC abort message */
3351 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3352 imsi := g_pars.imsi,
3353 sid := gsup_ms_req_complete.ies[1].val.session_id,
3354 state := OSMO_GSUP_SESSION_STATE_END
3355 );
3356
3357 /* Abort transaction */
3358 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3359 /* Expect GSUP message indicating abort */
3360 f_expect_gsup_msg(gsup_abort);
3361
3362 f_expect_clear();
3363}
3364testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3365 var BSC_ConnHdlr vc_conn;
3366 f_init();
3367 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3368 vc_conn.done;
3369}
3370
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003371/* LU followed by MO USSD request and MT Release due to timeout */
3372private function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
3373runs on BSC_ConnHdlr {
3374 f_init_handler(pars);
3375
3376 /* Perform location update */
3377 f_perform_lu();
3378
3379 /* Send CM Service Request for SS/USSD */
3380 f_establish_fully(EST_TYPE_SS_ACT);
3381
3382 /* We need to inspect GSUP activity */
3383 f_create_gsup_expect(hex2str(g_pars.imsi));
3384
3385 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3386 invoke_id := 1,
3387 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3388 ussd_string := "#release_me");
3389
3390 /* Compose MO SS/REGISTER message with request */
3391 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3392 tid := 1, /* An arbitrary transaction identifier */
3393 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3394 facility := valueof(facility_ms_req));
3395
3396 /* Compose expected MSC -> HLR message */
3397 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3398 imsi := g_pars.imsi,
3399 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3400 ss := valueof(facility_ms_req));
3401
3402 /* To be used for sending response with correct session ID */
3403 var GSUP_PDU gsup_ms_req_complete;
3404
3405 /* Initiate a new SS transaction */
3406 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3407 /* Expect GSUP request with original Facility IE */
3408 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3409
3410 /* Don't respond, wait for timeout */
3411 f_sleep(3.0);
3412
3413 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3414 tid := 1, /* Should match the request's tid */
3415 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3416 cause := *, /* TODO: expect some specific value */
3417 facility := omit);
3418
3419 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3420 imsi := g_pars.imsi,
3421 sid := gsup_ms_req_complete.ies[1].val.session_id,
3422 state := OSMO_GSUP_SESSION_STATE_END,
3423 cause := ?); /* TODO: expect some specific value */
3424
3425 /* Expect release on both interfaces */
3426 interleave {
3427 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3428 [] GSUP.receive(gsup_rel) { };
3429 }
3430
3431 f_expect_clear();
3432 setverdict(pass);
3433}
3434testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3435 var BSC_ConnHdlr vc_conn;
3436 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003437 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003438 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3439 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003440 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003441}
3442
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003443/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
3444private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3445 pars.net.expect_auth := true;
3446 pars.net.expect_ciph := true;
3447 pars.net.kc_support := '02'O; /* A5/1 only */
3448 f_init_handler(pars);
3449
3450 g_pars.vec := f_gen_auth_vec_2g();
3451
3452 /* Can't use f_perform_lu() directly. Code below is based on it. */
3453
3454 /* tell GSUP dispatcher to send this IMSI to us */
3455 f_create_gsup_expect(hex2str(g_pars.imsi));
3456
3457 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3458 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
3459 f_bssap_compl_l3(l3_lu);
3460
3461 f_mm_auth();
3462
3463 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3464 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3465 alt {
3466 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3467 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
3468 }
3469 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3470 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3471 mtc.stop;
3472 }
3473 [] BSSAP.receive {
3474 setverdict(fail, "Unknown/unexpected BSSAP received");
3475 mtc.stop;
3476 }
3477 }
3478
3479 /* Expect LU reject from MSC. */
3480 alt {
3481 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3482 setverdict(pass);
3483 }
3484 [] BSSAP.receive {
3485 setverdict(fail, "Unknown/unexpected BSSAP received");
3486 mtc.stop;
3487 }
3488 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01003489 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003490}
3491
3492testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
3493 var BSC_ConnHdlr vc_conn;
3494 f_init();
3495 f_vty_config(MSCVTY, "network", "encryption a5 1");
3496
3497 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52);
3498 vc_conn.done;
3499}
3500
Harald Weltef640a012018-04-14 17:49:21 +02003501/* TODO (SMS):
3502 * different user data lengths
3503 * SMPP transaction mode with unsuccessful delivery
3504 * queued MT-SMS with no paging response + later delivery
3505 * different data coding schemes
3506 * multi-part SMS
3507 * user-data headers
3508 * TP-PID for SMS to SIM
3509 * behavior if SMS memory is full + RP-SMMA
3510 * delivery reports
3511 * SMPP osmocom extensions
3512 * more-messages-to-send
3513 * SMS during ongoing call (SACCH/SAPI3)
3514 */
3515
3516/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01003517 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
3518 * malformed messages (missing IE, invalid message type): properly rejected?
3519 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
3520 * 3G/2G auth permutations
3521 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01003522 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01003523 * too long L3 INFO in DTAP
3524 * too long / padded BSSAP
3525 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01003526 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01003527
Harald Welte4263c522018-12-06 11:56:27 +01003528/* Perform a location updatye at the A-Interface and run some checks to confirm
3529 * that everything is back to normal. */
3530private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
3531 var SmsParameters spars := valueof(t_SmsPars);
3532
3533 /* Perform a location update, the SGs association is expected to fall
3534 * back to NULL */
3535 f_perform_lu();
3536 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3537
3538 /* Trigger a paging request and expect the paging on BSSMAP, this is
3539 * to make sure that pagings are sent throught the A-Interface again
3540 * and not throught the SGs interface.*/
3541 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
3542 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3543
3544 alt {
3545 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
3546 setverdict(pass);
3547 }
3548 [] SGsAP.receive {
3549 setverdict(fail, "Received unexpected message on SGs");
3550 }
3551 }
3552
3553 /* Send an SMS to make sure that also payload messages are routed
3554 * throught the A-Interface again */
3555 f_establish_fully(EST_TYPE_MO_SMS);
3556 f_mo_sms(spars);
3557 f_expect_clear();
3558}
3559
3560private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3561 var charstring vlr_name;
3562 f_init_handler(pars);
3563
3564 vlr_name := f_sgsap_reset_mme(mp_mme_name);
3565 log("VLR name: ", vlr_name);
3566 setverdict(pass);
3567}
3568
3569testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003570 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003571 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003572 f_init(1, true);
3573 pars := f_init_pars(11810, true);
3574 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003575 vc_conn.done;
3576}
3577
3578/* like f_mm_auth() but for SGs */
3579function f_mm_auth_sgs() runs on BSC_ConnHdlr {
3580 if (g_pars.net.expect_auth) {
3581 g_pars.vec := f_gen_auth_vec_3g();
3582 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
3583 g_pars.vec.sres,
3584 g_pars.vec.kc,
3585 g_pars.vec.ik,
3586 g_pars.vec.ck,
3587 g_pars.vec.autn,
3588 g_pars.vec.res));
3589 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
3590 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
3591 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
3592 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
3593 }
3594}
3595
3596/* like f_perform_lu(), but on SGs rather than BSSAP */
3597function f_sgs_perform_lu() runs on BSC_ConnHdlr {
3598 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3599 var PDU_SGsAP lur;
3600 var PDU_SGsAP lua;
3601 var PDU_SGsAP mm_info;
3602 var octetstring mm_info_dtap;
3603
3604 /* tell GSUP dispatcher to send this IMSI to us */
3605 f_create_gsup_expect(hex2str(g_pars.imsi));
3606
3607 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3608 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3609 /* Old LAI, if MS sends it */
3610 /* TMSI status, if MS has no valid TMSI */
3611 /* IMEISV, if it supports "automatic device detection" */
3612 /* TAI, if available in MME */
3613 /* E-CGI, if available in MME */
3614 SGsAP.send(lur);
3615
3616 /* FIXME: is this really done over SGs? The Ue is already authenticated
3617 * via the MME ... */
3618 f_mm_auth_sgs();
3619
3620 /* Expect MSC to perform LU with HLR */
3621 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3622 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
3623 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
3624 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
3625
3626 alt {
3627 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
3628 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
3629 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
3630 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
3631 }
3632 setverdict(pass);
3633 }
3634 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3635 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
3636 }
3637 [] SGsAP.receive {
3638 setverdict(fail, "Received unexpected message on SGs");
3639 }
3640 }
3641
3642 /* Check MM information */
3643 if (mp_mm_info == true) {
3644 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
3645 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
3646 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
3647 setverdict(fail, "Unexpected MM Information");
3648 }
3649 }
3650
3651 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3652}
3653
3654private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3655 f_init_handler(pars);
3656 f_sgs_perform_lu();
3657 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3658
3659 f_sgsap_bssmap_screening();
3660
3661 setverdict(pass);
3662}
3663testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003664 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003665 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003666 f_init(1, true);
3667 pars := f_init_pars(11811, true);
3668 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003669 vc_conn.done;
3670}
3671
3672/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
3673private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3674 f_init_handler(pars);
3675 var PDU_SGsAP lur;
3676
3677 f_create_gsup_expect(hex2str(g_pars.imsi));
3678 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3679 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3680 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3681 SGsAP.send(lur);
3682
3683 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3684 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
3685 alt {
3686 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3687 setverdict(pass);
3688 }
3689 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
3690 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
3691 mtc.stop;
3692 }
3693 [] SGsAP.receive {
3694 setverdict(fail, "Received unexpected message on SGs");
3695 }
3696 }
3697
3698 f_sgsap_bssmap_screening();
3699
3700 setverdict(pass);
3701}
3702testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003703 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003704 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003705 f_init(1, true);
3706 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01003707
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003708 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003709 vc_conn.done;
3710}
3711
3712/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
3713private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3714 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3715 var PDU_SGsAP lur;
3716
3717 f_init_handler(pars);
3718
3719 /* tell GSUP dispatcher to send this IMSI to us */
3720 f_create_gsup_expect(hex2str(g_pars.imsi));
3721
3722 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3723 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3724 /* Old LAI, if MS sends it */
3725 /* TMSI status, if MS has no valid TMSI */
3726 /* IMEISV, if it supports "automatic device detection" */
3727 /* TAI, if available in MME */
3728 /* E-CGI, if available in MME */
3729 SGsAP.send(lur);
3730
3731 /* FIXME: is this really done over SGs? The Ue is already authenticated
3732 * via the MME ... */
3733 f_mm_auth_sgs();
3734
3735 /* Expect MSC to perform LU with HLR */
3736 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3737 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
3738 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
3739 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
3740
3741 alt {
3742 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
3743 setverdict(pass);
3744 }
3745 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3746 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
3747 }
3748 [] SGsAP.receive {
3749 setverdict(fail, "Received unexpected message on SGs");
3750 }
3751 }
3752
3753 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3754
3755 /* Wait until the VLR has abort the TMSI reallocation procedure */
3756 f_sleep(45.0);
3757
3758 /* The outcome does not change the SGs state, see also 5.2.3.4 */
3759 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3760
3761 f_sgsap_bssmap_screening();
3762
3763 setverdict(pass);
3764}
3765testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003766 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003767 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003768 f_init(1, true);
3769 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01003770
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003771 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003772 vc_conn.done;
3773}
3774
3775private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
3776runs on BSC_ConnHdlr {
3777 f_init_handler(pars);
3778 f_sgs_perform_lu();
3779 f_sleep(3.0);
3780
3781 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3782 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
3783 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
3784 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3785
3786 f_sgsap_bssmap_screening();
3787
3788 setverdict(pass);
3789}
3790testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003791 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003792 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003793 f_init(1, true);
3794 pars := f_init_pars(11814, true);
3795 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003796 vc_conn.done;
3797}
3798
3799private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
3800runs on BSC_ConnHdlr {
3801 f_init_handler(pars);
3802 f_sgs_perform_lu();
3803 f_sleep(3.0);
3804
3805 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3806 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
3807 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
3808 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3809 /* FIXME: How to verify that VLR has removed MM context? */
3810
3811 f_sgsap_bssmap_screening();
3812
3813 setverdict(pass);
3814}
3815testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003816 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003817 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003818 f_init(1, true);
3819 pars := f_init_pars(11815, true);
3820 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003821 vc_conn.done;
3822}
3823
3824/* Trigger a paging request via VTY and send a paging reject in response */
3825private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
3826runs on BSC_ConnHdlr {
3827 f_init_handler(pars);
3828 f_sgs_perform_lu();
3829 f_sleep(1.0);
3830
3831 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3832 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3833 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3834 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3835
3836 /* Initiate paging via VTY */
3837 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3838 alt {
3839 [] SGsAP.receive(exp_resp) {
3840 setverdict(pass);
3841 }
3842 [] SGsAP.receive {
3843 setverdict(fail, "Received unexpected message on SGs");
3844 }
3845 }
3846
3847 /* Now reject the paging */
3848 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
3849
3850 /* Wait for the states inside the MSC to settle and check the state
3851 * of the SGs Association */
3852 f_sleep(1.0);
3853 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3854
3855 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
3856 * but we also need to cover tha case where the cause code indicates an
3857 * "IMSI detached for EPS services". In those cases the VLR is expected to
3858 * try paging on tha A/Iu interface. This will be another testcase similar to
3859 * this one, but extended with checks for the presence of the A/Iu paging
3860 * messages. */
3861
3862 f_sgsap_bssmap_screening();
3863
3864 setverdict(pass);
3865}
3866testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003867 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003868 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003869 f_init(1, true);
3870 pars := f_init_pars(11816, true);
3871 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003872 vc_conn.done;
3873}
3874
3875/* Trigger a paging request via VTY and send a paging reject that indicates
3876 * that the subscriber intentionally rejected the call. */
3877private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
3878runs on BSC_ConnHdlr {
3879 f_init_handler(pars);
3880 f_sgs_perform_lu();
3881 f_sleep(1.0);
3882
3883 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3884 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3885 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3886 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3887
3888 /* Initiate paging via VTY */
3889 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3890 alt {
3891 [] SGsAP.receive(exp_resp) {
3892 setverdict(pass);
3893 }
3894 [] SGsAP.receive {
3895 setverdict(fail, "Received unexpected message on SGs");
3896 }
3897 }
3898
3899 /* Now reject the paging */
3900 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
3901
3902 /* Wait for the states inside the MSC to settle and check the state
3903 * of the SGs Association */
3904 f_sleep(1.0);
3905 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3906
3907 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
3908 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
3909 * to check back how this works and how it can be tested */
3910
3911 f_sgsap_bssmap_screening();
3912
3913 setverdict(pass);
3914}
3915testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003916 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003917 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003918 f_init(1, true);
3919 pars := f_init_pars(11817, true);
3920 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003921 vc_conn.done;
3922}
3923
3924/* Trigger a paging request via VTY and send an UE unreacable messge in response */
3925private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
3926runs on BSC_ConnHdlr {
3927 f_init_handler(pars);
3928 f_sgs_perform_lu();
3929 f_sleep(1.0);
3930
3931 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3932 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3933 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3934 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3935
3936 /* Initiate paging via VTY */
3937 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3938 alt {
3939 [] SGsAP.receive(exp_resp) {
3940 setverdict(pass);
3941 }
3942 [] SGsAP.receive {
3943 setverdict(fail, "Received unexpected message on SGs");
3944 }
3945 }
3946
3947 /* Now pretend that the UE is unreachable */
3948 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
3949
3950 /* Wait for the states inside the MSC to settle and check the state
3951 * of the SGs Association. */
3952 f_sleep(1.0);
3953 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3954
3955 f_sgsap_bssmap_screening();
3956
3957 setverdict(pass);
3958}
3959testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003960 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003961 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003962 f_init(1, true);
3963 pars := f_init_pars(11818, true);
3964 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003965 vc_conn.done;
3966}
3967
3968/* Trigger a paging request via VTY but don't respond to it */
3969private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
3970runs on BSC_ConnHdlr {
3971 f_init_handler(pars);
3972 f_sgs_perform_lu();
3973 f_sleep(1.0);
3974
3975 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3976 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3977 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3978 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3979
3980 /* Initiate paging via VTY */
3981 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3982 alt {
3983 [] SGsAP.receive(exp_resp) {
3984 setverdict(pass);
3985 }
3986 [] SGsAP.receive {
3987 setverdict(fail, "Received unexpected message on SGs");
3988 }
3989 }
3990
3991 /* Now do nothing, the MSC/VLR should fail silently to page after a
3992 * few seconds, The SGs association must remain unchanged. */
3993 f_sleep(15.0);
3994 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3995
3996 f_sgsap_bssmap_screening();
3997
3998 setverdict(pass);
3999}
4000testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004001 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004002 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004003 f_init(1, true);
4004 pars := f_init_pars(11819, true);
4005 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004006 vc_conn.done;
4007}
4008
4009/* Trigger a paging request via VTY and slip in an LU */
4010private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4011runs on BSC_ConnHdlr {
4012 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4013 f_init_handler(pars);
4014
4015 /* First we prepar the situation, where the SGs association is in state
4016 * NULL and the confirmed by radio contact indicator is set to false
4017 * as well. This can be archived by performing an SGs LU and then
4018 * resetting the VLR */
4019 f_sgs_perform_lu();
4020 f_sgsap_reset_mme(mp_mme_name);
4021 f_sleep(1.0);
4022 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4023
4024 /* Perform a paging, expect the paging messages on the SGs interface */
4025 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4026 alt {
4027 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4028 setverdict(pass);
4029 }
4030 [] SGsAP.receive {
4031 setverdict(fail, "Received unexpected message on SGs");
4032 }
4033 }
4034
4035 /* Perform the LU as normal */
4036 f_sgs_perform_lu();
4037 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4038
4039 /* Expect a new paging request right after the LU */
4040 alt {
4041 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4042 setverdict(pass);
4043 }
4044 [] SGsAP.receive {
4045 setverdict(fail, "Received unexpected message on SGs");
4046 }
4047 }
4048
4049 /* Test is done now, lets round everything up by rejecting the paging
4050 * cleanly. */
4051 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4052 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4053
4054 f_sgsap_bssmap_screening();
4055
4056 setverdict(pass);
4057}
4058testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004059 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004060 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004061 f_init(1, true);
4062 pars := f_init_pars(11820, true);
4063 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004064 vc_conn.done;
4065}
4066
4067/* Send unexpected unit-data through the SGs interface */
4068private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4069 f_init_handler(pars);
4070 f_sleep(1.0);
4071
4072 /* This simulates what happens when a subscriber without SGs
4073 * association gets unitdata via the SGs interface. */
4074
4075 /* Make sure the subscriber exists and the SGs association
4076 * is in NULL state */
4077 f_perform_lu();
4078 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4079
4080 /* Send some random unit data, the MSC/VLR should send a release
4081 * immediately. */
4082 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4083 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
4084
4085 f_sgsap_bssmap_screening();
4086
4087 setverdict(pass);
4088}
4089testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004090 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004091 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004092 f_init(1, true);
4093 pars := f_init_pars(11821, true);
4094 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004095 vc_conn.done;
4096}
4097
4098/* Send unsolicited unit-data through the SGs interface */
4099private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4100 f_init_handler(pars);
4101 f_sleep(1.0);
4102
4103 /* This simulates what happens when the MME attempts to send unitdata
4104 * to a subscriber that is completely unknown to the VLR */
4105
4106 /* Send some random unit data, the MSC/VLR should send a release
4107 * immediately. */
4108 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4109 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
4110
4111 f_sgsap_bssmap_screening();
4112
4113 setverdict(pass);
4114}
4115testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004116 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004117 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004118 f_init(1, true);
4119 pars := f_init_pars(11822, true);
4120 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004121 vc_conn.done;
4122}
4123
4124private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
4125 /* FIXME: Match an actual payload (second questionmark), the type is
4126 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
4127 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
4128 setverdict(fail, "Unexpected SMS related PDU from MSC");
4129 mtc.stop;
4130 }
4131}
4132
4133/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
4134function f_mt_sms_sgs(inout SmsParameters spars)
4135runs on BSC_ConnHdlr {
4136 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4137 var template (value) RPDU_MS_SGSN rp_mo;
4138 var template (value) PDU_ML3_MS_NW l3_mo;
4139
4140 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4141 var template RPDU_SGSN_MS rp_mt;
4142 var template PDU_ML3_NW_MS l3_mt;
4143
4144 var PDU_ML3_NW_MS sgsap_l3_mt;
4145
4146 var default d := activate(as_other_sms_sgs());
4147
4148 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
4149 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
4150 rp_mt := tr_RP_DATA_MT(?, ?, omit, tp_mt);
4151 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
4152
4153 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
4154
4155 /* Extract relevant identifiers */
4156 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
4157 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
4158
4159 /* send CP-ACK for CP-DATA just received */
4160 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
4161
4162 SGsAP.send(l3_mo);
4163
4164 /* send RP-ACK for RP-DATA */
4165 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
4166 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
4167
4168 SGsAP.send(l3_mo);
4169
4170 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
4171 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
4172
4173 SGsAP.receive(l3_mt);
4174
4175 deactivate(d);
4176
4177 setverdict(pass);
4178}
4179
4180/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
4181function f_mo_sms_sgs(inout SmsParameters spars)
4182runs on BSC_ConnHdlr {
4183 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4184 var template (value) RPDU_MS_SGSN rp_mo;
4185 var template (value) PDU_ML3_MS_NW l3_mo;
4186
4187 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4188 var template RPDU_SGSN_MS rp_mt;
4189 var template PDU_ML3_NW_MS l3_mt;
4190
4191 var default d := activate(as_other_sms_sgs());
4192
4193 /* just in case this is routed to SMPP.. */
4194 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
4195
4196 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
4197 spars.tp.udl, spars.tp.ud);
4198 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, spars.rp.orig, spars.rp.dest, tp_mo);
4199 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
4200
4201 SGsAP.send(l3_mo);
4202
4203 /* receive CP-ACK for CP-DATA above */
4204 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
4205
4206 if (ispresent(spars.exp_rp_err)) {
4207 /* expect an RP-ERROR message from MSC with given cause */
4208 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
4209 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4210 SGsAP.receive(l3_mt);
4211 /* send CP-ACK for CP-DATA just received */
4212 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4213 SGsAP.send(l3_mo);
4214 } else {
4215 /* expect RP-ACK for RP-DATA */
4216 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
4217 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4218 SGsAP.receive(l3_mt);
4219 /* send CP-ACO for CP-DATA just received */
4220 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4221 SGsAP.send(l3_mo);
4222 }
4223
4224 deactivate(d);
4225
4226 setverdict(pass);
4227}
4228
4229private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
4230runs on BSC_ConnHdlr {
4231 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
4232}
4233
4234/* Send a MT SMS via SGs interface */
4235private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4236 f_init_handler(pars);
4237 f_sgs_perform_lu();
4238 f_sleep(1.0);
4239 var SmsParameters spars := valueof(t_SmsPars);
4240 spars.tp.ud := 'C8329BFD064D9B53'O;
4241
4242 /* Trigger SMS via VTY */
4243 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4244 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4245
4246 /* Expect a paging request and respond accordingly with a service request */
4247 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
4248 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
4249
4250 /* Connection is now live, receive the MT-SMS */
4251 f_mt_sms_sgs(spars);
4252
4253 /* Expect a concluding release from the MSC */
4254 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4255
4256 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4257 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4258
4259 f_sgsap_bssmap_screening();
4260
4261 setverdict(pass);
4262}
4263testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004264 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004265 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004266 f_init(1, true);
4267 pars := f_init_pars(11823, true);
4268 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004269 vc_conn.done;
4270}
4271
4272/* Send a MO SMS via SGs interface */
4273private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4274 f_init_handler(pars);
4275 f_sgs_perform_lu();
4276 f_sleep(1.0);
4277 var SmsParameters spars := valueof(t_SmsPars);
4278 spars.tp.ud := 'C8329BFD064D9B53'O;
4279
4280 /* Send the MO-SMS */
4281 f_mo_sms_sgs(spars);
4282
4283 /* Expect a concluding release from the MSC/VLR */
4284 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4285
4286 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4287 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4288
4289 setverdict(pass);
4290
4291 f_sgsap_bssmap_screening()
4292}
4293testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004294 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004295 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004296 f_init(1, true);
4297 pars := f_init_pars(11824, true);
4298 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004299 vc_conn.done;
4300}
4301
4302/* Trigger sending of an MT sms via VTY but never respond to anything */
4303private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4304 f_init_handler(pars, 170.0);
4305 f_sgs_perform_lu();
4306 f_sleep(1.0);
4307
4308 var SmsParameters spars := valueof(t_SmsPars);
4309 spars.tp.ud := 'C8329BFD064D9B53'O;
4310 var integer page_count := 0;
4311 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4312 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4313 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4314 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4315
4316 /* Trigger SMS via VTY */
4317 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4318
4319 /* Expect the MSC/VLR to page exactly 10 times before giving up */
4320 alt {
4321 [] SGsAP.receive(exp_pag_req)
4322 {
4323 page_count := page_count + 1;
4324
4325 if (page_count < 10) {
4326 repeat;
4327 }
4328 }
4329 [] SGsAP.receive {
4330 setverdict(fail, "unexpected SGsAP message received");
4331 self.stop;
4332 }
4333 }
4334
4335 /* Wait some time to make sure the MSC is not delivering any further
4336 * paging messages or anything else that could be unexpected. */
4337 timer T := 20.0;
4338 T.start
4339 alt {
4340 [] SGsAP.receive(exp_pag_req)
4341 {
4342 setverdict(fail, "paging seems not to stop!");
4343 mtc.stop;
4344 }
4345 [] SGsAP.receive {
4346 setverdict(fail, "unexpected SGsAP message received");
4347 self.stop;
4348 }
4349 [] T.timeout {
4350 setverdict(pass);
4351 }
4352 }
4353
4354 /* Even on a failed paging the SGs Association should stay intact */
4355 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4356
4357 /* Note: We do not execute f_sgsap_bssmap_screening() here since the
4358 * MSC/VLR would re-try to deliver the test SMS trigered above and
4359 * so the screening would fail. */
4360
4361 /* Expire the subscriber now to avoid that the MSC will try the SMS
4362 * delivery at some later point. */
4363 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
4364
4365 setverdict(pass);
4366}
4367testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004368 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004369 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004370 f_init(1, true);
4371 pars := f_init_pars(11825, true);
4372 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004373 vc_conn.done;
4374}
4375
4376/* Trigger sending of an MT sms via VTY but reject the paging immediately */
4377private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4378 f_init_handler(pars, 150.0);
4379 f_sgs_perform_lu();
4380 f_sleep(1.0);
4381
4382 var SmsParameters spars := valueof(t_SmsPars);
4383 spars.tp.ud := 'C8329BFD064D9B53'O;
4384 var integer page_count := 0;
4385 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4386 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4387 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4388 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4389
4390 /* Trigger SMS via VTY */
4391 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4392
4393 /* Expect a paging request and reject it immediately */
4394 SGsAP.receive(exp_pag_req);
4395 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4396
4397 /* The MSC/VLR should no longer try to page once the paging has been
4398 * rejected. Wait some time and check if there are no unexpected
4399 * messages on the SGs interface. */
4400 timer T := 20.0;
4401 T.start
4402 alt {
4403 [] SGsAP.receive(exp_pag_req)
4404 {
4405 setverdict(fail, "paging seems not to stop!");
4406 mtc.stop;
4407 }
4408 [] SGsAP.receive {
4409 setverdict(fail, "unexpected SGsAP message received");
4410 self.stop;
4411 }
4412 [] T.timeout {
4413 setverdict(pass);
4414 }
4415 }
4416
4417 /* A rejected paging with IMSI_unknown (see above) should always send
4418 * the SGs association to NULL. */
4419 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4420
4421 f_sgsap_bssmap_screening();
4422
4423 /* Expire the subscriber now to avoid that the MSC will try the SMS
4424 * delivery at some later point. */
4425 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
4426
4427 setverdict(pass);
4428}
4429testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004430 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004431 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004432 f_init(1, true);
4433 pars := f_init_pars(11826, true);
4434 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004435 vc_conn.done;
4436}
4437
4438/* Perform an MT CSDB call including LU */
4439private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
4440 f_init_handler(pars);
4441
4442 /* Be sure that the BSSMAP reset is done before we begin. */
4443 f_sleep(2.0);
4444
4445 /* Testcase variation: See what happens when we do a regular BSSMAP
4446 * LU first (this should not hurt in any way!) */
4447 if (bssmap_lu) {
4448 f_perform_lu();
4449 }
4450
4451 f_sgs_perform_lu();
4452 f_sleep(1.0);
4453
4454 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4455 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
4456 cpars.bss_rtp_port := 1110;
4457 cpars.mgcp_connection_id_bss := '10004'H;
4458 cpars.mgcp_connection_id_mss := '10005'H;
4459
4460 /* Note: This is an optional parameter. When the call-agent (MSC) does
4461 * supply a full endpoint name this setting will be overwritten. */
4462 cpars.mgcp_ep := "rtpbridge/1@mgw";
4463
4464 /* Initiate a call via MNCC interface */
4465 f_mt_call_initate(cpars);
4466
4467 /* Expect a paging request and respond accordingly with a service request */
4468 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
4469 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
4470
4471 /* Complete the call, hold it for some time and then tear it down */
4472 f_mt_call_complete(cpars);
4473 f_sleep(3.0);
4474 f_call_hangup(cpars, true);
4475
4476 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4477 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4478
4479 /* Finally simulate the return of the UE to the 4G network */
4480 SGsAP.send(ts_SGsAP_MO_CSFB_IND(pars.imsi));
4481
4482 /* Test for successful return by triggering a paging, when the paging
4483 * request is received via SGs, we can be sure that the MSC/VLR has
4484 * recognized that the UE is now back on 4G */
4485 f_sleep(1.0);
4486 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4487 alt {
4488 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4489 setverdict(pass);
4490 }
4491 [] SGsAP.receive {
4492 setverdict(fail, "Received unexpected message on SGs");
4493 }
4494 }
4495
4496 f_sgsap_bssmap_screening();
4497
4498 setverdict(pass);
4499}
4500
4501/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
4502private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4503 f_mt_lu_and_csfb_call(id, pars, true);
4504}
4505testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004506 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004507 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004508 f_init(1, true);
4509 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01004510
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004511 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004512 vc_conn.done;
4513}
4514
4515
4516/* Perform a SGSAP LU and then make a CSFB call */
4517private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4518 f_mt_lu_and_csfb_call(id, pars, false);
4519}
4520testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004521 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004522 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004523 f_init(1, true);
4524 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01004525
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004526 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004527 vc_conn.done;
4528}
4529
4530/* SGs TODO:
4531 * LU attempt for IMSI without NAM_PS in HLR
4532 * LU attempt with AUTH FAIL due to invalid RES/SRES
4533 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
4534 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
4535 * implicit IMSI detach from EPS
4536 * implicit IMSI detach from non-EPS
4537 * MM INFO
4538 *
4539 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004540
4541control {
Philipp Maier328d1662018-03-07 10:40:27 +01004542 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01004543 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01004544 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01004545 execute( TC_lu_imsi_reject() );
4546 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01004547 execute( TC_lu_imsi_auth_tmsi() );
4548 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01004549 execute( TC_lu_and_mo_call() );
Harald Welte071ed732018-01-23 19:53:52 +01004550 execute( TC_lu_auth_sai_timeout() );
4551 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01004552 execute( TC_lu_clear_request() );
4553 execute( TC_lu_disconnect() );
4554 execute( TC_lu_by_imei() );
4555 execute( TC_lu_by_tmsi_noauth_unknown() );
4556 execute( TC_imsi_detach_by_imsi() );
4557 execute( TC_imsi_detach_by_tmsi() );
4558 execute( TC_imsi_detach_by_imei() );
4559 execute( TC_emerg_call_imei_reject() );
4560 execute( TC_emerg_call_imsi() );
4561 execute( TC_cm_serv_req_vgcs_reject() );
4562 execute( TC_cm_serv_req_vbs_reject() );
4563 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01004564 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01004565 execute( TC_lu_auth_2G_fail() );
4566 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
4567 execute( TC_cl3_no_payload() );
4568 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01004569 execute( TC_establish_and_nothing() );
4570 execute( TC_mo_setup_and_nothing() );
4571 execute( TC_mo_crcx_ran_timeout() );
4572 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01004573 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01004574 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01004575 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01004576 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01004577 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
4578 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
4579 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01004580 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01004581 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
4582 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01004583 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01004584 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02004585 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01004586
4587 execute( TC_lu_and_mt_call() );
4588
Harald Weltef45efeb2018-04-09 18:19:24 +02004589 execute( TC_lu_and_mo_sms() );
4590 execute( TC_lu_and_mt_sms() );
Philipp Maier3983e702018-11-22 19:01:33 +01004591 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Harald Weltef640a012018-04-14 17:49:21 +02004592 execute( TC_smpp_mo_sms() );
4593 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02004594
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07004595 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07004596 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07004597 execute( TC_gsup_mt_sms_ack() );
4598 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07004599 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07004600 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07004601
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07004602 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07004603 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07004604 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07004605 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07004606 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07004607 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07004608
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004609 execute( TC_cipher_complete_with_invalid_cipher() );
4610
Harald Welte4263c522018-12-06 11:56:27 +01004611 execute( TC_sgsap_reset() );
4612 execute( TC_sgsap_lu() );
4613 execute( TC_sgsap_lu_imsi_reject() );
4614 execute( TC_sgsap_lu_and_nothing() );
4615 execute( TC_sgsap_expl_imsi_det_eps() );
4616 execute( TC_sgsap_expl_imsi_det_noneps() );
4617 execute( TC_sgsap_paging_rej() );
4618 execute( TC_sgsap_paging_subscr_rej() );
4619 execute( TC_sgsap_paging_ue_unr() );
4620 execute( TC_sgsap_paging_and_nothing() );
4621 execute( TC_sgsap_paging_and_lu() );
4622 execute( TC_sgsap_mt_sms() );
4623 execute( TC_sgsap_mo_sms() );
4624 execute( TC_sgsap_mt_sms_and_nothing() );
4625 execute( TC_sgsap_mt_sms_and_reject() );
4626 execute( TC_sgsap_unexp_ud() );
4627 execute( TC_sgsap_unsol_ud() );
4628 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
4629 execute( TC_sgsap_lu_and_mt_call() );
4630
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01004631 /* Run this last: at the time of writing this test crashes the MSC */
4632 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Philipp Maierdb7fb8d2019-02-11 10:50:13 +01004633 execute( TC_gsup_mt_multi_part_sms() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02004634 execute( TC_mo_cc_bssmap_clear() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01004635}
4636
4637
4638}