blob: f6e857799d69cda8bbef0773a92712ac4ffefff7 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
19
20import from M3UA_Types all;
21import from M3UA_Emulation all;
22
23import from MTP3asp_Types all;
24import from MTP3asp_PortType all;
25
26import from SCCPasp_Types all;
27import from SCCP_Types all;
28import from SCCP_Emulation all;
29
30import from SCTPasp_Types all;
31import from SCTPasp_PortType all;
32
Harald Weltea49e36e2018-01-21 19:29:33 +010033import from Osmocom_CTRL_Functions all;
34import from Osmocom_CTRL_Types all;
35import from Osmocom_CTRL_Adapter all;
36
Harald Welte3ca1c902018-01-24 18:51:27 +010037import from TELNETasp_PortType all;
38import from Osmocom_VTY_Functions all;
39
Harald Weltea49e36e2018-01-21 19:29:33 +010040import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010041import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010042
Harald Welte4aa970c2018-01-26 10:38:09 +010043import from MGCP_Emulation all;
44import from MGCP_Types all;
45import from MGCP_Templates all;
46import from SDP_Types all;
47
Harald Weltea49e36e2018-01-21 19:29:33 +010048import from GSUP_Emulation all;
49import from GSUP_Types all;
50import from IPA_Emulation all;
51
Harald Weltef6dd64d2017-11-19 12:09:51 +010052import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020053import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010054import from BSSAP_CodecPort all;
55import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020056import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010057import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020058import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010059
Harald Welte4263c522018-12-06 11:56:27 +010060import from SGsAP_Templates all;
61import from SGsAP_Types all;
62import from SGsAP_Emulation all;
63
Harald Weltea49e36e2018-01-21 19:29:33 +010064import from MobileL3_Types all;
65import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070066import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010067import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010068import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010069
Harald Weltef640a012018-04-14 17:49:21 +020070import from SMPP_Types all;
71import from SMPP_Templates all;
72import from SMPP_Emulation all;
73
Stefan Sperlingc307e682018-06-14 15:15:46 +020074import from SCCP_Templates all;
75
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070076import from SS_Types all;
77import from SS_Templates all;
78import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010079import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070080
Philipp Maier948747b2019-04-02 15:22:33 +020081import from TCCConversion_Functions all;
82
Harald Welte9b751a62019-04-14 17:39:29 +020083const integer NUM_BSC := 3;
Harald Weltef6dd64d2017-11-19 12:09:51 +010084
Harald Welte4263c522018-12-06 11:56:27 +010085/* Needed for SGsAP SMS */
86import from MobileL3_SMS_Types all;
87
Harald Weltea4ca4462018-02-09 00:17:14 +010088type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010089 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010090
Harald Welte6811d102019-04-14 22:23:14 +020091 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010092
Harald Weltea49e36e2018-01-21 19:29:33 +010093 /* no 'adapter_CT' for MNCC or GSUP */
94 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010095 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010096 var GSUP_Emulation_CT vc_GSUP;
97 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020098 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +010099 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100100
101 /* only to get events from IPA underneath GSUP */
102 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100103 /* VTY to MSC */
104 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100105
106 /* A port to directly send BSSAP messages. This port is used for
107 * tests that require low level access to sen arbitrary BSSAP
108 * messages. Run f_init_bssap_direct() to connect and initialize */
109 port BSSAP_CODEC_PT BSSAP_DIRECT;
110
111 /* When BSSAP messages are directly sent, then the connection
112 * handler is not active, which means that also no guard timer is
113 * set up. The following timer will serve as a replacement */
114 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100115
116 /* Configure T(tias) over VTY, seconds */
117 var integer g_msc_sccp_timer_ias := 7 * 60;
118 /* Configure T(tiar) over VTY, seconds */
119 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100120}
121
122modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100123 /* remote parameters of IUT */
124 charstring mp_msc_ip := "127.0.0.1";
125 integer mp_msc_ctrl_port := 4255;
126 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100127
Harald Weltea49e36e2018-01-21 19:29:33 +0100128 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100129 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100130 charstring mp_hlr_ip := "127.0.0.1";
131 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100132 charstring mp_mgw_ip := "127.0.0.1";
133 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100134
Harald Weltea49e36e2018-01-21 19:29:33 +0100135 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100136
Harald Weltef640a012018-04-14 17:49:21 +0200137 integer mp_msc_smpp_port := 2775;
138 charstring mp_smpp_system_id := "msc_tester";
139 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100140 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
141 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200142
Harald Welte6811d102019-04-14 22:23:14 +0200143 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200144 {
145 sccp_service_type := "mtp3_itu",
146 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
147 own_pc := 185,
148 own_ssn := 254,
149 peer_pc := 187,
150 peer_ssn := 254,
151 sio := '83'O,
152 rctx := 0
153 },
154 {
155 sccp_service_type := "mtp3_itu",
156 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
157 own_pc := 186,
158 own_ssn := 254,
159 peer_pc := 187,
160 peer_ssn := 254,
161 sio := '83'O,
162 rctx := 1
163 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100164 };
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200165
166 boolean mp_enable_cell_id_test := true;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100167}
168
Philipp Maier328d1662018-03-07 10:40:27 +0100169/* altstep for the global guard timer (only used when BSSAP_DIRECT
170 * is used for communication */
171private altstep as_Tguard_direct() runs on MTC_CT {
172 [] Tguard_direct.timeout {
173 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200174 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100175 }
176}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100177
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100178private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
179 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
180 if (respond) {
181 var BIT1 tid_remote := '1'B;
182 if (cpars.mo_call) {
183 tid_remote := '0'B;
184 }
185 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
186 }
187 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100188}
189
Harald Weltef640a012018-04-14 17:49:21 +0200190function f_init_smpp(charstring id) runs on MTC_CT {
191 id := id & "-SMPP";
192 var EsmePars pars := {
193 mode := MODE_TRANSCEIVER,
194 bind := {
195 system_id := mp_smpp_system_id,
196 password := mp_smpp_password,
197 system_type := "MSC_Tests",
198 interface_version := hex2int('34'H),
199 addr_ton := unknown,
200 addr_npi := unknown,
201 address_range := ""
202 },
203 esme_role := true
204 }
205
206 vc_SMPP := SMPP_Emulation_CT.create(id);
207 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
Harald Welte4698a4c2020-08-18 22:57:52 +0200208 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", 0));
Harald Weltef640a012018-04-14 17:49:21 +0200209}
210
211
Harald Weltea49e36e2018-01-21 19:29:33 +0100212function f_init_mncc(charstring id) runs on MTC_CT {
213 id := id & "-MNCC";
214 var MnccOps ops := {
215 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
216 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
217 }
218
219 vc_MNCC := MNCC_Emulation_CT.create(id);
220 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
221 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100222}
223
Harald Welte4aa970c2018-01-26 10:38:09 +0100224function f_init_mgcp(charstring id) runs on MTC_CT {
225 id := id & "-MGCP";
226 var MGCPOps ops := {
227 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
228 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
229 }
230 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100231 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100232 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100233 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200234 mgw_udp_port := mp_mgw_port,
235 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100236 }
237
238 vc_MGCP := MGCP_Emulation_CT.create(id);
239 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
240 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
241}
242
Philipp Maierc09a1312019-04-09 16:05:26 +0200243function ForwardUnitdataCallback(PDU_SGsAP msg)
244runs on SGsAP_Emulation_CT return template PDU_SGsAP {
245 SGsAP_CLIENT.send(msg);
246 return omit;
247}
248
Harald Welte4263c522018-12-06 11:56:27 +0100249function f_init_sgsap(charstring id) runs on MTC_CT {
250 id := id & "-SGsAP";
251 var SGsAPOps ops := {
252 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200253 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100254 }
255 var SGsAP_conn_parameters pars := {
256 remote_ip := mp_msc_ip,
257 remote_sctp_port := 29118,
258 local_ip := "",
259 local_sctp_port := -1
260 }
261
262 vc_SGsAP := SGsAP_Emulation_CT.create(id);
263 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
264 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
265}
266
267
Harald Weltea49e36e2018-01-21 19:29:33 +0100268function f_init_gsup(charstring id) runs on MTC_CT {
269 id := id & "-GSUP";
270 var GsupOps ops := {
271 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
272 }
273
274 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
275 vc_GSUP := GSUP_Emulation_CT.create(id);
276
277 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
278 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
279 /* we use this hack to get events like ASP_IPA_EVENT_UP */
280 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
281
282 vc_GSUP.start(GSUP_Emulation.main(ops, id));
283 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
284
285 /* wait for incoming connection to GSUP port before proceeding */
286 timer T := 10.0;
287 T.start;
288 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700289 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100290 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100291 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200292 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100293 }
294 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100295}
296
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200297function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100298
299 if (g_initialized == true) {
300 return;
301 }
302 g_initialized := true;
303
Philipp Maier75932982018-03-27 14:52:35 +0200304 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200305 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200306 }
307
308 for (var integer i := 0; i < num_bsc; i := i + 1) {
309 if (isbound(mp_bssap_cfg[i])) {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200310 var RanOps ranops := BSC_RanOps;
311 ranops.use_osmux := osmux;
312 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
Harald Welte3ca0ce12019-04-23 17:18:48 +0200313 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200314 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200315 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200316 }
317 }
318
Harald Weltea49e36e2018-01-21 19:29:33 +0100319 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
320 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100321 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200322
323 if (gsup == true) {
324 f_init_gsup("MSC_Test");
325 }
Harald Weltef640a012018-04-14 17:49:21 +0200326 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100327
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100328 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100329 f_init_sgsap("MSC_Test");
330 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100331
332 map(self:MSCVTY, system:MSCVTY);
333 f_vty_set_prompts(MSCVTY);
334 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100335
336 /* set some defaults */
337 f_vty_config(MSCVTY, "network", "authentication optional");
338 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200339 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100340 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100341 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
342 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +0200343 if (osmux) {
344 f_vty_config(MSCVTY, "msc", "osmux on");
345 } else {
346 f_vty_config(MSCVTY, "msc", "osmux off");
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200347 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100348}
349
Philipp Maier328d1662018-03-07 10:40:27 +0100350/* Initialize for a direct connection to BSSAP. This function is an alternative
351 * to f_init() when the high level functions of the BSC_ConnectionHandler are
352 * not needed. */
353function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200354 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200355 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100356
357 /* Start guard timer and activate it as default */
358 Tguard_direct.start
359 activate(as_Tguard_direct());
360}
361
Harald Weltea49e36e2018-01-21 19:29:33 +0100362type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100363
Harald Weltea49e36e2018-01-21 19:29:33 +0100364/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200365function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200366 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O,
367 boolean verify_cell_id := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200368runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100369 var BSC_ConnHdlrNetworkPars net_pars := {
370 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
371 expect_tmsi := true,
372 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200373 expect_ciph := false,
374 expect_imei := false,
375 expect_imei_early := false,
376 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
377 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100378 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100379 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200380 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
381 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100382 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100383 imei := f_gen_imei(imsi_suffix),
384 imsi := f_gen_imsi(imsi_suffix),
385 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100386 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100387 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100388 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100389 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100390 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100391 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100392 send_early_cm := true,
393 ipa_ctrl_ip := mp_msc_ip,
394 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100395 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100396 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200397 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200398 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100399 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200400 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200401 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200402 ran_is_geran := ran_is_geran,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200403 use_osmux := use_osmux,
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200404 use_ipv6 := false,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200405 verify_cell_id := mp_enable_cell_id_test and verify_cell_id
Harald Weltea49e36e2018-01-21 19:29:33 +0100406 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200407 if (not ran_is_geran) {
408 pars.use_umts_aka := true;
409 pars.net.expect_auth := true;
410 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100411 return pars;
412}
413
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200414function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars, integer bssap_idx := 0) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100415 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200416 var charstring id := testcasename() & int2str(bssap_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100417
418 vc_conn := BSC_ConnHdlr.create(id);
419 /* BSSMAP part / A interface */
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200420 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:CLIENT);
421 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100422 /* MNCC part */
423 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
424 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100425 /* MGCP part */
426 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
427 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100428 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200429 if (pars.gsup_enable == true) {
430 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
431 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
432 }
Harald Weltef640a012018-04-14 17:49:21 +0200433 /* SMPP part */
434 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
435 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100436 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100437 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100438 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
439 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
440 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100441
Harald Weltea10db902018-01-27 12:44:49 +0100442 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
443 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100444 vc_conn.start(derefers(fn)(id, pars));
445 return vc_conn;
446}
447
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200448function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false,
449 boolean verify_cell_id := true)
Harald Welte9b751a62019-04-14 17:39:29 +0200450runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200451 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux, verify_cell_id := verify_cell_id));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100452}
453
Harald Weltea49e36e2018-01-21 19:29:33 +0100454private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100455 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100456 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100457}
Harald Weltea49e36e2018-01-21 19:29:33 +0100458testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
459 var BSC_ConnHdlr vc_conn;
460 f_init();
461
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100462 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100463 vc_conn.done;
464}
465
466private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100467 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100468 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100469 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100470}
Harald Weltea49e36e2018-01-21 19:29:33 +0100471testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
472 var BSC_ConnHdlr vc_conn;
473 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100474 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100475
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100476 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100477 vc_conn.done;
478}
479
480/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200481friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100482 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100483 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
484
485 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200486 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100487 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100488 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
489 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
490 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100491 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
492 f_expect_clear();
493 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100494 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
495 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200496 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100497 }
498 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100499}
500testcase TC_lu_imsi_reject() runs on MTC_CT {
501 var BSC_ConnHdlr vc_conn;
502 f_init();
503
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200504 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100505 vc_conn.done;
506}
507
Harald Weltee13cfb22019-04-23 16:52:02 +0200508
509
Harald Weltea49e36e2018-01-21 19:29:33 +0100510/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200511friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100512 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100513 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
514
515 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200516 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100517 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100518 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
519 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
520 alt {
521 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100522 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
523 f_expect_clear();
524 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100525 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
526 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200527 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100528 }
529 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100530}
531testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
532 var BSC_ConnHdlr vc_conn;
533 f_init();
534
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200535 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100536 vc_conn.done;
537}
538
Harald Weltee13cfb22019-04-23 16:52:02 +0200539
Harald Welte7b1b2812018-01-22 21:23:06 +0100540private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100541 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100542 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100543 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100544}
545testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
546 var BSC_ConnHdlr vc_conn;
547 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100548 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100549
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100550 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100551 vc_conn.done;
552}
553
Harald Weltee13cfb22019-04-23 16:52:02 +0200554
555friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200556 pars.net.expect_auth := true;
557 pars.use_umts_aka := true;
558 f_init_handler(pars);
559 f_perform_lu();
560}
561testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
562 var BSC_ConnHdlr vc_conn;
563 f_init();
564 f_vty_config(MSCVTY, "network", "authentication required");
565
566 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
567 vc_conn.done;
568}
Harald Weltea49e36e2018-01-21 19:29:33 +0100569
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100570/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
571 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
572 */
573friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
574
575 f_init_handler(pars);
576
577 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
578 var PDU_DTAP_MT dtap_mt;
579
580 /* tell GSUP dispatcher to send this IMSI to us */
581 f_create_gsup_expect(hex2str(g_pars.imsi));
582
583 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
584 if (g_pars.ran_is_geran) {
585 f_bssap_compl_l3(l3_lu);
586 if (g_pars.send_early_cm) {
587 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
588 }
589 } else {
590 f_ranap_initial_ue(l3_lu);
591 }
592
593 f_mm_imei_early();
594 f_mm_common();
595 f_msc_lu_hlr();
596 f_mm_imei();
597
598 alt {
599 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
600 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
601 setverdict(fail, "Expected LU ACK, but received LU REJ");
602 mtc.stop;
603 }
604 }
605
606 /* currently (due to bug OS#4337), an extra LU reject is received before
607 terminating the connection. Enabling following line makes the test
608 pass: */
609 //f_expect_lu_reject('16'O); /* Cause: congestion */
610
611 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
612 extra time to avoid race conditons... */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200613 f_expect_clear(7.0, verify_vlr_cell_id := false);
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100614
615 setverdict(pass);
616}
617testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
618 var BSC_ConnHdlr vc_conn;
619 f_init();
620
621 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
622 vc_conn.done;
623}
624
Harald Weltee13cfb22019-04-23 16:52:02 +0200625
Harald Weltea49e36e2018-01-21 19:29:33 +0100626/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200627friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100628runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100629 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100630
631 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100632 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100633 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100634
635 f_create_gsup_expect(hex2str(g_pars.imsi));
636
637 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200638 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200639 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100640
641 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100642 T.start;
643 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100644 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
645 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200646 [] BSSAP.receive {
647 setverdict(fail, "Received unexpected BSSAP");
648 mtc.stop;
649 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100650 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
651 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200652 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100653 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200654 [] T.timeout {
Neels Hofmeyrf1c3c212020-08-19 13:15:32 +0000655 setverdict(fail, "Timeout waiting for CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200656 mtc.stop;
657 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100658 }
659
Harald Welte1ddc7162018-01-27 14:25:46 +0100660 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100661}
Harald Weltea49e36e2018-01-21 19:29:33 +0100662testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
663 var BSC_ConnHdlr vc_conn;
664 f_init();
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200665 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100666 vc_conn.done;
667}
668
Harald Weltee13cfb22019-04-23 16:52:02 +0200669
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000670/* Send CM SERVICE REQ for TMSI that has never performed LU before */
671friend function f_tc_cmserv_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
672runs on BSC_ConnHdlr {
673 f_init_handler(pars);
674
675 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('57111111'O));
676 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
677 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
678
679 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
680 f_cl3_or_initial_ue(l3_info);
681 f_mm_auth();
682
683 timer T := 10.0;
684 T.start;
685 alt {
686 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
687 [] BSSAP.receive {
688 setverdict(fail, "Received unexpected BSSAP");
689 mtc.stop;
690 }
691 [] T.timeout {
692 setverdict(fail, "Timeout waiting for CM SERV REJ");
693 mtc.stop;
694 }
695 }
696
697 f_expect_clear();
698}
699testcase TC_cmserv_tmsi_unknown() runs on MTC_CT {
700 var BSC_ConnHdlr vc_conn;
701 f_init();
702 vc_conn := f_start_handler(refers(f_tc_cmserv_tmsi_unknown), 57, verify_cell_id := false);
703 vc_conn.done;
704}
705
Neels Hofmeyr14d0b132020-08-19 13:49:05 +0000706/* Send Paging Response for IMSI that has never performed LU before */
707friend function f_tc_paging_response_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
708runs on BSC_ConnHdlr {
709 f_init_handler(pars);
710
711 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
712 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
713 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
714
715 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
716 f_cl3_or_initial_ue(l3_info);
717
718 /* The Paging Response gets rejected by a direct Clear Command */
719 f_expect_clear();
720}
721testcase TC_paging_response_imsi_unknown() runs on MTC_CT {
722 var BSC_ConnHdlr vc_conn;
723 f_init();
724 vc_conn := f_start_handler(refers(f_tc_paging_response_imsi_unknown), 58, verify_cell_id := false);
725 vc_conn.done;
726}
727
728/* Send Paging Response for TMSI that has never performed LU before */
729friend function f_tc_paging_response_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
730runs on BSC_ConnHdlr {
731 f_init_handler(pars);
732
733 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('59111111'O));
734 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
735 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
736
737 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
738 f_cl3_or_initial_ue(l3_info);
739
740 /* The Paging Response gets rejected by a direct Clear Command */
741 f_expect_clear();
742}
743testcase TC_paging_response_tmsi_unknown() runs on MTC_CT {
744 var BSC_ConnHdlr vc_conn;
745 f_init();
746 vc_conn := f_start_handler(refers(f_tc_paging_response_tmsi_unknown), 59, verify_cell_id := false);
747 vc_conn.done;
748}
749
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000750
Harald Weltee13cfb22019-04-23 16:52:02 +0200751friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100752 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200753 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100754 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100755 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100756}
757testcase TC_lu_and_mo_call() runs on MTC_CT {
758 var BSC_ConnHdlr vc_conn;
759 f_init();
760
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100761 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100762 vc_conn.done;
763}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200764friend function f_tc_lu_and_mo_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
765 f_init_handler(pars);
766 var CallParameters cpars := valueof(t_CallParams);
767 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
768 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
769 cpars.bss_rtp_ip := "::3";
770 f_perform_lu();
771 f_mo_call(cpars);
772}
773testcase TC_lu_and_mo_call_ipv6() runs on MTC_CT {
774 var BSC_ConnHdlr vc_conn;
775 f_init();
776
777 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call_ipv6), 7);
778 vc_conn.done;
779}
Harald Welte071ed732018-01-23 19:53:52 +0100780
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100781/* Verify T(iar) triggers and releases the channel */
782friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
783 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
784 f_init_handler(pars);
785 var CallParameters cpars := valueof(t_CallParams);
786 f_perform_lu();
787 f_mo_call_establish(cpars);
788
789 /* Expect the channel cleared upon T(iar) triggered: */
790 T_wait_iar.start;
791 alt {
792 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
793 T_wait_iar.stop
794 setverdict(pass);
795 }
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100796 [] T_wait_iar.timeout {
797 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
798 mtc.stop;
799 }
800 }
Harald Welte4a3fa712020-08-19 08:57:33 +0200801 /* DLCX for both directions; if we don't do this, we might receive either of the two during
802 * shutdown causing race conditions */
803 MGCP.receive(tr_DLCX(?));
804 MGCP.receive(tr_DLCX(?));
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100805
806 setverdict(pass);
807}
808testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
809 var BSC_ConnHdlr vc_conn;
810
811 /* Set T(iar) in MSC low enough that it will trigger before other side
812 has time to keep alive with a T(ias). Keep recommended ratio of
813 T(iar) >= T(ias)*2 */
814 g_msc_sccp_timer_ias := 2;
815 g_msc_sccp_timer_iar := 5;
816
817 f_init();
818
819 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
820 vc_conn.done;
821}
822
Harald Weltee13cfb22019-04-23 16:52:02 +0200823
Harald Welte071ed732018-01-23 19:53:52 +0100824/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200825friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100826 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100827
828 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
829 var PDU_DTAP_MT dtap_mt;
830
831 /* tell GSUP dispatcher to send this IMSI to us */
832 f_create_gsup_expect(hex2str(g_pars.imsi));
833
834 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200835 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100836
837 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200838 if (pars.ran_is_geran) {
839 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
840 }
Harald Welte071ed732018-01-23 19:53:52 +0100841
842 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
843 /* The HLR would normally return an auth vector here, but we fail to do so. */
844
845 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100846 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100847}
848testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
849 var BSC_ConnHdlr vc_conn;
850 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100851 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100852
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200853 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8, verify_cell_id := false);
Harald Welte071ed732018-01-23 19:53:52 +0100854 vc_conn.done;
855}
856
Harald Weltee13cfb22019-04-23 16:52:02 +0200857
Harald Welte071ed732018-01-23 19:53:52 +0100858/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200859friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100860 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100861
862 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
863 var PDU_DTAP_MT dtap_mt;
864
865 /* tell GSUP dispatcher to send this IMSI to us */
866 f_create_gsup_expect(hex2str(g_pars.imsi));
867
868 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200869 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100870
871 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200872 if (pars.ran_is_geran) {
873 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
874 }
Harald Welte071ed732018-01-23 19:53:52 +0100875
876 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
877 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
878
879 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100880 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100881}
882testcase TC_lu_auth_sai_err() runs on MTC_CT {
883 var BSC_ConnHdlr vc_conn;
884 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100885 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100886
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200887 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9, verify_cell_id := false);
Harald Welte2bb825f2018-01-22 11:31:18 +0100888 vc_conn.done;
889}
Harald Weltea49e36e2018-01-21 19:29:33 +0100890
Harald Weltee13cfb22019-04-23 16:52:02 +0200891
Harald Weltebc881782018-01-23 20:09:15 +0100892/* Test LU but BSC will send a clear request in the middle */
893private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100894 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100895
896 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
897 var PDU_DTAP_MT dtap_mt;
898
899 /* tell GSUP dispatcher to send this IMSI to us */
900 f_create_gsup_expect(hex2str(g_pars.imsi));
901
902 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200903 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +0200904 f_expect_common_id();
Harald Weltebc881782018-01-23 20:09:15 +0100905
906 /* Send Early Classmark, just for the fun of it */
907 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
908
909 f_sleep(1.0);
910 /* send clear request in the middle of the LU */
911 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200912 alt {
913 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
914 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
915 }
Harald Weltebc881782018-01-23 20:09:15 +0100916 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100917 alt {
918 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200919 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
920 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200921 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200922 repeat;
923 }
Harald Welte6811d102019-04-14 22:23:14 +0200924 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100925 }
Harald Weltebc881782018-01-23 20:09:15 +0100926 setverdict(pass);
927}
928testcase TC_lu_clear_request() runs on MTC_CT {
929 var BSC_ConnHdlr vc_conn;
930 f_init();
931
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100932 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100933 vc_conn.done;
934}
935
Harald Welte66af9e62018-01-24 17:28:21 +0100936/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200937friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100938 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100939
940 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
941 var PDU_DTAP_MT dtap_mt;
942
943 /* tell GSUP dispatcher to send this IMSI to us */
944 f_create_gsup_expect(hex2str(g_pars.imsi));
945
946 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200947 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +0100948
949 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200950 if (pars.ran_is_geran) {
951 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
952 }
Harald Welte66af9e62018-01-24 17:28:21 +0100953
954 f_sleep(1.0);
955 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +0200956 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +0100957 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +0100958 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +0100959}
960testcase TC_lu_disconnect() runs on MTC_CT {
961 var BSC_ConnHdlr vc_conn;
962 f_init();
963
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100964 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100965 vc_conn.done;
966}
967
Harald Welteba7b6d92018-01-23 21:32:34 +0100968/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +0200969friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100970 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100971
Harald Welte256571e2018-01-24 18:47:19 +0100972 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100973 var PDU_DTAP_MT dtap_mt;
974
975 /* tell GSUP dispatcher to send this IMSI to us */
976 f_create_gsup_expect(hex2str(g_pars.imsi));
977
978 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200979 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100980
981 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200982 if (pars.ran_is_geran) {
983 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
984 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100985 /* wait for LU reject, ignore any ID REQ */
986 alt {
987 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
988 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
989 }
990 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100991 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100992}
993testcase TC_lu_by_imei() runs on MTC_CT {
994 var BSC_ConnHdlr vc_conn;
995 f_init();
996
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200997 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12, verify_cell_id := false);
Harald Welteba7b6d92018-01-23 21:32:34 +0100998 vc_conn.done;
999}
1000
Harald Weltee13cfb22019-04-23 16:52:02 +02001001
Harald Welteba7b6d92018-01-23 21:32:34 +01001002/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
1003private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001004 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
1005 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +01001006 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001007
1008 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
1009 var PDU_DTAP_MT dtap_mt;
1010
1011 /* tell GSUP dispatcher to send this IMSI to us */
1012 f_create_gsup_expect(hex2str(g_pars.imsi));
1013
1014 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001015 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001016
1017 /* Send Early Classmark, just for the fun of it */
1018 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1019
1020 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +02001021 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001022 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +01001023 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
Harald Welte79f1e452020-08-18 22:55:02 +02001024 f_expect_common_id();
Harald Welteba7b6d92018-01-23 21:32:34 +01001025
1026 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1027 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1028 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1029 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1030 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1031
1032 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +01001033 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1034 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1035 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001036 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1037 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001038 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +01001039 }
1040 }
1041
Philipp Maier9b690e42018-12-21 11:50:03 +01001042 /* Wait for MM-Information (if enabled) */
1043 f_expect_mm_info();
1044
Harald Welteba7b6d92018-01-23 21:32:34 +01001045 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001046 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001047}
1048testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
1049 var BSC_ConnHdlr vc_conn;
1050 f_init();
1051
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001052 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +01001053 vc_conn.done;
1054}
1055
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001056/* Test LU by unknown TMSI, while the IMSI is already attached: osmo-msc should switch to the attached vlr_subscr. */
1057private function f_tc_attached_imsi_lu_unknown_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1058 f_init_handler(pars);
1059
1060 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('56111111'O);
1061 var PDU_DTAP_MT dtap_mt;
1062
1063 /* tell GSUP dispatcher to send this IMSI to us */
1064 f_create_gsup_expect(hex2str(g_pars.imsi));
1065
1066 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1067 f_cl3_or_initial_ue(l3_lu);
1068
1069 /* Send Early Classmark, just for the fun of it */
1070 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1071
1072 /* Wait for + respond to ID REQ (IMSI) */
1073 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1074 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1075 f_expect_common_id();
1076
1077 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1078 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1079 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1080 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1081 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1082
1083 alt {
1084 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1085 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1086 }
1087 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1088 setverdict(fail, "Expected LU ACK, but received REJ");
1089 mtc.stop;
1090 }
1091 }
1092
1093 /* Wait for MM-Information (if enabled) */
1094 f_expect_mm_info();
1095
1096 /* wait for normal teardown */
1097 f_expect_clear();
1098
1099 /* Now the same IMSI is still attached in the VLR, and a LU with an unknown TMSI reveals the same IMSI only
1100 * later during ID Response. osmo-msc first creates a new vlr_subscr for the unknown TMSI, and as soon as the
1101 * IMSI becomes known, must notice that this IMSI is still regarded as attached, and must not create evil twins.
1102 */
1103
1104 /* (since the TMSI Reallocation happened, we could do this with exactly the same TMSI as above, but for test
1105 * readability just use a different one.) */
1106 l3_lu := f_build_lu_tmsi('56222222'O);
1107 f_cl3_or_initial_ue(l3_lu);
1108
1109 /* Wait for + respond to ID REQ (IMSI) */
1110 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1111 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1112 f_expect_common_id();
1113
1114 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1115 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1116 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1117 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1118 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1119
1120 alt {
1121 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1122 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1123 }
1124 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1125 setverdict(fail, "Expected LU ACK, but received REJ");
1126 mtc.stop;
1127 }
1128 }
1129
1130 /* Wait for MM-Information (if enabled) */
1131 f_expect_mm_info();
1132
1133 /* wait for normal teardown */
1134 f_expect_clear();
1135}
1136testcase TC_attached_imsi_lu_unknown_tmsi() runs on MTC_CT {
1137 var BSC_ConnHdlr vc_conn;
1138 f_init();
1139
1140 vc_conn := f_start_handler(refers(f_tc_attached_imsi_lu_unknown_tmsi), 56);
1141 vc_conn.done;
1142}
1143
Harald Welte4d15fa72020-08-19 08:58:28 +02001144friend function f_imsi_detach_by_imsi() runs on BSC_ConnHdlr {
Harald Welte45164da2018-01-24 12:51:27 +01001145 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1146
1147 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001148 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001149
1150 /* Send Early Classmark, just for the fun of it? */
Harald Welte4d15fa72020-08-19 08:58:28 +02001151 if (g_pars.ran_is_geran) {
Harald Weltee13cfb22019-04-23 16:52:02 +02001152 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1153 }
Harald Welte45164da2018-01-24 12:51:27 +01001154
1155 /* wait for normal teardown */
Harald Welte4d15fa72020-08-19 08:58:28 +02001156 f_expect_clear(verify_vlr_cell_id := false);
1157}
1158
1159
1160/* Test IMSI DETACH (MI=IMSI) */
1161friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1162 f_init_handler(pars);
1163
1164 f_imsi_detach_by_imsi();
Harald Welte45164da2018-01-24 12:51:27 +01001165}
1166testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
1167 var BSC_ConnHdlr vc_conn;
1168 f_init();
1169
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001170 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001171 vc_conn.done;
1172}
1173
Harald Weltee13cfb22019-04-23 16:52:02 +02001174
Harald Welte45164da2018-01-24 12:51:27 +01001175/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001176friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001177 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001178
1179 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
1180
1181 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001182 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001183
1184 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001185 if (pars.ran_is_geran) {
1186 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1187 }
Harald Welte45164da2018-01-24 12:51:27 +01001188
1189 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001190 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001191}
1192testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1193 var BSC_ConnHdlr vc_conn;
1194 f_init();
1195
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001196 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001197 vc_conn.done;
1198}
1199
Harald Weltee13cfb22019-04-23 16:52:02 +02001200
Harald Welte45164da2018-01-24 12:51:27 +01001201/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001202friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001203 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001204
Harald Welte256571e2018-01-24 18:47:19 +01001205 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001206
1207 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001208 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001209
1210 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001211 if (pars.ran_is_geran) {
1212 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1213 }
Harald Welte45164da2018-01-24 12:51:27 +01001214
1215 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001216 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001217}
1218testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1219 var BSC_ConnHdlr vc_conn;
1220 f_init();
1221
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001222 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001223 vc_conn.done;
1224}
1225
1226
1227/* helper function for an emergency call. caller passes in mobile identity to use */
1228private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001229 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1230 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001231
Harald Welte0bef21e2018-02-10 09:48:23 +01001232 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001233}
1234
1235/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001236friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001237 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001238
Harald Welte256571e2018-01-24 18:47:19 +01001239 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001240 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001241 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001242 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001243 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001244}
1245testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1246 var BSC_ConnHdlr vc_conn;
1247 f_init();
1248
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001249 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001250 vc_conn.done;
1251}
1252
Harald Weltee13cfb22019-04-23 16:52:02 +02001253
Harald Welted5b91402018-01-24 18:48:16 +01001254/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001255friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001256 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001257 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001258 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001259 /* Then issue emergency call identified by IMSI */
1260 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1261}
1262testcase TC_emerg_call_imsi() runs on MTC_CT {
1263 var BSC_ConnHdlr vc_conn;
1264 f_init();
1265
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001266 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001267 vc_conn.done;
1268}
1269
Harald Weltee13cfb22019-04-23 16:52:02 +02001270
Harald Welte45164da2018-01-24 12:51:27 +01001271/* CM Service Request for VGCS -> reject */
1272private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001273 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001274
1275 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001276 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001277
1278 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001279 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001280 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001281 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001282 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001283}
1284testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1285 var BSC_ConnHdlr vc_conn;
1286 f_init();
1287
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001288 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001289 vc_conn.done;
1290}
1291
1292/* CM Service Request for VBS -> reject */
1293private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001294 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001295
1296 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001297 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001298
1299 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001300 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001301 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001302 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001303 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001304}
1305testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1306 var BSC_ConnHdlr vc_conn;
1307 f_init();
1308
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001309 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001310 vc_conn.done;
1311}
1312
1313/* CM Service Request for LCS -> reject */
1314private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001315 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001316
1317 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001318 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001319
1320 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001321 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001322 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001323 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001324 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001325}
1326testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1327 var BSC_ConnHdlr vc_conn;
1328 f_init();
1329
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001330 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001331 vc_conn.done;
1332}
1333
Harald Welte0195ab12018-01-24 21:50:20 +01001334/* CM Re-Establishment Request */
1335private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001336 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001337
1338 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001339 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001340
1341 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1342 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001343 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001344 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001345 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001346}
1347testcase TC_cm_reest_req_reject() runs on MTC_CT {
1348 var BSC_ConnHdlr vc_conn;
1349 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001350
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001351 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001352 vc_conn.done;
1353}
1354
Harald Weltec638f4d2018-01-24 22:00:36 +01001355/* Test LU (with authentication enabled), with wrong response from MS */
1356private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001357 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001358
1359 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1360
1361 /* tell GSUP dispatcher to send this IMSI to us */
1362 f_create_gsup_expect(hex2str(g_pars.imsi));
1363
1364 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001365 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001366
1367 /* Send Early Classmark, just for the fun of it */
1368 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1369
1370 var AuthVector vec := f_gen_auth_vec_2g();
1371 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1372 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1373 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1374
1375 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1376 /* Send back wrong auth response */
1377 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1378
1379 /* Expect GSUP AUTH FAIL REP to HLR */
1380 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1381
1382 /* Expect LU REJECT with Cause == Illegal MS */
1383 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001384 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001385}
1386testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1387 var BSC_ConnHdlr vc_conn;
1388 f_init();
1389 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001390
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001391 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23, verify_cell_id := false);
Harald Weltec638f4d2018-01-24 22:00:36 +01001392 vc_conn.done;
1393}
1394
Harald Weltede371492018-01-27 23:44:41 +01001395/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001396private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001397 pars.net.expect_auth := true;
1398 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001399 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001400 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001401}
1402testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1403 var BSC_ConnHdlr vc_conn;
1404 f_init();
1405 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001406 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1407
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001408 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001409 vc_conn.done;
1410}
1411
Harald Welte1af6ea82018-01-25 18:33:15 +01001412/* Test Complete L3 without payload */
1413private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001414 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001415
1416 /* Send Complete L3 Info with empty L3 frame */
1417 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1418 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1419
Harald Weltef466eb42018-01-27 14:26:54 +01001420 timer T := 5.0;
1421 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001422 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001423 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001424 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001425 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001426 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001427 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001428 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001429 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001430 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001431 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001432 }
1433 setverdict(pass);
1434}
1435testcase TC_cl3_no_payload() runs on MTC_CT {
1436 var BSC_ConnHdlr vc_conn;
1437 f_init();
1438
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001439 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001440 vc_conn.done;
1441}
1442
1443/* Test Complete L3 with random payload */
1444private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001445 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001446
Daniel Willmannaa14a382018-07-26 08:29:45 +02001447 /* length is limited by PDU_BSSAP length field which includes some
1448 * other fields beside l3info payload. So payl can only be 240 bytes
1449 * Since rnd() returns values < 1 multiply with 241
1450 */
1451 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001452 var octetstring payl := f_rnd_octstring(len);
1453
1454 /* Send Complete L3 Info with empty L3 frame */
1455 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1456 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1457
Harald Weltef466eb42018-01-27 14:26:54 +01001458 timer T := 5.0;
1459 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001460 alt {
1461 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001462 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001463 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001464 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001465 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001466 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001467 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001468 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001469 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001470 }
1471 setverdict(pass);
1472}
1473testcase TC_cl3_rnd_payload() runs on MTC_CT {
1474 var BSC_ConnHdlr vc_conn;
1475 f_init();
1476
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001477 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001478 vc_conn.done;
1479}
1480
Harald Welte116e4332018-01-26 22:17:48 +01001481/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001482friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001483 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001484
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001485 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001486
Harald Welteb9e86fa2018-04-09 18:18:31 +02001487 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001488 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001489}
1490testcase TC_establish_and_nothing() runs on MTC_CT {
1491 var BSC_ConnHdlr vc_conn;
1492 f_init();
1493
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001494 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001495 vc_conn.done;
1496}
1497
Harald Weltee13cfb22019-04-23 16:52:02 +02001498
Harald Welte12510c52018-01-26 22:26:24 +01001499/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001500friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001501 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001502
Harald Welte12510c52018-01-26 22:26:24 +01001503 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001504 cpars.mgw_conn_2.resp := 0;
1505 cpars.stop_after_cc_setup := true;
1506
1507 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001508
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001509 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001510
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001511 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001512
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001513 var default ccrel := activate(as_optional_cc_rel(cpars));
1514
Philipp Maier109e6aa2018-10-17 10:53:32 +02001515 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001516
1517 deactivate(ccrel);
1518
1519 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001520}
1521testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1522 var BSC_ConnHdlr vc_conn;
1523 f_init();
1524
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001525 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001526 vc_conn.done;
1527}
1528
Harald Weltee13cfb22019-04-23 16:52:02 +02001529
Harald Welte3ab88002018-01-26 22:37:25 +01001530/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001531friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001532 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001533 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1534 var MNCC_PDU mncc;
1535 var MgcpCommand mgcp_cmd;
1536
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001537 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001538 /* Do not respond to the second CRCX */
1539 cpars.mgw_conn_2.resp := 0;
1540 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001541
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001542 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001543
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001544 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001545
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001546 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001547}
1548testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1549 var BSC_ConnHdlr vc_conn;
1550 f_init();
1551
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001552 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001553 vc_conn.done;
1554}
1555
Harald Weltee13cfb22019-04-23 16:52:02 +02001556
Harald Welte0cc82d92018-01-26 22:52:34 +01001557/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001558friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001559 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001560
Harald Welte0cc82d92018-01-26 22:52:34 +01001561 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001562
1563 /* Respond with error for the first CRCX */
1564 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001565
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001566 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001567 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001568
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001569 var default ccrel := activate(as_optional_cc_rel(cpars));
1570 f_expect_clear(60.0);
1571 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001572}
1573testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1574 var BSC_ConnHdlr vc_conn;
1575 f_init();
1576
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001577 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001578 vc_conn.done;
1579}
1580
Harald Welte3ab88002018-01-26 22:37:25 +01001581
Harald Welte812f7a42018-01-27 00:49:18 +01001582/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1583private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1584 var MNCC_PDU mncc;
1585 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001586
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001587 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001588 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001589
1590 /* Allocate call reference and send SETUP via MNCC to MSC */
1591 cpars.mncc_callref := f_rnd_int(2147483648);
1592 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1593 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1594
1595 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001596 f_expect_paging();
1597
Harald Welte812f7a42018-01-27 00:49:18 +01001598 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001599 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001600
1601 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1602
1603 /* MSC->MS: SETUP */
1604 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1605}
1606
1607/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001608friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001609 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001610 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1611 var MNCC_PDU mncc;
1612 var MgcpCommand mgcp_cmd;
1613
1614 f_mt_call_start(cpars);
1615
1616 /* MS->MSC: CALL CONFIRMED */
1617 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1618
1619 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1620
1621 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1622 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001623
1624 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1625 * set an endpoint name that fits the pattern. If not, just use the
1626 * endpoint name from the request */
1627 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1628 cpars.mgcp_ep := "rtpbridge/1@mgw";
1629 } else {
1630 cpars.mgcp_ep := mgcp_cmd.line.ep;
1631 }
1632
Harald Welte812f7a42018-01-27 00:49:18 +01001633 /* Respond to CRCX with error */
1634 var MgcpResponse mgcp_rsp := {
1635 line := {
1636 code := "542",
1637 trans_id := mgcp_cmd.line.trans_id,
1638 string := "FORCED_FAIL"
1639 },
Harald Welte812f7a42018-01-27 00:49:18 +01001640 sdp := omit
1641 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001642 var MgcpParameter mgcp_rsp_param := {
1643 code := "Z",
1644 val := cpars.mgcp_ep
1645 };
1646 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001647 MGCP.send(mgcp_rsp);
1648
1649 timer T := 30.0;
1650 T.start;
1651 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001652 [] T.timeout {
1653 setverdict(fail, "Timeout waiting for channel release");
1654 mtc.stop;
1655 }
Harald Welte812f7a42018-01-27 00:49:18 +01001656 [] MNCC.receive { repeat; }
1657 [] GSUP.receive { repeat; }
1658 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1659 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1660 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1661 repeat;
1662 }
1663 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001664 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001665 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001666 }
1667}
1668testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1669 var BSC_ConnHdlr vc_conn;
1670 f_init();
1671
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001672 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001673 vc_conn.done;
1674}
1675
1676
Harald Weltee13cfb22019-04-23 16:52:02 +02001677
Harald Welte812f7a42018-01-27 00:49:18 +01001678/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001679friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001680 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001681 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1682 var MNCC_PDU mncc;
1683 var MgcpCommand mgcp_cmd;
1684
1685 f_mt_call_start(cpars);
1686
1687 /* MS->MSC: CALL CONFIRMED */
1688 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1689 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1690
1691 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1692 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1693 cpars.mgcp_ep := mgcp_cmd.line.ep;
1694 /* FIXME: Respond to CRCX */
1695
1696 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1697 timer T := 190.0;
1698 T.start;
1699 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001700 [] T.timeout {
1701 setverdict(fail, "Timeout waiting for T310");
1702 mtc.stop;
1703 }
Harald Welte812f7a42018-01-27 00:49:18 +01001704 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1705 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1706 }
1707 }
1708 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1709 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1710 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1711 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1712
1713 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001714 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1715 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1716 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1717 repeat;
1718 }
Harald Welte5946b332018-03-18 23:32:21 +01001719 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001720 }
1721}
1722testcase TC_mt_t310() runs on MTC_CT {
1723 var BSC_ConnHdlr vc_conn;
1724 f_init();
1725
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001726 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001727 vc_conn.done;
1728}
1729
Harald Weltee13cfb22019-04-23 16:52:02 +02001730
Harald Welte167458a2018-01-27 15:58:16 +01001731/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001732friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001733 f_init_handler(pars);
1734 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001735
1736 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001737 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001738
1739 /* First MO call should succeed */
1740 f_mo_call(cpars);
1741
1742 /* Cancel the subscriber in the VLR */
1743 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1744 alt {
1745 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1746 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1747 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001748 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001749 }
1750 }
1751
1752 /* Follow-up transactions should fail */
1753 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1754 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001755 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001756 alt {
1757 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1758 [] BSSAP.receive {
1759 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001760 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001761 }
1762 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001763
1764 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001765 setverdict(pass);
1766}
1767testcase TC_gsup_cancel() runs on MTC_CT {
1768 var BSC_ConnHdlr vc_conn;
1769 f_init();
1770
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001771 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33, verify_cell_id := false);
Harald Welte167458a2018-01-27 15:58:16 +01001772 vc_conn.done;
1773}
1774
Harald Weltee13cfb22019-04-23 16:52:02 +02001775
Harald Welte9de84792018-01-28 01:06:35 +01001776/* A5/1 only permitted on network side, and MS capable to do it */
1777private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1778 pars.net.expect_auth := true;
1779 pars.net.expect_ciph := true;
1780 pars.net.kc_support := '02'O; /* A5/1 only */
1781 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001782 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001783}
1784testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1785 var BSC_ConnHdlr vc_conn;
1786 f_init();
1787 f_vty_config(MSCVTY, "network", "authentication required");
1788 f_vty_config(MSCVTY, "network", "encryption a5 1");
1789
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001790 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001791 vc_conn.done;
1792}
1793
1794/* A5/3 only permitted on network side, and MS capable to do it */
1795private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1796 pars.net.expect_auth := true;
1797 pars.net.expect_ciph := true;
1798 pars.net.kc_support := '08'O; /* A5/3 only */
1799 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001800 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001801}
1802testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1803 var BSC_ConnHdlr vc_conn;
1804 f_init();
1805 f_vty_config(MSCVTY, "network", "authentication required");
1806 f_vty_config(MSCVTY, "network", "encryption a5 3");
1807
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001808 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001809 vc_conn.done;
1810}
1811
1812/* A5/3 only permitted on network side, and MS with only A5/1 support */
1813private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1814 pars.net.expect_auth := true;
1815 pars.net.expect_ciph := true;
1816 pars.net.kc_support := '08'O; /* A5/3 only */
1817 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1818 f_init_handler(pars, 15.0);
1819
1820 /* cannot use f_perform_lu() as we expect a reject */
1821 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1822 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001823 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001824 if (pars.send_early_cm) {
1825 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1826 } else {
1827 pars.cm1.esind := '0'B;
1828 }
Harald Welte9de84792018-01-28 01:06:35 +01001829 f_mm_auth();
1830 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001831 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1832 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1833 repeat;
1834 }
Harald Welte5946b332018-03-18 23:32:21 +01001835 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1836 f_expect_clear();
1837 }
Harald Welte9de84792018-01-28 01:06:35 +01001838 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1839 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001840 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001841 }
1842 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001843 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001844 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001845 }
1846 }
1847 setverdict(pass);
1848}
1849testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1850 var BSC_ConnHdlr vc_conn;
1851 f_init();
1852 f_vty_config(MSCVTY, "network", "authentication required");
1853 f_vty_config(MSCVTY, "network", "encryption a5 3");
1854
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001855 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001856 vc_conn.done;
1857}
1858testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1859 var BSC_ConnHdlrPars pars;
1860 var BSC_ConnHdlr vc_conn;
1861 f_init();
1862 f_vty_config(MSCVTY, "network", "authentication required");
1863 f_vty_config(MSCVTY, "network", "encryption a5 3");
1864
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001865 pars := f_init_pars(361, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001866 pars.send_early_cm := false;
1867 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001868 vc_conn.done;
1869}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001870testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1871 var BSC_ConnHdlr vc_conn;
1872 f_init();
1873 f_vty_config(MSCVTY, "network", "authentication required");
1874 f_vty_config(MSCVTY, "network", "encryption a5 3");
1875
1876 /* Make sure the MSC category is on DEBUG level to trigger the log
1877 * message that is reported in OS#2947 to trigger the segfault */
1878 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1879
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001880 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362, verify_cell_id := false);
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001881 vc_conn.done;
1882}
Harald Welte9de84792018-01-28 01:06:35 +01001883
1884/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1885private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1886 pars.net.expect_auth := true;
1887 pars.net.expect_ciph := true;
1888 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1889 pars.cm1.a5_1 := '1'B;
1890 pars.cm2.a5_1 := '1'B;
1891 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1892 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1893 f_init_handler(pars, 15.0);
1894
1895 /* cannot use f_perform_lu() as we expect a reject */
1896 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1897 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001898 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001899 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1900 f_mm_auth();
1901 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001902 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1903 f_expect_clear();
1904 }
Harald Welte9de84792018-01-28 01:06:35 +01001905 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1906 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001907 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001908 }
1909 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001910 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001911 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001912 }
1913 }
1914 setverdict(pass);
1915}
1916testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1917 var BSC_ConnHdlr vc_conn;
1918 f_init();
1919 f_vty_config(MSCVTY, "network", "authentication required");
1920 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1921
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001922 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37, verify_cell_id := false);
Harald Welte9de84792018-01-28 01:06:35 +01001923 vc_conn.done;
1924}
1925
1926/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1927private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1928 pars.net.expect_auth := true;
1929 pars.net.expect_ciph := true;
1930 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1931 pars.cm1.a5_1 := '1'B;
1932 pars.cm2.a5_1 := '1'B;
1933 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1934 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1935 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001936 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001937}
1938testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1939 var BSC_ConnHdlr vc_conn;
1940 f_init();
1941 f_vty_config(MSCVTY, "network", "authentication required");
1942 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1943
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001944 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001945 vc_conn.done;
1946}
1947
Harald Welte33ec09b2018-02-10 15:34:46 +01001948/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01001949friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01001950 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001951 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001952 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01001953
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001954 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001955 f_mt_call(cpars);
1956}
1957testcase TC_lu_and_mt_call() runs on MTC_CT {
1958 var BSC_ConnHdlr vc_conn;
1959 f_init();
1960
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001961 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001962 vc_conn.done;
1963}
1964
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001965testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
1966 var BSC_ConnHdlr vc_conn;
1967 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001968
1969 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
1970 vc_conn.done;
1971}
1972
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02001973/* LU followed by MT call (including paging) */
1974friend function f_tc_lu_and_mt_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1975 f_init_handler(pars);
1976 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1977 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
1978 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
1979 cpars.bss_rtp_ip := "::3";
1980 f_perform_lu();
1981 f_mt_call(cpars);
1982}
1983testcase TC_lu_and_mt_call_ipv6() runs on MTC_CT {
1984 var BSC_ConnHdlr vc_conn;
1985 f_init();
1986
1987 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_ipv6), 39);
1988 vc_conn.done;
1989}
1990
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01001991/* MT call while already Paging */
1992friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1993 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1994 var SmsParameters spars := valueof(t_SmsPars);
1995 var OCT4 tmsi;
1996
1997 f_init_handler(pars);
1998
1999 /* Perform location update */
2000 f_perform_lu();
2001
2002 /* register an 'expect' for given IMSI (+TMSI) */
2003 if (isvalue(g_pars.tmsi)) {
2004 tmsi := g_pars.tmsi;
2005 } else {
2006 tmsi := 'FFFFFFFF'O;
2007 }
2008 f_ran_register_imsi(g_pars.imsi, tmsi);
2009
2010 log("start Paging by an SMS");
2011 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2012
2013 /* MSC->BSC: expect PAGING from MSC */
2014 f_expect_paging();
2015
2016 log("MNCC signals MT call, before Paging Response");
2017 f_mt_call_initate(cpars);
2018 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
2019
2020 f_sleep(0.5);
2021 log("phone answers Paging, expecting both SMS and MT call to be established");
2022 f_establish_fully(EST_TYPE_PAG_RESP);
2023 spars.tp.ud := 'C8329BFD064D9B53'O;
2024 interleave {
2025 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
2026 log("Got SMS-DELIVER");
2027 };
2028 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
2029 log("Got CC Setup");
2030 };
2031 }
2032 setverdict(pass);
2033 log("success, tear down");
2034 var default ccrel := activate(as_optional_cc_rel(cpars));
2035 if (g_pars.ran_is_geran) {
2036 BSSAP.send(ts_BSSMAP_ClearRequest(0));
2037 } else {
2038 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
2039 }
2040 f_expect_clear();
2041 deactivate(ccrel);
2042 f_vty_sms_clear(hex2str(g_pars.imsi));
2043}
2044testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
2045 var BSC_ConnHdlrPars pars;
2046 var BSC_ConnHdlr vc_conn;
2047 f_init();
2048 pars := f_init_pars(391);
2049 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
2050 vc_conn.done;
2051}
2052
Daniel Willmann8b084372018-02-04 13:35:26 +01002053/* Test MO Call SETUP with DTMF */
2054private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2055 f_init_handler(pars);
2056 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01002057
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002058 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01002059 f_mo_seq_dtmf_dup(cpars);
2060}
2061testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
2062 var BSC_ConnHdlr vc_conn;
2063 f_init();
2064
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002065 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01002066 vc_conn.done;
2067}
Harald Welte9de84792018-01-28 01:06:35 +01002068
Philipp Maier328d1662018-03-07 10:40:27 +01002069testcase TC_cr_before_reset() runs on MTC_CT {
2070 timer T := 4.0;
2071 var boolean reset_ack_seen := false;
2072 f_init_bssap_direct();
2073
Harald Welte3ca0ce12019-04-23 17:18:48 +02002074 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02002075
Daniel Willmanne8018962018-08-21 14:18:00 +02002076 f_sleep(3.0);
2077
Philipp Maier328d1662018-03-07 10:40:27 +01002078 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02002079 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01002080
2081 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02002082 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01002083 T.start
2084 alt {
2085 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
2086 reset_ack_seen := true;
2087 repeat;
2088 }
2089
2090 /* Acknowledge MSC sided reset requests */
2091 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02002092 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01002093 repeat;
2094 }
2095
2096 /* Ignore all other messages (e.g CR from the connection request) */
2097 [] BSSAP_DIRECT.receive { repeat }
2098
2099 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
2100 * deadlock situation. The MSC is then unable to respond to any
2101 * further BSSMAP RESET or any other sort of traffic. */
2102 [reset_ack_seen == true] T.timeout { setverdict(pass) }
2103 [reset_ack_seen == false] T.timeout {
2104 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02002105 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01002106 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01002107 }
Philipp Maier328d1662018-03-07 10:40:27 +01002108}
Harald Welte9de84792018-01-28 01:06:35 +01002109
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002110/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02002111friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002112 f_init_handler(pars);
2113 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2114 var MNCC_PDU mncc;
2115 var MgcpCommand mgcp_cmd;
2116
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002117 /* Do not respond to the second CRCX */
2118 cpars.mgw_conn_2.resp := 0;
2119
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002120 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002121 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002122
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002123 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002124
2125 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002126
2127 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002128}
2129testcase TC_mo_release_timeout() runs on MTC_CT {
2130 var BSC_ConnHdlr vc_conn;
2131 f_init();
2132
2133 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
2134 vc_conn.done;
2135}
2136
Harald Welte12510c52018-01-26 22:26:24 +01002137
Philipp Maier2a98a732018-03-19 16:06:12 +01002138/* LU followed by MT call (including paging) */
2139private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2140 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002141 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01002142
2143 /* Intentionally disable the CRCX response */
2144 cpars.mgw_drop_dlcx := true;
2145
2146 /* Perform location update and call */
2147 f_perform_lu();
2148 f_mt_call(cpars);
2149}
2150testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
2151 var BSC_ConnHdlr vc_conn;
2152 f_init();
2153
2154 /* Perform an almost normal looking locationupdate + mt-call, but do
2155 * not respond to the DLCX at the end of the call */
2156 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
2157 vc_conn.done;
2158
2159 /* Wait a guard period until the MGCP layer in the MSC times out,
2160 * if the MSC is vulnerable to the use-after-free situation that is
2161 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
2162 * segfault now */
2163 f_sleep(6.0);
2164
2165 /* Run the init procedures once more. If the MSC has crashed, this
2166 * this will fail */
2167 f_init();
2168}
Harald Welte45164da2018-01-24 12:51:27 +01002169
Philipp Maier75932982018-03-27 14:52:35 +02002170/* Two BSSMAP resets from two different BSCs */
2171testcase TC_reset_two() runs on MTC_CT {
2172 var BSC_ConnHdlr vc_conn;
2173 f_init(2);
2174 f_sleep(2.0);
2175 setverdict(pass);
2176}
2177
Harald Weltee13cfb22019-04-23 16:52:02 +02002178/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
2179testcase TC_reset_two_1iu() runs on MTC_CT {
2180 var BSC_ConnHdlr vc_conn;
2181 f_init(3);
2182 f_sleep(2.0);
2183 setverdict(pass);
2184}
2185
Harald Weltef640a012018-04-14 17:49:21 +02002186/***********************************************************************
2187 * SMS Testing
2188 ***********************************************************************/
2189
Harald Weltef45efeb2018-04-09 18:19:24 +02002190/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002191friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002192 var SmsParameters spars := valueof(t_SmsPars);
2193
2194 f_init_handler(pars);
2195
2196 /* Perform location update and call */
2197 f_perform_lu();
2198
2199 f_establish_fully(EST_TYPE_MO_SMS);
2200
2201 //spars.exp_rp_err := 96; /* invalid mandatory information */
2202 f_mo_sms(spars);
2203
2204 f_expect_clear();
2205}
2206testcase TC_lu_and_mo_sms() runs on MTC_CT {
2207 var BSC_ConnHdlr vc_conn;
2208 f_init();
2209 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2210 vc_conn.done;
2211}
2212
Harald Weltee13cfb22019-04-23 16:52:02 +02002213
Harald Weltef45efeb2018-04-09 18:19:24 +02002214private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002215runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002216 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2217}
2218
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002219/* Remove still pending SMS */
2220private function f_vty_sms_clear(charstring imsi)
2221runs on BSC_ConnHdlr {
2222 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2223 f_vty_transceive(MSCVTY, "sms-queue clear");
2224}
2225
Harald Weltef45efeb2018-04-09 18:19:24 +02002226/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002227friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002228 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002229
2230 f_init_handler(pars);
2231
2232 /* Perform location update and call */
2233 f_perform_lu();
2234
2235 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002236 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002237
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002238 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002239
2240 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002241 f_expect_paging();
2242
Harald Weltef45efeb2018-04-09 18:19:24 +02002243 /* Establish DTAP / BSSAP / SCCP connection */
2244 f_establish_fully(EST_TYPE_PAG_RESP);
2245
2246 spars.tp.ud := 'C8329BFD064D9B53'O;
2247 f_mt_sms(spars);
2248
2249 f_expect_clear();
2250}
2251testcase TC_lu_and_mt_sms() runs on MTC_CT {
2252 var BSC_ConnHdlrPars pars;
2253 var BSC_ConnHdlr vc_conn;
2254 f_init();
2255 pars := f_init_pars(43);
2256 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002257 vc_conn.done;
2258}
2259
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002260/* SMS added while already Paging */
2261friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2262 var SmsParameters spars := valueof(t_SmsPars);
2263 var OCT4 tmsi;
2264
2265 f_init_handler(pars);
2266
2267 f_perform_lu();
2268
2269 /* register an 'expect' for given IMSI (+TMSI) */
2270 if (isvalue(g_pars.tmsi)) {
2271 tmsi := g_pars.tmsi;
2272 } else {
2273 tmsi := 'FFFFFFFF'O;
2274 }
2275 f_ran_register_imsi(g_pars.imsi, tmsi);
2276
2277 log("first SMS");
2278 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2279
2280 /* MSC->BSC: expect PAGING from MSC */
2281 f_expect_paging();
2282
2283 log("second SMS");
2284 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2285 * with the pending paging. Another SMS: */
2286 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2287
2288 /* Establish DTAP / BSSAP / SCCP connection */
2289 f_establish_fully(EST_TYPE_PAG_RESP);
2290
2291 spars.tp.ud := 'C8329BFD064D9B53'O;
2292 f_mt_sms(spars);
2293
2294 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2295 f_mt_sms(spars);
2296
2297 f_expect_clear();
2298}
2299testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2300 var BSC_ConnHdlrPars pars;
2301 var BSC_ConnHdlr vc_conn;
2302 f_init();
2303 pars := f_init_pars(44);
2304 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2305 vc_conn.done;
2306}
Harald Weltee13cfb22019-04-23 16:52:02 +02002307
Philipp Maier3983e702018-11-22 19:01:33 +01002308/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002309friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002310 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002311
Philipp Maier3983e702018-11-22 19:01:33 +01002312 f_init_handler(pars, 150.0);
2313
2314 /* Perform location update */
2315 f_perform_lu();
2316
2317 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002318 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002319
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002320 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2321
Neels Hofmeyr16237742019-03-06 15:34:01 +01002322 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002323 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002324
2325 /* Wait some time to make sure the MSC is not delivering any further
2326 * paging messages or anything else that could be unexpected. */
2327 timer T := 20.0;
2328 T.start
2329 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002330 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2331 setverdict(fail, "paging seems not to stop!");
2332 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002333 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002334 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2335 setverdict(fail, "paging seems not to stop!");
2336 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002337 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002338 [] BSSAP.receive {
2339 setverdict(fail, "unexpected BSSAP message received");
2340 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002341 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002342 [] T.timeout {
2343 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002344 }
2345 }
2346
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002347 f_vty_sms_clear(hex2str(g_pars.imsi));
2348
Philipp Maier3983e702018-11-22 19:01:33 +01002349 setverdict(pass);
2350}
2351testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2352 var BSC_ConnHdlrPars pars;
2353 var BSC_ConnHdlr vc_conn;
2354 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002355 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002356 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002357 vc_conn.done;
2358}
2359
Alexander Couzensfc02f242019-09-12 03:43:18 +02002360/* LU followed by MT SMS with repeated paging */
2361friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2362 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002363
2364 f_init_handler(pars);
2365
2366 /* Perform location update and call */
2367 f_perform_lu();
2368
2369 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002370 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002371
2372 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2373
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002374 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002375 /* MSC->BSC: expect PAGING from MSC */
2376 f_expect_paging();
2377
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002378 if (g_pars.ran_is_geran) {
2379 log("GERAN: expect no further Paging");
2380 } else {
2381 log("UTRAN: expect more Paging");
2382 }
2383
2384 timer T := 5.0;
2385 T.start;
2386 alt {
2387 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2388 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2389 mtc.stop;
2390 }
2391 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2392 log("UTRAN: second Paging received, as expected");
2393 setverdict(pass);
2394 }
2395 [] T.timeout {
2396 if (g_pars.ran_is_geran) {
2397 log("GERAN: No further Paging received, as expected");
2398 setverdict(pass);
2399 } else {
2400 setverdict(fail, "UTRAN: Expected a second Paging");
2401 mtc.stop;
2402 }
2403 }
2404 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002405
2406 /* Establish DTAP / BSSAP / SCCP connection */
2407 f_establish_fully(EST_TYPE_PAG_RESP);
2408
2409 spars.tp.ud := 'C8329BFD064D9B53'O;
2410 f_mt_sms(spars);
2411
2412 f_expect_clear();
2413}
2414testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2415 var BSC_ConnHdlrPars pars;
2416 var BSC_ConnHdlr vc_conn;
2417 f_init();
2418 pars := f_init_pars(1844);
2419 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2420 vc_conn.done;
2421}
Harald Weltee13cfb22019-04-23 16:52:02 +02002422
Harald Weltef640a012018-04-14 17:49:21 +02002423/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002424friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002425 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002426
Harald Weltef640a012018-04-14 17:49:21 +02002427 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002428
Harald Weltef640a012018-04-14 17:49:21 +02002429 /* Perform location update so IMSI is known + registered in MSC/VLR */
2430 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002431
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002432 /* MS/UE submits a MO SMS */
2433 f_establish_fully(EST_TYPE_MO_SMS);
2434 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002435
2436 var SMPP_PDU smpp;
2437 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2438 tr_smpp.body.deliver_sm := {
2439 service_type := "CMT",
2440 source_addr_ton := network_specific,
2441 source_addr_npi := isdn,
2442 source_addr := hex2str(pars.msisdn),
2443 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2444 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2445 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2446 esm_class := '00000001'B,
2447 protocol_id := 0,
2448 priority_flag := 0,
2449 schedule_delivery_time := "",
2450 replace_if_present := 0,
2451 data_coding := '00000001'B,
2452 sm_default_msg_id := 0,
2453 sm_length := ?,
2454 short_message := spars.tp.ud,
2455 opt_pars := {
2456 {
2457 tag := user_message_reference,
2458 len := 2,
2459 opt_value := {
2460 int2_val := oct2int(spars.tp.msg_ref)
2461 }
2462 }
2463 }
2464 };
2465 alt {
2466 [] SMPP.receive(tr_smpp) -> value smpp {
2467 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2468 }
2469 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2470 }
2471
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002472 /* MSC terminates the SMS transaction with RP-ACK */
2473 f_mo_sms_wait_rp_ack(spars);
2474
Harald Weltef640a012018-04-14 17:49:21 +02002475 f_expect_clear();
2476}
2477testcase TC_smpp_mo_sms() runs on MTC_CT {
2478 var BSC_ConnHdlr vc_conn;
2479 f_init();
2480 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2481 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2482 vc_conn.done;
2483 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2484}
2485
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002486/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2487friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2488runs on BSC_ConnHdlr {
2489 var SmsParameters spars := valueof(t_SmsPars);
2490 var SMPP_PDU smpp_pdu;
2491 timer T := 3.0;
2492
2493 f_init_handler(pars);
2494
2495 /* Perform location update */
2496 f_perform_lu();
2497
2498 /* MS/UE submits a MO SMS */
2499 f_establish_fully(EST_TYPE_MO_SMS);
2500 f_mo_sms_submit(spars);
2501
2502 /* ESME responds with an error (Invalid Destination Address) */
2503 T.start;
2504 alt {
2505 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2506 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2507 }
2508 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2509 [] T.timeout {
2510 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2511 mtc.stop;
2512 }
2513 }
2514
2515 /* Expect RP-ERROR on BSSAP interface */
2516 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2517 f_mo_sms_wait_rp_ack(spars);
2518
2519 f_expect_clear();
2520}
2521testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2522 var BSC_ConnHdlr vc_conn;
2523 f_init();
2524 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2525 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2526 vc_conn.done;
2527 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2528}
2529
Harald Weltee13cfb22019-04-23 16:52:02 +02002530
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002531/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002532friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002533runs on BSC_ConnHdlr {
2534 var SmsParameters spars := valueof(t_SmsPars);
2535 var GSUP_PDU gsup_msg_rx;
2536 var octetstring sm_tpdu;
2537
2538 f_init_handler(pars);
2539
2540 /* We need to inspect GSUP activity */
2541 f_create_gsup_expect(hex2str(g_pars.imsi));
2542
2543 /* Perform location update */
2544 f_perform_lu();
2545
2546 /* Send CM Service Request for SMS */
2547 f_establish_fully(EST_TYPE_MO_SMS);
2548
2549 /* Prepare expected SM-RP-UI (SM TPDU) */
2550 enc_TPDU_RP_DATA_MS_SGSN_fast(
2551 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2552 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2553 spars.tp.udl, spars.tp.ud)),
2554 sm_tpdu);
2555
2556 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2557 imsi := g_pars.imsi,
2558 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002559 /* SM-RP-DA: SMSC address */
2560 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2561 number := spars.rp.smsc_addr.rP_NumberDigits,
2562 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2563 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2564 ext := spars.rp.smsc_addr.rP_Ext)),
2565 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2566 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2567 number := g_pars.msisdn,
2568 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2569 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002570 /* TODO: can we use decmatch here? */
2571 sm_rp_ui := sm_tpdu
2572 );
2573
2574 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2575 f_mo_sms_submit(spars);
2576 alt {
2577 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002578 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002579 setverdict(pass);
2580 }
2581 [] GSUP.receive {
2582 log("RX unexpected GSUP message");
2583 setverdict(fail);
2584 mtc.stop;
2585 }
2586 }
2587
2588 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2589 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2590 imsi := g_pars.imsi,
2591 sm_rp_mr := spars.rp.msg_ref)));
2592 /* Expect RP-ACK on DTAP */
2593 f_mo_sms_wait_rp_ack(spars);
2594
2595 f_expect_clear();
2596}
2597testcase TC_gsup_mo_sms() runs on MTC_CT {
2598 var BSC_ConnHdlr vc_conn;
2599 f_init();
2600 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2601 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2602 vc_conn.done;
2603 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2604}
2605
Harald Weltee13cfb22019-04-23 16:52:02 +02002606
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002607/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002608friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002609runs on BSC_ConnHdlr {
2610 var SmsParameters spars := valueof(t_SmsPars);
2611 var GSUP_PDU gsup_msg_rx;
2612
2613 f_init_handler(pars);
2614
2615 /* We need to inspect GSUP activity */
2616 f_create_gsup_expect(hex2str(g_pars.imsi));
2617
2618 /* Perform location update */
2619 f_perform_lu();
2620
2621 /* Send CM Service Request for SMS */
2622 f_establish_fully(EST_TYPE_MO_SMS);
2623
2624 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2625 imsi := g_pars.imsi,
2626 sm_rp_mr := spars.rp.msg_ref,
2627 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2628 );
2629
2630 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2631 f_mo_smma(spars);
2632 alt {
2633 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002634 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002635 setverdict(pass);
2636 }
2637 [] GSUP.receive {
2638 log("RX unexpected GSUP message");
2639 setverdict(fail);
2640 mtc.stop;
2641 }
2642 }
2643
2644 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2645 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2646 imsi := g_pars.imsi,
2647 sm_rp_mr := spars.rp.msg_ref)));
2648 /* Expect RP-ACK on DTAP */
2649 f_mo_sms_wait_rp_ack(spars);
2650
2651 f_expect_clear();
2652}
2653testcase TC_gsup_mo_smma() runs on MTC_CT {
2654 var BSC_ConnHdlr vc_conn;
2655 f_init();
2656 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2657 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2658 vc_conn.done;
2659 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2660}
2661
Harald Weltee13cfb22019-04-23 16:52:02 +02002662
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002663/* Helper for sending MT SMS over GSUP */
2664private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2665runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002666 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002667 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2668 number := spars.rp.smsc_addr.rP_NumberDigits,
2669 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2670 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2671 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002672
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002673 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2674 imsi := g_pars.imsi,
2675 /* NOTE: MSC should assign RP-MR itself */
2676 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002677 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002678 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002679 /* Encoded SMS TPDU (taken from Wireshark)
2680 * FIXME: we should encode spars somehow */
2681 sm_rp_ui := '00068021436500008111328130858200'O,
2682 sm_rp_mms := mms
2683 ));
2684}
2685
2686/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002687friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002688runs on BSC_ConnHdlr {
2689 var SmsParameters spars := valueof(t_SmsPars);
2690
2691 f_init_handler(pars);
2692
2693 /* We need to inspect GSUP activity */
2694 f_create_gsup_expect(hex2str(g_pars.imsi));
2695
2696 /* Perform location update */
2697 f_perform_lu();
2698
2699 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002700 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002701
2702 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2703 imsi := g_pars.imsi,
2704 /* NOTE: MSC should assign RP-MR itself */
2705 sm_rp_mr := ?
2706 );
2707
2708 /* Submit a MT SMS on GSUP */
2709 f_gsup_forwardSM_req(spars);
2710
2711 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002712 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002713 f_establish_fully(EST_TYPE_PAG_RESP);
2714
2715 /* Wait for MT SMS on DTAP */
2716 f_mt_sms_expect(spars);
2717
2718 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2719 f_mt_sms_send_rp_ack(spars);
2720 alt {
2721 [] GSUP.receive(mt_forwardSM_res) {
2722 log("RX MT-forwardSM-Res (RP-ACK)");
2723 setverdict(pass);
2724 }
2725 [] GSUP.receive {
2726 log("RX unexpected GSUP message");
2727 setverdict(fail);
2728 mtc.stop;
2729 }
2730 }
2731
2732 f_expect_clear();
2733}
2734testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2735 var BSC_ConnHdlrPars pars;
2736 var BSC_ConnHdlr vc_conn;
2737 f_init();
2738 pars := f_init_pars(90);
2739 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2740 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2741 vc_conn.done;
2742 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2743}
2744
Harald Weltee13cfb22019-04-23 16:52:02 +02002745
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002746/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002747friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002748runs on BSC_ConnHdlr {
2749 var SmsParameters spars := valueof(t_SmsPars);
2750 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2751
2752 f_init_handler(pars);
2753
2754 /* We need to inspect GSUP activity */
2755 f_create_gsup_expect(hex2str(g_pars.imsi));
2756
2757 /* Perform location update */
2758 f_perform_lu();
2759
2760 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002761 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002762
2763 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2764 imsi := g_pars.imsi,
2765 /* NOTE: MSC should assign RP-MR itself */
2766 sm_rp_mr := ?,
2767 sm_rp_cause := sm_rp_cause
2768 );
2769
2770 /* Submit a MT SMS on GSUP */
2771 f_gsup_forwardSM_req(spars);
2772
2773 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002774 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002775 f_establish_fully(EST_TYPE_PAG_RESP);
2776
2777 /* Wait for MT SMS on DTAP */
2778 f_mt_sms_expect(spars);
2779
2780 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2781 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2782 alt {
2783 [] GSUP.receive(mt_forwardSM_err) {
2784 log("RX MT-forwardSM-Err (RP-ERROR)");
2785 setverdict(pass);
2786 mtc.stop;
2787 }
2788 [] GSUP.receive {
2789 log("RX unexpected GSUP message");
2790 setverdict(fail);
2791 mtc.stop;
2792 }
2793 }
2794
2795 f_expect_clear();
2796}
2797testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2798 var BSC_ConnHdlrPars pars;
2799 var BSC_ConnHdlr vc_conn;
2800 f_init();
2801 pars := f_init_pars(91);
2802 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2803 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2804 vc_conn.done;
2805 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2806}
2807
Harald Weltee13cfb22019-04-23 16:52:02 +02002808
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002809/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002810friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002811runs on BSC_ConnHdlr {
2812 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2813 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2814
2815 f_init_handler(pars);
2816
2817 /* We need to inspect GSUP activity */
2818 f_create_gsup_expect(hex2str(g_pars.imsi));
2819
2820 /* Perform location update */
2821 f_perform_lu();
2822
2823 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002824 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002825
2826 /* Submit the 1st MT SMS on GSUP */
2827 log("TX MT-forwardSM-Req for the 1st SMS");
2828 f_gsup_forwardSM_req(spars1);
2829
2830 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002831 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002832 f_establish_fully(EST_TYPE_PAG_RESP);
2833
2834 /* Wait for 1st MT SMS on DTAP */
2835 f_mt_sms_expect(spars1);
2836 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2837 ", SM-RP-MR is ", spars1.rp.msg_ref);
2838
2839 /* Submit the 2nd MT SMS on GSUP */
2840 log("TX MT-forwardSM-Req for the 2nd SMS");
2841 f_gsup_forwardSM_req(spars2);
2842
2843 /* Wait for 2nd MT SMS on DTAP */
2844 f_mt_sms_expect(spars2);
2845 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2846 ", SM-RP-MR is ", spars2.rp.msg_ref);
2847
2848 /* Both transaction IDs shall be different */
2849 if (spars1.tid == spars2.tid) {
2850 log("Both DTAP transaction IDs shall be different");
2851 setverdict(fail);
2852 }
2853
2854 /* Both SM-RP-MR values shall be different */
2855 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2856 log("Both SM-RP-MR values shall be different");
2857 setverdict(fail);
2858 }
2859
2860 /* Both SM-RP-MR values shall be assigned */
2861 if (spars1.rp.msg_ref == 'FF'O) {
2862 log("Unassigned SM-RP-MR value for the 1st SMS");
2863 setverdict(fail);
2864 }
2865 if (spars2.rp.msg_ref == 'FF'O) {
2866 log("Unassigned SM-RP-MR value for the 2nd SMS");
2867 setverdict(fail);
2868 }
2869
2870 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2871 f_mt_sms_send_rp_ack(spars1);
2872 alt {
2873 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2874 imsi := g_pars.imsi,
2875 sm_rp_mr := spars1.rp.msg_ref
2876 )) {
2877 log("RX MT-forwardSM-Res (RP-ACK)");
2878 setverdict(pass);
2879 }
2880 [] GSUP.receive {
2881 log("RX unexpected GSUP message");
2882 setverdict(fail);
2883 mtc.stop;
2884 }
2885 }
2886
2887 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2888 f_mt_sms_send_rp_ack(spars2);
2889 alt {
2890 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2891 imsi := g_pars.imsi,
2892 sm_rp_mr := spars2.rp.msg_ref
2893 )) {
2894 log("RX MT-forwardSM-Res (RP-ACK)");
2895 setverdict(pass);
2896 }
2897 [] GSUP.receive {
2898 log("RX unexpected GSUP message");
2899 setverdict(fail);
2900 mtc.stop;
2901 }
2902 }
2903
2904 f_expect_clear();
2905}
2906testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2907 var BSC_ConnHdlrPars pars;
2908 var BSC_ConnHdlr vc_conn;
2909 f_init();
2910 pars := f_init_pars(92);
2911 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2912 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2913 vc_conn.done;
2914 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2915}
2916
Harald Weltee13cfb22019-04-23 16:52:02 +02002917
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002918/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002919friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002920runs on BSC_ConnHdlr {
2921 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2922 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2923
2924 f_init_handler(pars);
2925
2926 /* We need to inspect GSUP activity */
2927 f_create_gsup_expect(hex2str(g_pars.imsi));
2928
2929 /* Perform location update */
2930 f_perform_lu();
2931
2932 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002933 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002934
2935 /* Send CM Service Request for MO SMMA */
2936 f_establish_fully(EST_TYPE_MO_SMS);
2937
2938 /* Submit MO SMMA on DTAP */
2939 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2940 spars_mo.rp.msg_ref := '00'O;
2941 f_mo_smma(spars_mo);
2942
2943 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2944 alt {
2945 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2946 imsi := g_pars.imsi,
2947 sm_rp_mr := spars_mo.rp.msg_ref,
2948 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2949 )) {
2950 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2951 setverdict(pass);
2952 }
2953 [] GSUP.receive {
2954 log("RX unexpected GSUP message");
2955 setverdict(fail);
2956 mtc.stop;
2957 }
2958 }
2959
2960 /* Submit MT SMS on GSUP */
2961 log("TX MT-forwardSM-Req for the MT SMS");
2962 f_gsup_forwardSM_req(spars_mt);
2963
2964 /* Wait for MT SMS on DTAP */
2965 f_mt_sms_expect(spars_mt);
2966 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2967 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2968
2969 /* Both SM-RP-MR values shall be different */
2970 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2971 log("Both SM-RP-MR values shall be different");
2972 setverdict(fail);
2973 }
2974
2975 /* SM-RP-MR value for MT SMS shall be assigned */
2976 if (spars_mt.rp.msg_ref == 'FF'O) {
2977 log("Unassigned SM-RP-MR value for the MT SMS");
2978 setverdict(fail);
2979 }
2980
2981 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2982 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2983 imsi := g_pars.imsi,
2984 sm_rp_mr := spars_mo.rp.msg_ref)));
2985 /* Expect RP-ACK for MO SMMA on DTAP */
2986 f_mo_sms_wait_rp_ack(spars_mo);
2987
2988 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2989 f_mt_sms_send_rp_ack(spars_mt);
2990 alt {
2991 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2992 imsi := g_pars.imsi,
2993 sm_rp_mr := spars_mt.rp.msg_ref
2994 )) {
2995 log("RX MT-forwardSM-Res (RP-ACK)");
2996 setverdict(pass);
2997 }
2998 [] GSUP.receive {
2999 log("RX unexpected GSUP message");
3000 setverdict(fail);
3001 mtc.stop;
3002 }
3003 }
3004
3005 f_expect_clear();
3006}
3007testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
3008 var BSC_ConnHdlrPars pars;
3009 var BSC_ConnHdlr vc_conn;
3010 f_init();
3011 pars := f_init_pars(93);
3012 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3013 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
3014 vc_conn.done;
3015 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3016}
3017
Harald Weltee13cfb22019-04-23 16:52:02 +02003018
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003019/* Test multi-part MT-SMS over GSUP */
3020private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
3021runs on BSC_ConnHdlr {
3022 var SmsParameters spars := valueof(t_SmsPars);
3023
3024 f_init_handler(pars);
3025
3026 /* We need to inspect GSUP activity */
3027 f_create_gsup_expect(hex2str(g_pars.imsi));
3028
3029 /* Perform location update */
3030 f_perform_lu();
3031
3032 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003033 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003034
3035 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
3036 imsi := g_pars.imsi,
3037 /* NOTE: MSC should assign RP-MR itself */
3038 sm_rp_mr := ?
3039 );
3040
3041 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
3042 for (var integer i := 3; i >= 0; i := i-1) {
3043 /* Submit a MT SMS on GSUP (MMS is decremented) */
3044 f_gsup_forwardSM_req(spars, int2oct(i, 1));
3045
3046 /* Expect Paging Request and Establish connection */
3047 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02003048 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003049 f_establish_fully(EST_TYPE_PAG_RESP);
3050 }
3051
3052 /* Wait for MT SMS on DTAP */
3053 f_mt_sms_expect(spars);
3054
3055 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
3056 f_mt_sms_send_rp_ack(spars);
3057 alt {
3058 [] GSUP.receive(mt_forwardSM_res) {
3059 log("RX MT-forwardSM-Res (RP-ACK)");
3060 setverdict(pass);
3061 }
3062 [] GSUP.receive {
3063 log("RX unexpected GSUP message");
3064 setverdict(fail);
3065 mtc.stop;
3066 }
3067 }
3068
3069 /* Keep some 'distance' between transmissions */
3070 f_sleep(1.5);
3071 }
3072
3073 f_expect_clear();
3074}
3075testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
3076 var BSC_ConnHdlrPars pars;
3077 var BSC_ConnHdlr vc_conn;
3078 f_init();
3079 pars := f_init_pars(91);
3080 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3081 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
3082 vc_conn.done;
3083 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3084}
3085
Harald Weltef640a012018-04-14 17:49:21 +02003086/* convert GSM L3 TON to SMPP_TON enum */
3087function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
3088 select (ton) {
3089 case ('000'B) { return unknown; }
3090 case ('001'B) { return international; }
3091 case ('010'B) { return national; }
3092 case ('011'B) { return network_specific; }
3093 case ('100'B) { return subscriber_number; }
3094 case ('101'B) { return alphanumeric; }
3095 case ('110'B) { return abbreviated; }
3096 }
3097 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02003098 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003099}
3100/* convert GSM L3 NPI to SMPP_NPI enum */
3101function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
3102 select (npi) {
3103 case ('0000'B) { return unknown; }
3104 case ('0001'B) { return isdn; }
3105 case ('0011'B) { return data; }
3106 case ('0100'B) { return telex; }
3107 case ('0110'B) { return land_mobile; }
3108 case ('1000'B) { return national; }
3109 case ('1001'B) { return private_; }
3110 case ('1010'B) { return ermes; }
3111 }
3112 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02003113 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003114}
3115
3116/* build a SMPP_SM from SmsParameters */
3117function f_mt_sm_from_spars(SmsParameters spars)
3118runs on BSC_ConnHdlr return SMPP_SM {
3119 var SMPP_SM sm := {
3120 service_type := "CMT",
3121 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
3122 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
3123 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
3124 dest_addr_ton := international,
3125 dest_addr_npi := isdn,
3126 destination_addr := hex2str(g_pars.msisdn),
3127 esm_class := '00000001'B,
3128 protocol_id := 0,
3129 priority_flag := 0,
3130 schedule_delivery_time := "",
3131 validity_period := "",
3132 registered_delivery := '00000000'B,
3133 replace_if_present := 0,
3134 data_coding := '00000001'B,
3135 sm_default_msg_id := 0,
3136 sm_length := spars.tp.udl,
3137 short_message := spars.tp.ud,
3138 opt_pars := {}
3139 };
3140 return sm;
3141}
3142
3143/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
3144private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
3145 var SMPP_SM sm := f_mt_sm_from_spars(spars);
3146 if (trans_mode) {
3147 sm.esm_class := '00000010'B;
3148 }
3149
3150 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
3151 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
3152 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3153 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
3154 * before we expect the SMS delivery on the BSC/radio side */
3155 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3156 }
3157
3158 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02003159 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02003160 /* Establish DTAP / BSSAP / SCCP connection */
3161 f_establish_fully(EST_TYPE_PAG_RESP);
3162 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3163
3164 f_mt_sms(spars);
3165
3166 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3167 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3168 }
3169 f_expect_clear();
3170}
3171
3172/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
3173private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3174 f_init_handler(pars);
3175
3176 /* Perform location update so IMSI is known + registered in MSC/VLR */
3177 f_perform_lu();
3178 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3179
3180 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003181 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02003182
3183 var SmsParameters spars := valueof(t_SmsPars);
3184 /* TODO: test with more intelligent user data; test different coding schemes */
3185 spars.tp.ud := '00'O;
3186 spars.tp.udl := 1;
3187
3188 /* first test the non-transaction store+forward mode */
3189 f_smpp_mt_sms(spars, false);
3190
3191 /* then test the transaction mode */
3192 f_smpp_mt_sms(spars, true);
3193}
3194testcase TC_smpp_mt_sms() runs on MTC_CT {
3195 var BSC_ConnHdlr vc_conn;
3196 f_init();
3197 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
3198 vc_conn.done;
3199}
3200
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003201/***********************************************************************
3202 * USSD Testing
3203 ***********************************************************************/
3204
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003205private altstep as_unexp_gsup_or_bssap_msg()
3206runs on BSC_ConnHdlr {
3207 [] GSUP.receive {
3208 setverdict(fail, "Unknown/unexpected GSUP received");
3209 self.stop;
3210 }
3211 [] BSSAP.receive {
3212 setverdict(fail, "Unknown/unexpected BSSAP message received");
3213 self.stop;
3214 }
3215}
3216
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003217private function f_expect_gsup_msg(template GSUP_PDU msg,
3218 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003219runs on BSC_ConnHdlr return GSUP_PDU {
3220 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003221 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003222
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003223 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003224 alt {
3225 [] GSUP.receive(msg) -> value gsup_msg_complete {
3226 setverdict(pass);
3227 }
3228 /* We don't expect anything else */
3229 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003230 [] T.timeout {
3231 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3232 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003233 }
3234
3235 return gsup_msg_complete;
3236}
3237
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003238private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3239 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003240runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3241 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003242 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003243
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003244 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003245 alt {
3246 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3247 setverdict(pass);
3248 }
3249 /* We don't expect anything else */
3250 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003251 [] T.timeout {
3252 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3253 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003254 }
3255
3256 return bssap_msg_complete.dtap;
3257}
3258
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003259/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003260friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003261runs on BSC_ConnHdlr {
3262 f_init_handler(pars);
3263
3264 /* Perform location update */
3265 f_perform_lu();
3266
3267 /* Send CM Service Request for SS/USSD */
3268 f_establish_fully(EST_TYPE_SS_ACT);
3269
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003270 /* We need to inspect GSUP activity */
3271 f_create_gsup_expect(hex2str(g_pars.imsi));
3272
3273 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3274 invoke_id := 5, /* Phone may not start from 0 or 1 */
3275 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3276 ussd_string := "*#100#"
3277 );
3278
3279 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3280 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3281 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3282 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3283 )
3284
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003285 /* Compose a new SS/REGISTER message with request */
3286 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3287 tid := 1, /* We just need a single transaction */
3288 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003289 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003290 );
3291
3292 /* Compose SS/RELEASE_COMPLETE template with expected response */
3293 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3294 tid := 1, /* Response should arrive within the same transaction */
3295 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003296 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003297 );
3298
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003299 /* Compose expected MSC -> HLR message */
3300 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3301 imsi := g_pars.imsi,
3302 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3303 ss := valueof(facility_req)
3304 );
3305
3306 /* To be used for sending response with correct session ID */
3307 var GSUP_PDU gsup_req_complete;
3308
3309 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003310 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003311 /* Expect GSUP message containing the SS payload */
3312 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3313
3314 /* Compose the response from HLR using received session ID */
3315 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3316 imsi := g_pars.imsi,
3317 sid := gsup_req_complete.ies[1].val.session_id,
3318 state := OSMO_GSUP_SESSION_STATE_END,
3319 ss := valueof(facility_rsp)
3320 );
3321
3322 /* Finally, HLR terminates the session */
3323 GSUP.send(gsup_rsp);
3324 /* Expect RELEASE_COMPLETE message with the response */
3325 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003326
3327 f_expect_clear();
3328}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003329testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003330 var BSC_ConnHdlr vc_conn;
3331 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003332 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003333 vc_conn.done;
3334}
3335
Harald Weltee13cfb22019-04-23 16:52:02 +02003336
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003337/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003338friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003339runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003340 timer T := 5.0;
3341
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003342 f_init_handler(pars);
3343
3344 /* Perform location update */
3345 f_perform_lu();
3346
Harald Welte6811d102019-04-14 22:23:14 +02003347 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003348
3349 /* We need to inspect GSUP activity */
3350 f_create_gsup_expect(hex2str(g_pars.imsi));
3351
3352 /* Facility IE with network-originated USSD notification */
3353 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3354 op_code := SS_OP_CODE_USS_NOTIFY,
3355 ussd_string := "Mahlzeit!"
3356 );
3357
3358 /* Facility IE with acknowledgment to the USSD notification */
3359 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3360 /* In case of USSD notification, Return Result is empty */
3361 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3362 );
3363
3364 /* Compose a new MT SS/REGISTER message with USSD notification */
3365 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3366 tid := 0, /* FIXME: most likely, it should be 0 */
3367 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3368 facility := valueof(facility_req)
3369 );
3370
3371 /* Compose HLR -> MSC GSUP message */
3372 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3373 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003374 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003375 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3376 ss := valueof(facility_req)
3377 );
3378
3379 /* Send it to MSC and expect Paging Request */
3380 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003381 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003382 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003383 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3384 setverdict(pass);
3385 }
Harald Welte62113fc2019-05-09 13:04:02 +02003386 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003387 setverdict(pass);
3388 }
3389 /* We don't expect anything else */
3390 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003391 [] T.timeout {
3392 setverdict(fail, "Timeout waiting for Paging Request");
3393 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003394 }
3395
3396 /* Send Paging Response and expect USSD notification */
3397 f_establish_fully(EST_TYPE_PAG_RESP);
3398 /* Expect MT REGISTER message with USSD notification */
3399 f_expect_mt_dtap_msg(ussd_ntf);
3400
3401 /* Compose a new MO SS/FACILITY message with empty response */
3402 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3403 tid := 0, /* FIXME: it shall match the request tid */
3404 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3405 facility := valueof(facility_rsp)
3406 );
3407
3408 /* Compose expected MSC -> HLR GSUP message */
3409 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3410 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003411 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003412 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3413 ss := valueof(facility_rsp)
3414 );
3415
3416 /* MS sends response to the notification */
3417 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3418 /* Expect GSUP message containing the SS payload */
3419 f_expect_gsup_msg(gsup_rsp);
3420
3421 /* Compose expected MT SS/RELEASE COMPLETE message */
3422 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3423 tid := 0, /* FIXME: it shall match the request tid */
3424 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3425 facility := omit
3426 );
3427
3428 /* Compose MSC -> HLR GSUP message */
3429 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3430 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003431 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003432 state := OSMO_GSUP_SESSION_STATE_END
3433 );
3434
3435 /* Finally, HLR terminates the session */
3436 GSUP.send(gsup_term)
3437 /* Expect MT RELEASE COMPLETE without Facility IE */
3438 f_expect_mt_dtap_msg(ussd_term);
3439
3440 f_expect_clear();
3441}
3442testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3443 var BSC_ConnHdlr vc_conn;
3444 f_init();
3445 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3446 vc_conn.done;
3447}
3448
Harald Weltee13cfb22019-04-23 16:52:02 +02003449
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003450/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003451friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003452runs on BSC_ConnHdlr {
3453 f_init_handler(pars);
3454
3455 /* Call parameters taken from f_tc_lu_and_mt_call */
3456 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003457
3458 /* Perform location update */
3459 f_perform_lu();
3460
3461 /* Establish a MT call */
3462 f_mt_call_establish(cpars);
3463
3464 /* Hold the call for some time */
3465 f_sleep(1.0);
3466
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003467 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3468 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3469 ussd_string := "*#100#"
3470 );
3471
3472 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3473 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3474 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3475 )
3476
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003477 /* Compose a new SS/REGISTER message with request */
3478 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3479 tid := 1, /* We just need a single transaction */
3480 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003481 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003482 );
3483
3484 /* Compose SS/RELEASE_COMPLETE template with expected response */
3485 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3486 tid := 1, /* Response should arrive within the same transaction */
3487 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003488 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003489 );
3490
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003491 /* Compose expected MSC -> HLR message */
3492 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3493 imsi := g_pars.imsi,
3494 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3495 ss := valueof(facility_req)
3496 );
3497
3498 /* To be used for sending response with correct session ID */
3499 var GSUP_PDU gsup_req_complete;
3500
3501 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003502 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003503 /* Expect GSUP message containing the SS payload */
3504 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3505
3506 /* Compose the response from HLR using received session ID */
3507 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3508 imsi := g_pars.imsi,
3509 sid := gsup_req_complete.ies[1].val.session_id,
3510 state := OSMO_GSUP_SESSION_STATE_END,
3511 ss := valueof(facility_rsp)
3512 );
3513
3514 /* Finally, HLR terminates the session */
3515 GSUP.send(gsup_rsp);
3516 /* Expect RELEASE_COMPLETE message with the response */
3517 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003518
3519 /* Hold the call for some time */
3520 f_sleep(1.0);
3521
3522 /* Release the call (does Clear Complete itself) */
3523 f_call_hangup(cpars, true);
3524}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003525testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003526 var BSC_ConnHdlr vc_conn;
3527 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003528 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003529 vc_conn.done;
3530}
3531
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003532/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003533friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003534 f_init_handler(pars);
3535 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003536 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003537
3538 f_perform_lu();
3539
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003540 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003541 f_mo_call_establish(cpars);
3542 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003543 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003544
3545 f_sleep(1.0);
3546}
3547testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3548 var BSC_ConnHdlr vc_conn;
3549 f_init();
3550
3551 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3552 vc_conn.done;
3553}
3554
Harald Weltee13cfb22019-04-23 16:52:02 +02003555
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003556/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003557friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003558runs on BSC_ConnHdlr {
3559 f_init_handler(pars);
3560
3561 /* Call parameters taken from f_tc_lu_and_mt_call */
3562 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003563
3564 /* Perform location update */
3565 f_perform_lu();
3566
3567 /* Establish a MT call */
3568 f_mt_call_establish(cpars);
3569
3570 /* Hold the call for some time */
3571 f_sleep(1.0);
3572
3573 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3574 op_code := SS_OP_CODE_USS_REQUEST,
3575 ussd_string := "Please type anything..."
3576 );
3577
3578 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3579 op_code := SS_OP_CODE_USS_REQUEST,
3580 ussd_string := "Nope."
3581 )
3582
3583 /* Compose MT SS/REGISTER message with network-originated request */
3584 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3585 tid := 0, /* FIXME: most likely, it should be 0 */
3586 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3587 facility := valueof(facility_req)
3588 );
3589
3590 /* Compose HLR -> MSC GSUP message */
3591 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3592 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003593 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003594 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3595 ss := valueof(facility_req)
3596 );
3597
3598 /* Send it to MSC */
3599 GSUP.send(gsup_req);
3600 /* Expect MT REGISTER message with USSD request */
3601 f_expect_mt_dtap_msg(ussd_req);
3602
3603 /* Compose a new MO SS/FACILITY message with response */
3604 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3605 tid := 0, /* FIXME: it shall match the request tid */
3606 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3607 facility := valueof(facility_rsp)
3608 );
3609
3610 /* Compose expected MSC -> HLR GSUP message */
3611 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3612 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003613 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003614 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3615 ss := valueof(facility_rsp)
3616 );
3617
3618 /* MS sends response */
3619 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3620 f_expect_gsup_msg(gsup_rsp);
3621
3622 /* Compose expected MT SS/RELEASE COMPLETE message */
3623 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3624 tid := 0, /* FIXME: it shall match the request tid */
3625 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3626 facility := omit
3627 );
3628
3629 /* Compose MSC -> HLR GSUP message */
3630 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3631 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003632 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003633 state := OSMO_GSUP_SESSION_STATE_END
3634 );
3635
3636 /* Finally, HLR terminates the session */
3637 GSUP.send(gsup_term);
3638 /* Expect MT RELEASE COMPLETE without Facility IE */
3639 f_expect_mt_dtap_msg(ussd_term);
3640
3641 /* Hold the call for some time */
3642 f_sleep(1.0);
3643
3644 /* Release the call (does Clear Complete itself) */
3645 f_call_hangup(cpars, true);
3646}
3647testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3648 var BSC_ConnHdlr vc_conn;
3649 f_init();
3650 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3651 vc_conn.done;
3652}
3653
Harald Weltee13cfb22019-04-23 16:52:02 +02003654
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003655/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003656friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003657runs on BSC_ConnHdlr {
3658 f_init_handler(pars);
3659
3660 /* Perform location update */
3661 f_perform_lu();
3662
3663 /* Send CM Service Request for SS/USSD */
3664 f_establish_fully(EST_TYPE_SS_ACT);
3665
3666 /* We need to inspect GSUP activity */
3667 f_create_gsup_expect(hex2str(g_pars.imsi));
3668
3669 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3670 invoke_id := 1, /* Initial request */
3671 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3672 ussd_string := "*6766*266#"
3673 );
3674
3675 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3676 invoke_id := 2, /* Counter request */
3677 op_code := SS_OP_CODE_USS_REQUEST,
3678 ussd_string := "Password?!?"
3679 )
3680
3681 /* Compose MO SS/REGISTER message with request */
3682 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3683 tid := 1, /* We just need a single transaction */
3684 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3685 facility := valueof(facility_ms_req)
3686 );
3687
3688 /* Compose expected MSC -> HLR message */
3689 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3690 imsi := g_pars.imsi,
3691 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3692 ss := valueof(facility_ms_req)
3693 );
3694
3695 /* To be used for sending response with correct session ID */
3696 var GSUP_PDU gsup_ms_req_complete;
3697
3698 /* Initiate a new transaction */
3699 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3700 /* Expect GSUP request with original Facility IE */
3701 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3702
3703 /* Compose the response from HLR using received session ID */
3704 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3705 imsi := g_pars.imsi,
3706 sid := gsup_ms_req_complete.ies[1].val.session_id,
3707 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3708 ss := valueof(facility_net_req)
3709 );
3710
3711 /* Compose expected MT SS/FACILITY template with counter request */
3712 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3713 tid := 1, /* Response should arrive within the same transaction */
3714 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3715 facility := valueof(facility_net_req)
3716 );
3717
3718 /* Send response over GSUP */
3719 GSUP.send(gsup_net_req);
3720 /* Expect MT SS/FACILITY message with counter request */
3721 f_expect_mt_dtap_msg(ussd_net_req);
3722
3723 /* Compose MO SS/RELEASE COMPLETE */
3724 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3725 tid := 1, /* Response should arrive within the same transaction */
3726 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3727 facility := omit
3728 /* TODO: cause? */
3729 );
3730
3731 /* Compose expected HLR -> MSC abort message */
3732 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3733 imsi := g_pars.imsi,
3734 sid := gsup_ms_req_complete.ies[1].val.session_id,
3735 state := OSMO_GSUP_SESSION_STATE_END
3736 );
3737
3738 /* Abort transaction */
3739 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3740 /* Expect GSUP message indicating abort */
3741 f_expect_gsup_msg(gsup_abort);
3742
3743 f_expect_clear();
3744}
3745testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3746 var BSC_ConnHdlr vc_conn;
3747 f_init();
3748 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3749 vc_conn.done;
3750}
3751
Harald Weltee13cfb22019-04-23 16:52:02 +02003752
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003753/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003754friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003755runs on BSC_ConnHdlr {
3756 f_init_handler(pars);
3757
3758 /* Perform location update */
3759 f_perform_lu();
3760
3761 /* Send CM Service Request for SS/USSD */
3762 f_establish_fully(EST_TYPE_SS_ACT);
3763
3764 /* We need to inspect GSUP activity */
3765 f_create_gsup_expect(hex2str(g_pars.imsi));
3766
3767 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3768 invoke_id := 1,
3769 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3770 ussd_string := "#release_me");
3771
3772 /* Compose MO SS/REGISTER message with request */
3773 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3774 tid := 1, /* An arbitrary transaction identifier */
3775 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3776 facility := valueof(facility_ms_req));
3777
3778 /* Compose expected MSC -> HLR message */
3779 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3780 imsi := g_pars.imsi,
3781 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3782 ss := valueof(facility_ms_req));
3783
3784 /* To be used for sending response with correct session ID */
3785 var GSUP_PDU gsup_ms_req_complete;
3786
3787 /* Initiate a new SS transaction */
3788 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3789 /* Expect GSUP request with original Facility IE */
3790 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3791
3792 /* Don't respond, wait for timeout */
3793 f_sleep(3.0);
3794
3795 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3796 tid := 1, /* Should match the request's tid */
3797 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3798 cause := *, /* TODO: expect some specific value */
3799 facility := omit);
3800
3801 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3802 imsi := g_pars.imsi,
3803 sid := gsup_ms_req_complete.ies[1].val.session_id,
3804 state := OSMO_GSUP_SESSION_STATE_END,
3805 cause := ?); /* TODO: expect some specific value */
3806
3807 /* Expect release on both interfaces */
3808 interleave {
3809 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3810 [] GSUP.receive(gsup_rel) { };
3811 }
3812
3813 f_expect_clear();
3814 setverdict(pass);
3815}
3816testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3817 var BSC_ConnHdlr vc_conn;
3818 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003819 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003820 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3821 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003822 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003823}
3824
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003825/* MT (network-originated) USSD for unknown subscriber */
3826friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
3827runs on BSC_ConnHdlr {
3828 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
3829 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003830
3831 f_init_handler(pars);
3832 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
3833 f_create_gsup_expect(hex2str(imsi));
3834
3835 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3836 imsi := imsi,
3837 sid := sid,
3838 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3839 ss := f_rnd_octstring(23)
3840 );
3841
3842 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
3843 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3844 imsi := imsi,
3845 sid := sid,
3846 state := OSMO_GSUP_SESSION_STATE_END,
3847 cause := 2 /* FIXME: introduce an enumerated type! */
3848 );
3849
3850 /* Initiate a MT USSD notification */
3851 GSUP.send(gsup_req);
3852
3853 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07003854 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003855}
3856testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
3857 var BSC_ConnHdlr vc_conn;
3858 f_init();
3859 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
3860 vc_conn.done;
3861}
3862
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003863/* MO (mobile-originated) SS/USSD for unknown transaction */
3864friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
3865runs on BSC_ConnHdlr {
3866 f_init_handler(pars);
3867
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003868 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003869 f_create_gsup_expect(hex2str(g_pars.imsi));
3870
3871 /* Perform location update */
3872 f_perform_lu();
3873
3874 /* Send CM Service Request for SS/USSD */
3875 f_establish_fully(EST_TYPE_SS_ACT);
3876
3877 /* GSM 04.80 FACILITY message for a non-existing transaction */
3878 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
3879 tid := 1, /* An arbitrary transaction identifier */
3880 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3881 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3882 );
3883
3884 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
3885 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
3886 tid := 1, /* An arbitrary transaction identifier */
3887 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3888 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3889 );
3890
3891 /* Expected response from the network */
3892 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3893 tid := 1, /* Same as in the FACILITY message */
3894 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3895 facility := omit
3896 );
3897
3898 /* Send GSM 04.80 FACILITY for non-existing transaction */
3899 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
3900
3901 /* Expect GSM 04.80 RELEASE COMPLETE message */
3902 f_expect_mt_dtap_msg(mt_ss_rel);
3903 f_expect_clear();
3904
3905 /* Send another CM Service Request for SS/USSD */
3906 f_establish_fully(EST_TYPE_SS_ACT);
3907
3908 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
3909 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
3910
3911 /* Expect GSM 04.80 RELEASE COMPLETE message */
3912 f_expect_mt_dtap_msg(mt_ss_rel);
3913 f_expect_clear();
3914}
3915testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
3916 var BSC_ConnHdlr vc_conn;
3917 f_init();
3918 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
3919 vc_conn.done;
3920}
3921
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003922/* MT (network-originated) USSD for unknown session */
3923friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
3924runs on BSC_ConnHdlr {
3925 var OCT4 sid := '20000333'O;
3926
3927 f_init_handler(pars);
3928
3929 /* Perform location update */
3930 f_perform_lu();
3931
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003932 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003933 f_create_gsup_expect(hex2str(g_pars.imsi));
3934
3935 /* Request referencing a non-existing SS session */
3936 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3937 imsi := g_pars.imsi,
3938 sid := sid,
3939 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3940 ss := f_rnd_octstring(23)
3941 );
3942
3943 /* Error with some cause value */
3944 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3945 imsi := g_pars.imsi,
3946 sid := sid,
3947 state := OSMO_GSUP_SESSION_STATE_END,
3948 cause := ? /* FIXME: introduce an enumerated type! */
3949 );
3950
3951 /* Initiate a MT USSD notification */
3952 GSUP.send(gsup_req);
3953
3954 /* Expect GSUP PROC_SS_ERROR message */
3955 f_expect_gsup_msg(gsup_rsp);
3956}
3957testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
3958 var BSC_ConnHdlr vc_conn;
3959 f_init();
3960 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
3961 vc_conn.done;
3962}
3963
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003964/* MT (network-originated) USSD and no response to Paging Request */
3965friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
3966runs on BSC_ConnHdlr {
3967 timer TP := 2.0; /* Paging timer */
3968
3969 f_init_handler(pars);
3970
3971 /* Perform location update */
3972 f_perform_lu();
3973
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003974 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003975 f_create_gsup_expect(hex2str(g_pars.imsi));
3976
3977 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3978 imsi := g_pars.imsi,
3979 sid := '20000444'O,
3980 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3981 ss := f_rnd_octstring(23)
3982 );
3983
3984 /* Error with some cause value */
3985 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3986 imsi := g_pars.imsi,
3987 sid := '20000444'O,
3988 state := OSMO_GSUP_SESSION_STATE_END,
3989 cause := ? /* FIXME: introduce an enumerated type! */
3990 );
3991
3992 /* Initiate a MT USSD notification */
3993 GSUP.send(gsup_req);
3994
3995 /* Send it to MSC and expect Paging Request */
3996 TP.start;
3997 alt {
3998 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3999 setverdict(pass);
4000 }
4001 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4002 setverdict(pass);
4003 }
4004 /* We don't expect anything else */
4005 [] as_unexp_gsup_or_bssap_msg();
4006 [] TP.timeout {
4007 setverdict(fail, "Timeout waiting for Paging Request");
4008 }
4009 }
4010
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07004011 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
4012 * OsmoMSC waits for Paging Response 10 seconds by default. */
4013 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004014}
4015testcase TC_proc_ss_paging_fail() runs on MTC_CT {
4016 var BSC_ConnHdlr vc_conn;
4017 f_init();
4018 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
4019 vc_conn.done;
4020}
4021
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004022/* MT (network-originated) USSD followed by immediate abort */
4023friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
4024runs on BSC_ConnHdlr {
4025 var octetstring facility := f_rnd_octstring(23);
4026 var OCT4 sid := '20000555'O;
4027 timer TP := 2.0;
4028
4029 f_init_handler(pars);
4030
4031 /* Perform location update */
4032 f_perform_lu();
4033
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004034 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004035 f_create_gsup_expect(hex2str(g_pars.imsi));
4036
4037 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
4038 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4039 imsi := g_pars.imsi, sid := sid,
4040 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4041 ss := facility
4042 );
4043
4044 /* On the MS side, we expect GSM 04.80 REGISTER message */
4045 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
4046 tid := 0, /* Most likely, it should be 0 */
4047 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4048 facility := facility
4049 );
4050
4051 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
4052 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
4053 imsi := g_pars.imsi, sid := sid,
4054 state := OSMO_GSUP_SESSION_STATE_END,
4055 cause := 0 /* FIXME: introduce an enumerated type! */
4056 );
4057
4058 /* On the MS side, we expect GSM 04.80 REGISTER message */
4059 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4060 tid := 0, /* Most likely, it should be 0 */
4061 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4062 cause := *, /* FIXME: expect some specific cause value */
4063 facility := omit
4064 );
4065
4066 /* Initiate a MT USSD with random payload */
4067 GSUP.send(gsup_req);
4068
4069 /* Expect Paging Request */
4070 TP.start;
4071 alt {
4072 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4073 setverdict(pass);
4074 }
4075 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4076 setverdict(pass);
4077 }
4078 /* We don't expect anything else */
4079 [] as_unexp_gsup_or_bssap_msg();
4080 [] TP.timeout {
4081 setverdict(fail, "Timeout waiting for Paging Request");
4082 }
4083 }
4084
4085 /* Send Paging Response and establish connection */
4086 f_establish_fully(EST_TYPE_PAG_RESP);
4087 /* Expect MT REGISTER message with random facility */
4088 f_expect_mt_dtap_msg(dtap_reg);
4089
4090 /* HLR/EUSE decides to abort the session even
4091 * before getting any response from the MS */
4092 /* Initiate a MT USSD with random payload */
4093 GSUP.send(gsup_abort);
4094
4095 /* Expect RELEASE COMPLETE on ths MS side */
4096 f_expect_mt_dtap_msg(dtap_rel);
4097
4098 f_expect_clear();
4099}
4100testcase TC_proc_ss_abort() runs on MTC_CT {
4101 var BSC_ConnHdlr vc_conn;
4102 f_init();
4103 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
4104 vc_conn.done;
4105}
4106
Harald Weltee13cfb22019-04-23 16:52:02 +02004107
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01004108/* Verify multiple concurrent MO SS/USSD transactions
4109 * (one subscriber - one transaction) */
4110testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
4111 var BSC_ConnHdlr vc_conn[16];
4112 var integer i;
4113
4114 f_init();
4115
4116 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4117 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
4118 }
4119
4120 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4121 vc_conn[i].done;
4122 }
4123}
4124
4125/* Verify multiple concurrent MT SS/USSD transactions
4126 * (one subscriber - one transaction) */
4127testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
4128 var BSC_ConnHdlr vc_conn[16];
4129 var integer i;
4130 var OCT4 sid;
4131
4132 f_init();
4133
4134 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4135 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
4136 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
4137 f_init_pars(226 + i, gsup_sid := sid));
4138 }
4139
4140 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4141 vc_conn[i].done;
4142 }
4143}
4144
4145
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004146/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
4147private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4148 pars.net.expect_auth := true;
4149 pars.net.expect_ciph := true;
4150 pars.net.kc_support := '02'O; /* A5/1 only */
4151 f_init_handler(pars);
4152
4153 g_pars.vec := f_gen_auth_vec_2g();
4154
4155 /* Can't use f_perform_lu() directly. Code below is based on it. */
4156
4157 /* tell GSUP dispatcher to send this IMSI to us */
4158 f_create_gsup_expect(hex2str(g_pars.imsi));
4159
4160 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4161 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02004162 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004163
4164 f_mm_auth();
4165
4166 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4167 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4168 alt {
4169 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4170 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
4171 }
4172 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4173 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4174 mtc.stop;
4175 }
4176 [] BSSAP.receive {
4177 setverdict(fail, "Unknown/unexpected BSSAP received");
4178 mtc.stop;
4179 }
4180 }
Harald Welte79f1e452020-08-18 22:55:02 +02004181 f_expect_common_id();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004182
4183 /* Expect LU reject from MSC. */
4184 alt {
4185 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4186 setverdict(pass);
4187 }
4188 [] BSSAP.receive {
4189 setverdict(fail, "Unknown/unexpected BSSAP received");
4190 mtc.stop;
4191 }
4192 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01004193 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004194}
4195
4196testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
4197 var BSC_ConnHdlr vc_conn;
4198 f_init();
4199 f_vty_config(MSCVTY, "network", "encryption a5 1");
4200
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02004201 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52, verify_cell_id := false);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004202 vc_conn.done;
4203}
4204
Harald Welteb2284bd2019-05-10 11:30:43 +02004205/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
4206friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4207 f_init_handler(pars);
4208
4209 /* tell GSUP dispatcher to send this IMSI to us */
4210 f_create_gsup_expect(hex2str(g_pars.imsi));
4211
4212 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4213 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4214
4215 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4216 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4217 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +02004218 f_expect_common_id();
Harald Welteb2284bd2019-05-10 11:30:43 +02004219
4220 /* Expect LU reject from MSC. */
4221 alt {
4222 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4223 setverdict(pass);
4224 }
4225 [] BSSAP.receive {
4226 setverdict(fail, "Unknown/unexpected BSSAP received");
4227 mtc.stop;
4228 }
4229 }
4230 f_expect_clear();
4231}
4232testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4233 var BSC_ConnHdlr vc_conn;
4234 f_init();
4235 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4236 vc_conn.done;
4237}
4238
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004239private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4240 pars.net.expect_auth := true;
4241 pars.net.expect_ciph := true;
4242 pars.net.kc_support := kc_support;
4243 f_init_handler(pars);
4244
4245 g_pars.vec := f_gen_auth_vec_2g();
4246
4247 /* Can't use f_perform_lu() directly. Code below is based on it. */
4248
4249 /* tell GSUP dispatcher to send this IMSI to us */
4250 f_create_gsup_expect(hex2str(g_pars.imsi));
4251
4252 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4253 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4254 f_cl3_or_initial_ue(l3_lu);
4255
4256 f_mm_auth();
4257
4258 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4259 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4260 alt {
4261 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4262 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4263 }
4264 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4265 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4266 repeat;
4267 }
4268 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4269 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4270 mtc.stop;
4271 }
4272 [] BSSAP.receive {
4273 setverdict(fail, "Unknown/unexpected BSSAP received");
4274 mtc.stop;
4275 }
4276 }
Harald Welte79f1e452020-08-18 22:55:02 +02004277 f_expect_common_id();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004278
4279 /* TODO: Verify MSC is using the best cipher available! How? */
4280
4281 f_msc_lu_hlr();
4282 f_accept_reject_lu();
4283 f_expect_clear();
4284 setverdict(pass);
4285}
4286
4287/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4288private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4289 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4290}
4291
4292/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4293private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4294 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4295}
4296
4297/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4298private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4299 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4300}
4301
4302testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4303 var BSC_ConnHdlr vc_conn;
4304 f_init();
4305 f_vty_config(MSCVTY, "network", "encryption a5 1");
4306
4307 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4308 vc_conn.done;
4309}
4310
4311testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4312 var BSC_ConnHdlr vc_conn;
4313 f_init();
4314 f_vty_config(MSCVTY, "network", "encryption a5 3");
4315
4316 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4317 vc_conn.done;
4318}
4319
4320testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4321 var BSC_ConnHdlr vc_conn;
4322 f_init();
4323 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4324
4325 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4326 vc_conn.done;
4327}
Harald Welteb2284bd2019-05-10 11:30:43 +02004328
Harald Weltef640a012018-04-14 17:49:21 +02004329/* TODO (SMS):
4330 * different user data lengths
4331 * SMPP transaction mode with unsuccessful delivery
4332 * queued MT-SMS with no paging response + later delivery
4333 * different data coding schemes
4334 * multi-part SMS
4335 * user-data headers
4336 * TP-PID for SMS to SIM
4337 * behavior if SMS memory is full + RP-SMMA
4338 * delivery reports
4339 * SMPP osmocom extensions
4340 * more-messages-to-send
4341 * SMS during ongoing call (SACCH/SAPI3)
4342 */
4343
4344/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004345 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4346 * malformed messages (missing IE, invalid message type): properly rejected?
4347 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4348 * 3G/2G auth permutations
4349 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004350 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004351 * too long L3 INFO in DTAP
4352 * too long / padded BSSAP
4353 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004354 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004355
Harald Weltee13cfb22019-04-23 16:52:02 +02004356/***********************************************************************
4357 * SGsAP Testing
4358 ***********************************************************************/
4359
Philipp Maier948747b2019-04-02 15:22:33 +02004360/* Check if a subscriber exists in the VLR */
4361private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4362
4363 var CtrlValue active_subsribers;
4364 var integer rc;
4365 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4366
4367 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4368 if (rc < 0) {
4369 return false;
4370 }
4371
4372 return true;
4373}
4374
Harald Welte4263c522018-12-06 11:56:27 +01004375/* Perform a location updatye at the A-Interface and run some checks to confirm
4376 * that everything is back to normal. */
4377private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4378 var SmsParameters spars := valueof(t_SmsPars);
4379
4380 /* Perform a location update, the SGs association is expected to fall
4381 * back to NULL */
4382 f_perform_lu();
4383 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4384
4385 /* Trigger a paging request and expect the paging on BSSMAP, this is
4386 * to make sure that pagings are sent throught the A-Interface again
4387 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004388 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004389 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4390
4391 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004392 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4393 setverdict(pass);
4394 }
Harald Welte62113fc2019-05-09 13:04:02 +02004395 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004396 setverdict(pass);
4397 }
4398 [] SGsAP.receive {
4399 setverdict(fail, "Received unexpected message on SGs");
4400 }
4401 }
4402
4403 /* Send an SMS to make sure that also payload messages are routed
4404 * throught the A-Interface again */
4405 f_establish_fully(EST_TYPE_MO_SMS);
4406 f_mo_sms(spars);
4407 f_expect_clear();
4408}
4409
4410private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4411 var charstring vlr_name;
4412 f_init_handler(pars);
4413
4414 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4415 log("VLR name: ", vlr_name);
4416 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004417 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004418}
4419
4420testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004421 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004422 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004423 f_init(1, true);
4424 pars := f_init_pars(11810, true);
4425 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004426 vc_conn.done;
4427}
4428
4429/* like f_mm_auth() but for SGs */
4430function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4431 if (g_pars.net.expect_auth) {
4432 g_pars.vec := f_gen_auth_vec_3g();
4433 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4434 g_pars.vec.sres,
4435 g_pars.vec.kc,
4436 g_pars.vec.ik,
4437 g_pars.vec.ck,
4438 g_pars.vec.autn,
4439 g_pars.vec.res));
4440 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4441 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4442 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4443 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4444 }
4445}
4446
4447/* like f_perform_lu(), but on SGs rather than BSSAP */
4448function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4449 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4450 var PDU_SGsAP lur;
4451 var PDU_SGsAP lua;
4452 var PDU_SGsAP mm_info;
4453 var octetstring mm_info_dtap;
4454
4455 /* tell GSUP dispatcher to send this IMSI to us */
4456 f_create_gsup_expect(hex2str(g_pars.imsi));
4457
4458 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4459 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4460 /* Old LAI, if MS sends it */
4461 /* TMSI status, if MS has no valid TMSI */
4462 /* IMEISV, if it supports "automatic device detection" */
4463 /* TAI, if available in MME */
4464 /* E-CGI, if available in MME */
4465 SGsAP.send(lur);
4466
4467 /* FIXME: is this really done over SGs? The Ue is already authenticated
4468 * via the MME ... */
4469 f_mm_auth_sgs();
4470
4471 /* Expect MSC to perform LU with HLR */
4472 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4473 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4474 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4475 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4476
4477 alt {
4478 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4479 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4480 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4481 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4482 }
4483 setverdict(pass);
4484 }
4485 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4486 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4487 }
4488 [] SGsAP.receive {
4489 setverdict(fail, "Received unexpected message on SGs");
4490 }
4491 }
4492
4493 /* Check MM information */
4494 if (mp_mm_info == true) {
4495 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4496 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4497 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4498 setverdict(fail, "Unexpected MM Information");
4499 }
4500 }
4501
4502 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4503}
4504
4505private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4506 f_init_handler(pars);
4507 f_sgs_perform_lu();
4508 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4509
4510 f_sgsap_bssmap_screening();
4511
4512 setverdict(pass);
4513}
4514testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004515 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004516 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004517 f_init(1, true);
4518 pars := f_init_pars(11811, true);
4519 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004520 vc_conn.done;
4521}
4522
4523/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4524private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4525 f_init_handler(pars);
4526 var PDU_SGsAP lur;
4527
4528 f_create_gsup_expect(hex2str(g_pars.imsi));
4529 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4530 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4531 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4532 SGsAP.send(lur);
4533
4534 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4535 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4536 alt {
4537 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4538 setverdict(pass);
4539 }
4540 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4541 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4542 mtc.stop;
4543 }
4544 [] SGsAP.receive {
4545 setverdict(fail, "Received unexpected message on SGs");
4546 }
4547 }
4548
4549 f_sgsap_bssmap_screening();
4550
4551 setverdict(pass);
4552}
4553testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004554 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004555 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004556 f_init(1, true);
4557 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004558
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004559 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004560 vc_conn.done;
4561}
4562
4563/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4564private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4565 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4566 var PDU_SGsAP lur;
4567
4568 f_init_handler(pars);
4569
4570 /* tell GSUP dispatcher to send this IMSI to us */
4571 f_create_gsup_expect(hex2str(g_pars.imsi));
4572
4573 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4574 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4575 /* Old LAI, if MS sends it */
4576 /* TMSI status, if MS has no valid TMSI */
4577 /* IMEISV, if it supports "automatic device detection" */
4578 /* TAI, if available in MME */
4579 /* E-CGI, if available in MME */
4580 SGsAP.send(lur);
4581
4582 /* FIXME: is this really done over SGs? The Ue is already authenticated
4583 * via the MME ... */
4584 f_mm_auth_sgs();
4585
4586 /* Expect MSC to perform LU with HLR */
4587 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4588 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4589 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4590 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4591
4592 alt {
4593 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4594 setverdict(pass);
4595 }
4596 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4597 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4598 }
4599 [] SGsAP.receive {
4600 setverdict(fail, "Received unexpected message on SGs");
4601 }
4602 }
4603
4604 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4605
4606 /* Wait until the VLR has abort the TMSI reallocation procedure */
4607 f_sleep(45.0);
4608
4609 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4610 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4611
4612 f_sgsap_bssmap_screening();
4613
4614 setverdict(pass);
4615}
4616testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004617 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004618 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004619 f_init(1, true);
4620 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004621
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004622 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004623 vc_conn.done;
4624}
4625
4626private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4627runs on BSC_ConnHdlr {
4628 f_init_handler(pars);
4629 f_sgs_perform_lu();
4630 f_sleep(3.0);
4631
4632 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4633 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4634 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4635 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4636
4637 f_sgsap_bssmap_screening();
4638
4639 setverdict(pass);
4640}
4641testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004642 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004643 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004644 f_init(1, true);
4645 pars := f_init_pars(11814, true);
4646 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004647 vc_conn.done;
4648}
4649
Philipp Maierfc19f172019-03-21 11:17:54 +01004650private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4651runs on BSC_ConnHdlr {
4652 f_init_handler(pars);
4653 f_sgs_perform_lu();
4654 f_sleep(3.0);
4655
4656 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4657 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4658 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4659 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4660
4661 f_sgsap_bssmap_screening();
4662
4663 setverdict(pass);
4664}
4665testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4666 var BSC_ConnHdlrPars pars;
4667 var BSC_ConnHdlr vc_conn;
4668 f_init(1, true);
4669 pars := f_init_pars(11814, true);
4670 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4671 vc_conn.done;
4672}
4673
Harald Welte4263c522018-12-06 11:56:27 +01004674private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4675runs on BSC_ConnHdlr {
4676 f_init_handler(pars);
4677 f_sgs_perform_lu();
4678 f_sleep(3.0);
4679
4680 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4681 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4682 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004683
4684 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4685 setverdict(fail, "subscriber not removed from VLR");
4686 }
Harald Welte4263c522018-12-06 11:56:27 +01004687
4688 f_sgsap_bssmap_screening();
4689
4690 setverdict(pass);
4691}
4692testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004693 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004694 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004695 f_init(1, true);
4696 pars := f_init_pars(11815, true);
4697 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004698 vc_conn.done;
4699}
4700
Philipp Maier5d812702019-03-21 10:51:26 +01004701private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4702runs on BSC_ConnHdlr {
4703 f_init_handler(pars);
4704 f_sgs_perform_lu();
4705 f_sleep(3.0);
4706
4707 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4708 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4709 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4710
4711 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4712 setverdict(fail, "subscriber not removed from VLR");
4713 }
4714
4715 f_sgsap_bssmap_screening();
4716
4717 setverdict(pass);
4718}
4719testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4720 var BSC_ConnHdlrPars pars;
4721 var BSC_ConnHdlr vc_conn;
4722 f_init(1, true);
4723 pars := f_init_pars(11815, true);
4724 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4725 vc_conn.done;
4726}
4727
Harald Welte4263c522018-12-06 11:56:27 +01004728/* Trigger a paging request via VTY and send a paging reject in response */
4729private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4730runs on BSC_ConnHdlr {
4731 f_init_handler(pars);
4732 f_sgs_perform_lu();
4733 f_sleep(1.0);
4734
4735 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4736 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4737 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4738 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4739
4740 /* Initiate paging via VTY */
4741 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4742 alt {
4743 [] SGsAP.receive(exp_resp) {
4744 setverdict(pass);
4745 }
4746 [] SGsAP.receive {
4747 setverdict(fail, "Received unexpected message on SGs");
4748 }
4749 }
4750
4751 /* Now reject the paging */
4752 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4753
4754 /* Wait for the states inside the MSC to settle and check the state
4755 * of the SGs Association */
4756 f_sleep(1.0);
4757 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4758
4759 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4760 * but we also need to cover tha case where the cause code indicates an
4761 * "IMSI detached for EPS services". In those cases the VLR is expected to
4762 * try paging on tha A/Iu interface. This will be another testcase similar to
4763 * this one, but extended with checks for the presence of the A/Iu paging
4764 * messages. */
4765
4766 f_sgsap_bssmap_screening();
4767
4768 setverdict(pass);
4769}
4770testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004771 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004772 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004773 f_init(1, true);
4774 pars := f_init_pars(11816, true);
4775 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004776 vc_conn.done;
4777}
4778
4779/* Trigger a paging request via VTY and send a paging reject that indicates
4780 * that the subscriber intentionally rejected the call. */
4781private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4782runs on BSC_ConnHdlr {
4783 f_init_handler(pars);
4784 f_sgs_perform_lu();
4785 f_sleep(1.0);
4786
4787 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4788 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4789 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4790 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4791
4792 /* Initiate paging via VTY */
4793 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4794 alt {
4795 [] SGsAP.receive(exp_resp) {
4796 setverdict(pass);
4797 }
4798 [] SGsAP.receive {
4799 setverdict(fail, "Received unexpected message on SGs");
4800 }
4801 }
4802
4803 /* Now reject the paging */
4804 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4805
4806 /* Wait for the states inside the MSC to settle and check the state
4807 * of the SGs Association */
4808 f_sleep(1.0);
4809 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4810
4811 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4812 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4813 * to check back how this works and how it can be tested */
4814
4815 f_sgsap_bssmap_screening();
4816
4817 setverdict(pass);
4818}
4819testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004820 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004821 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004822 f_init(1, true);
4823 pars := f_init_pars(11817, true);
4824 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004825 vc_conn.done;
4826}
4827
4828/* Trigger a paging request via VTY and send an UE unreacable messge in response */
4829private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
4830runs on BSC_ConnHdlr {
4831 f_init_handler(pars);
4832 f_sgs_perform_lu();
4833 f_sleep(1.0);
4834
4835 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4836 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4837 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4838 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4839
4840 /* Initiate paging via VTY */
4841 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4842 alt {
4843 [] SGsAP.receive(exp_resp) {
4844 setverdict(pass);
4845 }
4846 [] SGsAP.receive {
4847 setverdict(fail, "Received unexpected message on SGs");
4848 }
4849 }
4850
4851 /* Now pretend that the UE is unreachable */
4852 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
4853
4854 /* Wait for the states inside the MSC to settle and check the state
4855 * of the SGs Association. */
4856 f_sleep(1.0);
4857 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4858
4859 f_sgsap_bssmap_screening();
4860
4861 setverdict(pass);
4862}
4863testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004864 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004865 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004866 f_init(1, true);
4867 pars := f_init_pars(11818, true);
4868 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004869 vc_conn.done;
4870}
4871
4872/* Trigger a paging request via VTY but don't respond to it */
4873private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
4874runs on BSC_ConnHdlr {
4875 f_init_handler(pars);
4876 f_sgs_perform_lu();
4877 f_sleep(1.0);
4878
4879 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4880 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02004881 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01004882 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4883 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4884
4885 /* Initiate paging via VTY */
4886 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4887 alt {
4888 [] SGsAP.receive(exp_resp) {
4889 setverdict(pass);
4890 }
4891 [] SGsAP.receive {
4892 setverdict(fail, "Received unexpected message on SGs");
4893 }
4894 }
4895
Philipp Maier34218102019-09-24 09:15:49 +02004896 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
4897 * after some time */
4898 timer T := 10.0;
4899 T.start
4900 alt {
4901 [] SGsAP.receive(exp_serv_abrt)
4902 {
4903 setverdict(pass);
4904 }
4905 [] SGsAP.receive {
4906 setverdict(fail, "unexpected SGsAP message received");
4907 self.stop;
4908 }
4909 [] T.timeout {
4910 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
4911 self.stop;
4912 }
4913 }
4914
4915 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01004916 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4917
4918 f_sgsap_bssmap_screening();
4919
4920 setverdict(pass);
4921}
4922testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004923 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004924 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004925 f_init(1, true);
4926 pars := f_init_pars(11819, true);
4927 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004928 vc_conn.done;
4929}
4930
4931/* Trigger a paging request via VTY and slip in an LU */
4932private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4933runs on BSC_ConnHdlr {
4934 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4935 f_init_handler(pars);
4936
4937 /* First we prepar the situation, where the SGs association is in state
4938 * NULL and the confirmed by radio contact indicator is set to false
4939 * as well. This can be archived by performing an SGs LU and then
4940 * resetting the VLR */
4941 f_sgs_perform_lu();
4942 f_sgsap_reset_mme(mp_mme_name);
4943 f_sleep(1.0);
4944 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4945
4946 /* Perform a paging, expect the paging messages on the SGs interface */
4947 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4948 alt {
4949 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4950 setverdict(pass);
4951 }
4952 [] SGsAP.receive {
4953 setverdict(fail, "Received unexpected message on SGs");
4954 }
4955 }
4956
4957 /* Perform the LU as normal */
4958 f_sgs_perform_lu();
4959 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4960
4961 /* Expect a new paging request right after the LU */
4962 alt {
4963 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4964 setverdict(pass);
4965 }
4966 [] SGsAP.receive {
4967 setverdict(fail, "Received unexpected message on SGs");
4968 }
4969 }
4970
4971 /* Test is done now, lets round everything up by rejecting the paging
4972 * cleanly. */
4973 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4974 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4975
4976 f_sgsap_bssmap_screening();
4977
4978 setverdict(pass);
4979}
4980testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004981 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004982 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004983 f_init(1, true);
4984 pars := f_init_pars(11820, true);
4985 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004986 vc_conn.done;
4987}
4988
4989/* Send unexpected unit-data through the SGs interface */
4990private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4991 f_init_handler(pars);
4992 f_sleep(1.0);
4993
4994 /* This simulates what happens when a subscriber without SGs
4995 * association gets unitdata via the SGs interface. */
4996
4997 /* Make sure the subscriber exists and the SGs association
4998 * is in NULL state */
4999 f_perform_lu();
5000 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5001
5002 /* Send some random unit data, the MSC/VLR should send a release
5003 * immediately. */
5004 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5005 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
5006
5007 f_sgsap_bssmap_screening();
5008
5009 setverdict(pass);
5010}
5011testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005012 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005013 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005014 f_init(1, true);
5015 pars := f_init_pars(11821, true);
5016 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005017 vc_conn.done;
5018}
5019
5020/* Send unsolicited unit-data through the SGs interface */
5021private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5022 f_init_handler(pars);
5023 f_sleep(1.0);
5024
5025 /* This simulates what happens when the MME attempts to send unitdata
5026 * to a subscriber that is completely unknown to the VLR */
5027
5028 /* Send some random unit data, the MSC/VLR should send a release
5029 * immediately. */
5030 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5031 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
5032
5033 f_sgsap_bssmap_screening();
5034
Harald Welte4d15fa72020-08-19 08:58:28 +02005035 /* clean-up VLR state about this subscriber */
5036 f_imsi_detach_by_imsi();
5037
Harald Welte4263c522018-12-06 11:56:27 +01005038 setverdict(pass);
5039}
5040testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005041 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005042 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005043 f_init(1, true);
5044 pars := f_init_pars(11822, true);
5045 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005046 vc_conn.done;
5047}
5048
5049private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
5050 /* FIXME: Match an actual payload (second questionmark), the type is
5051 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
5052 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
5053 setverdict(fail, "Unexpected SMS related PDU from MSC");
5054 mtc.stop;
5055 }
5056}
5057
5058/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
5059function f_mt_sms_sgs(inout SmsParameters spars)
5060runs on BSC_ConnHdlr {
5061 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5062 var template (value) RPDU_MS_SGSN rp_mo;
5063 var template (value) PDU_ML3_MS_NW l3_mo;
5064
5065 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5066 var template RPDU_SGSN_MS rp_mt;
5067 var template PDU_ML3_NW_MS l3_mt;
5068
5069 var PDU_ML3_NW_MS sgsap_l3_mt;
5070
5071 var default d := activate(as_other_sms_sgs());
5072
5073 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
5074 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09005075 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01005076 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
5077
5078 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
5079
5080 /* Extract relevant identifiers */
5081 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
5082 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
5083
5084 /* send CP-ACK for CP-DATA just received */
5085 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
5086
5087 SGsAP.send(l3_mo);
5088
5089 /* send RP-ACK for RP-DATA */
5090 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
5091 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
5092
5093 SGsAP.send(l3_mo);
5094
5095 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
5096 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
5097
5098 SGsAP.receive(l3_mt);
5099
5100 deactivate(d);
5101
5102 setverdict(pass);
5103}
5104
5105/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
5106function f_mo_sms_sgs(inout SmsParameters spars)
5107runs on BSC_ConnHdlr {
5108 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5109 var template (value) RPDU_MS_SGSN rp_mo;
5110 var template (value) PDU_ML3_MS_NW l3_mo;
5111
5112 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5113 var template RPDU_SGSN_MS rp_mt;
5114 var template PDU_ML3_NW_MS l3_mt;
5115
5116 var default d := activate(as_other_sms_sgs());
5117
5118 /* just in case this is routed to SMPP.. */
5119 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
5120
5121 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
5122 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09005123 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01005124 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
5125
5126 SGsAP.send(l3_mo);
5127
5128 /* receive CP-ACK for CP-DATA above */
5129 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
5130
5131 if (ispresent(spars.exp_rp_err)) {
5132 /* expect an RP-ERROR message from MSC with given cause */
5133 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
5134 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5135 SGsAP.receive(l3_mt);
5136 /* send CP-ACK for CP-DATA just received */
5137 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5138 SGsAP.send(l3_mo);
5139 } else {
5140 /* expect RP-ACK for RP-DATA */
5141 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
5142 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5143 SGsAP.receive(l3_mt);
5144 /* send CP-ACO for CP-DATA just received */
5145 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5146 SGsAP.send(l3_mo);
5147 }
5148
5149 deactivate(d);
5150
5151 setverdict(pass);
5152}
5153
5154private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
5155runs on BSC_ConnHdlr {
5156 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
5157}
5158
5159/* Send a MT SMS via SGs interface */
5160private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5161 f_init_handler(pars);
5162 f_sgs_perform_lu();
5163 f_sleep(1.0);
5164 var SmsParameters spars := valueof(t_SmsPars);
5165 spars.tp.ud := 'C8329BFD064D9B53'O;
5166
5167 /* Trigger SMS via VTY */
5168 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5169 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5170
5171 /* Expect a paging request and respond accordingly with a service request */
5172 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
5173 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
5174
5175 /* Connection is now live, receive the MT-SMS */
5176 f_mt_sms_sgs(spars);
5177
5178 /* Expect a concluding release from the MSC */
5179 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5180
5181 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5182 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5183
5184 f_sgsap_bssmap_screening();
5185
5186 setverdict(pass);
5187}
5188testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005189 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005190 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005191 f_init(1, true);
5192 pars := f_init_pars(11823, true);
5193 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005194 vc_conn.done;
5195}
5196
5197/* Send a MO SMS via SGs interface */
5198private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5199 f_init_handler(pars);
5200 f_sgs_perform_lu();
5201 f_sleep(1.0);
5202 var SmsParameters spars := valueof(t_SmsPars);
5203 spars.tp.ud := 'C8329BFD064D9B53'O;
5204
5205 /* Send the MO-SMS */
5206 f_mo_sms_sgs(spars);
5207
5208 /* Expect a concluding release from the MSC/VLR */
5209 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5210
5211 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5212 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5213
5214 setverdict(pass);
5215
5216 f_sgsap_bssmap_screening()
5217}
5218testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005219 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005220 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005221 f_init(1, true);
5222 pars := f_init_pars(11824, true);
5223 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005224 vc_conn.done;
5225}
5226
5227/* Trigger sending of an MT sms via VTY but never respond to anything */
5228private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5229 f_init_handler(pars, 170.0);
5230 f_sgs_perform_lu();
5231 f_sleep(1.0);
5232
5233 var SmsParameters spars := valueof(t_SmsPars);
5234 spars.tp.ud := 'C8329BFD064D9B53'O;
5235 var integer page_count := 0;
5236 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5237 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5238 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5239 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5240
5241 /* Trigger SMS via VTY */
5242 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5243
Neels Hofmeyr16237742019-03-06 15:34:01 +01005244 /* Expect the MSC/VLR to page exactly once */
5245 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005246
5247 /* Wait some time to make sure the MSC is not delivering any further
5248 * paging messages or anything else that could be unexpected. */
5249 timer T := 20.0;
5250 T.start
5251 alt {
5252 [] SGsAP.receive(exp_pag_req)
5253 {
5254 setverdict(fail, "paging seems not to stop!");
5255 mtc.stop;
5256 }
5257 [] SGsAP.receive {
5258 setverdict(fail, "unexpected SGsAP message received");
5259 self.stop;
5260 }
5261 [] T.timeout {
5262 setverdict(pass);
5263 }
5264 }
5265
5266 /* Even on a failed paging the SGs Association should stay intact */
5267 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5268
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005269 /* Make sure that the SMS we just inserted is cleared and the
5270 * subscriber is expired. This is necessary because otherwise the MSC
5271 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005272
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005273 f_vty_sms_clear(hex2str(g_pars.imsi));
5274
Harald Welte4263c522018-12-06 11:56:27 +01005275 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5276
5277 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005278
5279 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005280}
5281testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005282 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005283 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005284 f_init(1, true);
5285 pars := f_init_pars(11825, true);
5286 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005287 vc_conn.done;
5288}
5289
5290/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5291private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5292 f_init_handler(pars, 150.0);
5293 f_sgs_perform_lu();
5294 f_sleep(1.0);
5295
5296 var SmsParameters spars := valueof(t_SmsPars);
5297 spars.tp.ud := 'C8329BFD064D9B53'O;
5298 var integer page_count := 0;
5299 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5300 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5301 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5302 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5303
5304 /* Trigger SMS via VTY */
5305 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5306
5307 /* Expect a paging request and reject it immediately */
5308 SGsAP.receive(exp_pag_req);
5309 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5310
5311 /* The MSC/VLR should no longer try to page once the paging has been
5312 * rejected. Wait some time and check if there are no unexpected
5313 * messages on the SGs interface. */
5314 timer T := 20.0;
5315 T.start
5316 alt {
5317 [] SGsAP.receive(exp_pag_req)
5318 {
5319 setverdict(fail, "paging seems not to stop!");
5320 mtc.stop;
5321 }
5322 [] SGsAP.receive {
5323 setverdict(fail, "unexpected SGsAP message received");
5324 self.stop;
5325 }
5326 [] T.timeout {
5327 setverdict(pass);
5328 }
5329 }
5330
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005331 f_vty_sms_clear(hex2str(g_pars.imsi));
5332
Harald Welte4263c522018-12-06 11:56:27 +01005333 /* A rejected paging with IMSI_unknown (see above) should always send
5334 * the SGs association to NULL. */
5335 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5336
5337 f_sgsap_bssmap_screening();
5338
Harald Welte4263c522018-12-06 11:56:27 +01005339 setverdict(pass);
5340}
5341testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005342 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005343 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005344 f_init(1, true);
5345 pars := f_init_pars(11826, true);
5346 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005347 vc_conn.done;
5348}
5349
5350/* Perform an MT CSDB call including LU */
5351private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5352 f_init_handler(pars);
5353
5354 /* Be sure that the BSSMAP reset is done before we begin. */
5355 f_sleep(2.0);
5356
5357 /* Testcase variation: See what happens when we do a regular BSSMAP
5358 * LU first (this should not hurt in any way!) */
5359 if (bssmap_lu) {
5360 f_perform_lu();
5361 }
5362
5363 f_sgs_perform_lu();
5364 f_sleep(1.0);
5365
5366 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5367 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005368
5369 /* Initiate a call via MNCC interface */
5370 f_mt_call_initate(cpars);
5371
5372 /* Expect a paging request and respond accordingly with a service request */
5373 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5374 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5375
5376 /* Complete the call, hold it for some time and then tear it down */
5377 f_mt_call_complete(cpars);
5378 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005379 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005380
5381 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5382 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5383
Harald Welte4263c522018-12-06 11:56:27 +01005384 /* Test for successful return by triggering a paging, when the paging
5385 * request is received via SGs, we can be sure that the MSC/VLR has
5386 * recognized that the UE is now back on 4G */
5387 f_sleep(1.0);
5388 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5389 alt {
5390 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5391 setverdict(pass);
5392 }
5393 [] SGsAP.receive {
5394 setverdict(fail, "Received unexpected message on SGs");
5395 }
5396 }
5397
5398 f_sgsap_bssmap_screening();
5399
5400 setverdict(pass);
5401}
5402
5403/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5404private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5405 f_mt_lu_and_csfb_call(id, pars, true);
5406}
5407testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005408 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005409 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005410 f_init(1, true);
5411 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005412
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005413 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005414 vc_conn.done;
5415}
5416
Harald Welte4263c522018-12-06 11:56:27 +01005417/* Perform a SGSAP LU and then make a CSFB call */
5418private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5419 f_mt_lu_and_csfb_call(id, pars, false);
5420}
5421testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005422 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005423 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005424 f_init(1, true);
5425 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005426
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005427 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005428 vc_conn.done;
5429}
5430
Philipp Maier628c0052019-04-09 17:36:57 +02005431/* Simulate an HLR/VLR failure */
5432private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5433 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5434 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5435
5436 var PDU_SGsAP lur;
5437
5438 f_init_handler(pars);
5439
5440 /* Attempt location update (which is expected to fail) */
5441 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5442 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5443 SGsAP.send(lur);
5444
5445 /* Respond to SGsAP-RESET-INDICATION from VLR */
5446 alt {
5447 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5448 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5449 setverdict(pass);
5450 }
5451 [] SGsAP.receive {
5452 setverdict(fail, "Received unexpected message on SGs");
5453 }
5454 }
5455
5456 f_sleep(1.0);
5457 setverdict(pass);
5458}
5459testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5460 var BSC_ConnHdlrPars pars;
5461 var BSC_ConnHdlr vc_conn;
5462 f_init(1, true, false);
5463 pars := f_init_pars(11811, true, false);
5464 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5465 vc_conn.done;
5466}
5467
Harald Welte4263c522018-12-06 11:56:27 +01005468/* SGs TODO:
5469 * LU attempt for IMSI without NAM_PS in HLR
5470 * LU attempt with AUTH FAIL due to invalid RES/SRES
5471 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5472 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5473 * implicit IMSI detach from EPS
5474 * implicit IMSI detach from non-EPS
5475 * MM INFO
5476 *
5477 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005478
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005479private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5480 f_init_handler(pars);
5481 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005482
5483 f_perform_lu();
5484 f_mo_call_establish(cpars);
5485
5486 f_sleep(1.0);
5487
5488 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5489 var BssmapCause cause := enum2int(cause_val);
5490
5491 var template BSSMAP_FIELD_CellIdentificationList cil;
5492 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5493
5494 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5495 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5496
5497 f_call_hangup(cpars, true);
5498}
5499testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5500 var BSC_ConnHdlr vc_conn;
5501 f_init();
5502
5503 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5504 vc_conn.done;
5505}
5506
5507private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5508 var MgcpCommand mgcp_cmd;
5509 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005510 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005511 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005512 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005513 { int2str(cpars.rtp_payload_type) },
5514 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5515 cpars.rtp_sdp_format)),
5516 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005517 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_2.mgcp_connection_id, sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005518 repeat;
5519 }
5520}
5521
5522private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005523 var CallParameters cpars;
5524
5525 cpars := valueof(t_CallParams('12345'H, 0));
5526 if (pars.use_ipv6) {
5527 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5528 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5529 cpars.bss_rtp_ip := "::3";
5530 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005531
5532 f_init_handler(pars);
5533
5534 f_vty_transceive(MSCVTY, "configure terminal");
5535 f_vty_transceive(MSCVTY, "msc");
5536 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
5537 f_vty_transceive(MSCVTY, "neighbor a lac 5 ran-pc 0.24.2");
5538 f_vty_transceive(MSCVTY, "exit");
5539 f_vty_transceive(MSCVTY, "exit");
5540
5541 f_perform_lu();
5542 f_mo_call_establish(cpars);
5543
5544 f_sleep(1.0);
5545
5546 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5547
5548 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5549 var BssmapCause cause := enum2int(cause_val);
5550
5551 var template BSSMAP_FIELD_CellIdentificationList cil;
5552 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 5) } };
5553
5554 /* old BSS sends Handover Required */
5555 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5556
5557 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5558
5559 /* MSC forwards the RR Handover Command to old BSS */
5560 var PDU_BSSAP ho_command;
5561 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5562
5563 log("GOT HandoverCommand", ho_command);
5564
5565 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5566
5567 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5568 f_expect_clear();
5569
5570 log("FIRST inter-BSC Handover done");
5571
5572
5573 /* ------------------------ */
5574
5575 /* Ok, that went well, now the other BSC is handovering back here --
5576 * from now on this here is the new BSS. */
5577 f_create_bssmap_exp_handoverRequest(193);
5578
5579 var PDU_BSSAP ho_request;
5580 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5581
5582 /* new BSS composes a RR Handover Command */
5583 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5584 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005585 var BSSMAP_IE_AoIP_TransportLayerAddress tla tla :=
5586 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005587 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5588 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5589
5590 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5591
5592 f_sleep(0.5);
5593
5594 /* Notify that the MS is now over here */
5595
5596 BSSAP.send(ts_BSSMAP_HandoverDetect);
5597 f_sleep(0.1);
5598 BSSAP.send(ts_BSSMAP_HandoverComplete);
5599
5600 f_sleep(3.0);
5601
5602 deactivate(ack_mdcx);
5603
5604 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5605
5606 /* blatant cheating */
5607 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5608 last_n_sd[0] := 3;
5609 f_bssmap_continue_after_n_sd(last_n_sd);
5610
5611 f_call_hangup(cpars, true);
5612 f_sleep(1.0);
5613 deactivate(ccrel);
5614
5615 setverdict(pass);
5616}
5617private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005618 var charstring bss_rtp_ip;
5619 if (pars.use_ipv6) {
5620 bss_rtp_ip := "::8";
5621 } else {
5622 bss_rtp_ip := "1.2.3.4";
5623 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005624 f_init_handler(pars);
5625 f_create_bssmap_exp_handoverRequest(194);
5626
5627 var PDU_BSSAP ho_request;
5628 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5629
5630 /* new BSS composes a RR Handover Command */
5631 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5632 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005633 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
5634 valueof(f_ts_BSSMAP_IE_AoIP_TLA(bss_rtp_ip, 2342));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005635 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5636 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5637
5638 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5639
5640 f_sleep(0.5);
5641
5642 /* Notify that the MS is now over here */
5643
5644 BSSAP.send(ts_BSSMAP_HandoverDetect);
5645 f_sleep(0.1);
5646 BSSAP.send(ts_BSSMAP_HandoverComplete);
5647
5648 f_sleep(3.0);
5649
5650 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5651 * ... handover back to the first BSC :P */
5652
5653 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5654 var BssmapCause cause := enum2int(cause_val);
5655
5656 var template BSSMAP_FIELD_CellIdentificationList cil;
5657 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('262'H, '42'H, 23) } };
5658
5659 /* old BSS sends Handover Required */
5660 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5661
5662 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5663
5664 /* MSC forwards the RR Handover Command to old BSS */
5665 var PDU_BSSAP ho_command;
5666 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5667
5668 log("GOT HandoverCommand", ho_command);
5669
5670 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5671
5672 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5673 f_expect_clear();
5674 setverdict(pass);
5675}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005676function f_tc_ho_inter_bsc_main(boolean use_ipv6 := false) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005677 var BSC_ConnHdlr vc_conn0;
5678 var BSC_ConnHdlr vc_conn1;
5679 f_init(2);
5680
5681 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005682 pars0.use_ipv6 := use_ipv6;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005683 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005684 pars1.use_ipv6 := use_ipv6;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005685
5686 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0, 0);
5687 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1, 1);
5688 vc_conn0.done;
5689 vc_conn1.done;
5690}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005691testcase TC_ho_inter_bsc() runs on MTC_CT {
5692 f_tc_ho_inter_bsc_main(false);
5693}
5694testcase TC_ho_inter_bsc_ipv6() runs on MTC_CT {
5695 f_tc_ho_inter_bsc_main(true);
5696}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005697
5698function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5699 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5700 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5701 log("MS_NW patched enc_l3: ", enc_l3);
5702}
5703
5704private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005705 var CallParameters cpars;
5706
5707 cpars := valueof(t_CallParams('12345'H, 0));
5708 if (pars.use_ipv6) {
5709 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5710 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5711 cpars.bss_rtp_ip := "::3";
5712 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005713 var hexstring ho_number := f_gen_msisdn(99999);
5714
5715 f_init_handler(pars);
5716
5717 f_create_mncc_expect(hex2str(ho_number));
5718
5719 f_vty_transceive(MSCVTY, "configure terminal");
5720 f_vty_transceive(MSCVTY, "msc");
5721 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
5722 f_vty_transceive(MSCVTY, "exit");
5723 f_vty_transceive(MSCVTY, "exit");
5724
5725 f_perform_lu();
5726 f_mo_call_establish(cpars);
5727
5728 f_sleep(1.0);
5729
5730 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5731
5732 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5733 var BssmapCause cause := enum2int(cause_val);
5734
5735 var template BSSMAP_FIELD_CellIdentificationList cil;
5736 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('017'H, '017'H, 1) } };
5737
5738 /* old BSS sends Handover Required */
5739 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5740
5741 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
5742 * This MSC tries to reach the other MSC via GSUP. */
5743
5744 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
5745 var GSUP_PDU prep_ho_req;
5746 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
5747 pars.imsi, destination_name := remote_msc_name)) -> value prep_ho_req;
5748
5749 var GSUP_IeValue source_name_ie;
5750 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
5751 var octetstring local_msc_name := source_name_ie.source_name;
5752
5753 /* Remote MSC has figured out its BSC and signals success */
5754 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5755 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5756 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5757 aoIPTransportLayer := omit,
5758 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5759 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
5760 pars.imsi,
5761 ho_number,
5762 remote_msc_name, local_msc_name,
5763 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
5764
5765 /* MSC forwards the RR Handover Command to old BSS */
5766 BSSAP.receive(tr_BSSMAP_HandoverCommand);
5767
5768 /* The MS shows up at remote new BSS */
5769
5770 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5771 pars.imsi, remote_msc_name, local_msc_name,
5772 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5773 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
5774 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5775 f_sleep(0.1);
5776
5777 /* Save the MS sequence counters for use on the other connection */
5778 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5779
5780 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
5781 pars.imsi, remote_msc_name, local_msc_name,
5782 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5783 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
5784
5785 /* The local BSS conn clears, all communication goes via remote MSC now */
5786 f_expect_clear();
5787
5788 /**********************************/
5789 /* Play through some signalling across the inter-MSC link.
5790 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
5791
5792 if (false) {
5793 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
5794 invoke_id := 5, /* Phone may not start from 0 or 1 */
5795 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5796 ussd_string := "*#100#"
5797 );
5798
5799 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
5800 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
5801 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5802 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
5803 )
5804
5805 /* Compose a new SS/REGISTER message with request */
5806 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
5807 tid := 1, /* We just need a single transaction */
5808 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
5809 facility := valueof(facility_req)
5810 );
5811 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
5812
5813 /* Compose SS/RELEASE_COMPLETE template with expected response */
5814 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
5815 tid := 1, /* Response should arrive within the same transaction */
5816 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
5817 facility := valueof(facility_rsp)
5818 );
5819
5820 /* Compose expected MSC -> HLR message */
5821 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
5822 imsi := g_pars.imsi,
5823 state := OSMO_GSUP_SESSION_STATE_BEGIN,
5824 ss := valueof(facility_req)
5825 );
5826
5827 /* To be used for sending response with correct session ID */
5828 var GSUP_PDU gsup_req_complete;
5829
5830 /* Request own number */
5831 /* From remote MSC instead of BSSAP directly */
5832 /* Patch the correct N_SD value into the message. */
5833 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
5834 var RAN_Emulation.ConnectionData cd;
5835 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
5836 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5837 pars.imsi, remote_msc_name, local_msc_name,
5838 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5839 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
5840 ))
5841 ));
5842
5843 /* Expect GSUP message containing the SS payload */
5844 gsup_req_complete := f_expect_gsup_msg(gsup_req);
5845
5846 /* Compose the response from HLR using received session ID */
5847 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
5848 imsi := g_pars.imsi,
5849 sid := gsup_req_complete.ies[1].val.session_id,
5850 state := OSMO_GSUP_SESSION_STATE_END,
5851 ss := valueof(facility_rsp)
5852 );
5853
5854 /* Finally, HLR terminates the session */
5855 GSUP.send(gsup_rsp);
5856
5857 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
5858 var GSUP_PDU gsup_ussd_rsp;
5859 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5860 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
5861
5862 var GSUP_IeValue an_apdu;
5863 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
5864 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5865 mtc.stop;
5866 }
5867 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
5868 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
5869 log("Expecting", ussd_rsp);
5870 log("Got", dtap_mt);
5871 if (not match(dtap_mt, ussd_rsp)) {
5872 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5873 mtc.stop;
5874 }
5875 }
5876 /**********************************/
5877
5878
5879 /* inter-MSC handover back to the first MSC */
5880 f_create_bssmap_exp_handoverRequest(193);
5881 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
5882
5883 /* old BSS sends Handover Required, via inter-MSC E link: like
5884 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5885 * but via GSUP */
5886 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
5887 pars.imsi, remote_msc_name, local_msc_name,
5888 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5889 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
5890 ))
5891 ));
5892
5893 /* MSC asks local BSS to prepare Handover to it */
5894 BSSAP.receive(tr_BSSMAP_HandoverRequest);
5895
5896 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
5897 f_bssmap_continue_after_n_sd(last_n_sd);
5898
5899 /* new BSS composes a RR Handover Command */
5900 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5901 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005902 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
5903 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005904 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5905 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5906
5907 /* HandoverCommand goes out via remote MSC-I */
5908 var GSUP_PDU prep_subsq_ho_res;
5909 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
5910 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
5911
5912 /* MS shows up at the local BSS */
5913 BSSAP.send(ts_BSSMAP_HandoverDetect);
5914 f_sleep(0.1);
5915 BSSAP.send(ts_BSSMAP_HandoverComplete);
5916
5917 /* Handover Succeeded message */
5918 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5919 pars.imsi, destination_name := remote_msc_name));
5920
5921 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
5922 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
5923 pars.imsi, destination_name := remote_msc_name));
5924
5925 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
5926
5927 f_sleep(1.0);
5928 deactivate(ack_mdcx);
5929
5930 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
5931 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
5932 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
5933 MNCC.clear;
5934
5935 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5936 f_call_hangup(cpars, true);
5937 f_sleep(1.0);
5938 deactivate(ccrel);
5939
5940 setverdict(pass);
5941}
5942testcase TC_ho_inter_msc_out() runs on MTC_CT {
5943 var BSC_ConnHdlr vc_conn;
5944 f_init(1);
5945
5946 var BSC_ConnHdlrPars pars := f_init_pars(54);
5947
5948 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5949 vc_conn.done;
5950}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005951testcase TC_ho_inter_msc_out_ipv6() runs on MTC_CT {
5952 var BSC_ConnHdlr vc_conn;
5953 f_init(1);
5954
5955 var BSC_ConnHdlrPars pars := f_init_pars(54);
5956 pars.use_ipv6 := true;
5957
5958 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5959 vc_conn.done;
5960}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005961
Oliver Smith1d118ff2019-07-03 10:57:35 +02005962private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5963 pars.net.expect_auth := true;
5964 pars.net.expect_imei := true;
5965 f_init_handler(pars);
5966 f_perform_lu();
5967}
5968testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
5969 var BSC_ConnHdlr vc_conn;
5970 f_init();
5971 f_vty_config(MSCVTY, "network", "authentication required");
5972 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5973
5974 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
5975 vc_conn.done;
5976}
5977
5978private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5979 pars.net.expect_auth := true;
5980 pars.use_umts_aka := true;
5981 pars.net.expect_imei := true;
5982 f_init_handler(pars);
5983 f_perform_lu();
5984}
5985testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
5986 var BSC_ConnHdlr vc_conn;
5987 f_init();
5988 f_vty_config(MSCVTY, "network", "authentication required");
5989 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5990
5991 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
5992 vc_conn.done;
5993}
5994
5995private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5996 pars.net.expect_imei := true;
5997 f_init_handler(pars);
5998 f_perform_lu();
5999}
6000testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
6001 var BSC_ConnHdlr vc_conn;
6002 f_init();
6003 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6004
6005 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
6006 vc_conn.done;
6007}
6008
6009private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6010 pars.net.expect_tmsi := false;
6011 pars.net.expect_imei := true;
6012 f_init_handler(pars);
6013 f_perform_lu();
6014}
6015testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
6016 var BSC_ConnHdlr vc_conn;
6017 f_init();
6018 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6019 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6020
6021 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
6022 vc_conn.done;
6023}
6024
6025private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6026 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006027
6028 pars.net.expect_auth := true;
6029 pars.net.expect_imei := true;
6030 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6031 f_init_handler(pars);
6032
6033 /* Cannot use f_perform_lu() as we expect a reject */
6034 l3_lu := f_build_lu_imsi(g_pars.imsi)
6035 f_create_gsup_expect(hex2str(g_pars.imsi));
6036 f_bssap_compl_l3(l3_lu);
6037 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6038
6039 f_mm_common();
6040 f_msc_lu_hlr();
6041 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006042 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006043 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006044}
6045testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
6046 var BSC_ConnHdlr vc_conn;
6047 f_init();
6048 f_vty_config(MSCVTY, "network", "authentication required");
6049 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6050
6051 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
6052 vc_conn.done;
6053}
6054
6055private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6056 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006057
6058 pars.net.expect_auth := true;
6059 pars.net.expect_imei := true;
6060 pars.net.check_imei_error := true;
6061 f_init_handler(pars);
6062
6063 /* Cannot use f_perform_lu() as we expect a reject */
6064 l3_lu := f_build_lu_imsi(g_pars.imsi)
6065 f_create_gsup_expect(hex2str(g_pars.imsi));
6066 f_bssap_compl_l3(l3_lu);
6067 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6068
6069 f_mm_common();
6070 f_msc_lu_hlr();
6071 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006072 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006073 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006074}
6075testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
6076 var BSC_ConnHdlr vc_conn;
6077 f_init();
6078 f_vty_config(MSCVTY, "network", "authentication required");
6079 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6080
6081 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
6082 vc_conn.done;
6083}
6084
6085private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6086 pars.net.expect_auth := true;
6087 pars.net.expect_imei_early := true;
6088 f_init_handler(pars);
6089 f_perform_lu();
6090}
6091testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
6092 var BSC_ConnHdlr vc_conn;
6093 f_init();
6094 f_vty_config(MSCVTY, "network", "authentication required");
6095 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6096
6097 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
6098 vc_conn.done;
6099}
6100
6101private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6102 pars.net.expect_auth := true;
6103 pars.use_umts_aka := true;
6104 pars.net.expect_imei_early := true;
6105 f_init_handler(pars);
6106 f_perform_lu();
6107}
6108testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
6109 var BSC_ConnHdlr vc_conn;
6110 f_init();
6111 f_vty_config(MSCVTY, "network", "authentication required");
6112 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6113
6114 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
6115 vc_conn.done;
6116}
6117
6118private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6119 pars.net.expect_imei_early := true;
6120 f_init_handler(pars);
6121 f_perform_lu();
6122}
6123testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
6124 var BSC_ConnHdlr vc_conn;
6125 f_init();
6126 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6127
6128 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
6129 vc_conn.done;
6130}
6131
6132private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6133 pars.net.expect_tmsi := false;
6134 pars.net.expect_imei_early := true;
6135 f_init_handler(pars);
6136 f_perform_lu();
6137}
6138testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
6139 var BSC_ConnHdlr vc_conn;
6140 f_init();
6141 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6142 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6143
6144 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
6145 vc_conn.done;
6146}
6147
6148private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6149 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006150
6151 pars.net.expect_auth := true;
6152 pars.net.expect_imei_early := true;
6153 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6154 f_init_handler(pars);
6155
6156 /* Cannot use f_perform_lu() as we expect a reject */
6157 l3_lu := f_build_lu_imsi(g_pars.imsi)
6158 f_create_gsup_expect(hex2str(g_pars.imsi));
6159 f_bssap_compl_l3(l3_lu);
6160 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6161
6162 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006163 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006164 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006165}
6166testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
6167 var BSC_ConnHdlr vc_conn;
6168 f_init();
6169 f_vty_config(MSCVTY, "network", "authentication required");
6170 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6171
6172 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
6173 vc_conn.done;
6174}
6175
6176private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6177 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006178
6179 pars.net.expect_auth := true;
6180 pars.net.expect_imei_early := true;
6181 pars.net.check_imei_error := true;
6182 f_init_handler(pars);
6183
6184 /* Cannot use f_perform_lu() as we expect a reject */
6185 l3_lu := f_build_lu_imsi(g_pars.imsi)
6186 f_create_gsup_expect(hex2str(g_pars.imsi));
6187 f_bssap_compl_l3(l3_lu);
6188 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6189
6190 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006191 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006192 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006193}
6194testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
6195 var BSC_ConnHdlr vc_conn;
6196 f_init();
6197 f_vty_config(MSCVTY, "network", "authentication required");
6198 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6199
6200 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
6201 vc_conn.done;
6202}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006203
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006204friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6205 f_init_handler(pars);
6206 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6207
6208 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
6209 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
6210 * will cause a use-after-free after that event dispatch. */
6211 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
6212 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
6213 cpars.rtp_sdp_format := "FOO/8000";
6214 cpars.expect_release := true;
6215
6216 f_perform_lu();
6217 f_mo_call_establish(cpars);
6218}
6219testcase TC_invalid_mgcp_crash() runs on MTC_CT {
6220 var BSC_ConnHdlr vc_conn;
6221 f_init();
6222
6223 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
6224 vc_conn.done;
6225}
6226
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006227friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
6228runs on BSC_ConnHdlr {
6229 pars.tmsi := 'FFFFFFFF'O;
6230 f_init_handler(pars);
6231
6232 f_create_gsup_expect(hex2str(g_pars.imsi));
6233
6234 /* Initiate Location Updating using an unknown TMSI */
6235 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
6236
6237 /* Expect an Identity Request, send response with no identity */
6238 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
6239 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
6240 lengthIndicator := 1,
6241 mobileIdentityV := {
6242 typeOfIdentity := '000'B,
6243 oddEvenInd_identity := {
6244 no_identity := {
6245 oddevenIndicator := '0'B,
6246 fillerDigits := '00000'H
6247 }
6248 }
6249 }
6250 })));
6251
6252 f_expect_lu_reject();
6253 f_expect_clear();
6254}
6255testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
6256 var BSC_ConnHdlr vc_conn;
6257
6258 f_init();
6259
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006260 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7, verify_cell_id := false);
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006261 vc_conn.done;
6262}
6263
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006264/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6265 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6266 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6267friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6268runs on BSC_ConnHdlr {
6269 var charstring imsi := hex2str(pars.imsi);
6270
6271 f_init_handler(pars);
6272
6273 /* Perform location update */
6274 f_perform_lu();
6275
6276 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6277 f_create_gsup_expect(hex2str(g_pars.imsi));
6278
6279 /* Initiate paging procedure from the VTY */
6280 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6281 f_expect_paging();
6282
6283 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6284 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6285
6286 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6287 f_establish_fully(EST_TYPE_PAG_RESP);
6288
6289 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6290 * In this case we do not send anything and just wait for a Clear Command. */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006291 f_expect_clear(verify_vlr_cell_id := false);
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006292}
6293testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6294 var BSC_ConnHdlr vc_conn;
6295
6296 f_init();
6297
6298 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6299 vc_conn.done;
6300}
6301
Harald Weltef6dd64d2017-11-19 12:09:51 +01006302control {
Philipp Maier328d1662018-03-07 10:40:27 +01006303 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006304 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01006305 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006306 execute( TC_lu_imsi_reject() );
6307 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01006308 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02006309 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01006310 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01006311 execute( TC_cmserv_imsi_unknown() );
Neels Hofmeyr13737fb2020-08-19 13:16:14 +00006312 execute( TC_cmserv_tmsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01006313 execute( TC_lu_and_mo_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006314 execute( TC_lu_and_mo_call_ipv6() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01006315 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01006316 execute( TC_lu_auth_sai_timeout() );
6317 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006318 execute( TC_lu_clear_request() );
6319 execute( TC_lu_disconnect() );
6320 execute( TC_lu_by_imei() );
6321 execute( TC_lu_by_tmsi_noauth_unknown() );
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00006322 execute( TC_attached_imsi_lu_unknown_tmsi() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006323 execute( TC_imsi_detach_by_imsi() );
6324 execute( TC_imsi_detach_by_tmsi() );
6325 execute( TC_imsi_detach_by_imei() );
6326 execute( TC_emerg_call_imei_reject() );
6327 execute( TC_emerg_call_imsi() );
6328 execute( TC_cm_serv_req_vgcs_reject() );
6329 execute( TC_cm_serv_req_vbs_reject() );
6330 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01006331 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01006332 execute( TC_lu_auth_2G_fail() );
6333 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
6334 execute( TC_cl3_no_payload() );
6335 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01006336 execute( TC_establish_and_nothing() );
6337 execute( TC_mo_setup_and_nothing() );
6338 execute( TC_mo_crcx_ran_timeout() );
6339 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01006340 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01006341 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01006342 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01006343 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01006344 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
6345 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
6346 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01006347 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01006348 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
6349 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01006350 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01006351 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02006352 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006353
6354 execute( TC_lu_and_mt_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006355 execute( TC_lu_and_mt_call_ipv6() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006356 execute( TC_lu_and_mt_call_already_paging() );
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +02006357 execute( TC_lu_and_mt_call_osmux() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006358
Harald Weltef45efeb2018-04-09 18:19:24 +02006359 execute( TC_lu_and_mo_sms() );
6360 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006361 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01006362 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02006363 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02006364 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07006365 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02006366 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02006367
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006368 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07006369 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07006370 execute( TC_gsup_mt_sms_ack() );
6371 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07006372 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07006373 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07006374 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006375
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006376 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006377 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006378 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006379 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07006380 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07006381 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07006382
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006383 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07006384 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07006385 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07006386 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07006387 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006388
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01006389 execute( TC_multi_lu_and_mo_ussd() );
6390 execute( TC_multi_lu_and_mt_ussd() );
6391
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006392 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01006393 execute( TC_cipher_complete_1_without_cipher() );
6394 execute( TC_cipher_complete_3_without_cipher() );
6395 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02006396 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006397
Harald Welte4263c522018-12-06 11:56:27 +01006398 execute( TC_sgsap_reset() );
6399 execute( TC_sgsap_lu() );
6400 execute( TC_sgsap_lu_imsi_reject() );
6401 execute( TC_sgsap_lu_and_nothing() );
6402 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01006403 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01006404 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01006405 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01006406 execute( TC_sgsap_paging_rej() );
6407 execute( TC_sgsap_paging_subscr_rej() );
6408 execute( TC_sgsap_paging_ue_unr() );
6409 execute( TC_sgsap_paging_and_nothing() );
6410 execute( TC_sgsap_paging_and_lu() );
6411 execute( TC_sgsap_mt_sms() );
6412 execute( TC_sgsap_mo_sms() );
6413 execute( TC_sgsap_mt_sms_and_nothing() );
6414 execute( TC_sgsap_mt_sms_and_reject() );
6415 execute( TC_sgsap_unexp_ud() );
6416 execute( TC_sgsap_unsol_ud() );
6417 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
6418 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02006419 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01006420
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006421 execute( TC_ho_inter_bsc_unknown_cell() );
6422 execute( TC_ho_inter_bsc() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006423 execute( TC_ho_inter_bsc_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006424
6425 execute( TC_ho_inter_msc_out() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006426 execute( TC_ho_inter_msc_out_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006427
Oliver Smith1d118ff2019-07-03 10:57:35 +02006428 execute( TC_lu_imsi_auth_tmsi_check_imei() );
6429 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
6430 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
6431 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
6432 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
6433 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
6434 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
6435 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
6436 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
6437 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
6438 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
6439 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
6440
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01006441 /* Run this last: at the time of writing this test crashes the MSC */
6442 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02006443 execute( TC_mo_cc_bssmap_clear() );
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006444 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006445 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006446 execute( TC_lu_and_expire_while_paging() );
Neels Hofmeyr14d0b132020-08-19 13:49:05 +00006447 execute( TC_paging_response_imsi_unknown() );
6448 execute( TC_paging_response_tmsi_unknown() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01006449}
6450
6451
6452}