blob: c290d7c8501c26f007925e462cd5e5f94361b693 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
19
20import from M3UA_Types all;
21import from M3UA_Emulation all;
22
23import from MTP3asp_Types all;
24import from MTP3asp_PortType all;
25
26import from SCCPasp_Types all;
27import from SCCP_Types all;
28import from SCCP_Emulation all;
29
30import from SCTPasp_Types all;
31import from SCTPasp_PortType all;
32
Harald Weltea49e36e2018-01-21 19:29:33 +010033import from Osmocom_CTRL_Functions all;
34import from Osmocom_CTRL_Types all;
35import from Osmocom_CTRL_Adapter all;
36
Harald Welte3ca1c902018-01-24 18:51:27 +010037import from TELNETasp_PortType all;
38import from Osmocom_VTY_Functions all;
39
Harald Weltea49e36e2018-01-21 19:29:33 +010040import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010041import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010042
Harald Welte4aa970c2018-01-26 10:38:09 +010043import from MGCP_Emulation all;
44import from MGCP_Types all;
45import from MGCP_Templates all;
46import from SDP_Types all;
47
Harald Weltea49e36e2018-01-21 19:29:33 +010048import from GSUP_Emulation all;
49import from GSUP_Types all;
50import from IPA_Emulation all;
51
Harald Weltef6dd64d2017-11-19 12:09:51 +010052import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020053import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010054import from BSSAP_CodecPort all;
55import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020056import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010057import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020058import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010059
Harald Welte4263c522018-12-06 11:56:27 +010060import from SGsAP_Templates all;
61import from SGsAP_Types all;
62import from SGsAP_Emulation all;
63
Harald Weltea49e36e2018-01-21 19:29:33 +010064import from MobileL3_Types all;
65import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070066import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010067import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010068import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010069
Harald Weltef640a012018-04-14 17:49:21 +020070import from SMPP_Types all;
71import from SMPP_Templates all;
72import from SMPP_Emulation all;
73
Stefan Sperlingc307e682018-06-14 15:15:46 +020074import from SCCP_Templates all;
75
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070076import from SS_Types all;
77import from SS_Templates all;
78import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010079import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070080
Philipp Maier948747b2019-04-02 15:22:33 +020081import from TCCConversion_Functions all;
82
Harald Welte9b751a62019-04-14 17:39:29 +020083const integer NUM_BSC := 3;
Harald Welte6811d102019-04-14 22:23:14 +020084type record of RAN_Configuration RAN_Configurations;
Harald Weltef6dd64d2017-11-19 12:09:51 +010085
Harald Welte4263c522018-12-06 11:56:27 +010086/* Needed for SGsAP SMS */
87import from MobileL3_SMS_Types all;
88
Harald Weltea4ca4462018-02-09 00:17:14 +010089type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010090 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010091
Harald Welte6811d102019-04-14 22:23:14 +020092 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010093
Harald Weltea49e36e2018-01-21 19:29:33 +010094 /* no 'adapter_CT' for MNCC or GSUP */
95 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010096 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010097 var GSUP_Emulation_CT vc_GSUP;
98 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020099 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +0100100 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100101
102 /* only to get events from IPA underneath GSUP */
103 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100104 /* VTY to MSC */
105 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100106
107 /* A port to directly send BSSAP messages. This port is used for
108 * tests that require low level access to sen arbitrary BSSAP
109 * messages. Run f_init_bssap_direct() to connect and initialize */
110 port BSSAP_CODEC_PT BSSAP_DIRECT;
111
112 /* When BSSAP messages are directly sent, then the connection
113 * handler is not active, which means that also no guard timer is
114 * set up. The following timer will serve as a replacement */
115 timer Tguard_direct := 60.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100116}
117
118modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100119 /* remote parameters of IUT */
120 charstring mp_msc_ip := "127.0.0.1";
121 integer mp_msc_ctrl_port := 4255;
122 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100123
Harald Weltea49e36e2018-01-21 19:29:33 +0100124 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100125 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100126 charstring mp_hlr_ip := "127.0.0.1";
127 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100128 charstring mp_mgw_ip := "127.0.0.1";
129 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100130
Harald Weltea49e36e2018-01-21 19:29:33 +0100131 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100132
Harald Weltef640a012018-04-14 17:49:21 +0200133 integer mp_msc_smpp_port := 2775;
134 charstring mp_smpp_system_id := "msc_tester";
135 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100136 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
137 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200138
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200139 /* Whether to enable osmux tests. Can be dropped completely and enable
140 unconditionally once new version of osmo-msc is released (current
141 version: 1.3.1) */
142 boolean mp_enable_osmux_test := true;
143
Harald Welte6811d102019-04-14 22:23:14 +0200144 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200145 {
146 sccp_service_type := "mtp3_itu",
147 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
148 own_pc := 185,
149 own_ssn := 254,
150 peer_pc := 187,
151 peer_ssn := 254,
152 sio := '83'O,
153 rctx := 0
154 },
155 {
156 sccp_service_type := "mtp3_itu",
157 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
158 own_pc := 186,
159 own_ssn := 254,
160 peer_pc := 187,
161 peer_ssn := 254,
162 sio := '83'O,
163 rctx := 1
164 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100165 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100166}
167
Philipp Maier328d1662018-03-07 10:40:27 +0100168/* altstep for the global guard timer (only used when BSSAP_DIRECT
169 * is used for communication */
170private altstep as_Tguard_direct() runs on MTC_CT {
171 [] Tguard_direct.timeout {
172 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200173 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100174 }
175}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100176
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100177private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
178 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
179 if (respond) {
180 var BIT1 tid_remote := '1'B;
181 if (cpars.mo_call) {
182 tid_remote := '0'B;
183 }
184 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
185 }
186 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100187}
188
Harald Weltef640a012018-04-14 17:49:21 +0200189function f_init_smpp(charstring id) runs on MTC_CT {
190 id := id & "-SMPP";
191 var EsmePars pars := {
192 mode := MODE_TRANSCEIVER,
193 bind := {
194 system_id := mp_smpp_system_id,
195 password := mp_smpp_password,
196 system_type := "MSC_Tests",
197 interface_version := hex2int('34'H),
198 addr_ton := unknown,
199 addr_npi := unknown,
200 address_range := ""
201 },
202 esme_role := true
203 }
204
205 vc_SMPP := SMPP_Emulation_CT.create(id);
206 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
207 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", -1));
208}
209
210
Harald Weltea49e36e2018-01-21 19:29:33 +0100211function f_init_mncc(charstring id) runs on MTC_CT {
212 id := id & "-MNCC";
213 var MnccOps ops := {
214 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
215 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
216 }
217
218 vc_MNCC := MNCC_Emulation_CT.create(id);
219 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
220 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100221}
222
Harald Welte4aa970c2018-01-26 10:38:09 +0100223function f_init_mgcp(charstring id) runs on MTC_CT {
224 id := id & "-MGCP";
225 var MGCPOps ops := {
226 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
227 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
228 }
229 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100230 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100231 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100232 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200233 mgw_udp_port := mp_mgw_port,
234 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100235 }
236
237 vc_MGCP := MGCP_Emulation_CT.create(id);
238 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
239 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
240}
241
Philipp Maierc09a1312019-04-09 16:05:26 +0200242function ForwardUnitdataCallback(PDU_SGsAP msg)
243runs on SGsAP_Emulation_CT return template PDU_SGsAP {
244 SGsAP_CLIENT.send(msg);
245 return omit;
246}
247
Harald Welte4263c522018-12-06 11:56:27 +0100248function f_init_sgsap(charstring id) runs on MTC_CT {
249 id := id & "-SGsAP";
250 var SGsAPOps ops := {
251 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200252 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100253 }
254 var SGsAP_conn_parameters pars := {
255 remote_ip := mp_msc_ip,
256 remote_sctp_port := 29118,
257 local_ip := "",
258 local_sctp_port := -1
259 }
260
261 vc_SGsAP := SGsAP_Emulation_CT.create(id);
262 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
263 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
264}
265
266
Harald Weltea49e36e2018-01-21 19:29:33 +0100267function f_init_gsup(charstring id) runs on MTC_CT {
268 id := id & "-GSUP";
269 var GsupOps ops := {
270 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
271 }
272
273 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
274 vc_GSUP := GSUP_Emulation_CT.create(id);
275
276 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
277 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
278 /* we use this hack to get events like ASP_IPA_EVENT_UP */
279 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
280
281 vc_GSUP.start(GSUP_Emulation.main(ops, id));
282 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
283
284 /* wait for incoming connection to GSUP port before proceeding */
285 timer T := 10.0;
286 T.start;
287 alt {
288 [] GSUP_IPA_EVENT.receive(t_ASP_IPA_EVT_UD(ASP_IPA_EVENT_UP)) { }
289 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100290 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200291 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100292 }
293 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100294}
295
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200296function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100297
298 if (g_initialized == true) {
299 return;
300 }
301 g_initialized := true;
302
Philipp Maier75932982018-03-27 14:52:35 +0200303 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200304 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200305 }
306
307 for (var integer i := 0; i < num_bsc; i := i + 1) {
308 if (isbound(mp_bssap_cfg[i])) {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200309 var RanOps ranops := BSC_RanOps;
310 ranops.use_osmux := osmux;
311 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
Harald Welte3ca0ce12019-04-23 17:18:48 +0200312 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200313 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200314 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200315 }
316 }
317
Harald Weltea49e36e2018-01-21 19:29:33 +0100318 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
319 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100320 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200321
322 if (gsup == true) {
323 f_init_gsup("MSC_Test");
324 }
Harald Weltef640a012018-04-14 17:49:21 +0200325 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100326
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100327 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100328 f_init_sgsap("MSC_Test");
329 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100330
331 map(self:MSCVTY, system:MSCVTY);
332 f_vty_set_prompts(MSCVTY);
333 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100334
335 /* set some defaults */
336 f_vty_config(MSCVTY, "network", "authentication optional");
337 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200338 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100339 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200340 if (mp_enable_osmux_test) {
341 if (osmux) {
342 f_vty_config(MSCVTY, "msc", "osmux on");
343 } else {
344 f_vty_config(MSCVTY, "msc", "osmux off");
345 }
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200346 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100347}
348
Philipp Maier328d1662018-03-07 10:40:27 +0100349/* Initialize for a direct connection to BSSAP. This function is an alternative
350 * to f_init() when the high level functions of the BSC_ConnectionHandler are
351 * not needed. */
352function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200353 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200354 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100355
356 /* Start guard timer and activate it as default */
357 Tguard_direct.start
358 activate(as_Tguard_direct());
359}
360
Harald Weltea49e36e2018-01-21 19:29:33 +0100361type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100362
Harald Weltea49e36e2018-01-21 19:29:33 +0100363/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200364function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200365 boolean ran_is_geran := true, boolean use_osmux := false)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200366runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100367 var BSC_ConnHdlrNetworkPars net_pars := {
368 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
369 expect_tmsi := true,
370 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200371 expect_ciph := false,
372 expect_imei := false,
373 expect_imei_early := false,
374 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
375 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100376 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100377 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200378 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
379 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100380 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100381 imei := f_gen_imei(imsi_suffix),
382 imsi := f_gen_imsi(imsi_suffix),
383 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100384 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100385 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100386 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100387 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100388 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100389 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100390 send_early_cm := true,
391 ipa_ctrl_ip := mp_msc_ip,
392 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100393 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100394 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200395 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200396 gsup_enable := gsup,
Harald Weltec1f937a2019-04-21 21:19:23 +0200397 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200398 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200399 ran_is_geran := ran_is_geran,
400 use_osmux := use_osmux
Harald Weltea49e36e2018-01-21 19:29:33 +0100401 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200402 if (not ran_is_geran) {
403 pars.use_umts_aka := true;
404 pars.net.expect_auth := true;
405 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100406 return pars;
407}
408
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200409function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars, integer bssap_idx := 0) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100410 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200411 var charstring id := testcasename() & int2str(bssap_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100412
413 vc_conn := BSC_ConnHdlr.create(id);
414 /* BSSMAP part / A interface */
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200415 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:CLIENT);
416 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100417 /* MNCC part */
418 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
419 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100420 /* MGCP part */
421 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
422 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100423 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200424 if (pars.gsup_enable == true) {
425 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
426 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
427 }
Harald Weltef640a012018-04-14 17:49:21 +0200428 /* SMPP part */
429 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
430 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100431 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100432 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100433 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
434 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
435 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100436
Harald Weltea10db902018-01-27 12:44:49 +0100437 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
438 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100439 vc_conn.start(derefers(fn)(id, pars));
440 return vc_conn;
441}
442
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200443function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false)
Harald Welte9b751a62019-04-14 17:39:29 +0200444runs on MTC_CT return BSC_ConnHdlr {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200445 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100446}
447
Harald Weltea49e36e2018-01-21 19:29:33 +0100448private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100449 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100450 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100451}
Harald Weltea49e36e2018-01-21 19:29:33 +0100452testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
453 var BSC_ConnHdlr vc_conn;
454 f_init();
455
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100456 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100457 vc_conn.done;
458}
459
460private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100461 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100462 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100463 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100464}
Harald Weltea49e36e2018-01-21 19:29:33 +0100465testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
466 var BSC_ConnHdlr vc_conn;
467 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100468 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100469
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100470 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100471 vc_conn.done;
472}
473
474/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200475friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100476 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100477 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
478
479 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200480 f_cl3_or_initial_ue(l3_lu);
Harald Welteb7817992019-05-09 13:15:39 +0200481 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100482 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
483 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
484 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100485 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
486 f_expect_clear();
487 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100488 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
489 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200490 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100491 }
492 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100493}
494testcase TC_lu_imsi_reject() runs on MTC_CT {
495 var BSC_ConnHdlr vc_conn;
496 f_init();
497
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100498 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3);
Harald Weltea49e36e2018-01-21 19:29:33 +0100499 vc_conn.done;
500}
501
Harald Weltee13cfb22019-04-23 16:52:02 +0200502
503
Harald Weltea49e36e2018-01-21 19:29:33 +0100504/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200505friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100506 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100507 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
508
509 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200510 f_cl3_or_initial_ue(l3_lu);
Harald Welteb7817992019-05-09 13:15:39 +0200511 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100512 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
513 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
514 alt {
515 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100516 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
517 f_expect_clear();
518 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100519 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
520 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200521 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100522 }
523 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100524}
525testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
526 var BSC_ConnHdlr vc_conn;
527 f_init();
528
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100529 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4);
Harald Weltea49e36e2018-01-21 19:29:33 +0100530 vc_conn.done;
531}
532
Harald Weltee13cfb22019-04-23 16:52:02 +0200533
Harald Welte7b1b2812018-01-22 21:23:06 +0100534private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100535 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100536 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100537 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100538}
539testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
540 var BSC_ConnHdlr vc_conn;
541 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100542 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100543
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100544 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100545 vc_conn.done;
546}
547
Harald Weltee13cfb22019-04-23 16:52:02 +0200548
549friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200550 pars.net.expect_auth := true;
551 pars.use_umts_aka := true;
552 f_init_handler(pars);
553 f_perform_lu();
554}
555testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
556 var BSC_ConnHdlr vc_conn;
557 f_init();
558 f_vty_config(MSCVTY, "network", "authentication required");
559
560 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
561 vc_conn.done;
562}
Harald Weltea49e36e2018-01-21 19:29:33 +0100563
Harald Weltee13cfb22019-04-23 16:52:02 +0200564
Harald Weltea49e36e2018-01-21 19:29:33 +0100565/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200566friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100567runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100568 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100569
570 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100571 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100572 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100573
574 f_create_gsup_expect(hex2str(g_pars.imsi));
575
576 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200577 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200578 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100579
580 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100581 T.start;
582 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100583 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
584 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200585 [] BSSAP.receive {
586 setverdict(fail, "Received unexpected BSSAP");
587 mtc.stop;
588 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100589 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
590 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200591 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100592 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200593 [] T.timeout {
594 setverdict(fail, "Timeout waiting for CM SERV REQ");
595 mtc.stop;
596 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100597 }
598
Harald Welte1ddc7162018-01-27 14:25:46 +0100599 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100600}
Harald Weltea49e36e2018-01-21 19:29:33 +0100601testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
602 var BSC_ConnHdlr vc_conn;
603 f_init();
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100604 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6);
Harald Weltea49e36e2018-01-21 19:29:33 +0100605 vc_conn.done;
606}
607
Harald Weltee13cfb22019-04-23 16:52:02 +0200608
609friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100610 f_init_handler(pars);
Harald Welteb71901a2018-01-26 19:16:05 +0100611 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
612 cpars.bss_rtp_port := 1110;
613 cpars.mgcp_connection_id_bss := '22222'H;
614 cpars.mgcp_connection_id_mss := '33333'H;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100615 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte2bb825f2018-01-22 11:31:18 +0100616
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100617 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100618 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100619}
620testcase TC_lu_and_mo_call() runs on MTC_CT {
621 var BSC_ConnHdlr vc_conn;
622 f_init();
623
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100624 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100625 vc_conn.done;
626}
627
Harald Weltee13cfb22019-04-23 16:52:02 +0200628
Harald Welte071ed732018-01-23 19:53:52 +0100629/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200630friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100631 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100632
633 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
634 var PDU_DTAP_MT dtap_mt;
635
636 /* tell GSUP dispatcher to send this IMSI to us */
637 f_create_gsup_expect(hex2str(g_pars.imsi));
638
639 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200640 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100641
642 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200643 if (pars.ran_is_geran) {
644 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
645 }
Harald Welte071ed732018-01-23 19:53:52 +0100646
647 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
648 /* The HLR would normally return an auth vector here, but we fail to do so. */
649
650 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100651 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100652}
653testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
654 var BSC_ConnHdlr vc_conn;
655 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100656 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100657
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100658 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8);
Harald Welte071ed732018-01-23 19:53:52 +0100659 vc_conn.done;
660}
661
Harald Weltee13cfb22019-04-23 16:52:02 +0200662
Harald Welte071ed732018-01-23 19:53:52 +0100663/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200664friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100665 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100666
667 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
668 var PDU_DTAP_MT dtap_mt;
669
670 /* tell GSUP dispatcher to send this IMSI to us */
671 f_create_gsup_expect(hex2str(g_pars.imsi));
672
673 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200674 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100675
676 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200677 if (pars.ran_is_geran) {
678 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
679 }
Harald Welte071ed732018-01-23 19:53:52 +0100680
681 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
682 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
683
684 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100685 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100686}
687testcase TC_lu_auth_sai_err() runs on MTC_CT {
688 var BSC_ConnHdlr vc_conn;
689 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100690 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100691
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100692 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9);
Harald Welte2bb825f2018-01-22 11:31:18 +0100693 vc_conn.done;
694}
Harald Weltea49e36e2018-01-21 19:29:33 +0100695
Harald Weltee13cfb22019-04-23 16:52:02 +0200696
Harald Weltebc881782018-01-23 20:09:15 +0100697/* Test LU but BSC will send a clear request in the middle */
698private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100699 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100700
701 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
702 var PDU_DTAP_MT dtap_mt;
703
704 /* tell GSUP dispatcher to send this IMSI to us */
705 f_create_gsup_expect(hex2str(g_pars.imsi));
706
707 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200708 f_cl3_or_initial_ue(l3_lu);
Harald Weltebc881782018-01-23 20:09:15 +0100709
710 /* Send Early Classmark, just for the fun of it */
711 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
712
713 f_sleep(1.0);
714 /* send clear request in the middle of the LU */
715 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200716 alt {
717 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
718 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
719 }
Harald Weltebc881782018-01-23 20:09:15 +0100720 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100721 alt {
722 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200723 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
724 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200725 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200726 repeat;
727 }
Harald Welte6811d102019-04-14 22:23:14 +0200728 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100729 }
Harald Weltebc881782018-01-23 20:09:15 +0100730 setverdict(pass);
731}
732testcase TC_lu_clear_request() runs on MTC_CT {
733 var BSC_ConnHdlr vc_conn;
734 f_init();
735
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100736 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100737 vc_conn.done;
738}
739
Harald Welte66af9e62018-01-24 17:28:21 +0100740/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200741friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100742 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100743
744 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
745 var PDU_DTAP_MT dtap_mt;
746
747 /* tell GSUP dispatcher to send this IMSI to us */
748 f_create_gsup_expect(hex2str(g_pars.imsi));
749
750 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200751 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +0100752
753 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200754 if (pars.ran_is_geran) {
755 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
756 }
Harald Welte66af9e62018-01-24 17:28:21 +0100757
758 f_sleep(1.0);
759 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +0200760 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +0100761 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +0100762 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +0100763}
764testcase TC_lu_disconnect() runs on MTC_CT {
765 var BSC_ConnHdlr vc_conn;
766 f_init();
767
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100768 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100769 vc_conn.done;
770}
771
Harald Welteba7b6d92018-01-23 21:32:34 +0100772/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +0200773friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100774 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100775
Harald Welte256571e2018-01-24 18:47:19 +0100776 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100777 var PDU_DTAP_MT dtap_mt;
778
779 /* tell GSUP dispatcher to send this IMSI to us */
780 f_create_gsup_expect(hex2str(g_pars.imsi));
781
782 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200783 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100784
785 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200786 if (pars.ran_is_geran) {
787 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
788 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100789 /* wait for LU reject, ignore any ID REQ */
790 alt {
791 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
792 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
793 }
794 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100795 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100796}
797testcase TC_lu_by_imei() runs on MTC_CT {
798 var BSC_ConnHdlr vc_conn;
799 f_init();
800
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100801 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12);
Harald Welteba7b6d92018-01-23 21:32:34 +0100802 vc_conn.done;
803}
804
Harald Weltee13cfb22019-04-23 16:52:02 +0200805
Harald Welteba7b6d92018-01-23 21:32:34 +0100806/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
807private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200808 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
809 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100810 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100811
812 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
813 var PDU_DTAP_MT dtap_mt;
814
815 /* tell GSUP dispatcher to send this IMSI to us */
816 f_create_gsup_expect(hex2str(g_pars.imsi));
817
818 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200819 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100820
821 /* Send Early Classmark, just for the fun of it */
822 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
823
824 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +0200825 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200826 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100827 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
828
829 /* Expect MSC to do UpdateLocation to HLR; respond to it */
830 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
831 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
832 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
833 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
834
835 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100836 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
837 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
838 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100839 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
840 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200841 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +0100842 }
843 }
844
Philipp Maier9b690e42018-12-21 11:50:03 +0100845 /* Wait for MM-Information (if enabled) */
846 f_expect_mm_info();
847
Harald Welteba7b6d92018-01-23 21:32:34 +0100848 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100849 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100850}
851testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
852 var BSC_ConnHdlr vc_conn;
853 f_init();
854
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100855 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100856 vc_conn.done;
857}
858
859
Harald Welte45164da2018-01-24 12:51:27 +0100860/* Test IMSI DETACH (MI=IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200861friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100862 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100863
864 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
865
866 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200867 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100868
869 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200870 if (pars.ran_is_geran) {
871 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
872 }
Harald Welte45164da2018-01-24 12:51:27 +0100873
874 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100875 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100876}
877testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
878 var BSC_ConnHdlr vc_conn;
879 f_init();
880
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100881 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14);
Harald Welte45164da2018-01-24 12:51:27 +0100882 vc_conn.done;
883}
884
Harald Weltee13cfb22019-04-23 16:52:02 +0200885
Harald Welte45164da2018-01-24 12:51:27 +0100886/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200887friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100888 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100889
890 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
891
892 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200893 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100894
895 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200896 if (pars.ran_is_geran) {
897 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
898 }
Harald Welte45164da2018-01-24 12:51:27 +0100899
900 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100901 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100902}
903testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
904 var BSC_ConnHdlr vc_conn;
905 f_init();
906
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100907 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15);
Harald Welte45164da2018-01-24 12:51:27 +0100908 vc_conn.done;
909}
910
Harald Weltee13cfb22019-04-23 16:52:02 +0200911
Harald Welte45164da2018-01-24 12:51:27 +0100912/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +0200913friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100914 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100915
Harald Welte256571e2018-01-24 18:47:19 +0100916 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +0100917
918 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200919 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100920
921 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200922 if (pars.ran_is_geran) {
923 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
924 }
Harald Welte45164da2018-01-24 12:51:27 +0100925
926 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100927 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100928}
929testcase TC_imsi_detach_by_imei() runs on MTC_CT {
930 var BSC_ConnHdlr vc_conn;
931 f_init();
932
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100933 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16);
Harald Welte45164da2018-01-24 12:51:27 +0100934 vc_conn.done;
935}
936
937
938/* helper function for an emergency call. caller passes in mobile identity to use */
939private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +0100940 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
941 cpars.emergency := true;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100942 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte45164da2018-01-24 12:51:27 +0100943
Harald Welte0bef21e2018-02-10 09:48:23 +0100944 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +0100945}
946
947/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200948friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100949 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100950
Harald Welte256571e2018-01-24 18:47:19 +0100951 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100952 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +0200953 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +0100954 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +0100955 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100956}
957testcase TC_emerg_call_imei_reject() runs on MTC_CT {
958 var BSC_ConnHdlr vc_conn;
959 f_init();
960
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100961 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17);
Harald Welte45164da2018-01-24 12:51:27 +0100962 vc_conn.done;
963}
964
Harald Weltee13cfb22019-04-23 16:52:02 +0200965
Harald Welted5b91402018-01-24 18:48:16 +0100966/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200967friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100968 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100969 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100970 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +0100971 /* Then issue emergency call identified by IMSI */
972 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
973}
974testcase TC_emerg_call_imsi() runs on MTC_CT {
975 var BSC_ConnHdlr vc_conn;
976 f_init();
977
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100978 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +0100979 vc_conn.done;
980}
981
Harald Weltee13cfb22019-04-23 16:52:02 +0200982
Harald Welte45164da2018-01-24 12:51:27 +0100983/* CM Service Request for VGCS -> reject */
984private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100985 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100986
987 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100988 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +0100989
990 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100991 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +0200992 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +0100993 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +0100994 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100995}
996testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
997 var BSC_ConnHdlr vc_conn;
998 f_init();
999
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001000 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001001 vc_conn.done;
1002}
1003
1004/* CM Service Request for VBS -> reject */
1005private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001006 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001007
1008 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001009 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001010
1011 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001012 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001013 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001014 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001015 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001016}
1017testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1018 var BSC_ConnHdlr vc_conn;
1019 f_init();
1020
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001021 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001022 vc_conn.done;
1023}
1024
1025/* CM Service Request for LCS -> reject */
1026private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001027 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001028
1029 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001030 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001031
1032 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001033 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001034 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001035 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001036 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001037}
1038testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1039 var BSC_ConnHdlr vc_conn;
1040 f_init();
1041
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001042 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001043 vc_conn.done;
1044}
1045
Harald Welte0195ab12018-01-24 21:50:20 +01001046/* CM Re-Establishment Request */
1047private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001048 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001049
1050 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001051 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001052
1053 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1054 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001055 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001056 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001057 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001058}
1059testcase TC_cm_reest_req_reject() runs on MTC_CT {
1060 var BSC_ConnHdlr vc_conn;
1061 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001062
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001063 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001064 vc_conn.done;
1065}
1066
Harald Weltec638f4d2018-01-24 22:00:36 +01001067/* Test LU (with authentication enabled), with wrong response from MS */
1068private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001069 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001070
1071 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1072
1073 /* tell GSUP dispatcher to send this IMSI to us */
1074 f_create_gsup_expect(hex2str(g_pars.imsi));
1075
1076 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001077 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001078
1079 /* Send Early Classmark, just for the fun of it */
1080 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1081
1082 var AuthVector vec := f_gen_auth_vec_2g();
1083 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1084 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1085 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1086
1087 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1088 /* Send back wrong auth response */
1089 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1090
1091 /* Expect GSUP AUTH FAIL REP to HLR */
1092 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1093
1094 /* Expect LU REJECT with Cause == Illegal MS */
1095 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001096 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001097}
1098testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1099 var BSC_ConnHdlr vc_conn;
1100 f_init();
1101 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001102
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001103 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23);
Harald Weltec638f4d2018-01-24 22:00:36 +01001104 vc_conn.done;
1105}
1106
Harald Weltede371492018-01-27 23:44:41 +01001107/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001108private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001109 pars.net.expect_auth := true;
1110 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001111 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001112 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001113}
1114testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1115 var BSC_ConnHdlr vc_conn;
1116 f_init();
1117 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001118 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1119
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001120 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001121 vc_conn.done;
1122}
1123
Harald Welte1af6ea82018-01-25 18:33:15 +01001124/* Test Complete L3 without payload */
1125private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001126 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001127
1128 /* Send Complete L3 Info with empty L3 frame */
1129 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1130 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1131
Harald Weltef466eb42018-01-27 14:26:54 +01001132 timer T := 5.0;
1133 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001134 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001135 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001136 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001137 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001138 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001139 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001140 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001141 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001142 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001143 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001144 }
1145 setverdict(pass);
1146}
1147testcase TC_cl3_no_payload() runs on MTC_CT {
1148 var BSC_ConnHdlr vc_conn;
1149 f_init();
1150
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001151 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001152 vc_conn.done;
1153}
1154
1155/* Test Complete L3 with random payload */
1156private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001157 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001158
Daniel Willmannaa14a382018-07-26 08:29:45 +02001159 /* length is limited by PDU_BSSAP length field which includes some
1160 * other fields beside l3info payload. So payl can only be 240 bytes
1161 * Since rnd() returns values < 1 multiply with 241
1162 */
1163 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001164 var octetstring payl := f_rnd_octstring(len);
1165
1166 /* Send Complete L3 Info with empty L3 frame */
1167 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1168 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1169
Harald Weltef466eb42018-01-27 14:26:54 +01001170 timer T := 5.0;
1171 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001172 alt {
1173 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001174 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001175 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001176 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001177 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001178 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001179 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001180 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001181 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001182 }
1183 setverdict(pass);
1184}
1185testcase TC_cl3_rnd_payload() runs on MTC_CT {
1186 var BSC_ConnHdlr vc_conn;
1187 f_init();
1188
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001189 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001190 vc_conn.done;
1191}
1192
Harald Welte116e4332018-01-26 22:17:48 +01001193/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001194friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001195 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001196
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001197 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001198
Harald Welteb9e86fa2018-04-09 18:18:31 +02001199 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001200 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001201}
1202testcase TC_establish_and_nothing() runs on MTC_CT {
1203 var BSC_ConnHdlr vc_conn;
1204 f_init();
1205
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001206 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001207 vc_conn.done;
1208}
1209
Harald Weltee13cfb22019-04-23 16:52:02 +02001210
Harald Welte12510c52018-01-26 22:26:24 +01001211/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001212friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001213 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001214
Harald Welte12510c52018-01-26 22:26:24 +01001215 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1216
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001217 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001218
Harald Welteb9e86fa2018-04-09 18:18:31 +02001219 f_establish_fully();
Harald Welte12510c52018-01-26 22:26:24 +01001220 f_create_mncc_expect(hex2str(cpars.called_party));
1221 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1222
1223 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1224
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001225 var default ccrel := activate(as_optional_cc_rel(cpars));
1226
Philipp Maier109e6aa2018-10-17 10:53:32 +02001227 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001228
1229 deactivate(ccrel);
1230
1231 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001232}
1233testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1234 var BSC_ConnHdlr vc_conn;
1235 f_init();
1236
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001237 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001238 vc_conn.done;
1239}
1240
Harald Weltee13cfb22019-04-23 16:52:02 +02001241
Harald Welte3ab88002018-01-26 22:37:25 +01001242/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001243friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001244 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001245 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1246 var MNCC_PDU mncc;
1247 var MgcpCommand mgcp_cmd;
1248
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001249 f_perform_lu();
Harald Welte3ab88002018-01-26 22:37:25 +01001250
Harald Welteb9e86fa2018-04-09 18:18:31 +02001251 f_establish_fully();
Harald Welte3ab88002018-01-26 22:37:25 +01001252 f_create_mncc_expect(hex2str(cpars.called_party));
1253 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1254
1255 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1256 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1257 cpars.mncc_callref := mncc.u.signal.callref;
1258 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1259 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1260
1261 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Harald Welte1852a842018-01-26 22:53:36 +01001262 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1263 cpars.mgcp_ep := mgcp_cmd.line.ep;
Harald Welte3ab88002018-01-26 22:37:25 +01001264 /* never respond to this */
1265
Philipp Maier8e58f592018-03-14 11:10:56 +01001266 /* When the connection with the MGW fails, the MSC will first request
1267 * a release via call control. We will answer this request normally. */
1268 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1269 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1270
Harald Welte1ddc7162018-01-27 14:25:46 +01001271 f_expect_clear(30.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001272}
1273testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1274 var BSC_ConnHdlr vc_conn;
1275 f_init();
1276
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001277 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001278 vc_conn.done;
1279}
1280
Harald Weltee13cfb22019-04-23 16:52:02 +02001281
Harald Welte0cc82d92018-01-26 22:52:34 +01001282/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001283friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001284 f_init_handler(pars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001285 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1286 var MNCC_PDU mncc;
1287 var MgcpCommand mgcp_cmd;
1288
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001289 f_perform_lu();
Harald Welte0cc82d92018-01-26 22:52:34 +01001290
Harald Welteb9e86fa2018-04-09 18:18:31 +02001291 f_establish_fully();
Harald Welte0cc82d92018-01-26 22:52:34 +01001292 f_create_mncc_expect(hex2str(cpars.called_party));
1293 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1294
1295 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1296 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1297 cpars.mncc_callref := mncc.u.signal.callref;
1298 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1299 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1300
1301 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001302
1303 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1304 * set an endpoint name that fits the pattern. If not, just use the
1305 * endpoint name from the request */
1306 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1307 cpars.mgcp_ep := "rtpbridge/1@mgw";
1308 } else {
1309 cpars.mgcp_ep := mgcp_cmd.line.ep;
1310 }
1311
Harald Welte0cc82d92018-01-26 22:52:34 +01001312 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001313
Harald Welte0cc82d92018-01-26 22:52:34 +01001314 /* Respond to CRCX with error */
1315 var MgcpResponse mgcp_rsp := {
1316 line := {
1317 code := "542",
1318 trans_id := mgcp_cmd.line.trans_id,
1319 string := "FORCED_FAIL"
1320 },
Harald Welte0cc82d92018-01-26 22:52:34 +01001321 sdp := omit
1322 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001323 var MgcpParameter mgcp_rsp_param := {
1324 code := "Z",
1325 val := cpars.mgcp_ep
1326 };
1327 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte0cc82d92018-01-26 22:52:34 +01001328 MGCP.send(mgcp_rsp);
1329
1330 timer T := 30.0;
1331 T.start;
1332 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001333 [] T.timeout {
1334 setverdict(fail, "Timeout waiting for channel release");
1335 mtc.stop;
1336 }
Daniel Willmann5868e622018-02-15 17:42:59 +01001337 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
1338 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1339 repeat;
1340 }
Harald Welte0cc82d92018-01-26 22:52:34 +01001341 [] MNCC.receive { repeat; }
1342 [] GSUP.receive { repeat; }
Philipp Maierc6e06f72018-04-11 18:12:23 +02001343 /* Note: As we did not respond properly to the CRCX from the MSC we
1344 * expect the MSC to omit any further MGCP operation (At least in the
1345 * the current implementation, there is no recovery mechanism implemented
1346 * and a DLCX can not be performed as the MSC does not know a specific
1347 * endpoint yet. */
Daniel Willmannafce8662018-07-06 23:11:32 +02001348 [] MGCP.receive {
1349 setverdict(fail, "Unexpected MGCP message");
1350 mtc.stop;
1351 }
Harald Welte5946b332018-03-18 23:32:21 +01001352 [] as_clear_cmd_compl_disc();
Harald Welte0cc82d92018-01-26 22:52:34 +01001353 }
1354}
1355testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1356 var BSC_ConnHdlr vc_conn;
1357 f_init();
1358
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001359 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001360 vc_conn.done;
1361}
1362
Harald Welte3ab88002018-01-26 22:37:25 +01001363
Harald Welte812f7a42018-01-27 00:49:18 +01001364/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1365private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1366 var MNCC_PDU mncc;
1367 var MgcpCommand mgcp_cmd;
1368 var OCT4 tmsi;
1369
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001370 f_perform_lu();
Harald Welte812f7a42018-01-27 00:49:18 +01001371 if (isvalue(g_pars.tmsi)) {
1372 tmsi := g_pars.tmsi;
1373 } else {
1374 tmsi := 'FFFFFFFF'O;
1375 }
Harald Welte6811d102019-04-14 22:23:14 +02001376 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001377
1378 /* Allocate call reference and send SETUP via MNCC to MSC */
1379 cpars.mncc_callref := f_rnd_int(2147483648);
1380 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1381 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1382
1383 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001384 f_expect_paging();
1385
Harald Welte812f7a42018-01-27 00:49:18 +01001386 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001387 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001388
1389 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1390
1391 /* MSC->MS: SETUP */
1392 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1393}
1394
1395/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001396friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001397 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001398 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1399 var MNCC_PDU mncc;
1400 var MgcpCommand mgcp_cmd;
1401
1402 f_mt_call_start(cpars);
1403
1404 /* MS->MSC: CALL CONFIRMED */
1405 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1406
1407 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1408
1409 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1410 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001411
1412 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1413 * set an endpoint name that fits the pattern. If not, just use the
1414 * endpoint name from the request */
1415 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1416 cpars.mgcp_ep := "rtpbridge/1@mgw";
1417 } else {
1418 cpars.mgcp_ep := mgcp_cmd.line.ep;
1419 }
1420
Harald Welte812f7a42018-01-27 00:49:18 +01001421 /* Respond to CRCX with error */
1422 var MgcpResponse mgcp_rsp := {
1423 line := {
1424 code := "542",
1425 trans_id := mgcp_cmd.line.trans_id,
1426 string := "FORCED_FAIL"
1427 },
Harald Welte812f7a42018-01-27 00:49:18 +01001428 sdp := omit
1429 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001430 var MgcpParameter mgcp_rsp_param := {
1431 code := "Z",
1432 val := cpars.mgcp_ep
1433 };
1434 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001435 MGCP.send(mgcp_rsp);
1436
1437 timer T := 30.0;
1438 T.start;
1439 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001440 [] T.timeout {
1441 setverdict(fail, "Timeout waiting for channel release");
1442 mtc.stop;
1443 }
Harald Welte812f7a42018-01-27 00:49:18 +01001444 [] MNCC.receive { repeat; }
1445 [] GSUP.receive { repeat; }
1446 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1447 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1448 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1449 repeat;
1450 }
1451 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001452 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001453 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001454 }
1455}
1456testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1457 var BSC_ConnHdlr vc_conn;
1458 f_init();
1459
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001460 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001461 vc_conn.done;
1462}
1463
1464
Harald Weltee13cfb22019-04-23 16:52:02 +02001465
Harald Welte812f7a42018-01-27 00:49:18 +01001466/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001467friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001468 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001469 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1470 var MNCC_PDU mncc;
1471 var MgcpCommand mgcp_cmd;
1472
1473 f_mt_call_start(cpars);
1474
1475 /* MS->MSC: CALL CONFIRMED */
1476 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1477 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1478
1479 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1480 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1481 cpars.mgcp_ep := mgcp_cmd.line.ep;
1482 /* FIXME: Respond to CRCX */
1483
1484 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1485 timer T := 190.0;
1486 T.start;
1487 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001488 [] T.timeout {
1489 setverdict(fail, "Timeout waiting for T310");
1490 mtc.stop;
1491 }
Harald Welte812f7a42018-01-27 00:49:18 +01001492 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1493 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1494 }
1495 }
1496 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1497 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1498 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1499 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1500
1501 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001502 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1503 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1504 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1505 repeat;
1506 }
Harald Welte5946b332018-03-18 23:32:21 +01001507 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001508 }
1509}
1510testcase TC_mt_t310() runs on MTC_CT {
1511 var BSC_ConnHdlr vc_conn;
1512 f_init();
1513
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001514 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001515 vc_conn.done;
1516}
1517
Harald Weltee13cfb22019-04-23 16:52:02 +02001518
Harald Welte167458a2018-01-27 15:58:16 +01001519/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001520friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001521 f_init_handler(pars);
1522 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1523 cpars.bss_rtp_port := 1110;
1524 cpars.mgcp_connection_id_bss := '22222'H;
1525 cpars.mgcp_connection_id_mss := '33333'H;
Daniel Willmann9b0235b2018-07-24 12:13:34 +02001526 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte167458a2018-01-27 15:58:16 +01001527
1528 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001529 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001530
1531 /* First MO call should succeed */
1532 f_mo_call(cpars);
1533
1534 /* Cancel the subscriber in the VLR */
1535 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1536 alt {
1537 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1538 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1539 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001540 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001541 }
1542 }
1543
1544 /* Follow-up transactions should fail */
1545 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1546 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001547 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001548 alt {
1549 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1550 [] BSSAP.receive {
1551 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001552 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001553 }
1554 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001555
1556 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001557 setverdict(pass);
1558}
1559testcase TC_gsup_cancel() runs on MTC_CT {
1560 var BSC_ConnHdlr vc_conn;
1561 f_init();
1562
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001563 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33);
Harald Welte167458a2018-01-27 15:58:16 +01001564 vc_conn.done;
1565}
1566
Harald Weltee13cfb22019-04-23 16:52:02 +02001567
Harald Welte9de84792018-01-28 01:06:35 +01001568/* A5/1 only permitted on network side, and MS capable to do it */
1569private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1570 pars.net.expect_auth := true;
1571 pars.net.expect_ciph := true;
1572 pars.net.kc_support := '02'O; /* A5/1 only */
1573 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001574 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001575}
1576testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1577 var BSC_ConnHdlr vc_conn;
1578 f_init();
1579 f_vty_config(MSCVTY, "network", "authentication required");
1580 f_vty_config(MSCVTY, "network", "encryption a5 1");
1581
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001582 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001583 vc_conn.done;
1584}
1585
1586/* A5/3 only permitted on network side, and MS capable to do it */
1587private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1588 pars.net.expect_auth := true;
1589 pars.net.expect_ciph := true;
1590 pars.net.kc_support := '08'O; /* A5/3 only */
1591 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001592 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001593}
1594testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1595 var BSC_ConnHdlr vc_conn;
1596 f_init();
1597 f_vty_config(MSCVTY, "network", "authentication required");
1598 f_vty_config(MSCVTY, "network", "encryption a5 3");
1599
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001600 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001601 vc_conn.done;
1602}
1603
1604/* A5/3 only permitted on network side, and MS with only A5/1 support */
1605private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1606 pars.net.expect_auth := true;
1607 pars.net.expect_ciph := true;
1608 pars.net.kc_support := '08'O; /* A5/3 only */
1609 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1610 f_init_handler(pars, 15.0);
1611
1612 /* cannot use f_perform_lu() as we expect a reject */
1613 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1614 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001615 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001616 if (pars.send_early_cm) {
1617 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1618 } else {
1619 pars.cm1.esind := '0'B;
1620 }
Harald Welte9de84792018-01-28 01:06:35 +01001621 f_mm_auth();
1622 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001623 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1624 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1625 repeat;
1626 }
Harald Welte5946b332018-03-18 23:32:21 +01001627 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1628 f_expect_clear();
1629 }
Harald Welte9de84792018-01-28 01:06:35 +01001630 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1631 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001632 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001633 }
1634 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001635 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001636 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001637 }
1638 }
1639 setverdict(pass);
1640}
1641testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1642 var BSC_ConnHdlr vc_conn;
1643 f_init();
1644 f_vty_config(MSCVTY, "network", "authentication required");
1645 f_vty_config(MSCVTY, "network", "encryption a5 3");
1646
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001647 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360);
1648 vc_conn.done;
1649}
1650testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1651 var BSC_ConnHdlrPars pars;
1652 var BSC_ConnHdlr vc_conn;
1653 f_init();
1654 f_vty_config(MSCVTY, "network", "authentication required");
1655 f_vty_config(MSCVTY, "network", "encryption a5 3");
1656
1657 pars := f_init_pars(361);
1658 pars.send_early_cm := false;
1659 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001660 vc_conn.done;
1661}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001662testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1663 var BSC_ConnHdlr vc_conn;
1664 f_init();
1665 f_vty_config(MSCVTY, "network", "authentication required");
1666 f_vty_config(MSCVTY, "network", "encryption a5 3");
1667
1668 /* Make sure the MSC category is on DEBUG level to trigger the log
1669 * message that is reported in OS#2947 to trigger the segfault */
1670 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1671
1672 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362);
1673 vc_conn.done;
1674}
Harald Welte9de84792018-01-28 01:06:35 +01001675
1676/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1677private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1678 pars.net.expect_auth := true;
1679 pars.net.expect_ciph := true;
1680 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1681 pars.cm1.a5_1 := '1'B;
1682 pars.cm2.a5_1 := '1'B;
1683 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1684 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1685 f_init_handler(pars, 15.0);
1686
1687 /* cannot use f_perform_lu() as we expect a reject */
1688 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1689 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001690 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001691 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1692 f_mm_auth();
1693 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001694 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1695 f_expect_clear();
1696 }
Harald Welte9de84792018-01-28 01:06:35 +01001697 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1698 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001699 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001700 }
1701 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001702 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001703 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001704 }
1705 }
1706 setverdict(pass);
1707}
1708testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1709 var BSC_ConnHdlr vc_conn;
1710 f_init();
1711 f_vty_config(MSCVTY, "network", "authentication required");
1712 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1713
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001714 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37);
Harald Welte9de84792018-01-28 01:06:35 +01001715 vc_conn.done;
1716}
1717
1718/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1719private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1720 pars.net.expect_auth := true;
1721 pars.net.expect_ciph := true;
1722 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1723 pars.cm1.a5_1 := '1'B;
1724 pars.cm2.a5_1 := '1'B;
1725 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1726 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1727 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001728 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001729}
1730testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1731 var BSC_ConnHdlr vc_conn;
1732 f_init();
1733 f_vty_config(MSCVTY, "network", "authentication required");
1734 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1735
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001736 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001737 vc_conn.done;
1738}
1739
Harald Welte33ec09b2018-02-10 15:34:46 +01001740/* LU followed by MT call (including paging) */
1741private function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1742 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001743 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte33ec09b2018-02-10 15:34:46 +01001744 cpars.bss_rtp_port := 1110;
1745 cpars.mgcp_connection_id_bss := '10004'H;
1746 cpars.mgcp_connection_id_mss := '10005'H;
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001747 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01001748
Philipp Maier4b2692d2018-03-14 16:37:48 +01001749 /* Note: This is an optional parameter. When the call-agent (MSC) does
1750 * supply a full endpoint name this setting will be overwritten. */
1751 cpars.mgcp_ep := "rtpbridge/1@mgw";
1752
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001753 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001754 f_mt_call(cpars);
1755}
1756testcase TC_lu_and_mt_call() runs on MTC_CT {
1757 var BSC_ConnHdlr vc_conn;
1758 f_init();
1759
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001760 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001761 vc_conn.done;
1762}
1763
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001764testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
1765 var BSC_ConnHdlr vc_conn;
1766 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001767
1768 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
1769 vc_conn.done;
1770}
1771
Daniel Willmann8b084372018-02-04 13:35:26 +01001772/* Test MO Call SETUP with DTMF */
1773private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1774 f_init_handler(pars);
1775 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1776 cpars.bss_rtp_port := 1110;
1777 cpars.mgcp_connection_id_bss := '22222'H;
1778 cpars.mgcp_connection_id_mss := '33333'H;
Neels Hofmeyr3d22e4a2019-10-03 04:07:47 +02001779 cpars.mgcp_ep := "rtpbridge/1@mgw";
1780 cpars.mo_call := true;
Daniel Willmann8b084372018-02-04 13:35:26 +01001781
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001782 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001783 f_mo_seq_dtmf_dup(cpars);
1784}
1785testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1786 var BSC_ConnHdlr vc_conn;
1787 f_init();
1788
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001789 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001790 vc_conn.done;
1791}
Harald Welte9de84792018-01-28 01:06:35 +01001792
Philipp Maier328d1662018-03-07 10:40:27 +01001793testcase TC_cr_before_reset() runs on MTC_CT {
1794 timer T := 4.0;
1795 var boolean reset_ack_seen := false;
1796 f_init_bssap_direct();
1797
Harald Welte3ca0ce12019-04-23 17:18:48 +02001798 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02001799
Daniel Willmanne8018962018-08-21 14:18:00 +02001800 f_sleep(3.0);
1801
Philipp Maier328d1662018-03-07 10:40:27 +01001802 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001803 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001804
1805 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001806 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001807 T.start
1808 alt {
1809 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1810 reset_ack_seen := true;
1811 repeat;
1812 }
1813
1814 /* Acknowledge MSC sided reset requests */
1815 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001816 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001817 repeat;
1818 }
1819
1820 /* Ignore all other messages (e.g CR from the connection request) */
1821 [] BSSAP_DIRECT.receive { repeat }
1822
1823 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1824 * deadlock situation. The MSC is then unable to respond to any
1825 * further BSSMAP RESET or any other sort of traffic. */
1826 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1827 [reset_ack_seen == false] T.timeout {
1828 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02001829 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01001830 }
1831 }
1832}
Harald Welte9de84792018-01-28 01:06:35 +01001833
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001834/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02001835friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001836 f_init_handler(pars);
1837 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1838 var MNCC_PDU mncc;
1839 var MgcpCommand mgcp_cmd;
1840
1841 f_perform_lu();
1842
Harald Welteb9e86fa2018-04-09 18:18:31 +02001843 f_establish_fully();
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001844 f_create_mncc_expect(hex2str(cpars.called_party));
1845 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1846
1847 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1848 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1849 cpars.mncc_callref := mncc.u.signal.callref;
1850 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1851 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1852
1853 /* Drop CRCX */
1854 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1855
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001856 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001857
1858 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001859
1860 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001861}
1862testcase TC_mo_release_timeout() runs on MTC_CT {
1863 var BSC_ConnHdlr vc_conn;
1864 f_init();
1865
1866 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1867 vc_conn.done;
1868}
1869
Harald Welte12510c52018-01-26 22:26:24 +01001870
Philipp Maier2a98a732018-03-19 16:06:12 +01001871/* LU followed by MT call (including paging) */
1872private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1873 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001874 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01001875 cpars.bss_rtp_port := 1110;
1876 cpars.mgcp_connection_id_bss := '10004'H;
1877 cpars.mgcp_connection_id_mss := '10005'H;
1878
1879 /* Note: This is an optional parameter. When the call-agent (MSC) does
1880 * supply a full endpoint name this setting will be overwritten. */
1881 cpars.mgcp_ep := "rtpbridge/1@mgw";
1882
1883 /* Intentionally disable the CRCX response */
1884 cpars.mgw_drop_dlcx := true;
1885
1886 /* Perform location update and call */
1887 f_perform_lu();
1888 f_mt_call(cpars);
1889}
1890testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
1891 var BSC_ConnHdlr vc_conn;
1892 f_init();
1893
1894 /* Perform an almost normal looking locationupdate + mt-call, but do
1895 * not respond to the DLCX at the end of the call */
1896 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
1897 vc_conn.done;
1898
1899 /* Wait a guard period until the MGCP layer in the MSC times out,
1900 * if the MSC is vulnerable to the use-after-free situation that is
1901 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
1902 * segfault now */
1903 f_sleep(6.0);
1904
1905 /* Run the init procedures once more. If the MSC has crashed, this
1906 * this will fail */
1907 f_init();
1908}
Harald Welte45164da2018-01-24 12:51:27 +01001909
Philipp Maier75932982018-03-27 14:52:35 +02001910/* Two BSSMAP resets from two different BSCs */
1911testcase TC_reset_two() runs on MTC_CT {
1912 var BSC_ConnHdlr vc_conn;
1913 f_init(2);
1914 f_sleep(2.0);
1915 setverdict(pass);
1916}
1917
Harald Weltee13cfb22019-04-23 16:52:02 +02001918/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
1919testcase TC_reset_two_1iu() runs on MTC_CT {
1920 var BSC_ConnHdlr vc_conn;
1921 f_init(3);
1922 f_sleep(2.0);
1923 setverdict(pass);
1924}
1925
Harald Weltef640a012018-04-14 17:49:21 +02001926/***********************************************************************
1927 * SMS Testing
1928 ***********************************************************************/
1929
Harald Weltef45efeb2018-04-09 18:19:24 +02001930/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02001931friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02001932 var SmsParameters spars := valueof(t_SmsPars);
1933
1934 f_init_handler(pars);
1935
1936 /* Perform location update and call */
1937 f_perform_lu();
1938
1939 f_establish_fully(EST_TYPE_MO_SMS);
1940
1941 //spars.exp_rp_err := 96; /* invalid mandatory information */
1942 f_mo_sms(spars);
1943
1944 f_expect_clear();
1945}
1946testcase TC_lu_and_mo_sms() runs on MTC_CT {
1947 var BSC_ConnHdlr vc_conn;
1948 f_init();
1949 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
1950 vc_conn.done;
1951}
1952
Harald Weltee13cfb22019-04-23 16:52:02 +02001953
Harald Weltef45efeb2018-04-09 18:19:24 +02001954private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01001955runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02001956 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
1957}
1958
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01001959/* Remove still pending SMS */
1960private function f_vty_sms_clear(charstring imsi)
1961runs on BSC_ConnHdlr {
1962 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
1963 f_vty_transceive(MSCVTY, "sms-queue clear");
1964}
1965
Harald Weltef45efeb2018-04-09 18:19:24 +02001966/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02001967friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02001968 var SmsParameters spars := valueof(t_SmsPars);
1969 var OCT4 tmsi;
1970
1971 f_init_handler(pars);
1972
1973 /* Perform location update and call */
1974 f_perform_lu();
1975
1976 /* register an 'expect' for given IMSI (+TMSI) */
1977 if (isvalue(g_pars.tmsi)) {
1978 tmsi := g_pars.tmsi;
1979 } else {
1980 tmsi := 'FFFFFFFF'O;
1981 }
Harald Welte6811d102019-04-14 22:23:14 +02001982 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02001983
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01001984 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02001985
1986 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001987 f_expect_paging();
1988
Harald Weltef45efeb2018-04-09 18:19:24 +02001989 /* Establish DTAP / BSSAP / SCCP connection */
1990 f_establish_fully(EST_TYPE_PAG_RESP);
1991
1992 spars.tp.ud := 'C8329BFD064D9B53'O;
1993 f_mt_sms(spars);
1994
1995 f_expect_clear();
1996}
1997testcase TC_lu_and_mt_sms() runs on MTC_CT {
1998 var BSC_ConnHdlrPars pars;
1999 var BSC_ConnHdlr vc_conn;
2000 f_init();
2001 pars := f_init_pars(43);
2002 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002003 vc_conn.done;
2004}
2005
Harald Weltee13cfb22019-04-23 16:52:02 +02002006
Philipp Maier3983e702018-11-22 19:01:33 +01002007/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002008friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002009 var SmsParameters spars := valueof(t_SmsPars);
2010 var OCT4 tmsi;
Philipp Maier3983e702018-11-22 19:01:33 +01002011 f_init_handler(pars, 150.0);
2012
2013 /* Perform location update */
2014 f_perform_lu();
2015
2016 /* register an 'expect' for given IMSI (+TMSI) */
2017 if (isvalue(g_pars.tmsi)) {
2018 tmsi := g_pars.tmsi;
2019 } else {
2020 tmsi := 'FFFFFFFF'O;
2021 }
Harald Welte6811d102019-04-14 22:23:14 +02002022 f_ran_register_imsi(g_pars.imsi, tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002023
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002024 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2025
Neels Hofmeyr16237742019-03-06 15:34:01 +01002026 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002027 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002028
2029 /* Wait some time to make sure the MSC is not delivering any further
2030 * paging messages or anything else that could be unexpected. */
2031 timer T := 20.0;
2032 T.start
2033 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02002034 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi))
Philipp Maier3983e702018-11-22 19:01:33 +01002035 {
2036 setverdict(fail, "paging seems not to stop!");
2037 mtc.stop;
2038 }
Harald Welte62113fc2019-05-09 13:04:02 +02002039 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Weltee13cfb22019-04-23 16:52:02 +02002040 setverdict(fail, "paging seems not to stop!");
2041 mtc.stop;
2042 }
Philipp Maier3983e702018-11-22 19:01:33 +01002043 [] BSSAP.receive {
2044 setverdict(fail, "unexpected BSSAP message received");
2045 self.stop;
2046 }
2047 [] T.timeout {
2048 setverdict(pass);
2049 }
2050 }
2051
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002052 f_vty_sms_clear(hex2str(g_pars.imsi));
2053
Philipp Maier3983e702018-11-22 19:01:33 +01002054 setverdict(pass);
2055}
2056testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2057 var BSC_ConnHdlrPars pars;
2058 var BSC_ConnHdlr vc_conn;
2059 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002060 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002061 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002062 vc_conn.done;
2063}
2064
Alexander Couzensfc02f242019-09-12 03:43:18 +02002065/* LU followed by MT SMS with repeated paging */
2066friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2067 var SmsParameters spars := valueof(t_SmsPars);
2068 var OCT4 tmsi;
2069
2070 f_init_handler(pars);
2071
2072 /* Perform location update and call */
2073 f_perform_lu();
2074
2075 /* register an 'expect' for given IMSI (+TMSI) */
2076 if (isvalue(g_pars.tmsi)) {
2077 tmsi := g_pars.tmsi;
2078 } else {
2079 tmsi := 'FFFFFFFF'O;
2080 }
2081 f_ran_register_imsi(g_pars.imsi, tmsi);
2082
2083 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2084
2085 /* MSC->BSC: expect PAGING from MSC */
2086 f_expect_paging();
2087
2088 /* MSC->BSC: expect PAGING from MSC */
2089 f_expect_paging();
2090
2091 /* Establish DTAP / BSSAP / SCCP connection */
2092 f_establish_fully(EST_TYPE_PAG_RESP);
2093
2094 spars.tp.ud := 'C8329BFD064D9B53'O;
2095 f_mt_sms(spars);
2096
2097 f_expect_clear();
2098}
2099testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2100 var BSC_ConnHdlrPars pars;
2101 var BSC_ConnHdlr vc_conn;
2102 f_init();
2103 pars := f_init_pars(1844);
2104 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2105 vc_conn.done;
2106}
Harald Weltee13cfb22019-04-23 16:52:02 +02002107
Harald Weltef640a012018-04-14 17:49:21 +02002108/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002109friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002110 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002111
Harald Weltef640a012018-04-14 17:49:21 +02002112 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002113
Harald Weltef640a012018-04-14 17:49:21 +02002114 /* Perform location update so IMSI is known + registered in MSC/VLR */
2115 f_perform_lu();
2116 f_establish_fully(EST_TYPE_MO_SMS);
2117
2118 f_mo_sms(spars);
2119
2120 var SMPP_PDU smpp;
2121 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2122 tr_smpp.body.deliver_sm := {
2123 service_type := "CMT",
2124 source_addr_ton := network_specific,
2125 source_addr_npi := isdn,
2126 source_addr := hex2str(pars.msisdn),
2127 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2128 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2129 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2130 esm_class := '00000001'B,
2131 protocol_id := 0,
2132 priority_flag := 0,
2133 schedule_delivery_time := "",
2134 replace_if_present := 0,
2135 data_coding := '00000001'B,
2136 sm_default_msg_id := 0,
2137 sm_length := ?,
2138 short_message := spars.tp.ud,
2139 opt_pars := {
2140 {
2141 tag := user_message_reference,
2142 len := 2,
2143 opt_value := {
2144 int2_val := oct2int(spars.tp.msg_ref)
2145 }
2146 }
2147 }
2148 };
2149 alt {
2150 [] SMPP.receive(tr_smpp) -> value smpp {
2151 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2152 }
2153 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2154 }
2155
2156 f_expect_clear();
2157}
2158testcase TC_smpp_mo_sms() runs on MTC_CT {
2159 var BSC_ConnHdlr vc_conn;
2160 f_init();
2161 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2162 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2163 vc_conn.done;
2164 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2165}
2166
Harald Weltee13cfb22019-04-23 16:52:02 +02002167
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002168/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002169friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002170runs on BSC_ConnHdlr {
2171 var SmsParameters spars := valueof(t_SmsPars);
2172 var GSUP_PDU gsup_msg_rx;
2173 var octetstring sm_tpdu;
2174
2175 f_init_handler(pars);
2176
2177 /* We need to inspect GSUP activity */
2178 f_create_gsup_expect(hex2str(g_pars.imsi));
2179
2180 /* Perform location update */
2181 f_perform_lu();
2182
2183 /* Send CM Service Request for SMS */
2184 f_establish_fully(EST_TYPE_MO_SMS);
2185
2186 /* Prepare expected SM-RP-UI (SM TPDU) */
2187 enc_TPDU_RP_DATA_MS_SGSN_fast(
2188 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2189 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2190 spars.tp.udl, spars.tp.ud)),
2191 sm_tpdu);
2192
2193 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2194 imsi := g_pars.imsi,
2195 sm_rp_mr := spars.rp.msg_ref,
2196 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2197 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(?),
2198 /* FIXME: MSISDN coding troubles */
2199 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(?),
2200 /* TODO: can we use decmatch here? */
2201 sm_rp_ui := sm_tpdu
2202 );
2203
2204 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2205 f_mo_sms_submit(spars);
2206 alt {
2207 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
2208 log("RX MO-forwardSM-Req");
2209 log(gsup_msg_rx);
2210 setverdict(pass);
2211 }
2212 [] GSUP.receive {
2213 log("RX unexpected GSUP message");
2214 setverdict(fail);
2215 mtc.stop;
2216 }
2217 }
2218
2219 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2220 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2221 imsi := g_pars.imsi,
2222 sm_rp_mr := spars.rp.msg_ref)));
2223 /* Expect RP-ACK on DTAP */
2224 f_mo_sms_wait_rp_ack(spars);
2225
2226 f_expect_clear();
2227}
2228testcase TC_gsup_mo_sms() runs on MTC_CT {
2229 var BSC_ConnHdlr vc_conn;
2230 f_init();
2231 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2232 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2233 vc_conn.done;
2234 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2235}
2236
Harald Weltee13cfb22019-04-23 16:52:02 +02002237
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002238/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002239friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002240runs on BSC_ConnHdlr {
2241 var SmsParameters spars := valueof(t_SmsPars);
2242 var GSUP_PDU gsup_msg_rx;
2243
2244 f_init_handler(pars);
2245
2246 /* We need to inspect GSUP activity */
2247 f_create_gsup_expect(hex2str(g_pars.imsi));
2248
2249 /* Perform location update */
2250 f_perform_lu();
2251
2252 /* Send CM Service Request for SMS */
2253 f_establish_fully(EST_TYPE_MO_SMS);
2254
2255 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2256 imsi := g_pars.imsi,
2257 sm_rp_mr := spars.rp.msg_ref,
2258 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2259 );
2260
2261 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2262 f_mo_smma(spars);
2263 alt {
2264 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
2265 log("RX MO-ReadyForSM-Req");
2266 log(gsup_msg_rx);
2267 setverdict(pass);
2268 }
2269 [] GSUP.receive {
2270 log("RX unexpected GSUP message");
2271 setverdict(fail);
2272 mtc.stop;
2273 }
2274 }
2275
2276 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2277 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2278 imsi := g_pars.imsi,
2279 sm_rp_mr := spars.rp.msg_ref)));
2280 /* Expect RP-ACK on DTAP */
2281 f_mo_sms_wait_rp_ack(spars);
2282
2283 f_expect_clear();
2284}
2285testcase TC_gsup_mo_smma() runs on MTC_CT {
2286 var BSC_ConnHdlr vc_conn;
2287 f_init();
2288 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2289 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2290 vc_conn.done;
2291 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2292}
2293
Harald Weltee13cfb22019-04-23 16:52:02 +02002294
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002295/* Helper for sending MT SMS over GSUP */
2296private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2297runs on BSC_ConnHdlr {
2298 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2299 imsi := g_pars.imsi,
2300 /* NOTE: MSC should assign RP-MR itself */
2301 sm_rp_mr := 'FF'O,
2302 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2303 /* TODO: fix encoding of ts_GSUP_SM_RP_DA_IMSI */
2304 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(g_pars.msisdn)),
2305 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(g_pars.msisdn)),
2306 /* Encoded SMS TPDU (taken from Wireshark)
2307 * FIXME: we should encode spars somehow */
2308 sm_rp_ui := '00068021436500008111328130858200'O,
2309 sm_rp_mms := mms
2310 ));
2311}
2312
2313/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002314friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002315runs on BSC_ConnHdlr {
2316 var SmsParameters spars := valueof(t_SmsPars);
2317
2318 f_init_handler(pars);
2319
2320 /* We need to inspect GSUP activity */
2321 f_create_gsup_expect(hex2str(g_pars.imsi));
2322
2323 /* Perform location update */
2324 f_perform_lu();
2325
2326 /* Register an 'expect' for given IMSI (+TMSI) */
2327 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002328 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002329 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002330 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002331 }
2332
2333 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2334 imsi := g_pars.imsi,
2335 /* NOTE: MSC should assign RP-MR itself */
2336 sm_rp_mr := ?
2337 );
2338
2339 /* Submit a MT SMS on GSUP */
2340 f_gsup_forwardSM_req(spars);
2341
2342 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002343 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002344 f_establish_fully(EST_TYPE_PAG_RESP);
2345
2346 /* Wait for MT SMS on DTAP */
2347 f_mt_sms_expect(spars);
2348
2349 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2350 f_mt_sms_send_rp_ack(spars);
2351 alt {
2352 [] GSUP.receive(mt_forwardSM_res) {
2353 log("RX MT-forwardSM-Res (RP-ACK)");
2354 setverdict(pass);
2355 }
2356 [] GSUP.receive {
2357 log("RX unexpected GSUP message");
2358 setverdict(fail);
2359 mtc.stop;
2360 }
2361 }
2362
2363 f_expect_clear();
2364}
2365testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2366 var BSC_ConnHdlrPars pars;
2367 var BSC_ConnHdlr vc_conn;
2368 f_init();
2369 pars := f_init_pars(90);
2370 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2371 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2372 vc_conn.done;
2373 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2374}
2375
Harald Weltee13cfb22019-04-23 16:52:02 +02002376
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002377/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002378friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002379runs on BSC_ConnHdlr {
2380 var SmsParameters spars := valueof(t_SmsPars);
2381 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2382
2383 f_init_handler(pars);
2384
2385 /* We need to inspect GSUP activity */
2386 f_create_gsup_expect(hex2str(g_pars.imsi));
2387
2388 /* Perform location update */
2389 f_perform_lu();
2390
2391 /* Register an 'expect' for given IMSI (+TMSI) */
2392 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002393 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002394 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002395 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002396 }
2397
2398 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2399 imsi := g_pars.imsi,
2400 /* NOTE: MSC should assign RP-MR itself */
2401 sm_rp_mr := ?,
2402 sm_rp_cause := sm_rp_cause
2403 );
2404
2405 /* Submit a MT SMS on GSUP */
2406 f_gsup_forwardSM_req(spars);
2407
2408 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002409 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002410 f_establish_fully(EST_TYPE_PAG_RESP);
2411
2412 /* Wait for MT SMS on DTAP */
2413 f_mt_sms_expect(spars);
2414
2415 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2416 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2417 alt {
2418 [] GSUP.receive(mt_forwardSM_err) {
2419 log("RX MT-forwardSM-Err (RP-ERROR)");
2420 setverdict(pass);
2421 mtc.stop;
2422 }
2423 [] GSUP.receive {
2424 log("RX unexpected GSUP message");
2425 setverdict(fail);
2426 mtc.stop;
2427 }
2428 }
2429
2430 f_expect_clear();
2431}
2432testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2433 var BSC_ConnHdlrPars pars;
2434 var BSC_ConnHdlr vc_conn;
2435 f_init();
2436 pars := f_init_pars(91);
2437 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2438 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2439 vc_conn.done;
2440 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2441}
2442
Harald Weltee13cfb22019-04-23 16:52:02 +02002443
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002444/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002445friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002446runs on BSC_ConnHdlr {
2447 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2448 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2449
2450 f_init_handler(pars);
2451
2452 /* We need to inspect GSUP activity */
2453 f_create_gsup_expect(hex2str(g_pars.imsi));
2454
2455 /* Perform location update */
2456 f_perform_lu();
2457
2458 /* Register an 'expect' for given IMSI (+TMSI) */
2459 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002460 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002461 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002462 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002463 }
2464
2465 /* Submit the 1st MT SMS on GSUP */
2466 log("TX MT-forwardSM-Req for the 1st SMS");
2467 f_gsup_forwardSM_req(spars1);
2468
2469 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002470 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002471 f_establish_fully(EST_TYPE_PAG_RESP);
2472
2473 /* Wait for 1st MT SMS on DTAP */
2474 f_mt_sms_expect(spars1);
2475 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2476 ", SM-RP-MR is ", spars1.rp.msg_ref);
2477
2478 /* Submit the 2nd MT SMS on GSUP */
2479 log("TX MT-forwardSM-Req for the 2nd SMS");
2480 f_gsup_forwardSM_req(spars2);
2481
2482 /* Wait for 2nd MT SMS on DTAP */
2483 f_mt_sms_expect(spars2);
2484 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2485 ", SM-RP-MR is ", spars2.rp.msg_ref);
2486
2487 /* Both transaction IDs shall be different */
2488 if (spars1.tid == spars2.tid) {
2489 log("Both DTAP transaction IDs shall be different");
2490 setverdict(fail);
2491 }
2492
2493 /* Both SM-RP-MR values shall be different */
2494 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2495 log("Both SM-RP-MR values shall be different");
2496 setverdict(fail);
2497 }
2498
2499 /* Both SM-RP-MR values shall be assigned */
2500 if (spars1.rp.msg_ref == 'FF'O) {
2501 log("Unassigned SM-RP-MR value for the 1st SMS");
2502 setverdict(fail);
2503 }
2504 if (spars2.rp.msg_ref == 'FF'O) {
2505 log("Unassigned SM-RP-MR value for the 2nd SMS");
2506 setverdict(fail);
2507 }
2508
2509 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2510 f_mt_sms_send_rp_ack(spars1);
2511 alt {
2512 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2513 imsi := g_pars.imsi,
2514 sm_rp_mr := spars1.rp.msg_ref
2515 )) {
2516 log("RX MT-forwardSM-Res (RP-ACK)");
2517 setverdict(pass);
2518 }
2519 [] GSUP.receive {
2520 log("RX unexpected GSUP message");
2521 setverdict(fail);
2522 mtc.stop;
2523 }
2524 }
2525
2526 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2527 f_mt_sms_send_rp_ack(spars2);
2528 alt {
2529 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2530 imsi := g_pars.imsi,
2531 sm_rp_mr := spars2.rp.msg_ref
2532 )) {
2533 log("RX MT-forwardSM-Res (RP-ACK)");
2534 setverdict(pass);
2535 }
2536 [] GSUP.receive {
2537 log("RX unexpected GSUP message");
2538 setverdict(fail);
2539 mtc.stop;
2540 }
2541 }
2542
2543 f_expect_clear();
2544}
2545testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2546 var BSC_ConnHdlrPars pars;
2547 var BSC_ConnHdlr vc_conn;
2548 f_init();
2549 pars := f_init_pars(92);
2550 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2551 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2552 vc_conn.done;
2553 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2554}
2555
Harald Weltee13cfb22019-04-23 16:52:02 +02002556
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002557/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002558friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002559runs on BSC_ConnHdlr {
2560 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2561 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2562
2563 f_init_handler(pars);
2564
2565 /* We need to inspect GSUP activity */
2566 f_create_gsup_expect(hex2str(g_pars.imsi));
2567
2568 /* Perform location update */
2569 f_perform_lu();
2570
2571 /* Register an 'expect' for given IMSI (+TMSI) */
2572 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002573 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002574 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002575 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002576 }
2577
2578 /* Send CM Service Request for MO SMMA */
2579 f_establish_fully(EST_TYPE_MO_SMS);
2580
2581 /* Submit MO SMMA on DTAP */
2582 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2583 spars_mo.rp.msg_ref := '00'O;
2584 f_mo_smma(spars_mo);
2585
2586 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2587 alt {
2588 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2589 imsi := g_pars.imsi,
2590 sm_rp_mr := spars_mo.rp.msg_ref,
2591 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2592 )) {
2593 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2594 setverdict(pass);
2595 }
2596 [] GSUP.receive {
2597 log("RX unexpected GSUP message");
2598 setverdict(fail);
2599 mtc.stop;
2600 }
2601 }
2602
2603 /* Submit MT SMS on GSUP */
2604 log("TX MT-forwardSM-Req for the MT SMS");
2605 f_gsup_forwardSM_req(spars_mt);
2606
2607 /* Wait for MT SMS on DTAP */
2608 f_mt_sms_expect(spars_mt);
2609 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2610 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2611
2612 /* Both SM-RP-MR values shall be different */
2613 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2614 log("Both SM-RP-MR values shall be different");
2615 setverdict(fail);
2616 }
2617
2618 /* SM-RP-MR value for MT SMS shall be assigned */
2619 if (spars_mt.rp.msg_ref == 'FF'O) {
2620 log("Unassigned SM-RP-MR value for the MT SMS");
2621 setverdict(fail);
2622 }
2623
2624 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2625 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2626 imsi := g_pars.imsi,
2627 sm_rp_mr := spars_mo.rp.msg_ref)));
2628 /* Expect RP-ACK for MO SMMA on DTAP */
2629 f_mo_sms_wait_rp_ack(spars_mo);
2630
2631 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2632 f_mt_sms_send_rp_ack(spars_mt);
2633 alt {
2634 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2635 imsi := g_pars.imsi,
2636 sm_rp_mr := spars_mt.rp.msg_ref
2637 )) {
2638 log("RX MT-forwardSM-Res (RP-ACK)");
2639 setverdict(pass);
2640 }
2641 [] GSUP.receive {
2642 log("RX unexpected GSUP message");
2643 setverdict(fail);
2644 mtc.stop;
2645 }
2646 }
2647
2648 f_expect_clear();
2649}
2650testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
2651 var BSC_ConnHdlrPars pars;
2652 var BSC_ConnHdlr vc_conn;
2653 f_init();
2654 pars := f_init_pars(93);
2655 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2656 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
2657 vc_conn.done;
2658 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2659}
2660
Harald Weltee13cfb22019-04-23 16:52:02 +02002661
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002662/* Test multi-part MT-SMS over GSUP */
2663private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
2664runs on BSC_ConnHdlr {
2665 var SmsParameters spars := valueof(t_SmsPars);
2666
2667 f_init_handler(pars);
2668
2669 /* We need to inspect GSUP activity */
2670 f_create_gsup_expect(hex2str(g_pars.imsi));
2671
2672 /* Perform location update */
2673 f_perform_lu();
2674
2675 /* Register an 'expect' for given IMSI (+TMSI) */
2676 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002677 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002678 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002679 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002680 }
2681
2682 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2683 imsi := g_pars.imsi,
2684 /* NOTE: MSC should assign RP-MR itself */
2685 sm_rp_mr := ?
2686 );
2687
2688 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
2689 for (var integer i := 3; i >= 0; i := i-1) {
2690 /* Submit a MT SMS on GSUP (MMS is decremented) */
2691 f_gsup_forwardSM_req(spars, int2oct(i, 1));
2692
2693 /* Expect Paging Request and Establish connection */
2694 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02002695 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002696 f_establish_fully(EST_TYPE_PAG_RESP);
2697 }
2698
2699 /* Wait for MT SMS on DTAP */
2700 f_mt_sms_expect(spars);
2701
2702 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2703 f_mt_sms_send_rp_ack(spars);
2704 alt {
2705 [] GSUP.receive(mt_forwardSM_res) {
2706 log("RX MT-forwardSM-Res (RP-ACK)");
2707 setverdict(pass);
2708 }
2709 [] GSUP.receive {
2710 log("RX unexpected GSUP message");
2711 setverdict(fail);
2712 mtc.stop;
2713 }
2714 }
2715
2716 /* Keep some 'distance' between transmissions */
2717 f_sleep(1.5);
2718 }
2719
2720 f_expect_clear();
2721}
2722testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
2723 var BSC_ConnHdlrPars pars;
2724 var BSC_ConnHdlr vc_conn;
2725 f_init();
2726 pars := f_init_pars(91);
2727 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2728 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
2729 vc_conn.done;
2730 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2731}
2732
Harald Weltef640a012018-04-14 17:49:21 +02002733/* convert GSM L3 TON to SMPP_TON enum */
2734function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
2735 select (ton) {
2736 case ('000'B) { return unknown; }
2737 case ('001'B) { return international; }
2738 case ('010'B) { return national; }
2739 case ('011'B) { return network_specific; }
2740 case ('100'B) { return subscriber_number; }
2741 case ('101'B) { return alphanumeric; }
2742 case ('110'B) { return abbreviated; }
2743 }
2744 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02002745 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002746}
2747/* convert GSM L3 NPI to SMPP_NPI enum */
2748function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2749 select (npi) {
2750 case ('0000'B) { return unknown; }
2751 case ('0001'B) { return isdn; }
2752 case ('0011'B) { return data; }
2753 case ('0100'B) { return telex; }
2754 case ('0110'B) { return land_mobile; }
2755 case ('1000'B) { return national; }
2756 case ('1001'B) { return private_; }
2757 case ('1010'B) { return ermes; }
2758 }
2759 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02002760 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002761}
2762
2763/* build a SMPP_SM from SmsParameters */
2764function f_mt_sm_from_spars(SmsParameters spars)
2765runs on BSC_ConnHdlr return SMPP_SM {
2766 var SMPP_SM sm := {
2767 service_type := "CMT",
2768 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2769 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2770 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2771 dest_addr_ton := international,
2772 dest_addr_npi := isdn,
2773 destination_addr := hex2str(g_pars.msisdn),
2774 esm_class := '00000001'B,
2775 protocol_id := 0,
2776 priority_flag := 0,
2777 schedule_delivery_time := "",
2778 validity_period := "",
2779 registered_delivery := '00000000'B,
2780 replace_if_present := 0,
2781 data_coding := '00000001'B,
2782 sm_default_msg_id := 0,
2783 sm_length := spars.tp.udl,
2784 short_message := spars.tp.ud,
2785 opt_pars := {}
2786 };
2787 return sm;
2788}
2789
2790/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2791private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2792 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2793 if (trans_mode) {
2794 sm.esm_class := '00000010'B;
2795 }
2796
2797 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2798 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2799 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2800 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2801 * before we expect the SMS delivery on the BSC/radio side */
2802 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2803 }
2804
2805 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002806 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02002807 /* Establish DTAP / BSSAP / SCCP connection */
2808 f_establish_fully(EST_TYPE_PAG_RESP);
2809 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2810
2811 f_mt_sms(spars);
2812
2813 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2814 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2815 }
2816 f_expect_clear();
2817}
2818
2819/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2820private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2821 f_init_handler(pars);
2822
2823 /* Perform location update so IMSI is known + registered in MSC/VLR */
2824 f_perform_lu();
2825 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2826
2827 /* register an 'expect' for given IMSI (+TMSI) */
2828 var OCT4 tmsi;
2829 if (isvalue(g_pars.tmsi)) {
2830 tmsi := g_pars.tmsi;
2831 } else {
2832 tmsi := 'FFFFFFFF'O;
2833 }
Harald Welte6811d102019-04-14 22:23:14 +02002834 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02002835
2836 var SmsParameters spars := valueof(t_SmsPars);
2837 /* TODO: test with more intelligent user data; test different coding schemes */
2838 spars.tp.ud := '00'O;
2839 spars.tp.udl := 1;
2840
2841 /* first test the non-transaction store+forward mode */
2842 f_smpp_mt_sms(spars, false);
2843
2844 /* then test the transaction mode */
2845 f_smpp_mt_sms(spars, true);
2846}
2847testcase TC_smpp_mt_sms() runs on MTC_CT {
2848 var BSC_ConnHdlr vc_conn;
2849 f_init();
2850 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
2851 vc_conn.done;
2852}
2853
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002854/***********************************************************************
2855 * USSD Testing
2856 ***********************************************************************/
2857
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002858private altstep as_unexp_gsup_or_bssap_msg()
2859runs on BSC_ConnHdlr {
2860 [] GSUP.receive {
2861 setverdict(fail, "Unknown/unexpected GSUP received");
2862 self.stop;
2863 }
2864 [] BSSAP.receive {
2865 setverdict(fail, "Unknown/unexpected BSSAP message received");
2866 self.stop;
2867 }
2868}
2869
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07002870private function f_expect_gsup_msg(template GSUP_PDU msg,
2871 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002872runs on BSC_ConnHdlr return GSUP_PDU {
2873 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07002874 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002875
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002876 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002877 alt {
2878 [] GSUP.receive(msg) -> value gsup_msg_complete {
2879 setverdict(pass);
2880 }
2881 /* We don't expect anything else */
2882 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002883 [] T.timeout {
2884 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
2885 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002886 }
2887
2888 return gsup_msg_complete;
2889}
2890
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07002891private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
2892 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002893runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
2894 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07002895 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002896
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002897 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002898 alt {
2899 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
2900 setverdict(pass);
2901 }
2902 /* We don't expect anything else */
2903 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002904 [] T.timeout {
2905 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
2906 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002907 }
2908
2909 return bssap_msg_complete.dtap;
2910}
2911
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002912/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02002913friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002914runs on BSC_ConnHdlr {
2915 f_init_handler(pars);
2916
2917 /* Perform location update */
2918 f_perform_lu();
2919
2920 /* Send CM Service Request for SS/USSD */
2921 f_establish_fully(EST_TYPE_SS_ACT);
2922
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002923 /* We need to inspect GSUP activity */
2924 f_create_gsup_expect(hex2str(g_pars.imsi));
2925
2926 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2927 invoke_id := 5, /* Phone may not start from 0 or 1 */
2928 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2929 ussd_string := "*#100#"
2930 );
2931
2932 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
2933 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
2934 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2935 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
2936 )
2937
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002938 /* Compose a new SS/REGISTER message with request */
2939 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
2940 tid := 1, /* We just need a single transaction */
2941 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002942 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002943 );
2944
2945 /* Compose SS/RELEASE_COMPLETE template with expected response */
2946 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
2947 tid := 1, /* Response should arrive within the same transaction */
2948 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002949 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002950 );
2951
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002952 /* Compose expected MSC -> HLR message */
2953 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
2954 imsi := g_pars.imsi,
2955 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2956 ss := valueof(facility_req)
2957 );
2958
2959 /* To be used for sending response with correct session ID */
2960 var GSUP_PDU gsup_req_complete;
2961
2962 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002963 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002964 /* Expect GSUP message containing the SS payload */
2965 gsup_req_complete := f_expect_gsup_msg(gsup_req);
2966
2967 /* Compose the response from HLR using received session ID */
2968 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
2969 imsi := g_pars.imsi,
2970 sid := gsup_req_complete.ies[1].val.session_id,
2971 state := OSMO_GSUP_SESSION_STATE_END,
2972 ss := valueof(facility_rsp)
2973 );
2974
2975 /* Finally, HLR terminates the session */
2976 GSUP.send(gsup_rsp);
2977 /* Expect RELEASE_COMPLETE message with the response */
2978 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002979
2980 f_expect_clear();
2981}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002982testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002983 var BSC_ConnHdlr vc_conn;
2984 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002985 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002986 vc_conn.done;
2987}
2988
Harald Weltee13cfb22019-04-23 16:52:02 +02002989
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002990/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02002991friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002992runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002993 timer T := 5.0;
2994
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002995 f_init_handler(pars);
2996
2997 /* Perform location update */
2998 f_perform_lu();
2999
Harald Welte6811d102019-04-14 22:23:14 +02003000 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003001
3002 /* We need to inspect GSUP activity */
3003 f_create_gsup_expect(hex2str(g_pars.imsi));
3004
3005 /* Facility IE with network-originated USSD notification */
3006 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3007 op_code := SS_OP_CODE_USS_NOTIFY,
3008 ussd_string := "Mahlzeit!"
3009 );
3010
3011 /* Facility IE with acknowledgment to the USSD notification */
3012 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3013 /* In case of USSD notification, Return Result is empty */
3014 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3015 );
3016
3017 /* Compose a new MT SS/REGISTER message with USSD notification */
3018 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3019 tid := 0, /* FIXME: most likely, it should be 0 */
3020 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3021 facility := valueof(facility_req)
3022 );
3023
3024 /* Compose HLR -> MSC GSUP message */
3025 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3026 imsi := g_pars.imsi,
3027 sid := '20000101'O,
3028 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3029 ss := valueof(facility_req)
3030 );
3031
3032 /* Send it to MSC and expect Paging Request */
3033 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003034 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003035 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003036 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3037 setverdict(pass);
3038 }
Harald Welte62113fc2019-05-09 13:04:02 +02003039 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003040 setverdict(pass);
3041 }
3042 /* We don't expect anything else */
3043 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003044 [] T.timeout {
3045 setverdict(fail, "Timeout waiting for Paging Request");
3046 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003047 }
3048
3049 /* Send Paging Response and expect USSD notification */
3050 f_establish_fully(EST_TYPE_PAG_RESP);
3051 /* Expect MT REGISTER message with USSD notification */
3052 f_expect_mt_dtap_msg(ussd_ntf);
3053
3054 /* Compose a new MO SS/FACILITY message with empty response */
3055 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3056 tid := 0, /* FIXME: it shall match the request tid */
3057 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3058 facility := valueof(facility_rsp)
3059 );
3060
3061 /* Compose expected MSC -> HLR GSUP message */
3062 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3063 imsi := g_pars.imsi,
3064 sid := '20000101'O,
3065 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3066 ss := valueof(facility_rsp)
3067 );
3068
3069 /* MS sends response to the notification */
3070 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3071 /* Expect GSUP message containing the SS payload */
3072 f_expect_gsup_msg(gsup_rsp);
3073
3074 /* Compose expected MT SS/RELEASE COMPLETE message */
3075 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3076 tid := 0, /* FIXME: it shall match the request tid */
3077 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3078 facility := omit
3079 );
3080
3081 /* Compose MSC -> HLR GSUP message */
3082 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3083 imsi := g_pars.imsi,
3084 sid := '20000101'O,
3085 state := OSMO_GSUP_SESSION_STATE_END
3086 );
3087
3088 /* Finally, HLR terminates the session */
3089 GSUP.send(gsup_term)
3090 /* Expect MT RELEASE COMPLETE without Facility IE */
3091 f_expect_mt_dtap_msg(ussd_term);
3092
3093 f_expect_clear();
3094}
3095testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3096 var BSC_ConnHdlr vc_conn;
3097 f_init();
3098 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3099 vc_conn.done;
3100}
3101
Harald Weltee13cfb22019-04-23 16:52:02 +02003102
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003103/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003104friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003105runs on BSC_ConnHdlr {
3106 f_init_handler(pars);
3107
3108 /* Call parameters taken from f_tc_lu_and_mt_call */
3109 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3110 cpars.mgcp_connection_id_bss := '10004'H;
3111 cpars.mgcp_connection_id_mss := '10005'H;
3112 cpars.mgcp_ep := "rtpbridge/1@mgw";
3113 cpars.bss_rtp_port := 1110;
3114
3115 /* Perform location update */
3116 f_perform_lu();
3117
3118 /* Establish a MT call */
3119 f_mt_call_establish(cpars);
3120
3121 /* Hold the call for some time */
3122 f_sleep(1.0);
3123
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003124 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3125 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3126 ussd_string := "*#100#"
3127 );
3128
3129 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3130 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3131 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3132 )
3133
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003134 /* Compose a new SS/REGISTER message with request */
3135 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3136 tid := 1, /* We just need a single transaction */
3137 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003138 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003139 );
3140
3141 /* Compose SS/RELEASE_COMPLETE template with expected response */
3142 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3143 tid := 1, /* Response should arrive within the same transaction */
3144 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003145 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003146 );
3147
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003148 /* Compose expected MSC -> HLR message */
3149 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3150 imsi := g_pars.imsi,
3151 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3152 ss := valueof(facility_req)
3153 );
3154
3155 /* To be used for sending response with correct session ID */
3156 var GSUP_PDU gsup_req_complete;
3157
3158 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003159 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003160 /* Expect GSUP message containing the SS payload */
3161 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3162
3163 /* Compose the response from HLR using received session ID */
3164 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3165 imsi := g_pars.imsi,
3166 sid := gsup_req_complete.ies[1].val.session_id,
3167 state := OSMO_GSUP_SESSION_STATE_END,
3168 ss := valueof(facility_rsp)
3169 );
3170
3171 /* Finally, HLR terminates the session */
3172 GSUP.send(gsup_rsp);
3173 /* Expect RELEASE_COMPLETE message with the response */
3174 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003175
3176 /* Hold the call for some time */
3177 f_sleep(1.0);
3178
3179 /* Release the call (does Clear Complete itself) */
3180 f_call_hangup(cpars, true);
3181}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003182testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003183 var BSC_ConnHdlr vc_conn;
3184 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003185 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003186 vc_conn.done;
3187}
3188
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003189/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003190friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003191 f_init_handler(pars);
3192 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
3193 var MNCC_PDU mncc;
3194 var MgcpCommand mgcp_cmd;
3195
3196 f_perform_lu();
3197
3198 f_establish_fully();
3199 f_create_mncc_expect(hex2str(cpars.called_party));
3200 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
3201
3202 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
3203 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
3204 cpars.mncc_callref := mncc.u.signal.callref;
3205 log("mncc_callref=", cpars.mncc_callref);
3206 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
3207 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
3208
3209 MNCC.send(ts_MNCC_ALERT_req(cpars.mncc_callref));
3210 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_ALERTING(cpars.transaction_id)));
3211 MGCP.receive(tr_CRCX);
3212
3213 f_sleep(1.0);
Harald Weltee13cfb22019-04-23 16:52:02 +02003214 if (pars.ran_is_geran) {
3215 BSSAP.send(ts_BSSMAP_ClearRequest(0));
3216 } else {
3217 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
3218 }
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003219
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003220 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003221
Harald Weltee13cfb22019-04-23 16:52:02 +02003222 if (pars.ran_is_geran) {
3223 interleave {
3224 [] MNCC.receive(tr_MNCC_REL_ind(?, ?)) { };
3225 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003226 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Weltee13cfb22019-04-23 16:52:02 +02003227 };
3228 }
3229 } else {
3230 interleave {
3231 [] MNCC.receive(tr_MNCC_REL_ind(?, ?)) { };
3232 [] BSSAP.receive(tr_RANAP_IuReleaseCommand(?)) {
3233 BSSAP.send(ts_RANAP_IuReleaseComplete);
3234 };
3235 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003236 }
3237
3238 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003239
3240 f_sleep(1.0);
3241}
3242testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3243 var BSC_ConnHdlr vc_conn;
3244 f_init();
3245
3246 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3247 vc_conn.done;
3248}
3249
Harald Weltee13cfb22019-04-23 16:52:02 +02003250
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003251/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003252friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003253runs on BSC_ConnHdlr {
3254 f_init_handler(pars);
3255
3256 /* Call parameters taken from f_tc_lu_and_mt_call */
3257 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3258 cpars.mgcp_connection_id_bss := '10004'H;
3259 cpars.mgcp_connection_id_mss := '10005'H;
3260 cpars.mgcp_ep := "rtpbridge/1@mgw";
3261 cpars.bss_rtp_port := 1110;
3262
3263 /* Perform location update */
3264 f_perform_lu();
3265
3266 /* Establish a MT call */
3267 f_mt_call_establish(cpars);
3268
3269 /* Hold the call for some time */
3270 f_sleep(1.0);
3271
3272 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3273 op_code := SS_OP_CODE_USS_REQUEST,
3274 ussd_string := "Please type anything..."
3275 );
3276
3277 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3278 op_code := SS_OP_CODE_USS_REQUEST,
3279 ussd_string := "Nope."
3280 )
3281
3282 /* Compose MT SS/REGISTER message with network-originated request */
3283 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3284 tid := 0, /* FIXME: most likely, it should be 0 */
3285 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3286 facility := valueof(facility_req)
3287 );
3288
3289 /* Compose HLR -> MSC GSUP message */
3290 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3291 imsi := g_pars.imsi,
3292 sid := '20000101'O,
3293 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3294 ss := valueof(facility_req)
3295 );
3296
3297 /* Send it to MSC */
3298 GSUP.send(gsup_req);
3299 /* Expect MT REGISTER message with USSD request */
3300 f_expect_mt_dtap_msg(ussd_req);
3301
3302 /* Compose a new MO SS/FACILITY message with response */
3303 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3304 tid := 0, /* FIXME: it shall match the request tid */
3305 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3306 facility := valueof(facility_rsp)
3307 );
3308
3309 /* Compose expected MSC -> HLR GSUP message */
3310 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3311 imsi := g_pars.imsi,
3312 sid := '20000101'O,
3313 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3314 ss := valueof(facility_rsp)
3315 );
3316
3317 /* MS sends response */
3318 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3319 f_expect_gsup_msg(gsup_rsp);
3320
3321 /* Compose expected MT SS/RELEASE COMPLETE message */
3322 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3323 tid := 0, /* FIXME: it shall match the request tid */
3324 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3325 facility := omit
3326 );
3327
3328 /* Compose MSC -> HLR GSUP message */
3329 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3330 imsi := g_pars.imsi,
3331 sid := '20000101'O,
3332 state := OSMO_GSUP_SESSION_STATE_END
3333 );
3334
3335 /* Finally, HLR terminates the session */
3336 GSUP.send(gsup_term);
3337 /* Expect MT RELEASE COMPLETE without Facility IE */
3338 f_expect_mt_dtap_msg(ussd_term);
3339
3340 /* Hold the call for some time */
3341 f_sleep(1.0);
3342
3343 /* Release the call (does Clear Complete itself) */
3344 f_call_hangup(cpars, true);
3345}
3346testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3347 var BSC_ConnHdlr vc_conn;
3348 f_init();
3349 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3350 vc_conn.done;
3351}
3352
Harald Weltee13cfb22019-04-23 16:52:02 +02003353
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003354/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003355friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003356runs on BSC_ConnHdlr {
3357 f_init_handler(pars);
3358
3359 /* Perform location update */
3360 f_perform_lu();
3361
3362 /* Send CM Service Request for SS/USSD */
3363 f_establish_fully(EST_TYPE_SS_ACT);
3364
3365 /* We need to inspect GSUP activity */
3366 f_create_gsup_expect(hex2str(g_pars.imsi));
3367
3368 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3369 invoke_id := 1, /* Initial request */
3370 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3371 ussd_string := "*6766*266#"
3372 );
3373
3374 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3375 invoke_id := 2, /* Counter request */
3376 op_code := SS_OP_CODE_USS_REQUEST,
3377 ussd_string := "Password?!?"
3378 )
3379
3380 /* Compose MO SS/REGISTER message with request */
3381 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3382 tid := 1, /* We just need a single transaction */
3383 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3384 facility := valueof(facility_ms_req)
3385 );
3386
3387 /* Compose expected MSC -> HLR message */
3388 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3389 imsi := g_pars.imsi,
3390 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3391 ss := valueof(facility_ms_req)
3392 );
3393
3394 /* To be used for sending response with correct session ID */
3395 var GSUP_PDU gsup_ms_req_complete;
3396
3397 /* Initiate a new transaction */
3398 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3399 /* Expect GSUP request with original Facility IE */
3400 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3401
3402 /* Compose the response from HLR using received session ID */
3403 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3404 imsi := g_pars.imsi,
3405 sid := gsup_ms_req_complete.ies[1].val.session_id,
3406 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3407 ss := valueof(facility_net_req)
3408 );
3409
3410 /* Compose expected MT SS/FACILITY template with counter request */
3411 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3412 tid := 1, /* Response should arrive within the same transaction */
3413 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3414 facility := valueof(facility_net_req)
3415 );
3416
3417 /* Send response over GSUP */
3418 GSUP.send(gsup_net_req);
3419 /* Expect MT SS/FACILITY message with counter request */
3420 f_expect_mt_dtap_msg(ussd_net_req);
3421
3422 /* Compose MO SS/RELEASE COMPLETE */
3423 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3424 tid := 1, /* Response should arrive within the same transaction */
3425 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3426 facility := omit
3427 /* TODO: cause? */
3428 );
3429
3430 /* Compose expected HLR -> MSC abort message */
3431 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3432 imsi := g_pars.imsi,
3433 sid := gsup_ms_req_complete.ies[1].val.session_id,
3434 state := OSMO_GSUP_SESSION_STATE_END
3435 );
3436
3437 /* Abort transaction */
3438 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3439 /* Expect GSUP message indicating abort */
3440 f_expect_gsup_msg(gsup_abort);
3441
3442 f_expect_clear();
3443}
3444testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3445 var BSC_ConnHdlr vc_conn;
3446 f_init();
3447 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3448 vc_conn.done;
3449}
3450
Harald Weltee13cfb22019-04-23 16:52:02 +02003451
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003452/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003453friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003454runs on BSC_ConnHdlr {
3455 f_init_handler(pars);
3456
3457 /* Perform location update */
3458 f_perform_lu();
3459
3460 /* Send CM Service Request for SS/USSD */
3461 f_establish_fully(EST_TYPE_SS_ACT);
3462
3463 /* We need to inspect GSUP activity */
3464 f_create_gsup_expect(hex2str(g_pars.imsi));
3465
3466 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3467 invoke_id := 1,
3468 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3469 ussd_string := "#release_me");
3470
3471 /* Compose MO SS/REGISTER message with request */
3472 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3473 tid := 1, /* An arbitrary transaction identifier */
3474 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3475 facility := valueof(facility_ms_req));
3476
3477 /* Compose expected MSC -> HLR message */
3478 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3479 imsi := g_pars.imsi,
3480 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3481 ss := valueof(facility_ms_req));
3482
3483 /* To be used for sending response with correct session ID */
3484 var GSUP_PDU gsup_ms_req_complete;
3485
3486 /* Initiate a new SS transaction */
3487 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3488 /* Expect GSUP request with original Facility IE */
3489 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3490
3491 /* Don't respond, wait for timeout */
3492 f_sleep(3.0);
3493
3494 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3495 tid := 1, /* Should match the request's tid */
3496 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3497 cause := *, /* TODO: expect some specific value */
3498 facility := omit);
3499
3500 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3501 imsi := g_pars.imsi,
3502 sid := gsup_ms_req_complete.ies[1].val.session_id,
3503 state := OSMO_GSUP_SESSION_STATE_END,
3504 cause := ?); /* TODO: expect some specific value */
3505
3506 /* Expect release on both interfaces */
3507 interleave {
3508 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3509 [] GSUP.receive(gsup_rel) { };
3510 }
3511
3512 f_expect_clear();
3513 setverdict(pass);
3514}
3515testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3516 var BSC_ConnHdlr vc_conn;
3517 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003518 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003519 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3520 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003521 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003522}
3523
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003524/* MT (network-originated) USSD for unknown subscriber */
3525friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
3526runs on BSC_ConnHdlr {
3527 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
3528 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003529
3530 f_init_handler(pars);
3531 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
3532 f_create_gsup_expect(hex2str(imsi));
3533
3534 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3535 imsi := imsi,
3536 sid := sid,
3537 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3538 ss := f_rnd_octstring(23)
3539 );
3540
3541 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
3542 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3543 imsi := imsi,
3544 sid := sid,
3545 state := OSMO_GSUP_SESSION_STATE_END,
3546 cause := 2 /* FIXME: introduce an enumerated type! */
3547 );
3548
3549 /* Initiate a MT USSD notification */
3550 GSUP.send(gsup_req);
3551
3552 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07003553 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003554}
3555testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
3556 var BSC_ConnHdlr vc_conn;
3557 f_init();
3558 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
3559 vc_conn.done;
3560}
3561
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003562/* MO (mobile-originated) SS/USSD for unknown transaction */
3563friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
3564runs on BSC_ConnHdlr {
3565 f_init_handler(pars);
3566
3567 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
3568 f_create_gsup_expect(hex2str(g_pars.imsi));
3569
3570 /* Perform location update */
3571 f_perform_lu();
3572
3573 /* Send CM Service Request for SS/USSD */
3574 f_establish_fully(EST_TYPE_SS_ACT);
3575
3576 /* GSM 04.80 FACILITY message for a non-existing transaction */
3577 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
3578 tid := 1, /* An arbitrary transaction identifier */
3579 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3580 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3581 );
3582
3583 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
3584 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
3585 tid := 1, /* An arbitrary transaction identifier */
3586 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3587 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3588 );
3589
3590 /* Expected response from the network */
3591 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3592 tid := 1, /* Same as in the FACILITY message */
3593 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3594 facility := omit
3595 );
3596
3597 /* Send GSM 04.80 FACILITY for non-existing transaction */
3598 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
3599
3600 /* Expect GSM 04.80 RELEASE COMPLETE message */
3601 f_expect_mt_dtap_msg(mt_ss_rel);
3602 f_expect_clear();
3603
3604 /* Send another CM Service Request for SS/USSD */
3605 f_establish_fully(EST_TYPE_SS_ACT);
3606
3607 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
3608 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
3609
3610 /* Expect GSM 04.80 RELEASE COMPLETE message */
3611 f_expect_mt_dtap_msg(mt_ss_rel);
3612 f_expect_clear();
3613}
3614testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
3615 var BSC_ConnHdlr vc_conn;
3616 f_init();
3617 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
3618 vc_conn.done;
3619}
3620
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003621/* MT (network-originated) USSD for unknown session */
3622friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
3623runs on BSC_ConnHdlr {
3624 var OCT4 sid := '20000333'O;
3625
3626 f_init_handler(pars);
3627
3628 /* Perform location update */
3629 f_perform_lu();
3630
3631 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
3632 f_create_gsup_expect(hex2str(g_pars.imsi));
3633
3634 /* Request referencing a non-existing SS session */
3635 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3636 imsi := g_pars.imsi,
3637 sid := sid,
3638 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3639 ss := f_rnd_octstring(23)
3640 );
3641
3642 /* Error with some cause value */
3643 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3644 imsi := g_pars.imsi,
3645 sid := sid,
3646 state := OSMO_GSUP_SESSION_STATE_END,
3647 cause := ? /* FIXME: introduce an enumerated type! */
3648 );
3649
3650 /* Initiate a MT USSD notification */
3651 GSUP.send(gsup_req);
3652
3653 /* Expect GSUP PROC_SS_ERROR message */
3654 f_expect_gsup_msg(gsup_rsp);
3655}
3656testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
3657 var BSC_ConnHdlr vc_conn;
3658 f_init();
3659 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
3660 vc_conn.done;
3661}
3662
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003663/* MT (network-originated) USSD and no response to Paging Request */
3664friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
3665runs on BSC_ConnHdlr {
3666 timer TP := 2.0; /* Paging timer */
3667
3668 f_init_handler(pars);
3669
3670 /* Perform location update */
3671 f_perform_lu();
3672
3673 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
3674 f_create_gsup_expect(hex2str(g_pars.imsi));
3675
3676 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3677 imsi := g_pars.imsi,
3678 sid := '20000444'O,
3679 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3680 ss := f_rnd_octstring(23)
3681 );
3682
3683 /* Error with some cause value */
3684 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3685 imsi := g_pars.imsi,
3686 sid := '20000444'O,
3687 state := OSMO_GSUP_SESSION_STATE_END,
3688 cause := ? /* FIXME: introduce an enumerated type! */
3689 );
3690
3691 /* Initiate a MT USSD notification */
3692 GSUP.send(gsup_req);
3693
3694 /* Send it to MSC and expect Paging Request */
3695 TP.start;
3696 alt {
3697 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3698 setverdict(pass);
3699 }
3700 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
3701 setverdict(pass);
3702 }
3703 /* We don't expect anything else */
3704 [] as_unexp_gsup_or_bssap_msg();
3705 [] TP.timeout {
3706 setverdict(fail, "Timeout waiting for Paging Request");
3707 }
3708 }
3709
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07003710 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
3711 * OsmoMSC waits for Paging Response 10 seconds by default. */
3712 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003713}
3714testcase TC_proc_ss_paging_fail() runs on MTC_CT {
3715 var BSC_ConnHdlr vc_conn;
3716 f_init();
3717 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
3718 vc_conn.done;
3719}
3720
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07003721/* MT (network-originated) USSD followed by immediate abort */
3722friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
3723runs on BSC_ConnHdlr {
3724 var octetstring facility := f_rnd_octstring(23);
3725 var OCT4 sid := '20000555'O;
3726 timer TP := 2.0;
3727
3728 f_init_handler(pars);
3729
3730 /* Perform location update */
3731 f_perform_lu();
3732
3733 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
3734 f_create_gsup_expect(hex2str(g_pars.imsi));
3735
3736 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
3737 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3738 imsi := g_pars.imsi, sid := sid,
3739 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3740 ss := facility
3741 );
3742
3743 /* On the MS side, we expect GSM 04.80 REGISTER message */
3744 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
3745 tid := 0, /* Most likely, it should be 0 */
3746 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3747 facility := facility
3748 );
3749
3750 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
3751 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
3752 imsi := g_pars.imsi, sid := sid,
3753 state := OSMO_GSUP_SESSION_STATE_END,
3754 cause := 0 /* FIXME: introduce an enumerated type! */
3755 );
3756
3757 /* On the MS side, we expect GSM 04.80 REGISTER message */
3758 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3759 tid := 0, /* Most likely, it should be 0 */
3760 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3761 cause := *, /* FIXME: expect some specific cause value */
3762 facility := omit
3763 );
3764
3765 /* Initiate a MT USSD with random payload */
3766 GSUP.send(gsup_req);
3767
3768 /* Expect Paging Request */
3769 TP.start;
3770 alt {
3771 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3772 setverdict(pass);
3773 }
3774 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
3775 setverdict(pass);
3776 }
3777 /* We don't expect anything else */
3778 [] as_unexp_gsup_or_bssap_msg();
3779 [] TP.timeout {
3780 setverdict(fail, "Timeout waiting for Paging Request");
3781 }
3782 }
3783
3784 /* Send Paging Response and establish connection */
3785 f_establish_fully(EST_TYPE_PAG_RESP);
3786 /* Expect MT REGISTER message with random facility */
3787 f_expect_mt_dtap_msg(dtap_reg);
3788
3789 /* HLR/EUSE decides to abort the session even
3790 * before getting any response from the MS */
3791 /* Initiate a MT USSD with random payload */
3792 GSUP.send(gsup_abort);
3793
3794 /* Expect RELEASE COMPLETE on ths MS side */
3795 f_expect_mt_dtap_msg(dtap_rel);
3796
3797 f_expect_clear();
3798}
3799testcase TC_proc_ss_abort() runs on MTC_CT {
3800 var BSC_ConnHdlr vc_conn;
3801 f_init();
3802 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
3803 vc_conn.done;
3804}
3805
Harald Weltee13cfb22019-04-23 16:52:02 +02003806
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003807/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
3808private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3809 pars.net.expect_auth := true;
3810 pars.net.expect_ciph := true;
3811 pars.net.kc_support := '02'O; /* A5/1 only */
3812 f_init_handler(pars);
3813
3814 g_pars.vec := f_gen_auth_vec_2g();
3815
3816 /* Can't use f_perform_lu() directly. Code below is based on it. */
3817
3818 /* tell GSUP dispatcher to send this IMSI to us */
3819 f_create_gsup_expect(hex2str(g_pars.imsi));
3820
3821 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3822 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02003823 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003824
3825 f_mm_auth();
3826
3827 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3828 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3829 alt {
3830 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3831 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
3832 }
3833 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3834 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3835 mtc.stop;
3836 }
3837 [] BSSAP.receive {
3838 setverdict(fail, "Unknown/unexpected BSSAP received");
3839 mtc.stop;
3840 }
3841 }
3842
3843 /* Expect LU reject from MSC. */
3844 alt {
3845 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3846 setverdict(pass);
3847 }
3848 [] BSSAP.receive {
3849 setverdict(fail, "Unknown/unexpected BSSAP received");
3850 mtc.stop;
3851 }
3852 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01003853 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003854}
3855
3856testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
3857 var BSC_ConnHdlr vc_conn;
3858 f_init();
3859 f_vty_config(MSCVTY, "network", "encryption a5 1");
3860
3861 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52);
3862 vc_conn.done;
3863}
3864
Harald Welteb2284bd2019-05-10 11:30:43 +02003865/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
3866friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3867 f_init_handler(pars);
3868
3869 /* tell GSUP dispatcher to send this IMSI to us */
3870 f_create_gsup_expect(hex2str(g_pars.imsi));
3871
3872 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
3873 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
3874
3875 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3876 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
3877 f_cl3_or_initial_ue(l3_lu);
3878
3879 /* Expect LU reject from MSC. */
3880 alt {
3881 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3882 setverdict(pass);
3883 }
3884 [] BSSAP.receive {
3885 setverdict(fail, "Unknown/unexpected BSSAP received");
3886 mtc.stop;
3887 }
3888 }
3889 f_expect_clear();
3890}
3891testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
3892 var BSC_ConnHdlr vc_conn;
3893 f_init();
3894 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
3895 vc_conn.done;
3896}
3897
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01003898private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
3899 pars.net.expect_auth := true;
3900 pars.net.expect_ciph := true;
3901 pars.net.kc_support := kc_support;
3902 f_init_handler(pars);
3903
3904 g_pars.vec := f_gen_auth_vec_2g();
3905
3906 /* Can't use f_perform_lu() directly. Code below is based on it. */
3907
3908 /* tell GSUP dispatcher to send this IMSI to us */
3909 f_create_gsup_expect(hex2str(g_pars.imsi));
3910
3911 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3912 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
3913 f_cl3_or_initial_ue(l3_lu);
3914
3915 f_mm_auth();
3916
3917 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3918 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3919 alt {
3920 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3921 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
3922 }
3923 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
3924 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
3925 repeat;
3926 }
3927 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3928 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3929 mtc.stop;
3930 }
3931 [] BSSAP.receive {
3932 setverdict(fail, "Unknown/unexpected BSSAP received");
3933 mtc.stop;
3934 }
3935 }
3936
3937 /* TODO: Verify MSC is using the best cipher available! How? */
3938
3939 f_msc_lu_hlr();
3940 f_accept_reject_lu();
3941 f_expect_clear();
3942 setverdict(pass);
3943}
3944
3945/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
3946private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3947 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
3948}
3949
3950/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
3951private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3952 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
3953}
3954
3955/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
3956private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3957 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
3958}
3959
3960testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
3961 var BSC_ConnHdlr vc_conn;
3962 f_init();
3963 f_vty_config(MSCVTY, "network", "encryption a5 1");
3964
3965 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
3966 vc_conn.done;
3967}
3968
3969testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
3970 var BSC_ConnHdlr vc_conn;
3971 f_init();
3972 f_vty_config(MSCVTY, "network", "encryption a5 3");
3973
3974 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
3975 vc_conn.done;
3976}
3977
3978testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
3979 var BSC_ConnHdlr vc_conn;
3980 f_init();
3981 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
3982
3983 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
3984 vc_conn.done;
3985}
Harald Welteb2284bd2019-05-10 11:30:43 +02003986
Harald Weltef640a012018-04-14 17:49:21 +02003987/* TODO (SMS):
3988 * different user data lengths
3989 * SMPP transaction mode with unsuccessful delivery
3990 * queued MT-SMS with no paging response + later delivery
3991 * different data coding schemes
3992 * multi-part SMS
3993 * user-data headers
3994 * TP-PID for SMS to SIM
3995 * behavior if SMS memory is full + RP-SMMA
3996 * delivery reports
3997 * SMPP osmocom extensions
3998 * more-messages-to-send
3999 * SMS during ongoing call (SACCH/SAPI3)
4000 */
4001
4002/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004003 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4004 * malformed messages (missing IE, invalid message type): properly rejected?
4005 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4006 * 3G/2G auth permutations
4007 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004008 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004009 * too long L3 INFO in DTAP
4010 * too long / padded BSSAP
4011 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004012 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004013
Harald Weltee13cfb22019-04-23 16:52:02 +02004014/***********************************************************************
4015 * SGsAP Testing
4016 ***********************************************************************/
4017
Philipp Maier948747b2019-04-02 15:22:33 +02004018/* Check if a subscriber exists in the VLR */
4019private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4020
4021 var CtrlValue active_subsribers;
4022 var integer rc;
4023 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4024
4025 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4026 if (rc < 0) {
4027 return false;
4028 }
4029
4030 return true;
4031}
4032
Harald Welte4263c522018-12-06 11:56:27 +01004033/* Perform a location updatye at the A-Interface and run some checks to confirm
4034 * that everything is back to normal. */
4035private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4036 var SmsParameters spars := valueof(t_SmsPars);
4037
4038 /* Perform a location update, the SGs association is expected to fall
4039 * back to NULL */
4040 f_perform_lu();
4041 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4042
4043 /* Trigger a paging request and expect the paging on BSSMAP, this is
4044 * to make sure that pagings are sent throught the A-Interface again
4045 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004046 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004047 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4048
4049 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004050 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4051 setverdict(pass);
4052 }
Harald Welte62113fc2019-05-09 13:04:02 +02004053 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004054 setverdict(pass);
4055 }
4056 [] SGsAP.receive {
4057 setverdict(fail, "Received unexpected message on SGs");
4058 }
4059 }
4060
4061 /* Send an SMS to make sure that also payload messages are routed
4062 * throught the A-Interface again */
4063 f_establish_fully(EST_TYPE_MO_SMS);
4064 f_mo_sms(spars);
4065 f_expect_clear();
4066}
4067
4068private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4069 var charstring vlr_name;
4070 f_init_handler(pars);
4071
4072 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4073 log("VLR name: ", vlr_name);
4074 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004075 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004076}
4077
4078testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004079 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004080 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004081 f_init(1, true);
4082 pars := f_init_pars(11810, true);
4083 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004084 vc_conn.done;
4085}
4086
4087/* like f_mm_auth() but for SGs */
4088function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4089 if (g_pars.net.expect_auth) {
4090 g_pars.vec := f_gen_auth_vec_3g();
4091 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4092 g_pars.vec.sres,
4093 g_pars.vec.kc,
4094 g_pars.vec.ik,
4095 g_pars.vec.ck,
4096 g_pars.vec.autn,
4097 g_pars.vec.res));
4098 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4099 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4100 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4101 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4102 }
4103}
4104
4105/* like f_perform_lu(), but on SGs rather than BSSAP */
4106function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4107 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4108 var PDU_SGsAP lur;
4109 var PDU_SGsAP lua;
4110 var PDU_SGsAP mm_info;
4111 var octetstring mm_info_dtap;
4112
4113 /* tell GSUP dispatcher to send this IMSI to us */
4114 f_create_gsup_expect(hex2str(g_pars.imsi));
4115
4116 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4117 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4118 /* Old LAI, if MS sends it */
4119 /* TMSI status, if MS has no valid TMSI */
4120 /* IMEISV, if it supports "automatic device detection" */
4121 /* TAI, if available in MME */
4122 /* E-CGI, if available in MME */
4123 SGsAP.send(lur);
4124
4125 /* FIXME: is this really done over SGs? The Ue is already authenticated
4126 * via the MME ... */
4127 f_mm_auth_sgs();
4128
4129 /* Expect MSC to perform LU with HLR */
4130 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4131 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4132 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4133 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4134
4135 alt {
4136 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4137 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4138 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4139 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4140 }
4141 setverdict(pass);
4142 }
4143 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4144 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4145 }
4146 [] SGsAP.receive {
4147 setverdict(fail, "Received unexpected message on SGs");
4148 }
4149 }
4150
4151 /* Check MM information */
4152 if (mp_mm_info == true) {
4153 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4154 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4155 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4156 setverdict(fail, "Unexpected MM Information");
4157 }
4158 }
4159
4160 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4161}
4162
4163private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4164 f_init_handler(pars);
4165 f_sgs_perform_lu();
4166 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4167
4168 f_sgsap_bssmap_screening();
4169
4170 setverdict(pass);
4171}
4172testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004173 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004174 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004175 f_init(1, true);
4176 pars := f_init_pars(11811, true);
4177 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004178 vc_conn.done;
4179}
4180
4181/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4182private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4183 f_init_handler(pars);
4184 var PDU_SGsAP lur;
4185
4186 f_create_gsup_expect(hex2str(g_pars.imsi));
4187 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4188 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4189 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4190 SGsAP.send(lur);
4191
4192 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4193 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4194 alt {
4195 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4196 setverdict(pass);
4197 }
4198 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4199 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4200 mtc.stop;
4201 }
4202 [] SGsAP.receive {
4203 setverdict(fail, "Received unexpected message on SGs");
4204 }
4205 }
4206
4207 f_sgsap_bssmap_screening();
4208
4209 setverdict(pass);
4210}
4211testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004212 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004213 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004214 f_init(1, true);
4215 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004216
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004217 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004218 vc_conn.done;
4219}
4220
4221/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4222private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4223 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4224 var PDU_SGsAP lur;
4225
4226 f_init_handler(pars);
4227
4228 /* tell GSUP dispatcher to send this IMSI to us */
4229 f_create_gsup_expect(hex2str(g_pars.imsi));
4230
4231 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4232 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4233 /* Old LAI, if MS sends it */
4234 /* TMSI status, if MS has no valid TMSI */
4235 /* IMEISV, if it supports "automatic device detection" */
4236 /* TAI, if available in MME */
4237 /* E-CGI, if available in MME */
4238 SGsAP.send(lur);
4239
4240 /* FIXME: is this really done over SGs? The Ue is already authenticated
4241 * via the MME ... */
4242 f_mm_auth_sgs();
4243
4244 /* Expect MSC to perform LU with HLR */
4245 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4246 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4247 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4248 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4249
4250 alt {
4251 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4252 setverdict(pass);
4253 }
4254 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4255 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4256 }
4257 [] SGsAP.receive {
4258 setverdict(fail, "Received unexpected message on SGs");
4259 }
4260 }
4261
4262 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4263
4264 /* Wait until the VLR has abort the TMSI reallocation procedure */
4265 f_sleep(45.0);
4266
4267 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4268 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4269
4270 f_sgsap_bssmap_screening();
4271
4272 setverdict(pass);
4273}
4274testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004275 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004276 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004277 f_init(1, true);
4278 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004279
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004280 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004281 vc_conn.done;
4282}
4283
4284private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4285runs on BSC_ConnHdlr {
4286 f_init_handler(pars);
4287 f_sgs_perform_lu();
4288 f_sleep(3.0);
4289
4290 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4291 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4292 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4293 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4294
4295 f_sgsap_bssmap_screening();
4296
4297 setverdict(pass);
4298}
4299testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004300 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004301 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004302 f_init(1, true);
4303 pars := f_init_pars(11814, true);
4304 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004305 vc_conn.done;
4306}
4307
Philipp Maierfc19f172019-03-21 11:17:54 +01004308private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4309runs on BSC_ConnHdlr {
4310 f_init_handler(pars);
4311 f_sgs_perform_lu();
4312 f_sleep(3.0);
4313
4314 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4315 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4316 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4317 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4318
4319 f_sgsap_bssmap_screening();
4320
4321 setverdict(pass);
4322}
4323testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4324 var BSC_ConnHdlrPars pars;
4325 var BSC_ConnHdlr vc_conn;
4326 f_init(1, true);
4327 pars := f_init_pars(11814, true);
4328 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4329 vc_conn.done;
4330}
4331
Harald Welte4263c522018-12-06 11:56:27 +01004332private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4333runs on BSC_ConnHdlr {
4334 f_init_handler(pars);
4335 f_sgs_perform_lu();
4336 f_sleep(3.0);
4337
4338 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4339 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4340 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004341
4342 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4343 setverdict(fail, "subscriber not removed from VLR");
4344 }
Harald Welte4263c522018-12-06 11:56:27 +01004345
4346 f_sgsap_bssmap_screening();
4347
4348 setverdict(pass);
4349}
4350testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004351 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004352 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004353 f_init(1, true);
4354 pars := f_init_pars(11815, true);
4355 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004356 vc_conn.done;
4357}
4358
Philipp Maier5d812702019-03-21 10:51:26 +01004359private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4360runs on BSC_ConnHdlr {
4361 f_init_handler(pars);
4362 f_sgs_perform_lu();
4363 f_sleep(3.0);
4364
4365 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4366 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4367 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4368
4369 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4370 setverdict(fail, "subscriber not removed from VLR");
4371 }
4372
4373 f_sgsap_bssmap_screening();
4374
4375 setverdict(pass);
4376}
4377testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4378 var BSC_ConnHdlrPars pars;
4379 var BSC_ConnHdlr vc_conn;
4380 f_init(1, true);
4381 pars := f_init_pars(11815, true);
4382 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4383 vc_conn.done;
4384}
4385
Harald Welte4263c522018-12-06 11:56:27 +01004386/* Trigger a paging request via VTY and send a paging reject in response */
4387private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4388runs on BSC_ConnHdlr {
4389 f_init_handler(pars);
4390 f_sgs_perform_lu();
4391 f_sleep(1.0);
4392
4393 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4394 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4395 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4396 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4397
4398 /* Initiate paging via VTY */
4399 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4400 alt {
4401 [] SGsAP.receive(exp_resp) {
4402 setverdict(pass);
4403 }
4404 [] SGsAP.receive {
4405 setverdict(fail, "Received unexpected message on SGs");
4406 }
4407 }
4408
4409 /* Now reject the paging */
4410 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4411
4412 /* Wait for the states inside the MSC to settle and check the state
4413 * of the SGs Association */
4414 f_sleep(1.0);
4415 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4416
4417 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4418 * but we also need to cover tha case where the cause code indicates an
4419 * "IMSI detached for EPS services". In those cases the VLR is expected to
4420 * try paging on tha A/Iu interface. This will be another testcase similar to
4421 * this one, but extended with checks for the presence of the A/Iu paging
4422 * messages. */
4423
4424 f_sgsap_bssmap_screening();
4425
4426 setverdict(pass);
4427}
4428testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004429 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004430 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004431 f_init(1, true);
4432 pars := f_init_pars(11816, true);
4433 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004434 vc_conn.done;
4435}
4436
4437/* Trigger a paging request via VTY and send a paging reject that indicates
4438 * that the subscriber intentionally rejected the call. */
4439private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4440runs on BSC_ConnHdlr {
4441 f_init_handler(pars);
4442 f_sgs_perform_lu();
4443 f_sleep(1.0);
4444
4445 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4446 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4447 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4448 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4449
4450 /* Initiate paging via VTY */
4451 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4452 alt {
4453 [] SGsAP.receive(exp_resp) {
4454 setverdict(pass);
4455 }
4456 [] SGsAP.receive {
4457 setverdict(fail, "Received unexpected message on SGs");
4458 }
4459 }
4460
4461 /* Now reject the paging */
4462 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4463
4464 /* Wait for the states inside the MSC to settle and check the state
4465 * of the SGs Association */
4466 f_sleep(1.0);
4467 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4468
4469 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4470 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4471 * to check back how this works and how it can be tested */
4472
4473 f_sgsap_bssmap_screening();
4474
4475 setverdict(pass);
4476}
4477testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004478 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004479 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004480 f_init(1, true);
4481 pars := f_init_pars(11817, true);
4482 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004483 vc_conn.done;
4484}
4485
4486/* Trigger a paging request via VTY and send an UE unreacable messge in response */
4487private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
4488runs on BSC_ConnHdlr {
4489 f_init_handler(pars);
4490 f_sgs_perform_lu();
4491 f_sleep(1.0);
4492
4493 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4494 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4495 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4496 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4497
4498 /* Initiate paging via VTY */
4499 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4500 alt {
4501 [] SGsAP.receive(exp_resp) {
4502 setverdict(pass);
4503 }
4504 [] SGsAP.receive {
4505 setverdict(fail, "Received unexpected message on SGs");
4506 }
4507 }
4508
4509 /* Now pretend that the UE is unreachable */
4510 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
4511
4512 /* Wait for the states inside the MSC to settle and check the state
4513 * of the SGs Association. */
4514 f_sleep(1.0);
4515 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4516
4517 f_sgsap_bssmap_screening();
4518
4519 setverdict(pass);
4520}
4521testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004522 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004523 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004524 f_init(1, true);
4525 pars := f_init_pars(11818, true);
4526 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004527 vc_conn.done;
4528}
4529
4530/* Trigger a paging request via VTY but don't respond to it */
4531private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
4532runs on BSC_ConnHdlr {
4533 f_init_handler(pars);
4534 f_sgs_perform_lu();
4535 f_sleep(1.0);
4536
4537 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4538 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02004539 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01004540 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4541 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4542
4543 /* Initiate paging via VTY */
4544 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4545 alt {
4546 [] SGsAP.receive(exp_resp) {
4547 setverdict(pass);
4548 }
4549 [] SGsAP.receive {
4550 setverdict(fail, "Received unexpected message on SGs");
4551 }
4552 }
4553
Philipp Maier34218102019-09-24 09:15:49 +02004554 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
4555 * after some time */
4556 timer T := 10.0;
4557 T.start
4558 alt {
4559 [] SGsAP.receive(exp_serv_abrt)
4560 {
4561 setverdict(pass);
4562 }
4563 [] SGsAP.receive {
4564 setverdict(fail, "unexpected SGsAP message received");
4565 self.stop;
4566 }
4567 [] T.timeout {
4568 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
4569 self.stop;
4570 }
4571 }
4572
4573 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01004574 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4575
4576 f_sgsap_bssmap_screening();
4577
4578 setverdict(pass);
4579}
4580testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004581 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004582 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004583 f_init(1, true);
4584 pars := f_init_pars(11819, true);
4585 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004586 vc_conn.done;
4587}
4588
4589/* Trigger a paging request via VTY and slip in an LU */
4590private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4591runs on BSC_ConnHdlr {
4592 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4593 f_init_handler(pars);
4594
4595 /* First we prepar the situation, where the SGs association is in state
4596 * NULL and the confirmed by radio contact indicator is set to false
4597 * as well. This can be archived by performing an SGs LU and then
4598 * resetting the VLR */
4599 f_sgs_perform_lu();
4600 f_sgsap_reset_mme(mp_mme_name);
4601 f_sleep(1.0);
4602 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4603
4604 /* Perform a paging, expect the paging messages on the SGs interface */
4605 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4606 alt {
4607 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4608 setverdict(pass);
4609 }
4610 [] SGsAP.receive {
4611 setverdict(fail, "Received unexpected message on SGs");
4612 }
4613 }
4614
4615 /* Perform the LU as normal */
4616 f_sgs_perform_lu();
4617 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4618
4619 /* Expect a new paging request right after the LU */
4620 alt {
4621 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4622 setverdict(pass);
4623 }
4624 [] SGsAP.receive {
4625 setverdict(fail, "Received unexpected message on SGs");
4626 }
4627 }
4628
4629 /* Test is done now, lets round everything up by rejecting the paging
4630 * cleanly. */
4631 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4632 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4633
4634 f_sgsap_bssmap_screening();
4635
4636 setverdict(pass);
4637}
4638testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004639 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004640 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004641 f_init(1, true);
4642 pars := f_init_pars(11820, true);
4643 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004644 vc_conn.done;
4645}
4646
4647/* Send unexpected unit-data through the SGs interface */
4648private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4649 f_init_handler(pars);
4650 f_sleep(1.0);
4651
4652 /* This simulates what happens when a subscriber without SGs
4653 * association gets unitdata via the SGs interface. */
4654
4655 /* Make sure the subscriber exists and the SGs association
4656 * is in NULL state */
4657 f_perform_lu();
4658 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4659
4660 /* Send some random unit data, the MSC/VLR should send a release
4661 * immediately. */
4662 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4663 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
4664
4665 f_sgsap_bssmap_screening();
4666
4667 setverdict(pass);
4668}
4669testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004670 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004671 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004672 f_init(1, true);
4673 pars := f_init_pars(11821, true);
4674 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004675 vc_conn.done;
4676}
4677
4678/* Send unsolicited unit-data through the SGs interface */
4679private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4680 f_init_handler(pars);
4681 f_sleep(1.0);
4682
4683 /* This simulates what happens when the MME attempts to send unitdata
4684 * to a subscriber that is completely unknown to the VLR */
4685
4686 /* Send some random unit data, the MSC/VLR should send a release
4687 * immediately. */
4688 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4689 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
4690
4691 f_sgsap_bssmap_screening();
4692
4693 setverdict(pass);
4694}
4695testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004696 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004697 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004698 f_init(1, true);
4699 pars := f_init_pars(11822, true);
4700 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004701 vc_conn.done;
4702}
4703
4704private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
4705 /* FIXME: Match an actual payload (second questionmark), the type is
4706 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
4707 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
4708 setverdict(fail, "Unexpected SMS related PDU from MSC");
4709 mtc.stop;
4710 }
4711}
4712
4713/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
4714function f_mt_sms_sgs(inout SmsParameters spars)
4715runs on BSC_ConnHdlr {
4716 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4717 var template (value) RPDU_MS_SGSN rp_mo;
4718 var template (value) PDU_ML3_MS_NW l3_mo;
4719
4720 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4721 var template RPDU_SGSN_MS rp_mt;
4722 var template PDU_ML3_NW_MS l3_mt;
4723
4724 var PDU_ML3_NW_MS sgsap_l3_mt;
4725
4726 var default d := activate(as_other_sms_sgs());
4727
4728 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
4729 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
4730 rp_mt := tr_RP_DATA_MT(?, ?, omit, tp_mt);
4731 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
4732
4733 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
4734
4735 /* Extract relevant identifiers */
4736 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
4737 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
4738
4739 /* send CP-ACK for CP-DATA just received */
4740 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
4741
4742 SGsAP.send(l3_mo);
4743
4744 /* send RP-ACK for RP-DATA */
4745 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
4746 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
4747
4748 SGsAP.send(l3_mo);
4749
4750 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
4751 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
4752
4753 SGsAP.receive(l3_mt);
4754
4755 deactivate(d);
4756
4757 setverdict(pass);
4758}
4759
4760/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
4761function f_mo_sms_sgs(inout SmsParameters spars)
4762runs on BSC_ConnHdlr {
4763 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4764 var template (value) RPDU_MS_SGSN rp_mo;
4765 var template (value) PDU_ML3_MS_NW l3_mo;
4766
4767 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4768 var template RPDU_SGSN_MS rp_mt;
4769 var template PDU_ML3_NW_MS l3_mt;
4770
4771 var default d := activate(as_other_sms_sgs());
4772
4773 /* just in case this is routed to SMPP.. */
4774 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
4775
4776 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
4777 spars.tp.udl, spars.tp.ud);
4778 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, spars.rp.orig, spars.rp.dest, tp_mo);
4779 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
4780
4781 SGsAP.send(l3_mo);
4782
4783 /* receive CP-ACK for CP-DATA above */
4784 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
4785
4786 if (ispresent(spars.exp_rp_err)) {
4787 /* expect an RP-ERROR message from MSC with given cause */
4788 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
4789 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4790 SGsAP.receive(l3_mt);
4791 /* send CP-ACK for CP-DATA just received */
4792 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4793 SGsAP.send(l3_mo);
4794 } else {
4795 /* expect RP-ACK for RP-DATA */
4796 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
4797 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4798 SGsAP.receive(l3_mt);
4799 /* send CP-ACO for CP-DATA just received */
4800 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4801 SGsAP.send(l3_mo);
4802 }
4803
4804 deactivate(d);
4805
4806 setverdict(pass);
4807}
4808
4809private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
4810runs on BSC_ConnHdlr {
4811 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
4812}
4813
4814/* Send a MT SMS via SGs interface */
4815private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4816 f_init_handler(pars);
4817 f_sgs_perform_lu();
4818 f_sleep(1.0);
4819 var SmsParameters spars := valueof(t_SmsPars);
4820 spars.tp.ud := 'C8329BFD064D9B53'O;
4821
4822 /* Trigger SMS via VTY */
4823 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4824 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4825
4826 /* Expect a paging request and respond accordingly with a service request */
4827 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
4828 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
4829
4830 /* Connection is now live, receive the MT-SMS */
4831 f_mt_sms_sgs(spars);
4832
4833 /* Expect a concluding release from the MSC */
4834 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4835
4836 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4837 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4838
4839 f_sgsap_bssmap_screening();
4840
4841 setverdict(pass);
4842}
4843testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004844 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004845 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004846 f_init(1, true);
4847 pars := f_init_pars(11823, true);
4848 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004849 vc_conn.done;
4850}
4851
4852/* Send a MO SMS via SGs interface */
4853private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4854 f_init_handler(pars);
4855 f_sgs_perform_lu();
4856 f_sleep(1.0);
4857 var SmsParameters spars := valueof(t_SmsPars);
4858 spars.tp.ud := 'C8329BFD064D9B53'O;
4859
4860 /* Send the MO-SMS */
4861 f_mo_sms_sgs(spars);
4862
4863 /* Expect a concluding release from the MSC/VLR */
4864 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4865
4866 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4867 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4868
4869 setverdict(pass);
4870
4871 f_sgsap_bssmap_screening()
4872}
4873testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004874 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004875 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004876 f_init(1, true);
4877 pars := f_init_pars(11824, true);
4878 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004879 vc_conn.done;
4880}
4881
4882/* Trigger sending of an MT sms via VTY but never respond to anything */
4883private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4884 f_init_handler(pars, 170.0);
4885 f_sgs_perform_lu();
4886 f_sleep(1.0);
4887
4888 var SmsParameters spars := valueof(t_SmsPars);
4889 spars.tp.ud := 'C8329BFD064D9B53'O;
4890 var integer page_count := 0;
4891 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4892 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4893 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4894 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4895
4896 /* Trigger SMS via VTY */
4897 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4898
Neels Hofmeyr16237742019-03-06 15:34:01 +01004899 /* Expect the MSC/VLR to page exactly once */
4900 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01004901
4902 /* Wait some time to make sure the MSC is not delivering any further
4903 * paging messages or anything else that could be unexpected. */
4904 timer T := 20.0;
4905 T.start
4906 alt {
4907 [] SGsAP.receive(exp_pag_req)
4908 {
4909 setverdict(fail, "paging seems not to stop!");
4910 mtc.stop;
4911 }
4912 [] SGsAP.receive {
4913 setverdict(fail, "unexpected SGsAP message received");
4914 self.stop;
4915 }
4916 [] T.timeout {
4917 setverdict(pass);
4918 }
4919 }
4920
4921 /* Even on a failed paging the SGs Association should stay intact */
4922 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4923
Philipp Maier26bdb8c2019-09-24 09:21:12 +02004924 /* Make sure that the SMS we just inserted is cleared and the
4925 * subscriber is expired. This is necessary because otherwise the MSC
4926 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01004927
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01004928 f_vty_sms_clear(hex2str(g_pars.imsi));
4929
Harald Welte4263c522018-12-06 11:56:27 +01004930 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
4931
4932 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01004933
4934 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01004935}
4936testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004937 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004938 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004939 f_init(1, true);
4940 pars := f_init_pars(11825, true);
4941 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004942 vc_conn.done;
4943}
4944
4945/* Trigger sending of an MT sms via VTY but reject the paging immediately */
4946private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4947 f_init_handler(pars, 150.0);
4948 f_sgs_perform_lu();
4949 f_sleep(1.0);
4950
4951 var SmsParameters spars := valueof(t_SmsPars);
4952 spars.tp.ud := 'C8329BFD064D9B53'O;
4953 var integer page_count := 0;
4954 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4955 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4956 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4957 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4958
4959 /* Trigger SMS via VTY */
4960 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4961
4962 /* Expect a paging request and reject it immediately */
4963 SGsAP.receive(exp_pag_req);
4964 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4965
4966 /* The MSC/VLR should no longer try to page once the paging has been
4967 * rejected. Wait some time and check if there are no unexpected
4968 * messages on the SGs interface. */
4969 timer T := 20.0;
4970 T.start
4971 alt {
4972 [] SGsAP.receive(exp_pag_req)
4973 {
4974 setverdict(fail, "paging seems not to stop!");
4975 mtc.stop;
4976 }
4977 [] SGsAP.receive {
4978 setverdict(fail, "unexpected SGsAP message received");
4979 self.stop;
4980 }
4981 [] T.timeout {
4982 setverdict(pass);
4983 }
4984 }
4985
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01004986 f_vty_sms_clear(hex2str(g_pars.imsi));
4987
Harald Welte4263c522018-12-06 11:56:27 +01004988 /* A rejected paging with IMSI_unknown (see above) should always send
4989 * the SGs association to NULL. */
4990 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4991
4992 f_sgsap_bssmap_screening();
4993
Harald Welte4263c522018-12-06 11:56:27 +01004994 setverdict(pass);
4995}
4996testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004997 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004998 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004999 f_init(1, true);
5000 pars := f_init_pars(11826, true);
5001 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005002 vc_conn.done;
5003}
5004
5005/* Perform an MT CSDB call including LU */
5006private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5007 f_init_handler(pars);
5008
5009 /* Be sure that the BSSMAP reset is done before we begin. */
5010 f_sleep(2.0);
5011
5012 /* Testcase variation: See what happens when we do a regular BSSMAP
5013 * LU first (this should not hurt in any way!) */
5014 if (bssmap_lu) {
5015 f_perform_lu();
5016 }
5017
5018 f_sgs_perform_lu();
5019 f_sleep(1.0);
5020
5021 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5022 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
5023 cpars.bss_rtp_port := 1110;
5024 cpars.mgcp_connection_id_bss := '10004'H;
5025 cpars.mgcp_connection_id_mss := '10005'H;
5026
5027 /* Note: This is an optional parameter. When the call-agent (MSC) does
5028 * supply a full endpoint name this setting will be overwritten. */
5029 cpars.mgcp_ep := "rtpbridge/1@mgw";
5030
5031 /* Initiate a call via MNCC interface */
5032 f_mt_call_initate(cpars);
5033
5034 /* Expect a paging request and respond accordingly with a service request */
5035 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5036 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5037
5038 /* Complete the call, hold it for some time and then tear it down */
5039 f_mt_call_complete(cpars);
5040 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005041 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005042
5043 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5044 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5045
Harald Welte4263c522018-12-06 11:56:27 +01005046 /* Test for successful return by triggering a paging, when the paging
5047 * request is received via SGs, we can be sure that the MSC/VLR has
5048 * recognized that the UE is now back on 4G */
5049 f_sleep(1.0);
5050 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5051 alt {
5052 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5053 setverdict(pass);
5054 }
5055 [] SGsAP.receive {
5056 setverdict(fail, "Received unexpected message on SGs");
5057 }
5058 }
5059
5060 f_sgsap_bssmap_screening();
5061
5062 setverdict(pass);
5063}
5064
5065/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5066private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5067 f_mt_lu_and_csfb_call(id, pars, true);
5068}
5069testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005070 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005071 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005072 f_init(1, true);
5073 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005074
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005075 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005076 vc_conn.done;
5077}
5078
5079
5080/* Perform a SGSAP LU and then make a CSFB call */
5081private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5082 f_mt_lu_and_csfb_call(id, pars, false);
5083}
5084testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005085 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005086 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005087 f_init(1, true);
5088 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005089
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005090 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005091 vc_conn.done;
5092}
5093
Philipp Maier628c0052019-04-09 17:36:57 +02005094/* Simulate an HLR/VLR failure */
5095private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5096 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5097 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5098
5099 var PDU_SGsAP lur;
5100
5101 f_init_handler(pars);
5102
5103 /* Attempt location update (which is expected to fail) */
5104 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5105 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5106 SGsAP.send(lur);
5107
5108 /* Respond to SGsAP-RESET-INDICATION from VLR */
5109 alt {
5110 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5111 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5112 setverdict(pass);
5113 }
5114 [] SGsAP.receive {
5115 setverdict(fail, "Received unexpected message on SGs");
5116 }
5117 }
5118
5119 f_sleep(1.0);
5120 setverdict(pass);
5121}
5122testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5123 var BSC_ConnHdlrPars pars;
5124 var BSC_ConnHdlr vc_conn;
5125 f_init(1, true, false);
5126 pars := f_init_pars(11811, true, false);
5127 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5128 vc_conn.done;
5129}
5130
Harald Welte4263c522018-12-06 11:56:27 +01005131/* SGs TODO:
5132 * LU attempt for IMSI without NAM_PS in HLR
5133 * LU attempt with AUTH FAIL due to invalid RES/SRES
5134 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5135 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5136 * implicit IMSI detach from EPS
5137 * implicit IMSI detach from non-EPS
5138 * MM INFO
5139 *
5140 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005141
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005142private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5143 f_init_handler(pars);
5144 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
5145 cpars.bss_rtp_port := 1110;
5146 cpars.mgcp_connection_id_bss := '22222'H;
5147 cpars.mgcp_connection_id_mss := '33333'H;
5148 cpars.mgcp_ep := "rtpbridge/1@mgw";
5149 cpars.mo_call := true;
5150
5151 f_perform_lu();
5152 f_mo_call_establish(cpars);
5153
5154 f_sleep(1.0);
5155
5156 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5157 var BssmapCause cause := enum2int(cause_val);
5158
5159 var template BSSMAP_FIELD_CellIdentificationList cil;
5160 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5161
5162 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5163 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5164
5165 f_call_hangup(cpars, true);
5166}
5167testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5168 var BSC_ConnHdlr vc_conn;
5169 f_init();
5170
5171 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5172 vc_conn.done;
5173}
5174
5175private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5176 var MgcpCommand mgcp_cmd;
5177 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
5178 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_rtp_ip_mss, cpars.mgw_rtp_ip_mss,
5179 hex2str(cpars.mgcp_call_id), "42",
5180 cpars.mgw_rtp_port_mss,
5181 { int2str(cpars.rtp_payload_type) },
5182 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5183 cpars.rtp_sdp_format)),
5184 valueof(ts_SDP_ptime(20)) }));
5185 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgcp_connection_id_mss, sdp));
5186 repeat;
5187 }
5188}
5189
5190private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5191 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
5192 cpars.bss_rtp_port := 1110;
5193 cpars.mgcp_connection_id_bss := '22222'H;
5194 cpars.mgcp_connection_id_mss := '33333'H;
5195 cpars.mgcp_ep := "rtpbridge/1@mgw";
5196 cpars.mo_call := true;
5197
5198 f_init_handler(pars);
5199
5200 f_vty_transceive(MSCVTY, "configure terminal");
5201 f_vty_transceive(MSCVTY, "msc");
5202 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
5203 f_vty_transceive(MSCVTY, "neighbor a lac 5 ran-pc 0.24.2");
5204 f_vty_transceive(MSCVTY, "exit");
5205 f_vty_transceive(MSCVTY, "exit");
5206
5207 f_perform_lu();
5208 f_mo_call_establish(cpars);
5209
5210 f_sleep(1.0);
5211
5212 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5213
5214 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5215 var BssmapCause cause := enum2int(cause_val);
5216
5217 var template BSSMAP_FIELD_CellIdentificationList cil;
5218 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 5) } };
5219
5220 /* old BSS sends Handover Required */
5221 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5222
5223 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5224
5225 /* MSC forwards the RR Handover Command to old BSS */
5226 var PDU_BSSAP ho_command;
5227 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5228
5229 log("GOT HandoverCommand", ho_command);
5230
5231 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5232
5233 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5234 f_expect_clear();
5235
5236 log("FIRST inter-BSC Handover done");
5237
5238
5239 /* ------------------------ */
5240
5241 /* Ok, that went well, now the other BSC is handovering back here --
5242 * from now on this here is the new BSS. */
5243 f_create_bssmap_exp_handoverRequest(193);
5244
5245 var PDU_BSSAP ho_request;
5246 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5247
5248 /* new BSS composes a RR Handover Command */
5249 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5250 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5251 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5252 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5253 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5254
5255 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5256
5257 f_sleep(0.5);
5258
5259 /* Notify that the MS is now over here */
5260
5261 BSSAP.send(ts_BSSMAP_HandoverDetect);
5262 f_sleep(0.1);
5263 BSSAP.send(ts_BSSMAP_HandoverComplete);
5264
5265 f_sleep(3.0);
5266
5267 deactivate(ack_mdcx);
5268
5269 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5270
5271 /* blatant cheating */
5272 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5273 last_n_sd[0] := 3;
5274 f_bssmap_continue_after_n_sd(last_n_sd);
5275
5276 f_call_hangup(cpars, true);
5277 f_sleep(1.0);
5278 deactivate(ccrel);
5279
5280 setverdict(pass);
5281}
5282private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5283 f_init_handler(pars);
5284 f_create_bssmap_exp_handoverRequest(194);
5285
5286 var PDU_BSSAP ho_request;
5287 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5288
5289 /* new BSS composes a RR Handover Command */
5290 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5291 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5292 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5293 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5294 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5295
5296 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5297
5298 f_sleep(0.5);
5299
5300 /* Notify that the MS is now over here */
5301
5302 BSSAP.send(ts_BSSMAP_HandoverDetect);
5303 f_sleep(0.1);
5304 BSSAP.send(ts_BSSMAP_HandoverComplete);
5305
5306 f_sleep(3.0);
5307
5308 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5309 * ... handover back to the first BSC :P */
5310
5311 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5312 var BssmapCause cause := enum2int(cause_val);
5313
5314 var template BSSMAP_FIELD_CellIdentificationList cil;
5315 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('262'H, '42'H, 23) } };
5316
5317 /* old BSS sends Handover Required */
5318 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5319
5320 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5321
5322 /* MSC forwards the RR Handover Command to old BSS */
5323 var PDU_BSSAP ho_command;
5324 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5325
5326 log("GOT HandoverCommand", ho_command);
5327
5328 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5329
5330 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5331 f_expect_clear();
5332 setverdict(pass);
5333}
5334testcase TC_ho_inter_bsc() runs on MTC_CT {
5335 var BSC_ConnHdlr vc_conn0;
5336 var BSC_ConnHdlr vc_conn1;
5337 f_init(2);
5338
5339 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
5340 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
5341
5342 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0, 0);
5343 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1, 1);
5344 vc_conn0.done;
5345 vc_conn1.done;
5346}
5347
5348function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5349 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5350 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5351 log("MS_NW patched enc_l3: ", enc_l3);
5352}
5353
5354private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5355 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
5356 cpars.bss_rtp_port := 1110;
5357 cpars.mgcp_connection_id_bss := '22222'H;
5358 cpars.mgcp_connection_id_mss := '33333'H;
5359 cpars.mgcp_ep := "rtpbridge/1@mgw";
5360 cpars.mo_call := true;
5361 var hexstring ho_number := f_gen_msisdn(99999);
5362
5363 f_init_handler(pars);
5364
5365 f_create_mncc_expect(hex2str(ho_number));
5366
5367 f_vty_transceive(MSCVTY, "configure terminal");
5368 f_vty_transceive(MSCVTY, "msc");
5369 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
5370 f_vty_transceive(MSCVTY, "exit");
5371 f_vty_transceive(MSCVTY, "exit");
5372
5373 f_perform_lu();
5374 f_mo_call_establish(cpars);
5375
5376 f_sleep(1.0);
5377
5378 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5379
5380 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5381 var BssmapCause cause := enum2int(cause_val);
5382
5383 var template BSSMAP_FIELD_CellIdentificationList cil;
5384 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('017'H, '017'H, 1) } };
5385
5386 /* old BSS sends Handover Required */
5387 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5388
5389 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
5390 * This MSC tries to reach the other MSC via GSUP. */
5391
5392 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
5393 var GSUP_PDU prep_ho_req;
5394 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
5395 pars.imsi, destination_name := remote_msc_name)) -> value prep_ho_req;
5396
5397 var GSUP_IeValue source_name_ie;
5398 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
5399 var octetstring local_msc_name := source_name_ie.source_name;
5400
5401 /* Remote MSC has figured out its BSC and signals success */
5402 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5403 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5404 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5405 aoIPTransportLayer := omit,
5406 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5407 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
5408 pars.imsi,
5409 ho_number,
5410 remote_msc_name, local_msc_name,
5411 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
5412
5413 /* MSC forwards the RR Handover Command to old BSS */
5414 BSSAP.receive(tr_BSSMAP_HandoverCommand);
5415
5416 /* The MS shows up at remote new BSS */
5417
5418 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5419 pars.imsi, remote_msc_name, local_msc_name,
5420 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5421 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
5422 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5423 f_sleep(0.1);
5424
5425 /* Save the MS sequence counters for use on the other connection */
5426 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5427
5428 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
5429 pars.imsi, remote_msc_name, local_msc_name,
5430 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5431 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
5432
5433 /* The local BSS conn clears, all communication goes via remote MSC now */
5434 f_expect_clear();
5435
5436 /**********************************/
5437 /* Play through some signalling across the inter-MSC link.
5438 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
5439
5440 if (false) {
5441 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
5442 invoke_id := 5, /* Phone may not start from 0 or 1 */
5443 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5444 ussd_string := "*#100#"
5445 );
5446
5447 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
5448 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
5449 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5450 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
5451 )
5452
5453 /* Compose a new SS/REGISTER message with request */
5454 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
5455 tid := 1, /* We just need a single transaction */
5456 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
5457 facility := valueof(facility_req)
5458 );
5459 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
5460
5461 /* Compose SS/RELEASE_COMPLETE template with expected response */
5462 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
5463 tid := 1, /* Response should arrive within the same transaction */
5464 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
5465 facility := valueof(facility_rsp)
5466 );
5467
5468 /* Compose expected MSC -> HLR message */
5469 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
5470 imsi := g_pars.imsi,
5471 state := OSMO_GSUP_SESSION_STATE_BEGIN,
5472 ss := valueof(facility_req)
5473 );
5474
5475 /* To be used for sending response with correct session ID */
5476 var GSUP_PDU gsup_req_complete;
5477
5478 /* Request own number */
5479 /* From remote MSC instead of BSSAP directly */
5480 /* Patch the correct N_SD value into the message. */
5481 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
5482 var RAN_Emulation.ConnectionData cd;
5483 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
5484 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5485 pars.imsi, remote_msc_name, local_msc_name,
5486 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5487 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
5488 ))
5489 ));
5490
5491 /* Expect GSUP message containing the SS payload */
5492 gsup_req_complete := f_expect_gsup_msg(gsup_req);
5493
5494 /* Compose the response from HLR using received session ID */
5495 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
5496 imsi := g_pars.imsi,
5497 sid := gsup_req_complete.ies[1].val.session_id,
5498 state := OSMO_GSUP_SESSION_STATE_END,
5499 ss := valueof(facility_rsp)
5500 );
5501
5502 /* Finally, HLR terminates the session */
5503 GSUP.send(gsup_rsp);
5504
5505 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
5506 var GSUP_PDU gsup_ussd_rsp;
5507 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5508 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
5509
5510 var GSUP_IeValue an_apdu;
5511 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
5512 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5513 mtc.stop;
5514 }
5515 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
5516 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
5517 log("Expecting", ussd_rsp);
5518 log("Got", dtap_mt);
5519 if (not match(dtap_mt, ussd_rsp)) {
5520 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5521 mtc.stop;
5522 }
5523 }
5524 /**********************************/
5525
5526
5527 /* inter-MSC handover back to the first MSC */
5528 f_create_bssmap_exp_handoverRequest(193);
5529 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
5530
5531 /* old BSS sends Handover Required, via inter-MSC E link: like
5532 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5533 * but via GSUP */
5534 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
5535 pars.imsi, remote_msc_name, local_msc_name,
5536 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5537 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
5538 ))
5539 ));
5540
5541 /* MSC asks local BSS to prepare Handover to it */
5542 BSSAP.receive(tr_BSSMAP_HandoverRequest);
5543
5544 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
5545 f_bssmap_continue_after_n_sd(last_n_sd);
5546
5547 /* new BSS composes a RR Handover Command */
5548 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5549 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5550 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5551 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5552 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5553
5554 /* HandoverCommand goes out via remote MSC-I */
5555 var GSUP_PDU prep_subsq_ho_res;
5556 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
5557 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
5558
5559 /* MS shows up at the local BSS */
5560 BSSAP.send(ts_BSSMAP_HandoverDetect);
5561 f_sleep(0.1);
5562 BSSAP.send(ts_BSSMAP_HandoverComplete);
5563
5564 /* Handover Succeeded message */
5565 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5566 pars.imsi, destination_name := remote_msc_name));
5567
5568 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
5569 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
5570 pars.imsi, destination_name := remote_msc_name));
5571
5572 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
5573
5574 f_sleep(1.0);
5575 deactivate(ack_mdcx);
5576
5577 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
5578 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
5579 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
5580 MNCC.clear;
5581
5582 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5583 f_call_hangup(cpars, true);
5584 f_sleep(1.0);
5585 deactivate(ccrel);
5586
5587 setverdict(pass);
5588}
5589testcase TC_ho_inter_msc_out() runs on MTC_CT {
5590 var BSC_ConnHdlr vc_conn;
5591 f_init(1);
5592
5593 var BSC_ConnHdlrPars pars := f_init_pars(54);
5594
5595 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5596 vc_conn.done;
5597}
5598
Oliver Smith1d118ff2019-07-03 10:57:35 +02005599private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5600 pars.net.expect_auth := true;
5601 pars.net.expect_imei := true;
5602 f_init_handler(pars);
5603 f_perform_lu();
5604}
5605testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
5606 var BSC_ConnHdlr vc_conn;
5607 f_init();
5608 f_vty_config(MSCVTY, "network", "authentication required");
5609 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5610
5611 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
5612 vc_conn.done;
5613}
5614
5615private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5616 pars.net.expect_auth := true;
5617 pars.use_umts_aka := true;
5618 pars.net.expect_imei := true;
5619 f_init_handler(pars);
5620 f_perform_lu();
5621}
5622testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
5623 var BSC_ConnHdlr vc_conn;
5624 f_init();
5625 f_vty_config(MSCVTY, "network", "authentication required");
5626 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5627
5628 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
5629 vc_conn.done;
5630}
5631
5632private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5633 pars.net.expect_imei := true;
5634 f_init_handler(pars);
5635 f_perform_lu();
5636}
5637testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
5638 var BSC_ConnHdlr vc_conn;
5639 f_init();
5640 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5641
5642 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
5643 vc_conn.done;
5644}
5645
5646private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5647 pars.net.expect_tmsi := false;
5648 pars.net.expect_imei := true;
5649 f_init_handler(pars);
5650 f_perform_lu();
5651}
5652testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
5653 var BSC_ConnHdlr vc_conn;
5654 f_init();
5655 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
5656 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5657
5658 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
5659 vc_conn.done;
5660}
5661
5662private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5663 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005664
5665 pars.net.expect_auth := true;
5666 pars.net.expect_imei := true;
5667 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
5668 f_init_handler(pars);
5669
5670 /* Cannot use f_perform_lu() as we expect a reject */
5671 l3_lu := f_build_lu_imsi(g_pars.imsi)
5672 f_create_gsup_expect(hex2str(g_pars.imsi));
5673 f_bssap_compl_l3(l3_lu);
5674 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5675
5676 f_mm_common();
5677 f_msc_lu_hlr();
5678 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005679 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005680 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005681}
5682testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
5683 var BSC_ConnHdlr vc_conn;
5684 f_init();
5685 f_vty_config(MSCVTY, "network", "authentication required");
5686 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5687
5688 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
5689 vc_conn.done;
5690}
5691
5692private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5693 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005694
5695 pars.net.expect_auth := true;
5696 pars.net.expect_imei := true;
5697 pars.net.check_imei_error := true;
5698 f_init_handler(pars);
5699
5700 /* Cannot use f_perform_lu() as we expect a reject */
5701 l3_lu := f_build_lu_imsi(g_pars.imsi)
5702 f_create_gsup_expect(hex2str(g_pars.imsi));
5703 f_bssap_compl_l3(l3_lu);
5704 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5705
5706 f_mm_common();
5707 f_msc_lu_hlr();
5708 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005709 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005710 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005711}
5712testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
5713 var BSC_ConnHdlr vc_conn;
5714 f_init();
5715 f_vty_config(MSCVTY, "network", "authentication required");
5716 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5717
5718 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
5719 vc_conn.done;
5720}
5721
5722private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5723 pars.net.expect_auth := true;
5724 pars.net.expect_imei_early := true;
5725 f_init_handler(pars);
5726 f_perform_lu();
5727}
5728testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
5729 var BSC_ConnHdlr vc_conn;
5730 f_init();
5731 f_vty_config(MSCVTY, "network", "authentication required");
5732 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5733
5734 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
5735 vc_conn.done;
5736}
5737
5738private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5739 pars.net.expect_auth := true;
5740 pars.use_umts_aka := true;
5741 pars.net.expect_imei_early := true;
5742 f_init_handler(pars);
5743 f_perform_lu();
5744}
5745testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
5746 var BSC_ConnHdlr vc_conn;
5747 f_init();
5748 f_vty_config(MSCVTY, "network", "authentication required");
5749 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5750
5751 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
5752 vc_conn.done;
5753}
5754
5755private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5756 pars.net.expect_imei_early := true;
5757 f_init_handler(pars);
5758 f_perform_lu();
5759}
5760testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
5761 var BSC_ConnHdlr vc_conn;
5762 f_init();
5763 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5764
5765 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
5766 vc_conn.done;
5767}
5768
5769private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5770 pars.net.expect_tmsi := false;
5771 pars.net.expect_imei_early := true;
5772 f_init_handler(pars);
5773 f_perform_lu();
5774}
5775testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
5776 var BSC_ConnHdlr vc_conn;
5777 f_init();
5778 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
5779 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5780
5781 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
5782 vc_conn.done;
5783}
5784
5785private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5786 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005787
5788 pars.net.expect_auth := true;
5789 pars.net.expect_imei_early := true;
5790 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
5791 f_init_handler(pars);
5792
5793 /* Cannot use f_perform_lu() as we expect a reject */
5794 l3_lu := f_build_lu_imsi(g_pars.imsi)
5795 f_create_gsup_expect(hex2str(g_pars.imsi));
5796 f_bssap_compl_l3(l3_lu);
5797 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5798
5799 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005800 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005801 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005802}
5803testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
5804 var BSC_ConnHdlr vc_conn;
5805 f_init();
5806 f_vty_config(MSCVTY, "network", "authentication required");
5807 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5808
5809 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
5810 vc_conn.done;
5811}
5812
5813private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5814 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005815
5816 pars.net.expect_auth := true;
5817 pars.net.expect_imei_early := true;
5818 pars.net.check_imei_error := true;
5819 f_init_handler(pars);
5820
5821 /* Cannot use f_perform_lu() as we expect a reject */
5822 l3_lu := f_build_lu_imsi(g_pars.imsi)
5823 f_create_gsup_expect(hex2str(g_pars.imsi));
5824 f_bssap_compl_l3(l3_lu);
5825 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5826
5827 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005828 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005829 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005830}
5831testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
5832 var BSC_ConnHdlr vc_conn;
5833 f_init();
5834 f_vty_config(MSCVTY, "network", "authentication required");
5835 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5836
5837 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
5838 vc_conn.done;
5839}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005840
Harald Weltef6dd64d2017-11-19 12:09:51 +01005841control {
Philipp Maier328d1662018-03-07 10:40:27 +01005842 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01005843 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01005844 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01005845 execute( TC_lu_imsi_reject() );
5846 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01005847 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02005848 execute( TC_lu_imsi_auth3g_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01005849 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01005850 execute( TC_lu_and_mo_call() );
Harald Welte071ed732018-01-23 19:53:52 +01005851 execute( TC_lu_auth_sai_timeout() );
5852 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01005853 execute( TC_lu_clear_request() );
5854 execute( TC_lu_disconnect() );
5855 execute( TC_lu_by_imei() );
5856 execute( TC_lu_by_tmsi_noauth_unknown() );
5857 execute( TC_imsi_detach_by_imsi() );
5858 execute( TC_imsi_detach_by_tmsi() );
5859 execute( TC_imsi_detach_by_imei() );
5860 execute( TC_emerg_call_imei_reject() );
5861 execute( TC_emerg_call_imsi() );
5862 execute( TC_cm_serv_req_vgcs_reject() );
5863 execute( TC_cm_serv_req_vbs_reject() );
5864 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01005865 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01005866 execute( TC_lu_auth_2G_fail() );
5867 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
5868 execute( TC_cl3_no_payload() );
5869 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01005870 execute( TC_establish_and_nothing() );
5871 execute( TC_mo_setup_and_nothing() );
5872 execute( TC_mo_crcx_ran_timeout() );
5873 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01005874 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01005875 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01005876 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01005877 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01005878 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
5879 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
5880 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01005881 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01005882 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
5883 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01005884 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01005885 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02005886 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01005887
5888 execute( TC_lu_and_mt_call() );
5889
Harald Weltef45efeb2018-04-09 18:19:24 +02005890 execute( TC_lu_and_mo_sms() );
5891 execute( TC_lu_and_mt_sms() );
Philipp Maier3983e702018-11-22 19:01:33 +01005892 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02005893 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02005894 execute( TC_smpp_mo_sms() );
5895 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02005896
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07005897 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07005898 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07005899 execute( TC_gsup_mt_sms_ack() );
5900 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07005901 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07005902 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07005903 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07005904
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07005905 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07005906 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07005907 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07005908 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07005909 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07005910 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07005911
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07005912 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07005913 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07005914 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07005915 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07005916 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07005917
Stefan Sperling89eb1f32018-12-17 15:06:20 +01005918 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01005919 execute( TC_cipher_complete_1_without_cipher() );
5920 execute( TC_cipher_complete_3_without_cipher() );
5921 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02005922 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01005923
Harald Welte4263c522018-12-06 11:56:27 +01005924 execute( TC_sgsap_reset() );
5925 execute( TC_sgsap_lu() );
5926 execute( TC_sgsap_lu_imsi_reject() );
5927 execute( TC_sgsap_lu_and_nothing() );
5928 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01005929 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01005930 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01005931 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01005932 execute( TC_sgsap_paging_rej() );
5933 execute( TC_sgsap_paging_subscr_rej() );
5934 execute( TC_sgsap_paging_ue_unr() );
5935 execute( TC_sgsap_paging_and_nothing() );
5936 execute( TC_sgsap_paging_and_lu() );
5937 execute( TC_sgsap_mt_sms() );
5938 execute( TC_sgsap_mo_sms() );
5939 execute( TC_sgsap_mt_sms_and_nothing() );
5940 execute( TC_sgsap_mt_sms_and_reject() );
5941 execute( TC_sgsap_unexp_ud() );
5942 execute( TC_sgsap_unsol_ud() );
5943 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
5944 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02005945 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01005946
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005947 execute( TC_ho_inter_bsc_unknown_cell() );
5948 execute( TC_ho_inter_bsc() );
5949
5950 execute( TC_ho_inter_msc_out() );
5951
Oliver Smith1d118ff2019-07-03 10:57:35 +02005952 execute( TC_lu_imsi_auth_tmsi_check_imei() );
5953 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
5954 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
5955 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
5956 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
5957 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
5958 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
5959 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
5960 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
5961 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
5962 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
5963 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
5964
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01005965 /* Run this last: at the time of writing this test crashes the MSC */
5966 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02005967 execute( TC_mo_cc_bssmap_clear() );
Pau Espin Pedrol690d6592019-05-31 17:56:32 +02005968 if (mp_enable_osmux_test) {
5969 execute( TC_lu_and_mt_call_osmux() );
5970 }
Harald Weltef6dd64d2017-11-19 12:09:51 +01005971}
5972
5973
5974}