blob: e1e50881a65c72f7a2471cf30c94e91d8ae13cca [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Weltee13cfb22019-04-23 16:52:02 +02003friend module MSC_Tests_Iu;
4
Harald Weltef6dd64d2017-11-19 12:09:51 +01005import from General_Types all;
6import from Osmocom_Types all;
7
8import from M3UA_Types all;
9import from M3UA_Emulation all;
10
11import from MTP3asp_Types all;
12import from MTP3asp_PortType all;
13
14import from SCCPasp_Types all;
15import from SCCP_Types all;
16import from SCCP_Emulation all;
17
18import from SCTPasp_Types all;
19import from SCTPasp_PortType all;
20
Harald Weltea49e36e2018-01-21 19:29:33 +010021import from Osmocom_CTRL_Functions all;
22import from Osmocom_CTRL_Types all;
23import from Osmocom_CTRL_Adapter all;
24
Harald Welte3ca1c902018-01-24 18:51:27 +010025import from TELNETasp_PortType all;
26import from Osmocom_VTY_Functions all;
27
Harald Weltea49e36e2018-01-21 19:29:33 +010028import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010029import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010030
Harald Welte4aa970c2018-01-26 10:38:09 +010031import from MGCP_Emulation all;
32import from MGCP_Types all;
33import from MGCP_Templates all;
34import from SDP_Types all;
35
Harald Weltea49e36e2018-01-21 19:29:33 +010036import from GSUP_Emulation all;
37import from GSUP_Types all;
38import from IPA_Emulation all;
39
Harald Weltef6dd64d2017-11-19 12:09:51 +010040import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020041import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010042import from BSSAP_CodecPort all;
43import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020044import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010045import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020046import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010047
Harald Welte4263c522018-12-06 11:56:27 +010048import from SGsAP_Templates all;
49import from SGsAP_Types all;
50import from SGsAP_Emulation all;
51
Harald Weltea49e36e2018-01-21 19:29:33 +010052import from MobileL3_Types all;
53import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070054import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010055import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010056import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010057
Harald Weltef640a012018-04-14 17:49:21 +020058import from SMPP_Types all;
59import from SMPP_Templates all;
60import from SMPP_Emulation all;
61
Stefan Sperlingc307e682018-06-14 15:15:46 +020062import from SCCP_Templates all;
63
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070064import from SS_Types all;
65import from SS_Templates all;
66import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010067import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070068
Philipp Maier948747b2019-04-02 15:22:33 +020069import from TCCConversion_Functions all;
70
Harald Welte9b751a62019-04-14 17:39:29 +020071const integer NUM_BSC := 3;
Harald Welte6811d102019-04-14 22:23:14 +020072type record of RAN_Configuration RAN_Configurations;
Harald Weltef6dd64d2017-11-19 12:09:51 +010073
Harald Welte4263c522018-12-06 11:56:27 +010074/* Needed for SGsAP SMS */
75import from MobileL3_SMS_Types all;
76
Harald Weltea4ca4462018-02-09 00:17:14 +010077type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010078 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010079
Harald Welte6811d102019-04-14 22:23:14 +020080 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010081
Harald Weltea49e36e2018-01-21 19:29:33 +010082 /* no 'adapter_CT' for MNCC or GSUP */
83 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010084 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010085 var GSUP_Emulation_CT vc_GSUP;
86 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020087 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +010088 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +010089
90 /* only to get events from IPA underneath GSUP */
91 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +010092 /* VTY to MSC */
93 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +010094
95 /* A port to directly send BSSAP messages. This port is used for
96 * tests that require low level access to sen arbitrary BSSAP
97 * messages. Run f_init_bssap_direct() to connect and initialize */
98 port BSSAP_CODEC_PT BSSAP_DIRECT;
99
100 /* When BSSAP messages are directly sent, then the connection
101 * handler is not active, which means that also no guard timer is
102 * set up. The following timer will serve as a replacement */
103 timer Tguard_direct := 60.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100104}
105
106modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100107 /* remote parameters of IUT */
108 charstring mp_msc_ip := "127.0.0.1";
109 integer mp_msc_ctrl_port := 4255;
110 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100111
Harald Weltea49e36e2018-01-21 19:29:33 +0100112 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100113 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100114 charstring mp_hlr_ip := "127.0.0.1";
115 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100116 charstring mp_mgw_ip := "127.0.0.1";
117 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100118
Harald Weltea49e36e2018-01-21 19:29:33 +0100119 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100120
Harald Weltef640a012018-04-14 17:49:21 +0200121 integer mp_msc_smpp_port := 2775;
122 charstring mp_smpp_system_id := "msc_tester";
123 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100124 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
125 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200126
Harald Welte6811d102019-04-14 22:23:14 +0200127 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200128 {
129 sccp_service_type := "mtp3_itu",
130 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
131 own_pc := 185,
132 own_ssn := 254,
133 peer_pc := 187,
134 peer_ssn := 254,
135 sio := '83'O,
136 rctx := 0
137 },
138 {
139 sccp_service_type := "mtp3_itu",
140 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
141 own_pc := 186,
142 own_ssn := 254,
143 peer_pc := 187,
144 peer_ssn := 254,
145 sio := '83'O,
146 rctx := 1
147 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100148 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100149}
150
Philipp Maier328d1662018-03-07 10:40:27 +0100151/* altstep for the global guard timer (only used when BSSAP_DIRECT
152 * is used for communication */
153private altstep as_Tguard_direct() runs on MTC_CT {
154 [] Tguard_direct.timeout {
155 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200156 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100157 }
158}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100159
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100160private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
161 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
162 if (respond) {
163 var BIT1 tid_remote := '1'B;
164 if (cpars.mo_call) {
165 tid_remote := '0'B;
166 }
167 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
168 }
169 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100170}
171
Harald Weltef640a012018-04-14 17:49:21 +0200172function f_init_smpp(charstring id) runs on MTC_CT {
173 id := id & "-SMPP";
174 var EsmePars pars := {
175 mode := MODE_TRANSCEIVER,
176 bind := {
177 system_id := mp_smpp_system_id,
178 password := mp_smpp_password,
179 system_type := "MSC_Tests",
180 interface_version := hex2int('34'H),
181 addr_ton := unknown,
182 addr_npi := unknown,
183 address_range := ""
184 },
185 esme_role := true
186 }
187
188 vc_SMPP := SMPP_Emulation_CT.create(id);
189 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
190 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", -1));
191}
192
193
Harald Weltea49e36e2018-01-21 19:29:33 +0100194function f_init_mncc(charstring id) runs on MTC_CT {
195 id := id & "-MNCC";
196 var MnccOps ops := {
197 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
198 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
199 }
200
201 vc_MNCC := MNCC_Emulation_CT.create(id);
202 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
203 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100204}
205
Harald Welte4aa970c2018-01-26 10:38:09 +0100206function f_init_mgcp(charstring id) runs on MTC_CT {
207 id := id & "-MGCP";
208 var MGCPOps ops := {
209 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
210 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
211 }
212 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100213 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100214 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100215 mgw_ip := mp_mgw_ip,
216 mgw_udp_port := mp_mgw_port
Harald Welte4aa970c2018-01-26 10:38:09 +0100217 }
218
219 vc_MGCP := MGCP_Emulation_CT.create(id);
220 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
221 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
222}
223
Philipp Maierc09a1312019-04-09 16:05:26 +0200224function ForwardUnitdataCallback(PDU_SGsAP msg)
225runs on SGsAP_Emulation_CT return template PDU_SGsAP {
226 SGsAP_CLIENT.send(msg);
227 return omit;
228}
229
Harald Welte4263c522018-12-06 11:56:27 +0100230function f_init_sgsap(charstring id) runs on MTC_CT {
231 id := id & "-SGsAP";
232 var SGsAPOps ops := {
233 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200234 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100235 }
236 var SGsAP_conn_parameters pars := {
237 remote_ip := mp_msc_ip,
238 remote_sctp_port := 29118,
239 local_ip := "",
240 local_sctp_port := -1
241 }
242
243 vc_SGsAP := SGsAP_Emulation_CT.create(id);
244 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
245 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
246}
247
248
Harald Weltea49e36e2018-01-21 19:29:33 +0100249function f_init_gsup(charstring id) runs on MTC_CT {
250 id := id & "-GSUP";
251 var GsupOps ops := {
252 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
253 }
254
255 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
256 vc_GSUP := GSUP_Emulation_CT.create(id);
257
258 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
259 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
260 /* we use this hack to get events like ASP_IPA_EVENT_UP */
261 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
262
263 vc_GSUP.start(GSUP_Emulation.main(ops, id));
264 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
265
266 /* wait for incoming connection to GSUP port before proceeding */
267 timer T := 10.0;
268 T.start;
269 alt {
270 [] GSUP_IPA_EVENT.receive(t_ASP_IPA_EVT_UD(ASP_IPA_EVENT_UP)) { }
271 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100272 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200273 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100274 }
275 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100276}
277
Philipp Maierc09a1312019-04-09 16:05:26 +0200278function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100279
280 if (g_initialized == true) {
281 return;
282 }
283 g_initialized := true;
284
Philipp Maier75932982018-03-27 14:52:35 +0200285 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200286 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200287 }
288
289 for (var integer i := 0; i < num_bsc; i := i + 1) {
290 if (isbound(mp_bssap_cfg[i])) {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200291 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), BSC_RanOps);
292 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200293 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200294 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200295 }
296 }
297
Harald Weltea49e36e2018-01-21 19:29:33 +0100298 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
299 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100300 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200301
302 if (gsup == true) {
303 f_init_gsup("MSC_Test");
304 }
Harald Weltef640a012018-04-14 17:49:21 +0200305 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100306
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100307 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100308 f_init_sgsap("MSC_Test");
309 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100310
311 map(self:MSCVTY, system:MSCVTY);
312 f_vty_set_prompts(MSCVTY);
313 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100314
315 /* set some defaults */
316 f_vty_config(MSCVTY, "network", "authentication optional");
317 f_vty_config(MSCVTY, "msc", "assign-tmsi");
318 f_vty_config(MSCVTY, "network", "encryption a5 0");
Harald Weltef6dd64d2017-11-19 12:09:51 +0100319}
320
Philipp Maier328d1662018-03-07 10:40:27 +0100321/* Initialize for a direct connection to BSSAP. This function is an alternative
322 * to f_init() when the high level functions of the BSC_ConnectionHandler are
323 * not needed. */
324function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200325 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200326 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100327
328 /* Start guard timer and activate it as default */
329 Tguard_direct.start
330 activate(as_Tguard_direct());
331}
332
Harald Weltef6dd64d2017-11-19 12:09:51 +0100333template PDU_BSSAP ts_BSSAP_BSSMAP := {
334 discriminator := '0'B,
335 spare := '0000000'B,
336 dlci := omit,
337 lengthIndicator := 0, /* overwritten by codec */
338 pdu := ?
339}
340
341template PDU_BSSAP tr_BSSAP_BSSMAP := {
342 discriminator := '0'B,
343 spare := '0000000'B,
344 dlci := omit,
345 lengthIndicator := ?,
346 pdu := {
347 bssmap := ?
348 }
349}
350
351
352type integer BssmapCause;
353
354template (value) BSSMAP_IE_Cause ts_BSSMAP_IE_Cause(BssmapCause val) := {
355 elementIdentifier := '04'O,
356 lengthIndicator := 0,
357 causeValue := int2bit(val, 7),
358 extensionCauseValue := '0'B,
359 spare1 := omit
360}
361
362template (value) PDU_BSSAP ts_BSSMAP_Reset(BssmapCause cause) modifies ts_BSSAP_BSSMAP := {
363 pdu := {
364 bssmap := {
365 reset := {
366 messageType := '30'O,
367 cause := ts_BSSMAP_IE_Cause(cause),
368 a_InterfaceSelectorForReset := omit
369 }
370 }
371 }
372}
373
374template (value) PDU_BSSAP ts_BSSMAP_ResetAck modifies ts_BSSAP_BSSMAP := {
375 pdu := {
376 bssmap := {
377 resetAck := {
378 messageType := '31'O,
379 a_InterfaceSelectorForReset := omit
380 }
381 }
382 }
383}
384
385template PDU_BSSAP tr_BSSMAP_ResetAck modifies tr_BSSAP_BSSMAP := {
386 pdu := {
387 bssmap := {
388 resetAck := {
389 messageType := '31'O,
390 a_InterfaceSelectorForReset := *
391 }
392 }
393 }
394}
395
396template BSSMAP_IE_CellIdentifier ts_BSSMAP_IE_CellID := {
397 elementIdentifier := '05'O,
398 lengthIndicator := 0,
399 cellIdentifierDiscriminator := '0000'B,
400 spare1_4 := '0000'B,
401 cellIdentification := ?
402}
403
404type uint16_t BssmapLAC;
405type uint16_t BssmapCI;
406
407/*
408template BSSMAP_IE_CellIdentifier ts_CellId_CGI(mcc, mnc, lac, ci)
409modifies ts_BSSMAP_IE_CellID := {
410 cellIdentification := {
411 cI_LAC_CGI := {
412 mnc_mcc := FIXME,
413 lac := int2oct(lac, 2),
414 ci := int2oct(ci, 2)
415 }
416 }
417}
418*/
419
420template BSSMAP_IE_CellIdentifier ts_CellID_LAC_CI(BssmapLAC lac, BssmapCI ci)
421modifies ts_BSSMAP_IE_CellID := {
422 cellIdentification := {
423 cI_LAC_CI := {
424 lac := int2oct(lac, 2),
425 ci := int2oct(ci, 2)
426 }
427 }
428}
429
430template BSSMAP_IE_CellIdentifier ts_CellId_CI(BssmapCI ci)
431modifies ts_BSSMAP_IE_CellID := {
432 cellIdentification := {
433 cI_CI := int2oct(ci, 2)
434 }
435}
436
437template BSSMAP_IE_CellIdentifier ts_CellId_none
438modifies ts_BSSMAP_IE_CellID := {
439 cellIdentification := {
440 cI_noCell := ''O
441 }
442}
443
444
445template BSSMAP_IE_Layer3Information ts_BSSMAP_IE_L3Info(octetstring l3info) := {
446 elementIdentifier := '17'O,
447 lengthIndicator := 0,
448 layer3info := l3info
449}
450
451template PDU_BSSAP ts_BSSMAP_ComplL3(BSSMAP_IE_CellIdentifier cell_id, octetstring l3_info)
452modifies ts_BSSAP_BSSMAP := {
453 pdu := {
454 bssmap := {
455 completeLayer3Information := {
456 messageType := '57'O,
457 cellIdentifier := cell_id,
458 layer3Information := ts_BSSMAP_IE_L3Info(l3_info),
459 chosenChannel := omit,
460 lSAIdentifier := omit,
461 aPDU := omit,
462 codecList := omit,
463 redirectAttemptFlag := omit,
464 sendSequenceNumber := omit,
465 iMSI := omit
466 }
467 }
468 }
469}
470
Harald Weltea49e36e2018-01-21 19:29:33 +0100471type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100472
Harald Weltea49e36e2018-01-21 19:29:33 +0100473/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200474function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
475 boolean ran_is_geran := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200476runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100477 var BSC_ConnHdlrNetworkPars net_pars := {
478 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
479 expect_tmsi := true,
480 expect_auth := false,
481 expect_ciph := false
482 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100483 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200484 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
485 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100486 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100487 imei := f_gen_imei(imsi_suffix),
488 imsi := f_gen_imsi(imsi_suffix),
489 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100490 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100491 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100492 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100493 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100494 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100495 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100496 send_early_cm := true,
497 ipa_ctrl_ip := mp_msc_ip,
498 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100499 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100500 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200501 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200502 gsup_enable := gsup,
Harald Weltec1f937a2019-04-21 21:19:23 +0200503 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200504 use_umts_aka := false,
505 ran_is_geran := ran_is_geran
Harald Weltea49e36e2018-01-21 19:29:33 +0100506 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200507 if (not ran_is_geran) {
508 pars.use_umts_aka := true;
509 pars.net.expect_auth := true;
510 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100511 return pars;
512}
513
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200514function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars, integer bssap_idx := 0) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100515 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200516 var charstring id := testcasename() & int2str(bssap_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100517
518 vc_conn := BSC_ConnHdlr.create(id);
519 /* BSSMAP part / A interface */
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200520 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:CLIENT);
521 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100522 /* MNCC part */
523 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
524 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100525 /* MGCP part */
526 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
527 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100528 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200529 if (pars.gsup_enable == true) {
530 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
531 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
532 }
Harald Weltef640a012018-04-14 17:49:21 +0200533 /* SMPP part */
534 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
535 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100536 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100537 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100538 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
539 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
540 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100541
Harald Weltea10db902018-01-27 12:44:49 +0100542 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
543 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100544 vc_conn.start(derefers(fn)(id, pars));
545 return vc_conn;
546}
547
Harald Welte9b751a62019-04-14 17:39:29 +0200548function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true)
549runs on MTC_CT return BSC_ConnHdlr {
550 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100551}
552
Harald Weltea49e36e2018-01-21 19:29:33 +0100553private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100554 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100555 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100556}
Harald Weltea49e36e2018-01-21 19:29:33 +0100557testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
558 var BSC_ConnHdlr vc_conn;
559 f_init();
560
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100561 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100562 vc_conn.done;
563}
564
565private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100566 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100567 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100568 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100569}
Harald Weltea49e36e2018-01-21 19:29:33 +0100570testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
571 var BSC_ConnHdlr vc_conn;
572 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100573 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100574
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100575 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100576 vc_conn.done;
577}
578
579/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200580friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100581 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100582 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
583
584 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200585 f_cl3_or_initial_ue(l3_lu);
Harald Welteb7817992019-05-09 13:15:39 +0200586 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100587 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
588 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
589 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100590 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
591 f_expect_clear();
592 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100593 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
594 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200595 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100596 }
597 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100598}
599testcase TC_lu_imsi_reject() runs on MTC_CT {
600 var BSC_ConnHdlr vc_conn;
601 f_init();
602
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100603 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3);
Harald Weltea49e36e2018-01-21 19:29:33 +0100604 vc_conn.done;
605}
606
Harald Weltee13cfb22019-04-23 16:52:02 +0200607
608
Harald Weltea49e36e2018-01-21 19:29:33 +0100609/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200610friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100611 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100612 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
613
614 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200615 f_cl3_or_initial_ue(l3_lu);
Harald Welteb7817992019-05-09 13:15:39 +0200616 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100617 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
618 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
619 alt {
620 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100621 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
622 f_expect_clear();
623 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100624 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
625 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200626 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100627 }
628 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100629}
630testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
631 var BSC_ConnHdlr vc_conn;
632 f_init();
633
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100634 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4);
Harald Weltea49e36e2018-01-21 19:29:33 +0100635 vc_conn.done;
636}
637
Harald Weltee13cfb22019-04-23 16:52:02 +0200638
Harald Welte7b1b2812018-01-22 21:23:06 +0100639private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100640 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100641 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100642 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100643}
644testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
645 var BSC_ConnHdlr vc_conn;
646 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100647 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100648
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100649 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100650 vc_conn.done;
651}
652
Harald Weltee13cfb22019-04-23 16:52:02 +0200653
654friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200655 pars.net.expect_auth := true;
656 pars.use_umts_aka := true;
657 f_init_handler(pars);
658 f_perform_lu();
659}
660testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
661 var BSC_ConnHdlr vc_conn;
662 f_init();
663 f_vty_config(MSCVTY, "network", "authentication required");
664
665 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
666 vc_conn.done;
667}
Harald Weltea49e36e2018-01-21 19:29:33 +0100668
Harald Weltee13cfb22019-04-23 16:52:02 +0200669
Harald Weltea49e36e2018-01-21 19:29:33 +0100670/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200671friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100672runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100673 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100674
675 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100676 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100677 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100678
679 f_create_gsup_expect(hex2str(g_pars.imsi));
680
681 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200682 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200683 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100684
685 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100686 T.start;
687 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100688 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
689 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200690 [] BSSAP.receive {
691 setverdict(fail, "Received unexpected BSSAP");
692 mtc.stop;
693 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100694 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
695 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200696 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100697 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200698 [] T.timeout {
699 setverdict(fail, "Timeout waiting for CM SERV REQ");
700 mtc.stop;
701 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100702 }
703
Harald Welte1ddc7162018-01-27 14:25:46 +0100704 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100705}
Harald Weltea49e36e2018-01-21 19:29:33 +0100706testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
707 var BSC_ConnHdlr vc_conn;
708 f_init();
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100709 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6);
Harald Weltea49e36e2018-01-21 19:29:33 +0100710 vc_conn.done;
711}
712
Harald Weltee13cfb22019-04-23 16:52:02 +0200713
714friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100715 f_init_handler(pars);
Harald Welteb71901a2018-01-26 19:16:05 +0100716 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
717 cpars.bss_rtp_port := 1110;
718 cpars.mgcp_connection_id_bss := '22222'H;
719 cpars.mgcp_connection_id_mss := '33333'H;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100720 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte2bb825f2018-01-22 11:31:18 +0100721
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100722 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100723 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100724}
725testcase TC_lu_and_mo_call() runs on MTC_CT {
726 var BSC_ConnHdlr vc_conn;
727 f_init();
728
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100729 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100730 vc_conn.done;
731}
732
Harald Weltee13cfb22019-04-23 16:52:02 +0200733
Harald Welte071ed732018-01-23 19:53:52 +0100734/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200735friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100736 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100737
738 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
739 var PDU_DTAP_MT dtap_mt;
740
741 /* tell GSUP dispatcher to send this IMSI to us */
742 f_create_gsup_expect(hex2str(g_pars.imsi));
743
744 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200745 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100746
747 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200748 if (pars.ran_is_geran) {
749 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
750 }
Harald Welte071ed732018-01-23 19:53:52 +0100751
752 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
753 /* The HLR would normally return an auth vector here, but we fail to do so. */
754
755 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100756 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100757}
758testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
759 var BSC_ConnHdlr vc_conn;
760 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100761 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100762
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100763 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8);
Harald Welte071ed732018-01-23 19:53:52 +0100764 vc_conn.done;
765}
766
Harald Weltee13cfb22019-04-23 16:52:02 +0200767
Harald Welte071ed732018-01-23 19:53:52 +0100768/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200769friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100770 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100771
772 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
773 var PDU_DTAP_MT dtap_mt;
774
775 /* tell GSUP dispatcher to send this IMSI to us */
776 f_create_gsup_expect(hex2str(g_pars.imsi));
777
778 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200779 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100780
781 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200782 if (pars.ran_is_geran) {
783 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
784 }
Harald Welte071ed732018-01-23 19:53:52 +0100785
786 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
787 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
788
789 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100790 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100791}
792testcase TC_lu_auth_sai_err() runs on MTC_CT {
793 var BSC_ConnHdlr vc_conn;
794 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100795 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100796
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100797 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9);
Harald Welte2bb825f2018-01-22 11:31:18 +0100798 vc_conn.done;
799}
Harald Weltea49e36e2018-01-21 19:29:33 +0100800
Harald Weltee13cfb22019-04-23 16:52:02 +0200801
Harald Weltebc881782018-01-23 20:09:15 +0100802/* Test LU but BSC will send a clear request in the middle */
803private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100804 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100805
806 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
807 var PDU_DTAP_MT dtap_mt;
808
809 /* tell GSUP dispatcher to send this IMSI to us */
810 f_create_gsup_expect(hex2str(g_pars.imsi));
811
812 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200813 f_cl3_or_initial_ue(l3_lu);
Harald Weltebc881782018-01-23 20:09:15 +0100814
815 /* Send Early Classmark, just for the fun of it */
816 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
817
818 f_sleep(1.0);
819 /* send clear request in the middle of the LU */
820 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200821 alt {
822 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
823 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
824 }
Harald Weltebc881782018-01-23 20:09:15 +0100825 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100826 alt {
827 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200828 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
829 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200830 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200831 repeat;
832 }
Harald Welte6811d102019-04-14 22:23:14 +0200833 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100834 }
Harald Weltebc881782018-01-23 20:09:15 +0100835 setverdict(pass);
836}
837testcase TC_lu_clear_request() runs on MTC_CT {
838 var BSC_ConnHdlr vc_conn;
839 f_init();
840
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100841 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100842 vc_conn.done;
843}
844
Harald Welte66af9e62018-01-24 17:28:21 +0100845/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200846friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100847 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100848
849 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
850 var PDU_DTAP_MT dtap_mt;
851
852 /* tell GSUP dispatcher to send this IMSI to us */
853 f_create_gsup_expect(hex2str(g_pars.imsi));
854
855 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200856 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +0100857
858 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200859 if (pars.ran_is_geran) {
860 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
861 }
Harald Welte66af9e62018-01-24 17:28:21 +0100862
863 f_sleep(1.0);
864 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +0200865 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +0100866 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +0100867 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +0100868}
869testcase TC_lu_disconnect() runs on MTC_CT {
870 var BSC_ConnHdlr vc_conn;
871 f_init();
872
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100873 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100874 vc_conn.done;
875}
876
Harald Welteba7b6d92018-01-23 21:32:34 +0100877/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +0200878friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100879 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100880
Harald Welte256571e2018-01-24 18:47:19 +0100881 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100882 var PDU_DTAP_MT dtap_mt;
883
884 /* tell GSUP dispatcher to send this IMSI to us */
885 f_create_gsup_expect(hex2str(g_pars.imsi));
886
887 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200888 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100889
890 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200891 if (pars.ran_is_geran) {
892 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
893 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100894 /* wait for LU reject, ignore any ID REQ */
895 alt {
896 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
897 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
898 }
899 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100900 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100901}
902testcase TC_lu_by_imei() runs on MTC_CT {
903 var BSC_ConnHdlr vc_conn;
904 f_init();
905
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100906 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12);
Harald Welteba7b6d92018-01-23 21:32:34 +0100907 vc_conn.done;
908}
909
Harald Weltee13cfb22019-04-23 16:52:02 +0200910
Harald Welteba7b6d92018-01-23 21:32:34 +0100911/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
912private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200913 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
914 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100915 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100916
917 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
918 var PDU_DTAP_MT dtap_mt;
919
920 /* tell GSUP dispatcher to send this IMSI to us */
921 f_create_gsup_expect(hex2str(g_pars.imsi));
922
923 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200924 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100925
926 /* Send Early Classmark, just for the fun of it */
927 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
928
929 /* Wait for + respond to ID REQ (IMSI) */
930 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req('001'B)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200931 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100932 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
933
934 /* Expect MSC to do UpdateLocation to HLR; respond to it */
935 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
936 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
937 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
938 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
939
940 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100941 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
942 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
943 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100944 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
945 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200946 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +0100947 }
948 }
949
Philipp Maier9b690e42018-12-21 11:50:03 +0100950 /* Wait for MM-Information (if enabled) */
951 f_expect_mm_info();
952
Harald Welteba7b6d92018-01-23 21:32:34 +0100953 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100954 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100955}
956testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
957 var BSC_ConnHdlr vc_conn;
958 f_init();
959
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100960 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100961 vc_conn.done;
962}
963
964
Harald Welte45164da2018-01-24 12:51:27 +0100965/* Test IMSI DETACH (MI=IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200966friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100967 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100968
969 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
970
971 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200972 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100973
974 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200975 if (pars.ran_is_geran) {
976 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
977 }
Harald Welte45164da2018-01-24 12:51:27 +0100978
979 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100980 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100981}
982testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
983 var BSC_ConnHdlr vc_conn;
984 f_init();
985
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100986 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14);
Harald Welte45164da2018-01-24 12:51:27 +0100987 vc_conn.done;
988}
989
Harald Weltee13cfb22019-04-23 16:52:02 +0200990
Harald Welte45164da2018-01-24 12:51:27 +0100991/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200992friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100993 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100994
995 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
996
997 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200998 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100999
1000 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001001 if (pars.ran_is_geran) {
1002 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1003 }
Harald Welte45164da2018-01-24 12:51:27 +01001004
1005 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001006 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001007}
1008testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1009 var BSC_ConnHdlr vc_conn;
1010 f_init();
1011
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001012 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15);
Harald Welte45164da2018-01-24 12:51:27 +01001013 vc_conn.done;
1014}
1015
Harald Weltee13cfb22019-04-23 16:52:02 +02001016
Harald Welte45164da2018-01-24 12:51:27 +01001017/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001018friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001019 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001020
Harald Welte256571e2018-01-24 18:47:19 +01001021 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001022
1023 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001024 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001025
1026 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001027 if (pars.ran_is_geran) {
1028 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1029 }
Harald Welte45164da2018-01-24 12:51:27 +01001030
1031 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001032 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001033}
1034testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1035 var BSC_ConnHdlr vc_conn;
1036 f_init();
1037
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001038 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16);
Harald Welte45164da2018-01-24 12:51:27 +01001039 vc_conn.done;
1040}
1041
1042
1043/* helper function for an emergency call. caller passes in mobile identity to use */
1044private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001045 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1046 cpars.emergency := true;
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001047 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte45164da2018-01-24 12:51:27 +01001048
Harald Welte0bef21e2018-02-10 09:48:23 +01001049 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001050}
1051
1052/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001053friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001054 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001055
Harald Welte256571e2018-01-24 18:47:19 +01001056 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001057 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001058 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001059 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001060 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001061}
1062testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1063 var BSC_ConnHdlr vc_conn;
1064 f_init();
1065
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001066 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17);
Harald Welte45164da2018-01-24 12:51:27 +01001067 vc_conn.done;
1068}
1069
Harald Weltee13cfb22019-04-23 16:52:02 +02001070
Harald Welted5b91402018-01-24 18:48:16 +01001071/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001072friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001073 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001074 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001075 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001076 /* Then issue emergency call identified by IMSI */
1077 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1078}
1079testcase TC_emerg_call_imsi() runs on MTC_CT {
1080 var BSC_ConnHdlr vc_conn;
1081 f_init();
1082
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001083 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001084 vc_conn.done;
1085}
1086
Harald Weltee13cfb22019-04-23 16:52:02 +02001087
Harald Welte45164da2018-01-24 12:51:27 +01001088/* CM Service Request for VGCS -> reject */
1089private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001090 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001091
1092 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001093 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001094
1095 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001096 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001097 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001098 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001099 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001100}
1101testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1102 var BSC_ConnHdlr vc_conn;
1103 f_init();
1104
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001105 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001106 vc_conn.done;
1107}
1108
1109/* CM Service Request for VBS -> reject */
1110private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001111 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001112
1113 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001114 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001115
1116 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001117 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001118 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001119 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001120 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001121}
1122testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1123 var BSC_ConnHdlr vc_conn;
1124 f_init();
1125
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001126 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001127 vc_conn.done;
1128}
1129
1130/* CM Service Request for LCS -> reject */
1131private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001132 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001133
1134 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001135 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001136
1137 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001138 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001139 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001140 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001141 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001142}
1143testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1144 var BSC_ConnHdlr vc_conn;
1145 f_init();
1146
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001147 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001148 vc_conn.done;
1149}
1150
Harald Welte0195ab12018-01-24 21:50:20 +01001151/* CM Re-Establishment Request */
1152private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001153 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001154
1155 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001156 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001157
1158 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1159 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001160 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001161 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001162 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001163}
1164testcase TC_cm_reest_req_reject() runs on MTC_CT {
1165 var BSC_ConnHdlr vc_conn;
1166 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001167
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001168 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001169 vc_conn.done;
1170}
1171
Harald Weltec638f4d2018-01-24 22:00:36 +01001172/* Test LU (with authentication enabled), with wrong response from MS */
1173private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001174 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001175
1176 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1177
1178 /* tell GSUP dispatcher to send this IMSI to us */
1179 f_create_gsup_expect(hex2str(g_pars.imsi));
1180
1181 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001182 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001183
1184 /* Send Early Classmark, just for the fun of it */
1185 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1186
1187 var AuthVector vec := f_gen_auth_vec_2g();
1188 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1189 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1190 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1191
1192 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1193 /* Send back wrong auth response */
1194 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1195
1196 /* Expect GSUP AUTH FAIL REP to HLR */
1197 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1198
1199 /* Expect LU REJECT with Cause == Illegal MS */
1200 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001201 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001202}
1203testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1204 var BSC_ConnHdlr vc_conn;
1205 f_init();
1206 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001207
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001208 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23);
Harald Weltec638f4d2018-01-24 22:00:36 +01001209 vc_conn.done;
1210}
1211
Harald Weltede371492018-01-27 23:44:41 +01001212/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001213private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001214 pars.net.expect_auth := true;
1215 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001216 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001217 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001218}
1219testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1220 var BSC_ConnHdlr vc_conn;
1221 f_init();
1222 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001223 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1224
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001225 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001226 vc_conn.done;
1227}
1228
Harald Welte1af6ea82018-01-25 18:33:15 +01001229/* Test Complete L3 without payload */
1230private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001231 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001232
1233 /* Send Complete L3 Info with empty L3 frame */
1234 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1235 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1236
Harald Weltef466eb42018-01-27 14:26:54 +01001237 timer T := 5.0;
1238 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001239 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001240 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001241 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001242 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001243 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001244 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001245 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001246 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001247 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001248 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001249 }
1250 setverdict(pass);
1251}
1252testcase TC_cl3_no_payload() runs on MTC_CT {
1253 var BSC_ConnHdlr vc_conn;
1254 f_init();
1255
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001256 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001257 vc_conn.done;
1258}
1259
1260/* Test Complete L3 with random payload */
1261private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001262 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001263
Daniel Willmannaa14a382018-07-26 08:29:45 +02001264 /* length is limited by PDU_BSSAP length field which includes some
1265 * other fields beside l3info payload. So payl can only be 240 bytes
1266 * Since rnd() returns values < 1 multiply with 241
1267 */
1268 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001269 var octetstring payl := f_rnd_octstring(len);
1270
1271 /* Send Complete L3 Info with empty L3 frame */
1272 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1273 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1274
Harald Weltef466eb42018-01-27 14:26:54 +01001275 timer T := 5.0;
1276 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001277 alt {
1278 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001279 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001280 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001281 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001282 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001283 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001284 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001285 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001286 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001287 }
1288 setverdict(pass);
1289}
1290testcase TC_cl3_rnd_payload() runs on MTC_CT {
1291 var BSC_ConnHdlr vc_conn;
1292 f_init();
1293
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001294 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001295 vc_conn.done;
1296}
1297
Harald Welte116e4332018-01-26 22:17:48 +01001298/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001299friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001300 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001301
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001302 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001303
Harald Welteb9e86fa2018-04-09 18:18:31 +02001304 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001305 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001306}
1307testcase TC_establish_and_nothing() runs on MTC_CT {
1308 var BSC_ConnHdlr vc_conn;
1309 f_init();
1310
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001311 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001312 vc_conn.done;
1313}
1314
Harald Weltee13cfb22019-04-23 16:52:02 +02001315
Harald Welte12510c52018-01-26 22:26:24 +01001316/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001317friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001318 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001319
Harald Welte12510c52018-01-26 22:26:24 +01001320 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1321
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001322 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001323
Harald Welteb9e86fa2018-04-09 18:18:31 +02001324 f_establish_fully();
Harald Welte12510c52018-01-26 22:26:24 +01001325 f_create_mncc_expect(hex2str(cpars.called_party));
1326 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1327
1328 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1329
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001330 var default ccrel := activate(as_optional_cc_rel(cpars));
1331
Philipp Maier109e6aa2018-10-17 10:53:32 +02001332 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001333
1334 deactivate(ccrel);
1335
1336 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001337}
1338testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1339 var BSC_ConnHdlr vc_conn;
1340 f_init();
1341
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001342 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001343 vc_conn.done;
1344}
1345
Harald Weltee13cfb22019-04-23 16:52:02 +02001346
Harald Welte3ab88002018-01-26 22:37:25 +01001347/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001348friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001349 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001350 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1351 var MNCC_PDU mncc;
1352 var MgcpCommand mgcp_cmd;
1353
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001354 f_perform_lu();
Harald Welte3ab88002018-01-26 22:37:25 +01001355
Harald Welteb9e86fa2018-04-09 18:18:31 +02001356 f_establish_fully();
Harald Welte3ab88002018-01-26 22:37:25 +01001357 f_create_mncc_expect(hex2str(cpars.called_party));
1358 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1359
1360 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1361 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1362 cpars.mncc_callref := mncc.u.signal.callref;
1363 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1364 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1365
1366 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Harald Welte1852a842018-01-26 22:53:36 +01001367 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1368 cpars.mgcp_ep := mgcp_cmd.line.ep;
Harald Welte3ab88002018-01-26 22:37:25 +01001369 /* never respond to this */
1370
Philipp Maier8e58f592018-03-14 11:10:56 +01001371 /* When the connection with the MGW fails, the MSC will first request
1372 * a release via call control. We will answer this request normally. */
1373 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1374 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1375
Harald Welte1ddc7162018-01-27 14:25:46 +01001376 f_expect_clear(30.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001377}
1378testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1379 var BSC_ConnHdlr vc_conn;
1380 f_init();
1381
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001382 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001383 vc_conn.done;
1384}
1385
Harald Weltee13cfb22019-04-23 16:52:02 +02001386
Harald Welte0cc82d92018-01-26 22:52:34 +01001387/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001388friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001389 f_init_handler(pars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001390 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1391 var MNCC_PDU mncc;
1392 var MgcpCommand mgcp_cmd;
1393
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001394 f_perform_lu();
Harald Welte0cc82d92018-01-26 22:52:34 +01001395
Harald Welteb9e86fa2018-04-09 18:18:31 +02001396 f_establish_fully();
Harald Welte0cc82d92018-01-26 22:52:34 +01001397 f_create_mncc_expect(hex2str(cpars.called_party));
1398 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1399
1400 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1401 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1402 cpars.mncc_callref := mncc.u.signal.callref;
1403 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1404 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1405
1406 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001407
1408 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1409 * set an endpoint name that fits the pattern. If not, just use the
1410 * endpoint name from the request */
1411 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1412 cpars.mgcp_ep := "rtpbridge/1@mgw";
1413 } else {
1414 cpars.mgcp_ep := mgcp_cmd.line.ep;
1415 }
1416
Harald Welte0cc82d92018-01-26 22:52:34 +01001417 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001418
Harald Welte0cc82d92018-01-26 22:52:34 +01001419 /* Respond to CRCX with error */
1420 var MgcpResponse mgcp_rsp := {
1421 line := {
1422 code := "542",
1423 trans_id := mgcp_cmd.line.trans_id,
1424 string := "FORCED_FAIL"
1425 },
Harald Welte0cc82d92018-01-26 22:52:34 +01001426 sdp := omit
1427 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001428 var MgcpParameter mgcp_rsp_param := {
1429 code := "Z",
1430 val := cpars.mgcp_ep
1431 };
1432 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte0cc82d92018-01-26 22:52:34 +01001433 MGCP.send(mgcp_rsp);
1434
1435 timer T := 30.0;
1436 T.start;
1437 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001438 [] T.timeout {
1439 setverdict(fail, "Timeout waiting for channel release");
1440 mtc.stop;
1441 }
Daniel Willmann5868e622018-02-15 17:42:59 +01001442 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
1443 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1444 repeat;
1445 }
Harald Welte0cc82d92018-01-26 22:52:34 +01001446 [] MNCC.receive { repeat; }
1447 [] GSUP.receive { repeat; }
Philipp Maierc6e06f72018-04-11 18:12:23 +02001448 /* Note: As we did not respond properly to the CRCX from the MSC we
1449 * expect the MSC to omit any further MGCP operation (At least in the
1450 * the current implementation, there is no recovery mechanism implemented
1451 * and a DLCX can not be performed as the MSC does not know a specific
1452 * endpoint yet. */
Daniel Willmannafce8662018-07-06 23:11:32 +02001453 [] MGCP.receive {
1454 setverdict(fail, "Unexpected MGCP message");
1455 mtc.stop;
1456 }
Harald Welte5946b332018-03-18 23:32:21 +01001457 [] as_clear_cmd_compl_disc();
Harald Welte0cc82d92018-01-26 22:52:34 +01001458 }
1459}
1460testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1461 var BSC_ConnHdlr vc_conn;
1462 f_init();
1463
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001464 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001465 vc_conn.done;
1466}
1467
Harald Welte3ab88002018-01-26 22:37:25 +01001468
Harald Welte812f7a42018-01-27 00:49:18 +01001469/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1470private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1471 var MNCC_PDU mncc;
1472 var MgcpCommand mgcp_cmd;
1473 var OCT4 tmsi;
1474
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001475 f_perform_lu();
Harald Welte812f7a42018-01-27 00:49:18 +01001476 if (isvalue(g_pars.tmsi)) {
1477 tmsi := g_pars.tmsi;
1478 } else {
1479 tmsi := 'FFFFFFFF'O;
1480 }
Harald Welte6811d102019-04-14 22:23:14 +02001481 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001482
1483 /* Allocate call reference and send SETUP via MNCC to MSC */
1484 cpars.mncc_callref := f_rnd_int(2147483648);
1485 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1486 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1487
1488 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001489 f_expect_paging();
1490
Harald Welte812f7a42018-01-27 00:49:18 +01001491 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001492 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001493
1494 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1495
1496 /* MSC->MS: SETUP */
1497 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1498}
1499
1500/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001501friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001502 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001503 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1504 var MNCC_PDU mncc;
1505 var MgcpCommand mgcp_cmd;
1506
1507 f_mt_call_start(cpars);
1508
1509 /* MS->MSC: CALL CONFIRMED */
1510 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1511
1512 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1513
1514 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1515 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001516
1517 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1518 * set an endpoint name that fits the pattern. If not, just use the
1519 * endpoint name from the request */
1520 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1521 cpars.mgcp_ep := "rtpbridge/1@mgw";
1522 } else {
1523 cpars.mgcp_ep := mgcp_cmd.line.ep;
1524 }
1525
Harald Welte812f7a42018-01-27 00:49:18 +01001526 /* Respond to CRCX with error */
1527 var MgcpResponse mgcp_rsp := {
1528 line := {
1529 code := "542",
1530 trans_id := mgcp_cmd.line.trans_id,
1531 string := "FORCED_FAIL"
1532 },
Harald Welte812f7a42018-01-27 00:49:18 +01001533 sdp := omit
1534 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001535 var MgcpParameter mgcp_rsp_param := {
1536 code := "Z",
1537 val := cpars.mgcp_ep
1538 };
1539 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001540 MGCP.send(mgcp_rsp);
1541
1542 timer T := 30.0;
1543 T.start;
1544 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001545 [] T.timeout {
1546 setverdict(fail, "Timeout waiting for channel release");
1547 mtc.stop;
1548 }
Harald Welte812f7a42018-01-27 00:49:18 +01001549 [] MNCC.receive { repeat; }
1550 [] GSUP.receive { repeat; }
1551 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1552 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1553 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1554 repeat;
1555 }
1556 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001557 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001558 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001559 }
1560}
1561testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1562 var BSC_ConnHdlr vc_conn;
1563 f_init();
1564
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001565 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001566 vc_conn.done;
1567}
1568
1569
Harald Weltee13cfb22019-04-23 16:52:02 +02001570
Harald Welte812f7a42018-01-27 00:49:18 +01001571/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001572friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001573 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001574 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1575 var MNCC_PDU mncc;
1576 var MgcpCommand mgcp_cmd;
1577
1578 f_mt_call_start(cpars);
1579
1580 /* MS->MSC: CALL CONFIRMED */
1581 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1582 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1583
1584 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1585 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1586 cpars.mgcp_ep := mgcp_cmd.line.ep;
1587 /* FIXME: Respond to CRCX */
1588
1589 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1590 timer T := 190.0;
1591 T.start;
1592 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001593 [] T.timeout {
1594 setverdict(fail, "Timeout waiting for T310");
1595 mtc.stop;
1596 }
Harald Welte812f7a42018-01-27 00:49:18 +01001597 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1598 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1599 }
1600 }
1601 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1602 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1603 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1604 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1605
1606 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001607 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1608 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1609 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1610 repeat;
1611 }
Harald Welte5946b332018-03-18 23:32:21 +01001612 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001613 }
1614}
1615testcase TC_mt_t310() runs on MTC_CT {
1616 var BSC_ConnHdlr vc_conn;
1617 f_init();
1618
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001619 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001620 vc_conn.done;
1621}
1622
Harald Weltee13cfb22019-04-23 16:52:02 +02001623
Harald Welte167458a2018-01-27 15:58:16 +01001624/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001625friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001626 f_init_handler(pars);
1627 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1628 cpars.bss_rtp_port := 1110;
1629 cpars.mgcp_connection_id_bss := '22222'H;
1630 cpars.mgcp_connection_id_mss := '33333'H;
Daniel Willmann9b0235b2018-07-24 12:13:34 +02001631 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte167458a2018-01-27 15:58:16 +01001632
1633 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001634 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001635
1636 /* First MO call should succeed */
1637 f_mo_call(cpars);
1638
1639 /* Cancel the subscriber in the VLR */
1640 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1641 alt {
1642 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1643 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1644 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001645 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001646 }
1647 }
1648
1649 /* Follow-up transactions should fail */
1650 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1651 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001652 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001653 alt {
1654 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1655 [] BSSAP.receive {
1656 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001657 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001658 }
1659 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001660
1661 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001662 setverdict(pass);
1663}
1664testcase TC_gsup_cancel() runs on MTC_CT {
1665 var BSC_ConnHdlr vc_conn;
1666 f_init();
1667
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001668 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33);
Harald Welte167458a2018-01-27 15:58:16 +01001669 vc_conn.done;
1670}
1671
Harald Weltee13cfb22019-04-23 16:52:02 +02001672
Harald Welte9de84792018-01-28 01:06:35 +01001673/* A5/1 only permitted on network side, and MS capable to do it */
1674private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1675 pars.net.expect_auth := true;
1676 pars.net.expect_ciph := true;
1677 pars.net.kc_support := '02'O; /* A5/1 only */
1678 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001679 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001680}
1681testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1682 var BSC_ConnHdlr vc_conn;
1683 f_init();
1684 f_vty_config(MSCVTY, "network", "authentication required");
1685 f_vty_config(MSCVTY, "network", "encryption a5 1");
1686
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001687 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001688 vc_conn.done;
1689}
1690
1691/* A5/3 only permitted on network side, and MS capable to do it */
1692private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1693 pars.net.expect_auth := true;
1694 pars.net.expect_ciph := true;
1695 pars.net.kc_support := '08'O; /* A5/3 only */
1696 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001697 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001698}
1699testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1700 var BSC_ConnHdlr vc_conn;
1701 f_init();
1702 f_vty_config(MSCVTY, "network", "authentication required");
1703 f_vty_config(MSCVTY, "network", "encryption a5 3");
1704
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001705 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001706 vc_conn.done;
1707}
1708
1709/* A5/3 only permitted on network side, and MS with only A5/1 support */
1710private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1711 pars.net.expect_auth := true;
1712 pars.net.expect_ciph := true;
1713 pars.net.kc_support := '08'O; /* A5/3 only */
1714 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1715 f_init_handler(pars, 15.0);
1716
1717 /* cannot use f_perform_lu() as we expect a reject */
1718 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1719 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001720 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001721 if (pars.send_early_cm) {
1722 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1723 } else {
1724 pars.cm1.esind := '0'B;
1725 }
Harald Welte9de84792018-01-28 01:06:35 +01001726 f_mm_auth();
1727 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001728 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1729 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1730 repeat;
1731 }
Harald Welte5946b332018-03-18 23:32:21 +01001732 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1733 f_expect_clear();
1734 }
Harald Welte9de84792018-01-28 01:06:35 +01001735 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1736 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001737 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001738 }
1739 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001740 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001741 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001742 }
1743 }
1744 setverdict(pass);
1745}
1746testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1747 var BSC_ConnHdlr vc_conn;
1748 f_init();
1749 f_vty_config(MSCVTY, "network", "authentication required");
1750 f_vty_config(MSCVTY, "network", "encryption a5 3");
1751
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001752 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360);
1753 vc_conn.done;
1754}
1755testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1756 var BSC_ConnHdlrPars pars;
1757 var BSC_ConnHdlr vc_conn;
1758 f_init();
1759 f_vty_config(MSCVTY, "network", "authentication required");
1760 f_vty_config(MSCVTY, "network", "encryption a5 3");
1761
1762 pars := f_init_pars(361);
1763 pars.send_early_cm := false;
1764 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001765 vc_conn.done;
1766}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001767testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1768 var BSC_ConnHdlr vc_conn;
1769 f_init();
1770 f_vty_config(MSCVTY, "network", "authentication required");
1771 f_vty_config(MSCVTY, "network", "encryption a5 3");
1772
1773 /* Make sure the MSC category is on DEBUG level to trigger the log
1774 * message that is reported in OS#2947 to trigger the segfault */
1775 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1776
1777 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362);
1778 vc_conn.done;
1779}
Harald Welte9de84792018-01-28 01:06:35 +01001780
1781/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1782private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1783 pars.net.expect_auth := true;
1784 pars.net.expect_ciph := true;
1785 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1786 pars.cm1.a5_1 := '1'B;
1787 pars.cm2.a5_1 := '1'B;
1788 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1789 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1790 f_init_handler(pars, 15.0);
1791
1792 /* cannot use f_perform_lu() as we expect a reject */
1793 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1794 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001795 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001796 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1797 f_mm_auth();
1798 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001799 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1800 f_expect_clear();
1801 }
Harald Welte9de84792018-01-28 01:06:35 +01001802 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1803 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001804 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001805 }
1806 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001807 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001808 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001809 }
1810 }
1811 setverdict(pass);
1812}
1813testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1814 var BSC_ConnHdlr vc_conn;
1815 f_init();
1816 f_vty_config(MSCVTY, "network", "authentication required");
1817 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1818
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001819 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37);
Harald Welte9de84792018-01-28 01:06:35 +01001820 vc_conn.done;
1821}
1822
1823/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1824private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1825 pars.net.expect_auth := true;
1826 pars.net.expect_ciph := true;
1827 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1828 pars.cm1.a5_1 := '1'B;
1829 pars.cm2.a5_1 := '1'B;
1830 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1831 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1832 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001833 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001834}
1835testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1836 var BSC_ConnHdlr vc_conn;
1837 f_init();
1838 f_vty_config(MSCVTY, "network", "authentication required");
1839 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1840
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001841 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001842 vc_conn.done;
1843}
1844
Harald Welte33ec09b2018-02-10 15:34:46 +01001845/* LU followed by MT call (including paging) */
1846private function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1847 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001848 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte33ec09b2018-02-10 15:34:46 +01001849 cpars.bss_rtp_port := 1110;
1850 cpars.mgcp_connection_id_bss := '10004'H;
1851 cpars.mgcp_connection_id_mss := '10005'H;
1852
Philipp Maier4b2692d2018-03-14 16:37:48 +01001853 /* Note: This is an optional parameter. When the call-agent (MSC) does
1854 * supply a full endpoint name this setting will be overwritten. */
1855 cpars.mgcp_ep := "rtpbridge/1@mgw";
1856
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001857 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001858 f_mt_call(cpars);
1859}
1860testcase TC_lu_and_mt_call() runs on MTC_CT {
1861 var BSC_ConnHdlr vc_conn;
1862 f_init();
1863
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001864 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001865 vc_conn.done;
1866}
1867
Daniel Willmann8b084372018-02-04 13:35:26 +01001868/* Test MO Call SETUP with DTMF */
1869private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1870 f_init_handler(pars);
1871 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1872 cpars.bss_rtp_port := 1110;
1873 cpars.mgcp_connection_id_bss := '22222'H;
1874 cpars.mgcp_connection_id_mss := '33333'H;
1875
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001876 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001877 f_mo_seq_dtmf_dup(cpars);
1878}
1879testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1880 var BSC_ConnHdlr vc_conn;
1881 f_init();
1882
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001883 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001884 vc_conn.done;
1885}
Harald Welte9de84792018-01-28 01:06:35 +01001886
Philipp Maier328d1662018-03-07 10:40:27 +01001887testcase TC_cr_before_reset() runs on MTC_CT {
1888 timer T := 4.0;
1889 var boolean reset_ack_seen := false;
1890 f_init_bssap_direct();
1891
Harald Welte3ca0ce12019-04-23 17:18:48 +02001892 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02001893
Daniel Willmanne8018962018-08-21 14:18:00 +02001894 f_sleep(3.0);
1895
Philipp Maier328d1662018-03-07 10:40:27 +01001896 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001897 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001898
1899 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001900 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001901 T.start
1902 alt {
1903 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1904 reset_ack_seen := true;
1905 repeat;
1906 }
1907
1908 /* Acknowledge MSC sided reset requests */
1909 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001910 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001911 repeat;
1912 }
1913
1914 /* Ignore all other messages (e.g CR from the connection request) */
1915 [] BSSAP_DIRECT.receive { repeat }
1916
1917 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1918 * deadlock situation. The MSC is then unable to respond to any
1919 * further BSSMAP RESET or any other sort of traffic. */
1920 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1921 [reset_ack_seen == false] T.timeout {
1922 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02001923 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01001924 }
1925 }
1926}
Harald Welte9de84792018-01-28 01:06:35 +01001927
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001928/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02001929friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001930 f_init_handler(pars);
1931 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1932 var MNCC_PDU mncc;
1933 var MgcpCommand mgcp_cmd;
1934
1935 f_perform_lu();
1936
Harald Welteb9e86fa2018-04-09 18:18:31 +02001937 f_establish_fully();
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001938 f_create_mncc_expect(hex2str(cpars.called_party));
1939 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1940
1941 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1942 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1943 cpars.mncc_callref := mncc.u.signal.callref;
1944 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1945 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1946
1947 /* Drop CRCX */
1948 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1949
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001950 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001951
1952 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001953
1954 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001955}
1956testcase TC_mo_release_timeout() runs on MTC_CT {
1957 var BSC_ConnHdlr vc_conn;
1958 f_init();
1959
1960 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1961 vc_conn.done;
1962}
1963
Harald Welte12510c52018-01-26 22:26:24 +01001964
Philipp Maier2a98a732018-03-19 16:06:12 +01001965/* LU followed by MT call (including paging) */
1966private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1967 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001968 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01001969 cpars.bss_rtp_port := 1110;
1970 cpars.mgcp_connection_id_bss := '10004'H;
1971 cpars.mgcp_connection_id_mss := '10005'H;
1972
1973 /* Note: This is an optional parameter. When the call-agent (MSC) does
1974 * supply a full endpoint name this setting will be overwritten. */
1975 cpars.mgcp_ep := "rtpbridge/1@mgw";
1976
1977 /* Intentionally disable the CRCX response */
1978 cpars.mgw_drop_dlcx := true;
1979
1980 /* Perform location update and call */
1981 f_perform_lu();
1982 f_mt_call(cpars);
1983}
1984testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
1985 var BSC_ConnHdlr vc_conn;
1986 f_init();
1987
1988 /* Perform an almost normal looking locationupdate + mt-call, but do
1989 * not respond to the DLCX at the end of the call */
1990 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
1991 vc_conn.done;
1992
1993 /* Wait a guard period until the MGCP layer in the MSC times out,
1994 * if the MSC is vulnerable to the use-after-free situation that is
1995 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
1996 * segfault now */
1997 f_sleep(6.0);
1998
1999 /* Run the init procedures once more. If the MSC has crashed, this
2000 * this will fail */
2001 f_init();
2002}
Harald Welte45164da2018-01-24 12:51:27 +01002003
Philipp Maier75932982018-03-27 14:52:35 +02002004/* Two BSSMAP resets from two different BSCs */
2005testcase TC_reset_two() runs on MTC_CT {
2006 var BSC_ConnHdlr vc_conn;
2007 f_init(2);
2008 f_sleep(2.0);
2009 setverdict(pass);
2010}
2011
Harald Weltee13cfb22019-04-23 16:52:02 +02002012/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
2013testcase TC_reset_two_1iu() runs on MTC_CT {
2014 var BSC_ConnHdlr vc_conn;
2015 f_init(3);
2016 f_sleep(2.0);
2017 setverdict(pass);
2018}
2019
Harald Weltef640a012018-04-14 17:49:21 +02002020/***********************************************************************
2021 * SMS Testing
2022 ***********************************************************************/
2023
Harald Weltef45efeb2018-04-09 18:19:24 +02002024/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002025friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002026 var SmsParameters spars := valueof(t_SmsPars);
2027
2028 f_init_handler(pars);
2029
2030 /* Perform location update and call */
2031 f_perform_lu();
2032
2033 f_establish_fully(EST_TYPE_MO_SMS);
2034
2035 //spars.exp_rp_err := 96; /* invalid mandatory information */
2036 f_mo_sms(spars);
2037
2038 f_expect_clear();
2039}
2040testcase TC_lu_and_mo_sms() runs on MTC_CT {
2041 var BSC_ConnHdlr vc_conn;
2042 f_init();
2043 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2044 vc_conn.done;
2045}
2046
Harald Weltee13cfb22019-04-23 16:52:02 +02002047
Harald Weltef45efeb2018-04-09 18:19:24 +02002048private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002049runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002050 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2051}
2052
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002053/* Remove still pending SMS */
2054private function f_vty_sms_clear(charstring imsi)
2055runs on BSC_ConnHdlr {
2056 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2057 f_vty_transceive(MSCVTY, "sms-queue clear");
2058}
2059
Harald Weltef45efeb2018-04-09 18:19:24 +02002060/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002061friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002062 var SmsParameters spars := valueof(t_SmsPars);
2063 var OCT4 tmsi;
2064
2065 f_init_handler(pars);
2066
2067 /* Perform location update and call */
2068 f_perform_lu();
2069
2070 /* register an 'expect' for given IMSI (+TMSI) */
2071 if (isvalue(g_pars.tmsi)) {
2072 tmsi := g_pars.tmsi;
2073 } else {
2074 tmsi := 'FFFFFFFF'O;
2075 }
Harald Welte6811d102019-04-14 22:23:14 +02002076 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002077
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002078 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002079
2080 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002081 f_expect_paging();
2082
Harald Weltef45efeb2018-04-09 18:19:24 +02002083 /* Establish DTAP / BSSAP / SCCP connection */
2084 f_establish_fully(EST_TYPE_PAG_RESP);
2085
2086 spars.tp.ud := 'C8329BFD064D9B53'O;
2087 f_mt_sms(spars);
2088
2089 f_expect_clear();
2090}
2091testcase TC_lu_and_mt_sms() runs on MTC_CT {
2092 var BSC_ConnHdlrPars pars;
2093 var BSC_ConnHdlr vc_conn;
2094 f_init();
2095 pars := f_init_pars(43);
2096 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002097 vc_conn.done;
2098}
2099
Harald Weltee13cfb22019-04-23 16:52:02 +02002100
Philipp Maier3983e702018-11-22 19:01:33 +01002101/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002102friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002103 var SmsParameters spars := valueof(t_SmsPars);
2104 var OCT4 tmsi;
Philipp Maier3983e702018-11-22 19:01:33 +01002105 f_init_handler(pars, 150.0);
2106
2107 /* Perform location update */
2108 f_perform_lu();
2109
2110 /* register an 'expect' for given IMSI (+TMSI) */
2111 if (isvalue(g_pars.tmsi)) {
2112 tmsi := g_pars.tmsi;
2113 } else {
2114 tmsi := 'FFFFFFFF'O;
2115 }
Harald Welte6811d102019-04-14 22:23:14 +02002116 f_ran_register_imsi(g_pars.imsi, tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002117
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002118 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2119
Neels Hofmeyr16237742019-03-06 15:34:01 +01002120 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002121 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002122
2123 /* Wait some time to make sure the MSC is not delivering any further
2124 * paging messages or anything else that could be unexpected. */
2125 timer T := 20.0;
2126 T.start
2127 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02002128 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi))
Philipp Maier3983e702018-11-22 19:01:33 +01002129 {
2130 setverdict(fail, "paging seems not to stop!");
2131 mtc.stop;
2132 }
Harald Welte62113fc2019-05-09 13:04:02 +02002133 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Weltee13cfb22019-04-23 16:52:02 +02002134 setverdict(fail, "paging seems not to stop!");
2135 mtc.stop;
2136 }
Philipp Maier3983e702018-11-22 19:01:33 +01002137 [] BSSAP.receive {
2138 setverdict(fail, "unexpected BSSAP message received");
2139 self.stop;
2140 }
2141 [] T.timeout {
2142 setverdict(pass);
2143 }
2144 }
2145
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002146 f_vty_sms_clear(hex2str(g_pars.imsi));
2147
Philipp Maier3983e702018-11-22 19:01:33 +01002148 setverdict(pass);
2149}
2150testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2151 var BSC_ConnHdlrPars pars;
2152 var BSC_ConnHdlr vc_conn;
2153 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002154 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002155 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002156 vc_conn.done;
2157}
2158
Harald Weltee13cfb22019-04-23 16:52:02 +02002159
Harald Weltef640a012018-04-14 17:49:21 +02002160/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002161friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002162 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002163
Harald Weltef640a012018-04-14 17:49:21 +02002164 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002165
Harald Weltef640a012018-04-14 17:49:21 +02002166 /* Perform location update so IMSI is known + registered in MSC/VLR */
2167 f_perform_lu();
2168 f_establish_fully(EST_TYPE_MO_SMS);
2169
2170 f_mo_sms(spars);
2171
2172 var SMPP_PDU smpp;
2173 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2174 tr_smpp.body.deliver_sm := {
2175 service_type := "CMT",
2176 source_addr_ton := network_specific,
2177 source_addr_npi := isdn,
2178 source_addr := hex2str(pars.msisdn),
2179 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2180 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2181 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2182 esm_class := '00000001'B,
2183 protocol_id := 0,
2184 priority_flag := 0,
2185 schedule_delivery_time := "",
2186 replace_if_present := 0,
2187 data_coding := '00000001'B,
2188 sm_default_msg_id := 0,
2189 sm_length := ?,
2190 short_message := spars.tp.ud,
2191 opt_pars := {
2192 {
2193 tag := user_message_reference,
2194 len := 2,
2195 opt_value := {
2196 int2_val := oct2int(spars.tp.msg_ref)
2197 }
2198 }
2199 }
2200 };
2201 alt {
2202 [] SMPP.receive(tr_smpp) -> value smpp {
2203 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2204 }
2205 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2206 }
2207
2208 f_expect_clear();
2209}
2210testcase TC_smpp_mo_sms() runs on MTC_CT {
2211 var BSC_ConnHdlr vc_conn;
2212 f_init();
2213 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2214 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2215 vc_conn.done;
2216 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2217}
2218
Harald Weltee13cfb22019-04-23 16:52:02 +02002219
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002220/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002221friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002222runs on BSC_ConnHdlr {
2223 var SmsParameters spars := valueof(t_SmsPars);
2224 var GSUP_PDU gsup_msg_rx;
2225 var octetstring sm_tpdu;
2226
2227 f_init_handler(pars);
2228
2229 /* We need to inspect GSUP activity */
2230 f_create_gsup_expect(hex2str(g_pars.imsi));
2231
2232 /* Perform location update */
2233 f_perform_lu();
2234
2235 /* Send CM Service Request for SMS */
2236 f_establish_fully(EST_TYPE_MO_SMS);
2237
2238 /* Prepare expected SM-RP-UI (SM TPDU) */
2239 enc_TPDU_RP_DATA_MS_SGSN_fast(
2240 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2241 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2242 spars.tp.udl, spars.tp.ud)),
2243 sm_tpdu);
2244
2245 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2246 imsi := g_pars.imsi,
2247 sm_rp_mr := spars.rp.msg_ref,
2248 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2249 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(?),
2250 /* FIXME: MSISDN coding troubles */
2251 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(?),
2252 /* TODO: can we use decmatch here? */
2253 sm_rp_ui := sm_tpdu
2254 );
2255
2256 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2257 f_mo_sms_submit(spars);
2258 alt {
2259 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
2260 log("RX MO-forwardSM-Req");
2261 log(gsup_msg_rx);
2262 setverdict(pass);
2263 }
2264 [] GSUP.receive {
2265 log("RX unexpected GSUP message");
2266 setverdict(fail);
2267 mtc.stop;
2268 }
2269 }
2270
2271 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2272 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2273 imsi := g_pars.imsi,
2274 sm_rp_mr := spars.rp.msg_ref)));
2275 /* Expect RP-ACK on DTAP */
2276 f_mo_sms_wait_rp_ack(spars);
2277
2278 f_expect_clear();
2279}
2280testcase TC_gsup_mo_sms() runs on MTC_CT {
2281 var BSC_ConnHdlr vc_conn;
2282 f_init();
2283 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2284 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2285 vc_conn.done;
2286 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2287}
2288
Harald Weltee13cfb22019-04-23 16:52:02 +02002289
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002290/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002291friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002292runs on BSC_ConnHdlr {
2293 var SmsParameters spars := valueof(t_SmsPars);
2294 var GSUP_PDU gsup_msg_rx;
2295
2296 f_init_handler(pars);
2297
2298 /* We need to inspect GSUP activity */
2299 f_create_gsup_expect(hex2str(g_pars.imsi));
2300
2301 /* Perform location update */
2302 f_perform_lu();
2303
2304 /* Send CM Service Request for SMS */
2305 f_establish_fully(EST_TYPE_MO_SMS);
2306
2307 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2308 imsi := g_pars.imsi,
2309 sm_rp_mr := spars.rp.msg_ref,
2310 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2311 );
2312
2313 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2314 f_mo_smma(spars);
2315 alt {
2316 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
2317 log("RX MO-ReadyForSM-Req");
2318 log(gsup_msg_rx);
2319 setverdict(pass);
2320 }
2321 [] GSUP.receive {
2322 log("RX unexpected GSUP message");
2323 setverdict(fail);
2324 mtc.stop;
2325 }
2326 }
2327
2328 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2329 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2330 imsi := g_pars.imsi,
2331 sm_rp_mr := spars.rp.msg_ref)));
2332 /* Expect RP-ACK on DTAP */
2333 f_mo_sms_wait_rp_ack(spars);
2334
2335 f_expect_clear();
2336}
2337testcase TC_gsup_mo_smma() runs on MTC_CT {
2338 var BSC_ConnHdlr vc_conn;
2339 f_init();
2340 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2341 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2342 vc_conn.done;
2343 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2344}
2345
Harald Weltee13cfb22019-04-23 16:52:02 +02002346
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002347/* Helper for sending MT SMS over GSUP */
2348private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2349runs on BSC_ConnHdlr {
2350 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2351 imsi := g_pars.imsi,
2352 /* NOTE: MSC should assign RP-MR itself */
2353 sm_rp_mr := 'FF'O,
2354 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2355 /* TODO: fix encoding of ts_GSUP_SM_RP_DA_IMSI */
2356 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(g_pars.msisdn)),
2357 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(g_pars.msisdn)),
2358 /* Encoded SMS TPDU (taken from Wireshark)
2359 * FIXME: we should encode spars somehow */
2360 sm_rp_ui := '00068021436500008111328130858200'O,
2361 sm_rp_mms := mms
2362 ));
2363}
2364
2365/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002366friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002367runs on BSC_ConnHdlr {
2368 var SmsParameters spars := valueof(t_SmsPars);
2369
2370 f_init_handler(pars);
2371
2372 /* We need to inspect GSUP activity */
2373 f_create_gsup_expect(hex2str(g_pars.imsi));
2374
2375 /* Perform location update */
2376 f_perform_lu();
2377
2378 /* Register an 'expect' for given IMSI (+TMSI) */
2379 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002380 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002381 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002382 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002383 }
2384
2385 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2386 imsi := g_pars.imsi,
2387 /* NOTE: MSC should assign RP-MR itself */
2388 sm_rp_mr := ?
2389 );
2390
2391 /* Submit a MT SMS on GSUP */
2392 f_gsup_forwardSM_req(spars);
2393
2394 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002395 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002396 f_establish_fully(EST_TYPE_PAG_RESP);
2397
2398 /* Wait for MT SMS on DTAP */
2399 f_mt_sms_expect(spars);
2400
2401 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2402 f_mt_sms_send_rp_ack(spars);
2403 alt {
2404 [] GSUP.receive(mt_forwardSM_res) {
2405 log("RX MT-forwardSM-Res (RP-ACK)");
2406 setverdict(pass);
2407 }
2408 [] GSUP.receive {
2409 log("RX unexpected GSUP message");
2410 setverdict(fail);
2411 mtc.stop;
2412 }
2413 }
2414
2415 f_expect_clear();
2416}
2417testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2418 var BSC_ConnHdlrPars pars;
2419 var BSC_ConnHdlr vc_conn;
2420 f_init();
2421 pars := f_init_pars(90);
2422 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2423 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2424 vc_conn.done;
2425 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2426}
2427
Harald Weltee13cfb22019-04-23 16:52:02 +02002428
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002429/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002430friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002431runs on BSC_ConnHdlr {
2432 var SmsParameters spars := valueof(t_SmsPars);
2433 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2434
2435 f_init_handler(pars);
2436
2437 /* We need to inspect GSUP activity */
2438 f_create_gsup_expect(hex2str(g_pars.imsi));
2439
2440 /* Perform location update */
2441 f_perform_lu();
2442
2443 /* Register an 'expect' for given IMSI (+TMSI) */
2444 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002445 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002446 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002447 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002448 }
2449
2450 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2451 imsi := g_pars.imsi,
2452 /* NOTE: MSC should assign RP-MR itself */
2453 sm_rp_mr := ?,
2454 sm_rp_cause := sm_rp_cause
2455 );
2456
2457 /* Submit a MT SMS on GSUP */
2458 f_gsup_forwardSM_req(spars);
2459
2460 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002461 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002462 f_establish_fully(EST_TYPE_PAG_RESP);
2463
2464 /* Wait for MT SMS on DTAP */
2465 f_mt_sms_expect(spars);
2466
2467 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2468 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2469 alt {
2470 [] GSUP.receive(mt_forwardSM_err) {
2471 log("RX MT-forwardSM-Err (RP-ERROR)");
2472 setverdict(pass);
2473 mtc.stop;
2474 }
2475 [] GSUP.receive {
2476 log("RX unexpected GSUP message");
2477 setverdict(fail);
2478 mtc.stop;
2479 }
2480 }
2481
2482 f_expect_clear();
2483}
2484testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2485 var BSC_ConnHdlrPars pars;
2486 var BSC_ConnHdlr vc_conn;
2487 f_init();
2488 pars := f_init_pars(91);
2489 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2490 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2491 vc_conn.done;
2492 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2493}
2494
Harald Weltee13cfb22019-04-23 16:52:02 +02002495
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002496/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002497friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002498runs on BSC_ConnHdlr {
2499 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2500 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2501
2502 f_init_handler(pars);
2503
2504 /* We need to inspect GSUP activity */
2505 f_create_gsup_expect(hex2str(g_pars.imsi));
2506
2507 /* Perform location update */
2508 f_perform_lu();
2509
2510 /* Register an 'expect' for given IMSI (+TMSI) */
2511 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002512 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002513 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002514 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002515 }
2516
2517 /* Submit the 1st MT SMS on GSUP */
2518 log("TX MT-forwardSM-Req for the 1st SMS");
2519 f_gsup_forwardSM_req(spars1);
2520
2521 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002522 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002523 f_establish_fully(EST_TYPE_PAG_RESP);
2524
2525 /* Wait for 1st MT SMS on DTAP */
2526 f_mt_sms_expect(spars1);
2527 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2528 ", SM-RP-MR is ", spars1.rp.msg_ref);
2529
2530 /* Submit the 2nd MT SMS on GSUP */
2531 log("TX MT-forwardSM-Req for the 2nd SMS");
2532 f_gsup_forwardSM_req(spars2);
2533
2534 /* Wait for 2nd MT SMS on DTAP */
2535 f_mt_sms_expect(spars2);
2536 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2537 ", SM-RP-MR is ", spars2.rp.msg_ref);
2538
2539 /* Both transaction IDs shall be different */
2540 if (spars1.tid == spars2.tid) {
2541 log("Both DTAP transaction IDs shall be different");
2542 setverdict(fail);
2543 }
2544
2545 /* Both SM-RP-MR values shall be different */
2546 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2547 log("Both SM-RP-MR values shall be different");
2548 setverdict(fail);
2549 }
2550
2551 /* Both SM-RP-MR values shall be assigned */
2552 if (spars1.rp.msg_ref == 'FF'O) {
2553 log("Unassigned SM-RP-MR value for the 1st SMS");
2554 setverdict(fail);
2555 }
2556 if (spars2.rp.msg_ref == 'FF'O) {
2557 log("Unassigned SM-RP-MR value for the 2nd SMS");
2558 setverdict(fail);
2559 }
2560
2561 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2562 f_mt_sms_send_rp_ack(spars1);
2563 alt {
2564 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2565 imsi := g_pars.imsi,
2566 sm_rp_mr := spars1.rp.msg_ref
2567 )) {
2568 log("RX MT-forwardSM-Res (RP-ACK)");
2569 setverdict(pass);
2570 }
2571 [] GSUP.receive {
2572 log("RX unexpected GSUP message");
2573 setverdict(fail);
2574 mtc.stop;
2575 }
2576 }
2577
2578 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2579 f_mt_sms_send_rp_ack(spars2);
2580 alt {
2581 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2582 imsi := g_pars.imsi,
2583 sm_rp_mr := spars2.rp.msg_ref
2584 )) {
2585 log("RX MT-forwardSM-Res (RP-ACK)");
2586 setverdict(pass);
2587 }
2588 [] GSUP.receive {
2589 log("RX unexpected GSUP message");
2590 setverdict(fail);
2591 mtc.stop;
2592 }
2593 }
2594
2595 f_expect_clear();
2596}
2597testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2598 var BSC_ConnHdlrPars pars;
2599 var BSC_ConnHdlr vc_conn;
2600 f_init();
2601 pars := f_init_pars(92);
2602 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2603 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2604 vc_conn.done;
2605 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2606}
2607
Harald Weltee13cfb22019-04-23 16:52:02 +02002608
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002609/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002610friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002611runs on BSC_ConnHdlr {
2612 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2613 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2614
2615 f_init_handler(pars);
2616
2617 /* We need to inspect GSUP activity */
2618 f_create_gsup_expect(hex2str(g_pars.imsi));
2619
2620 /* Perform location update */
2621 f_perform_lu();
2622
2623 /* Register an 'expect' for given IMSI (+TMSI) */
2624 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002625 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002626 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002627 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002628 }
2629
2630 /* Send CM Service Request for MO SMMA */
2631 f_establish_fully(EST_TYPE_MO_SMS);
2632
2633 /* Submit MO SMMA on DTAP */
2634 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2635 spars_mo.rp.msg_ref := '00'O;
2636 f_mo_smma(spars_mo);
2637
2638 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2639 alt {
2640 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2641 imsi := g_pars.imsi,
2642 sm_rp_mr := spars_mo.rp.msg_ref,
2643 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2644 )) {
2645 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2646 setverdict(pass);
2647 }
2648 [] GSUP.receive {
2649 log("RX unexpected GSUP message");
2650 setverdict(fail);
2651 mtc.stop;
2652 }
2653 }
2654
2655 /* Submit MT SMS on GSUP */
2656 log("TX MT-forwardSM-Req for the MT SMS");
2657 f_gsup_forwardSM_req(spars_mt);
2658
2659 /* Wait for MT SMS on DTAP */
2660 f_mt_sms_expect(spars_mt);
2661 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2662 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2663
2664 /* Both SM-RP-MR values shall be different */
2665 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2666 log("Both SM-RP-MR values shall be different");
2667 setverdict(fail);
2668 }
2669
2670 /* SM-RP-MR value for MT SMS shall be assigned */
2671 if (spars_mt.rp.msg_ref == 'FF'O) {
2672 log("Unassigned SM-RP-MR value for the MT SMS");
2673 setverdict(fail);
2674 }
2675
2676 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2677 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2678 imsi := g_pars.imsi,
2679 sm_rp_mr := spars_mo.rp.msg_ref)));
2680 /* Expect RP-ACK for MO SMMA on DTAP */
2681 f_mo_sms_wait_rp_ack(spars_mo);
2682
2683 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2684 f_mt_sms_send_rp_ack(spars_mt);
2685 alt {
2686 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2687 imsi := g_pars.imsi,
2688 sm_rp_mr := spars_mt.rp.msg_ref
2689 )) {
2690 log("RX MT-forwardSM-Res (RP-ACK)");
2691 setverdict(pass);
2692 }
2693 [] GSUP.receive {
2694 log("RX unexpected GSUP message");
2695 setverdict(fail);
2696 mtc.stop;
2697 }
2698 }
2699
2700 f_expect_clear();
2701}
2702testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
2703 var BSC_ConnHdlrPars pars;
2704 var BSC_ConnHdlr vc_conn;
2705 f_init();
2706 pars := f_init_pars(93);
2707 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2708 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
2709 vc_conn.done;
2710 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2711}
2712
Harald Weltee13cfb22019-04-23 16:52:02 +02002713
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002714/* Test multi-part MT-SMS over GSUP */
2715private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
2716runs on BSC_ConnHdlr {
2717 var SmsParameters spars := valueof(t_SmsPars);
2718
2719 f_init_handler(pars);
2720
2721 /* We need to inspect GSUP activity */
2722 f_create_gsup_expect(hex2str(g_pars.imsi));
2723
2724 /* Perform location update */
2725 f_perform_lu();
2726
2727 /* Register an 'expect' for given IMSI (+TMSI) */
2728 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002729 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002730 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002731 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002732 }
2733
2734 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2735 imsi := g_pars.imsi,
2736 /* NOTE: MSC should assign RP-MR itself */
2737 sm_rp_mr := ?
2738 );
2739
2740 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
2741 for (var integer i := 3; i >= 0; i := i-1) {
2742 /* Submit a MT SMS on GSUP (MMS is decremented) */
2743 f_gsup_forwardSM_req(spars, int2oct(i, 1));
2744
2745 /* Expect Paging Request and Establish connection */
2746 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02002747 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002748 f_establish_fully(EST_TYPE_PAG_RESP);
2749 }
2750
2751 /* Wait for MT SMS on DTAP */
2752 f_mt_sms_expect(spars);
2753
2754 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2755 f_mt_sms_send_rp_ack(spars);
2756 alt {
2757 [] GSUP.receive(mt_forwardSM_res) {
2758 log("RX MT-forwardSM-Res (RP-ACK)");
2759 setverdict(pass);
2760 }
2761 [] GSUP.receive {
2762 log("RX unexpected GSUP message");
2763 setverdict(fail);
2764 mtc.stop;
2765 }
2766 }
2767
2768 /* Keep some 'distance' between transmissions */
2769 f_sleep(1.5);
2770 }
2771
2772 f_expect_clear();
2773}
2774testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
2775 var BSC_ConnHdlrPars pars;
2776 var BSC_ConnHdlr vc_conn;
2777 f_init();
2778 pars := f_init_pars(91);
2779 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2780 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
2781 vc_conn.done;
2782 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2783}
2784
Harald Weltef640a012018-04-14 17:49:21 +02002785/* convert GSM L3 TON to SMPP_TON enum */
2786function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
2787 select (ton) {
2788 case ('000'B) { return unknown; }
2789 case ('001'B) { return international; }
2790 case ('010'B) { return national; }
2791 case ('011'B) { return network_specific; }
2792 case ('100'B) { return subscriber_number; }
2793 case ('101'B) { return alphanumeric; }
2794 case ('110'B) { return abbreviated; }
2795 }
2796 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02002797 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002798}
2799/* convert GSM L3 NPI to SMPP_NPI enum */
2800function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2801 select (npi) {
2802 case ('0000'B) { return unknown; }
2803 case ('0001'B) { return isdn; }
2804 case ('0011'B) { return data; }
2805 case ('0100'B) { return telex; }
2806 case ('0110'B) { return land_mobile; }
2807 case ('1000'B) { return national; }
2808 case ('1001'B) { return private_; }
2809 case ('1010'B) { return ermes; }
2810 }
2811 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02002812 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002813}
2814
2815/* build a SMPP_SM from SmsParameters */
2816function f_mt_sm_from_spars(SmsParameters spars)
2817runs on BSC_ConnHdlr return SMPP_SM {
2818 var SMPP_SM sm := {
2819 service_type := "CMT",
2820 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2821 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2822 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2823 dest_addr_ton := international,
2824 dest_addr_npi := isdn,
2825 destination_addr := hex2str(g_pars.msisdn),
2826 esm_class := '00000001'B,
2827 protocol_id := 0,
2828 priority_flag := 0,
2829 schedule_delivery_time := "",
2830 validity_period := "",
2831 registered_delivery := '00000000'B,
2832 replace_if_present := 0,
2833 data_coding := '00000001'B,
2834 sm_default_msg_id := 0,
2835 sm_length := spars.tp.udl,
2836 short_message := spars.tp.ud,
2837 opt_pars := {}
2838 };
2839 return sm;
2840}
2841
2842/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2843private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2844 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2845 if (trans_mode) {
2846 sm.esm_class := '00000010'B;
2847 }
2848
2849 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2850 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2851 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2852 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2853 * before we expect the SMS delivery on the BSC/radio side */
2854 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2855 }
2856
2857 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002858 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02002859 /* Establish DTAP / BSSAP / SCCP connection */
2860 f_establish_fully(EST_TYPE_PAG_RESP);
2861 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2862
2863 f_mt_sms(spars);
2864
2865 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2866 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2867 }
2868 f_expect_clear();
2869}
2870
2871/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2872private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2873 f_init_handler(pars);
2874
2875 /* Perform location update so IMSI is known + registered in MSC/VLR */
2876 f_perform_lu();
2877 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2878
2879 /* register an 'expect' for given IMSI (+TMSI) */
2880 var OCT4 tmsi;
2881 if (isvalue(g_pars.tmsi)) {
2882 tmsi := g_pars.tmsi;
2883 } else {
2884 tmsi := 'FFFFFFFF'O;
2885 }
Harald Welte6811d102019-04-14 22:23:14 +02002886 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02002887
2888 var SmsParameters spars := valueof(t_SmsPars);
2889 /* TODO: test with more intelligent user data; test different coding schemes */
2890 spars.tp.ud := '00'O;
2891 spars.tp.udl := 1;
2892
2893 /* first test the non-transaction store+forward mode */
2894 f_smpp_mt_sms(spars, false);
2895
2896 /* then test the transaction mode */
2897 f_smpp_mt_sms(spars, true);
2898}
2899testcase TC_smpp_mt_sms() runs on MTC_CT {
2900 var BSC_ConnHdlr vc_conn;
2901 f_init();
2902 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
2903 vc_conn.done;
2904}
2905
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002906/***********************************************************************
2907 * USSD Testing
2908 ***********************************************************************/
2909
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002910private altstep as_unexp_gsup_or_bssap_msg()
2911runs on BSC_ConnHdlr {
2912 [] GSUP.receive {
2913 setverdict(fail, "Unknown/unexpected GSUP received");
2914 self.stop;
2915 }
2916 [] BSSAP.receive {
2917 setverdict(fail, "Unknown/unexpected BSSAP message received");
2918 self.stop;
2919 }
2920}
2921
2922private function f_expect_gsup_msg(template GSUP_PDU msg)
2923runs on BSC_ConnHdlr return GSUP_PDU {
2924 var GSUP_PDU gsup_msg_complete;
2925
2926 alt {
2927 [] GSUP.receive(msg) -> value gsup_msg_complete {
2928 setverdict(pass);
2929 }
2930 /* We don't expect anything else */
2931 [] as_unexp_gsup_or_bssap_msg();
2932 }
2933
2934 return gsup_msg_complete;
2935}
2936
2937private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg)
2938runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
2939 var PDU_DTAP_MT bssap_msg_complete;
2940
2941 alt {
2942 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
2943 setverdict(pass);
2944 }
2945 /* We don't expect anything else */
2946 [] as_unexp_gsup_or_bssap_msg();
2947 }
2948
2949 return bssap_msg_complete.dtap;
2950}
2951
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002952/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02002953friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002954runs on BSC_ConnHdlr {
2955 f_init_handler(pars);
2956
2957 /* Perform location update */
2958 f_perform_lu();
2959
2960 /* Send CM Service Request for SS/USSD */
2961 f_establish_fully(EST_TYPE_SS_ACT);
2962
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002963 /* We need to inspect GSUP activity */
2964 f_create_gsup_expect(hex2str(g_pars.imsi));
2965
2966 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2967 invoke_id := 5, /* Phone may not start from 0 or 1 */
2968 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2969 ussd_string := "*#100#"
2970 );
2971
2972 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
2973 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
2974 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2975 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
2976 )
2977
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002978 /* Compose a new SS/REGISTER message with request */
2979 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
2980 tid := 1, /* We just need a single transaction */
2981 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002982 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002983 );
2984
2985 /* Compose SS/RELEASE_COMPLETE template with expected response */
2986 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
2987 tid := 1, /* Response should arrive within the same transaction */
2988 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002989 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002990 );
2991
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002992 /* Compose expected MSC -> HLR message */
2993 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
2994 imsi := g_pars.imsi,
2995 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2996 ss := valueof(facility_req)
2997 );
2998
2999 /* To be used for sending response with correct session ID */
3000 var GSUP_PDU gsup_req_complete;
3001
3002 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003003 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003004 /* Expect GSUP message containing the SS payload */
3005 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3006
3007 /* Compose the response from HLR using received session ID */
3008 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3009 imsi := g_pars.imsi,
3010 sid := gsup_req_complete.ies[1].val.session_id,
3011 state := OSMO_GSUP_SESSION_STATE_END,
3012 ss := valueof(facility_rsp)
3013 );
3014
3015 /* Finally, HLR terminates the session */
3016 GSUP.send(gsup_rsp);
3017 /* Expect RELEASE_COMPLETE message with the response */
3018 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003019
3020 f_expect_clear();
3021}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003022testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003023 var BSC_ConnHdlr vc_conn;
3024 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003025 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003026 vc_conn.done;
3027}
3028
Harald Weltee13cfb22019-04-23 16:52:02 +02003029
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003030/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003031friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003032runs on BSC_ConnHdlr {
3033 f_init_handler(pars);
3034
3035 /* Perform location update */
3036 f_perform_lu();
3037
Harald Welte6811d102019-04-14 22:23:14 +02003038 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003039
3040 /* We need to inspect GSUP activity */
3041 f_create_gsup_expect(hex2str(g_pars.imsi));
3042
3043 /* Facility IE with network-originated USSD notification */
3044 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3045 op_code := SS_OP_CODE_USS_NOTIFY,
3046 ussd_string := "Mahlzeit!"
3047 );
3048
3049 /* Facility IE with acknowledgment to the USSD notification */
3050 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3051 /* In case of USSD notification, Return Result is empty */
3052 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3053 );
3054
3055 /* Compose a new MT SS/REGISTER message with USSD notification */
3056 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3057 tid := 0, /* FIXME: most likely, it should be 0 */
3058 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3059 facility := valueof(facility_req)
3060 );
3061
3062 /* Compose HLR -> MSC GSUP message */
3063 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3064 imsi := g_pars.imsi,
3065 sid := '20000101'O,
3066 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3067 ss := valueof(facility_req)
3068 );
3069
3070 /* Send it to MSC and expect Paging Request */
3071 GSUP.send(gsup_req);
3072 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003073 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3074 setverdict(pass);
3075 }
Harald Welte62113fc2019-05-09 13:04:02 +02003076 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003077 setverdict(pass);
3078 }
3079 /* We don't expect anything else */
3080 [] as_unexp_gsup_or_bssap_msg();
3081 }
3082
3083 /* Send Paging Response and expect USSD notification */
3084 f_establish_fully(EST_TYPE_PAG_RESP);
3085 /* Expect MT REGISTER message with USSD notification */
3086 f_expect_mt_dtap_msg(ussd_ntf);
3087
3088 /* Compose a new MO SS/FACILITY message with empty response */
3089 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3090 tid := 0, /* FIXME: it shall match the request tid */
3091 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3092 facility := valueof(facility_rsp)
3093 );
3094
3095 /* Compose expected MSC -> HLR GSUP message */
3096 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3097 imsi := g_pars.imsi,
3098 sid := '20000101'O,
3099 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3100 ss := valueof(facility_rsp)
3101 );
3102
3103 /* MS sends response to the notification */
3104 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3105 /* Expect GSUP message containing the SS payload */
3106 f_expect_gsup_msg(gsup_rsp);
3107
3108 /* Compose expected MT SS/RELEASE COMPLETE message */
3109 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3110 tid := 0, /* FIXME: it shall match the request tid */
3111 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3112 facility := omit
3113 );
3114
3115 /* Compose MSC -> HLR GSUP message */
3116 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3117 imsi := g_pars.imsi,
3118 sid := '20000101'O,
3119 state := OSMO_GSUP_SESSION_STATE_END
3120 );
3121
3122 /* Finally, HLR terminates the session */
3123 GSUP.send(gsup_term)
3124 /* Expect MT RELEASE COMPLETE without Facility IE */
3125 f_expect_mt_dtap_msg(ussd_term);
3126
3127 f_expect_clear();
3128}
3129testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3130 var BSC_ConnHdlr vc_conn;
3131 f_init();
3132 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3133 vc_conn.done;
3134}
3135
Harald Weltee13cfb22019-04-23 16:52:02 +02003136
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003137/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003138friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003139runs on BSC_ConnHdlr {
3140 f_init_handler(pars);
3141
3142 /* Call parameters taken from f_tc_lu_and_mt_call */
3143 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3144 cpars.mgcp_connection_id_bss := '10004'H;
3145 cpars.mgcp_connection_id_mss := '10005'H;
3146 cpars.mgcp_ep := "rtpbridge/1@mgw";
3147 cpars.bss_rtp_port := 1110;
3148
3149 /* Perform location update */
3150 f_perform_lu();
3151
3152 /* Establish a MT call */
3153 f_mt_call_establish(cpars);
3154
3155 /* Hold the call for some time */
3156 f_sleep(1.0);
3157
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003158 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3159 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3160 ussd_string := "*#100#"
3161 );
3162
3163 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3164 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3165 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3166 )
3167
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003168 /* Compose a new SS/REGISTER message with request */
3169 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3170 tid := 1, /* We just need a single transaction */
3171 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003172 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003173 );
3174
3175 /* Compose SS/RELEASE_COMPLETE template with expected response */
3176 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3177 tid := 1, /* Response should arrive within the same transaction */
3178 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003179 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003180 );
3181
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003182 /* Compose expected MSC -> HLR message */
3183 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3184 imsi := g_pars.imsi,
3185 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3186 ss := valueof(facility_req)
3187 );
3188
3189 /* To be used for sending response with correct session ID */
3190 var GSUP_PDU gsup_req_complete;
3191
3192 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003193 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003194 /* Expect GSUP message containing the SS payload */
3195 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3196
3197 /* Compose the response from HLR using received session ID */
3198 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3199 imsi := g_pars.imsi,
3200 sid := gsup_req_complete.ies[1].val.session_id,
3201 state := OSMO_GSUP_SESSION_STATE_END,
3202 ss := valueof(facility_rsp)
3203 );
3204
3205 /* Finally, HLR terminates the session */
3206 GSUP.send(gsup_rsp);
3207 /* Expect RELEASE_COMPLETE message with the response */
3208 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003209
3210 /* Hold the call for some time */
3211 f_sleep(1.0);
3212
3213 /* Release the call (does Clear Complete itself) */
3214 f_call_hangup(cpars, true);
3215}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003216testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003217 var BSC_ConnHdlr vc_conn;
3218 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003219 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003220 vc_conn.done;
3221}
3222
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003223/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003224friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003225 f_init_handler(pars);
3226 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
3227 var MNCC_PDU mncc;
3228 var MgcpCommand mgcp_cmd;
3229
3230 f_perform_lu();
3231
3232 f_establish_fully();
3233 f_create_mncc_expect(hex2str(cpars.called_party));
3234 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
3235
3236 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
3237 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
3238 cpars.mncc_callref := mncc.u.signal.callref;
3239 log("mncc_callref=", cpars.mncc_callref);
3240 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
3241 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
3242
3243 MNCC.send(ts_MNCC_ALERT_req(cpars.mncc_callref));
3244 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_ALERTING(cpars.transaction_id)));
3245 MGCP.receive(tr_CRCX);
3246
3247 f_sleep(1.0);
Harald Weltee13cfb22019-04-23 16:52:02 +02003248 if (pars.ran_is_geran) {
3249 BSSAP.send(ts_BSSMAP_ClearRequest(0));
3250 } else {
3251 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
3252 }
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003253
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003254 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003255
Harald Weltee13cfb22019-04-23 16:52:02 +02003256 if (pars.ran_is_geran) {
3257 interleave {
3258 [] MNCC.receive(tr_MNCC_REL_ind(?, ?)) { };
3259 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003260 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Weltee13cfb22019-04-23 16:52:02 +02003261 };
3262 }
3263 } else {
3264 interleave {
3265 [] MNCC.receive(tr_MNCC_REL_ind(?, ?)) { };
3266 [] BSSAP.receive(tr_RANAP_IuReleaseCommand(?)) {
3267 BSSAP.send(ts_RANAP_IuReleaseComplete);
3268 };
3269 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003270 }
3271
3272 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003273
3274 f_sleep(1.0);
3275}
3276testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3277 var BSC_ConnHdlr vc_conn;
3278 f_init();
3279
3280 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3281 vc_conn.done;
3282}
3283
Harald Weltee13cfb22019-04-23 16:52:02 +02003284
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003285/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003286friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003287runs on BSC_ConnHdlr {
3288 f_init_handler(pars);
3289
3290 /* Call parameters taken from f_tc_lu_and_mt_call */
3291 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3292 cpars.mgcp_connection_id_bss := '10004'H;
3293 cpars.mgcp_connection_id_mss := '10005'H;
3294 cpars.mgcp_ep := "rtpbridge/1@mgw";
3295 cpars.bss_rtp_port := 1110;
3296
3297 /* Perform location update */
3298 f_perform_lu();
3299
3300 /* Establish a MT call */
3301 f_mt_call_establish(cpars);
3302
3303 /* Hold the call for some time */
3304 f_sleep(1.0);
3305
3306 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3307 op_code := SS_OP_CODE_USS_REQUEST,
3308 ussd_string := "Please type anything..."
3309 );
3310
3311 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3312 op_code := SS_OP_CODE_USS_REQUEST,
3313 ussd_string := "Nope."
3314 )
3315
3316 /* Compose MT SS/REGISTER message with network-originated request */
3317 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3318 tid := 0, /* FIXME: most likely, it should be 0 */
3319 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3320 facility := valueof(facility_req)
3321 );
3322
3323 /* Compose HLR -> MSC GSUP message */
3324 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3325 imsi := g_pars.imsi,
3326 sid := '20000101'O,
3327 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3328 ss := valueof(facility_req)
3329 );
3330
3331 /* Send it to MSC */
3332 GSUP.send(gsup_req);
3333 /* Expect MT REGISTER message with USSD request */
3334 f_expect_mt_dtap_msg(ussd_req);
3335
3336 /* Compose a new MO SS/FACILITY message with response */
3337 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3338 tid := 0, /* FIXME: it shall match the request tid */
3339 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3340 facility := valueof(facility_rsp)
3341 );
3342
3343 /* Compose expected MSC -> HLR GSUP message */
3344 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3345 imsi := g_pars.imsi,
3346 sid := '20000101'O,
3347 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3348 ss := valueof(facility_rsp)
3349 );
3350
3351 /* MS sends response */
3352 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3353 f_expect_gsup_msg(gsup_rsp);
3354
3355 /* Compose expected MT SS/RELEASE COMPLETE message */
3356 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3357 tid := 0, /* FIXME: it shall match the request tid */
3358 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3359 facility := omit
3360 );
3361
3362 /* Compose MSC -> HLR GSUP message */
3363 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3364 imsi := g_pars.imsi,
3365 sid := '20000101'O,
3366 state := OSMO_GSUP_SESSION_STATE_END
3367 );
3368
3369 /* Finally, HLR terminates the session */
3370 GSUP.send(gsup_term);
3371 /* Expect MT RELEASE COMPLETE without Facility IE */
3372 f_expect_mt_dtap_msg(ussd_term);
3373
3374 /* Hold the call for some time */
3375 f_sleep(1.0);
3376
3377 /* Release the call (does Clear Complete itself) */
3378 f_call_hangup(cpars, true);
3379}
3380testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3381 var BSC_ConnHdlr vc_conn;
3382 f_init();
3383 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3384 vc_conn.done;
3385}
3386
Harald Weltee13cfb22019-04-23 16:52:02 +02003387
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003388/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003389friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003390runs on BSC_ConnHdlr {
3391 f_init_handler(pars);
3392
3393 /* Perform location update */
3394 f_perform_lu();
3395
3396 /* Send CM Service Request for SS/USSD */
3397 f_establish_fully(EST_TYPE_SS_ACT);
3398
3399 /* We need to inspect GSUP activity */
3400 f_create_gsup_expect(hex2str(g_pars.imsi));
3401
3402 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3403 invoke_id := 1, /* Initial request */
3404 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3405 ussd_string := "*6766*266#"
3406 );
3407
3408 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3409 invoke_id := 2, /* Counter request */
3410 op_code := SS_OP_CODE_USS_REQUEST,
3411 ussd_string := "Password?!?"
3412 )
3413
3414 /* Compose MO SS/REGISTER message with request */
3415 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3416 tid := 1, /* We just need a single transaction */
3417 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3418 facility := valueof(facility_ms_req)
3419 );
3420
3421 /* Compose expected MSC -> HLR message */
3422 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3423 imsi := g_pars.imsi,
3424 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3425 ss := valueof(facility_ms_req)
3426 );
3427
3428 /* To be used for sending response with correct session ID */
3429 var GSUP_PDU gsup_ms_req_complete;
3430
3431 /* Initiate a new transaction */
3432 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3433 /* Expect GSUP request with original Facility IE */
3434 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3435
3436 /* Compose the response from HLR using received session ID */
3437 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3438 imsi := g_pars.imsi,
3439 sid := gsup_ms_req_complete.ies[1].val.session_id,
3440 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3441 ss := valueof(facility_net_req)
3442 );
3443
3444 /* Compose expected MT SS/FACILITY template with counter request */
3445 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3446 tid := 1, /* Response should arrive within the same transaction */
3447 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3448 facility := valueof(facility_net_req)
3449 );
3450
3451 /* Send response over GSUP */
3452 GSUP.send(gsup_net_req);
3453 /* Expect MT SS/FACILITY message with counter request */
3454 f_expect_mt_dtap_msg(ussd_net_req);
3455
3456 /* Compose MO SS/RELEASE COMPLETE */
3457 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3458 tid := 1, /* Response should arrive within the same transaction */
3459 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3460 facility := omit
3461 /* TODO: cause? */
3462 );
3463
3464 /* Compose expected HLR -> MSC abort message */
3465 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3466 imsi := g_pars.imsi,
3467 sid := gsup_ms_req_complete.ies[1].val.session_id,
3468 state := OSMO_GSUP_SESSION_STATE_END
3469 );
3470
3471 /* Abort transaction */
3472 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3473 /* Expect GSUP message indicating abort */
3474 f_expect_gsup_msg(gsup_abort);
3475
3476 f_expect_clear();
3477}
3478testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3479 var BSC_ConnHdlr vc_conn;
3480 f_init();
3481 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3482 vc_conn.done;
3483}
3484
Harald Weltee13cfb22019-04-23 16:52:02 +02003485
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003486/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003487friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003488runs on BSC_ConnHdlr {
3489 f_init_handler(pars);
3490
3491 /* Perform location update */
3492 f_perform_lu();
3493
3494 /* Send CM Service Request for SS/USSD */
3495 f_establish_fully(EST_TYPE_SS_ACT);
3496
3497 /* We need to inspect GSUP activity */
3498 f_create_gsup_expect(hex2str(g_pars.imsi));
3499
3500 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3501 invoke_id := 1,
3502 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3503 ussd_string := "#release_me");
3504
3505 /* Compose MO SS/REGISTER message with request */
3506 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3507 tid := 1, /* An arbitrary transaction identifier */
3508 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3509 facility := valueof(facility_ms_req));
3510
3511 /* Compose expected MSC -> HLR message */
3512 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3513 imsi := g_pars.imsi,
3514 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3515 ss := valueof(facility_ms_req));
3516
3517 /* To be used for sending response with correct session ID */
3518 var GSUP_PDU gsup_ms_req_complete;
3519
3520 /* Initiate a new SS transaction */
3521 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3522 /* Expect GSUP request with original Facility IE */
3523 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3524
3525 /* Don't respond, wait for timeout */
3526 f_sleep(3.0);
3527
3528 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3529 tid := 1, /* Should match the request's tid */
3530 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3531 cause := *, /* TODO: expect some specific value */
3532 facility := omit);
3533
3534 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3535 imsi := g_pars.imsi,
3536 sid := gsup_ms_req_complete.ies[1].val.session_id,
3537 state := OSMO_GSUP_SESSION_STATE_END,
3538 cause := ?); /* TODO: expect some specific value */
3539
3540 /* Expect release on both interfaces */
3541 interleave {
3542 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3543 [] GSUP.receive(gsup_rel) { };
3544 }
3545
3546 f_expect_clear();
3547 setverdict(pass);
3548}
3549testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3550 var BSC_ConnHdlr vc_conn;
3551 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003552 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003553 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3554 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003555 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003556}
3557
Harald Weltee13cfb22019-04-23 16:52:02 +02003558
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003559/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
3560private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3561 pars.net.expect_auth := true;
3562 pars.net.expect_ciph := true;
3563 pars.net.kc_support := '02'O; /* A5/1 only */
3564 f_init_handler(pars);
3565
3566 g_pars.vec := f_gen_auth_vec_2g();
3567
3568 /* Can't use f_perform_lu() directly. Code below is based on it. */
3569
3570 /* tell GSUP dispatcher to send this IMSI to us */
3571 f_create_gsup_expect(hex2str(g_pars.imsi));
3572
3573 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3574 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02003575 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003576
3577 f_mm_auth();
3578
3579 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3580 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3581 alt {
3582 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3583 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
3584 }
3585 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3586 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3587 mtc.stop;
3588 }
3589 [] BSSAP.receive {
3590 setverdict(fail, "Unknown/unexpected BSSAP received");
3591 mtc.stop;
3592 }
3593 }
3594
3595 /* Expect LU reject from MSC. */
3596 alt {
3597 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3598 setverdict(pass);
3599 }
3600 [] BSSAP.receive {
3601 setverdict(fail, "Unknown/unexpected BSSAP received");
3602 mtc.stop;
3603 }
3604 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01003605 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003606}
3607
3608testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
3609 var BSC_ConnHdlr vc_conn;
3610 f_init();
3611 f_vty_config(MSCVTY, "network", "encryption a5 1");
3612
3613 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52);
3614 vc_conn.done;
3615}
3616
Harald Weltef640a012018-04-14 17:49:21 +02003617/* TODO (SMS):
3618 * different user data lengths
3619 * SMPP transaction mode with unsuccessful delivery
3620 * queued MT-SMS with no paging response + later delivery
3621 * different data coding schemes
3622 * multi-part SMS
3623 * user-data headers
3624 * TP-PID for SMS to SIM
3625 * behavior if SMS memory is full + RP-SMMA
3626 * delivery reports
3627 * SMPP osmocom extensions
3628 * more-messages-to-send
3629 * SMS during ongoing call (SACCH/SAPI3)
3630 */
3631
3632/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01003633 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
3634 * malformed messages (missing IE, invalid message type): properly rejected?
3635 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
3636 * 3G/2G auth permutations
3637 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01003638 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01003639 * too long L3 INFO in DTAP
3640 * too long / padded BSSAP
3641 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01003642 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01003643
Harald Weltee13cfb22019-04-23 16:52:02 +02003644/***********************************************************************
3645 * SGsAP Testing
3646 ***********************************************************************/
3647
Philipp Maier948747b2019-04-02 15:22:33 +02003648/* Check if a subscriber exists in the VLR */
3649private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
3650
3651 var CtrlValue active_subsribers;
3652 var integer rc;
3653 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
3654
3655 rc := f_strstr(active_subsribers, imsi_or_msisdn);
3656 if (rc < 0) {
3657 return false;
3658 }
3659
3660 return true;
3661}
3662
Harald Welte4263c522018-12-06 11:56:27 +01003663/* Perform a location updatye at the A-Interface and run some checks to confirm
3664 * that everything is back to normal. */
3665private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
3666 var SmsParameters spars := valueof(t_SmsPars);
3667
3668 /* Perform a location update, the SGs association is expected to fall
3669 * back to NULL */
3670 f_perform_lu();
3671 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3672
3673 /* Trigger a paging request and expect the paging on BSSMAP, this is
3674 * to make sure that pagings are sent throught the A-Interface again
3675 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02003676 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01003677 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3678
3679 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003680 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
3681 setverdict(pass);
3682 }
Harald Welte62113fc2019-05-09 13:04:02 +02003683 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01003684 setverdict(pass);
3685 }
3686 [] SGsAP.receive {
3687 setverdict(fail, "Received unexpected message on SGs");
3688 }
3689 }
3690
3691 /* Send an SMS to make sure that also payload messages are routed
3692 * throught the A-Interface again */
3693 f_establish_fully(EST_TYPE_MO_SMS);
3694 f_mo_sms(spars);
3695 f_expect_clear();
3696}
3697
3698private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3699 var charstring vlr_name;
3700 f_init_handler(pars);
3701
3702 vlr_name := f_sgsap_reset_mme(mp_mme_name);
3703 log("VLR name: ", vlr_name);
3704 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01003705 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01003706}
3707
3708testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003709 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003710 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003711 f_init(1, true);
3712 pars := f_init_pars(11810, true);
3713 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003714 vc_conn.done;
3715}
3716
3717/* like f_mm_auth() but for SGs */
3718function f_mm_auth_sgs() runs on BSC_ConnHdlr {
3719 if (g_pars.net.expect_auth) {
3720 g_pars.vec := f_gen_auth_vec_3g();
3721 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
3722 g_pars.vec.sres,
3723 g_pars.vec.kc,
3724 g_pars.vec.ik,
3725 g_pars.vec.ck,
3726 g_pars.vec.autn,
3727 g_pars.vec.res));
3728 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
3729 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
3730 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
3731 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
3732 }
3733}
3734
3735/* like f_perform_lu(), but on SGs rather than BSSAP */
3736function f_sgs_perform_lu() runs on BSC_ConnHdlr {
3737 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3738 var PDU_SGsAP lur;
3739 var PDU_SGsAP lua;
3740 var PDU_SGsAP mm_info;
3741 var octetstring mm_info_dtap;
3742
3743 /* tell GSUP dispatcher to send this IMSI to us */
3744 f_create_gsup_expect(hex2str(g_pars.imsi));
3745
3746 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3747 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3748 /* Old LAI, if MS sends it */
3749 /* TMSI status, if MS has no valid TMSI */
3750 /* IMEISV, if it supports "automatic device detection" */
3751 /* TAI, if available in MME */
3752 /* E-CGI, if available in MME */
3753 SGsAP.send(lur);
3754
3755 /* FIXME: is this really done over SGs? The Ue is already authenticated
3756 * via the MME ... */
3757 f_mm_auth_sgs();
3758
3759 /* Expect MSC to perform LU with HLR */
3760 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3761 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
3762 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
3763 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
3764
3765 alt {
3766 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
3767 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
3768 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
3769 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
3770 }
3771 setverdict(pass);
3772 }
3773 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3774 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
3775 }
3776 [] SGsAP.receive {
3777 setverdict(fail, "Received unexpected message on SGs");
3778 }
3779 }
3780
3781 /* Check MM information */
3782 if (mp_mm_info == true) {
3783 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
3784 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
3785 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
3786 setverdict(fail, "Unexpected MM Information");
3787 }
3788 }
3789
3790 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3791}
3792
3793private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3794 f_init_handler(pars);
3795 f_sgs_perform_lu();
3796 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3797
3798 f_sgsap_bssmap_screening();
3799
3800 setverdict(pass);
3801}
3802testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003803 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003804 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003805 f_init(1, true);
3806 pars := f_init_pars(11811, true);
3807 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003808 vc_conn.done;
3809}
3810
3811/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
3812private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3813 f_init_handler(pars);
3814 var PDU_SGsAP lur;
3815
3816 f_create_gsup_expect(hex2str(g_pars.imsi));
3817 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3818 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3819 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3820 SGsAP.send(lur);
3821
3822 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3823 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
3824 alt {
3825 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3826 setverdict(pass);
3827 }
3828 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
3829 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
3830 mtc.stop;
3831 }
3832 [] SGsAP.receive {
3833 setverdict(fail, "Received unexpected message on SGs");
3834 }
3835 }
3836
3837 f_sgsap_bssmap_screening();
3838
3839 setverdict(pass);
3840}
3841testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003842 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003843 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003844 f_init(1, true);
3845 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01003846
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003847 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003848 vc_conn.done;
3849}
3850
3851/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
3852private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3853 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3854 var PDU_SGsAP lur;
3855
3856 f_init_handler(pars);
3857
3858 /* tell GSUP dispatcher to send this IMSI to us */
3859 f_create_gsup_expect(hex2str(g_pars.imsi));
3860
3861 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3862 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3863 /* Old LAI, if MS sends it */
3864 /* TMSI status, if MS has no valid TMSI */
3865 /* IMEISV, if it supports "automatic device detection" */
3866 /* TAI, if available in MME */
3867 /* E-CGI, if available in MME */
3868 SGsAP.send(lur);
3869
3870 /* FIXME: is this really done over SGs? The Ue is already authenticated
3871 * via the MME ... */
3872 f_mm_auth_sgs();
3873
3874 /* Expect MSC to perform LU with HLR */
3875 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3876 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
3877 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
3878 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
3879
3880 alt {
3881 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
3882 setverdict(pass);
3883 }
3884 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3885 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
3886 }
3887 [] SGsAP.receive {
3888 setverdict(fail, "Received unexpected message on SGs");
3889 }
3890 }
3891
3892 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3893
3894 /* Wait until the VLR has abort the TMSI reallocation procedure */
3895 f_sleep(45.0);
3896
3897 /* The outcome does not change the SGs state, see also 5.2.3.4 */
3898 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3899
3900 f_sgsap_bssmap_screening();
3901
3902 setverdict(pass);
3903}
3904testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003905 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003906 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003907 f_init(1, true);
3908 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01003909
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003910 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003911 vc_conn.done;
3912}
3913
3914private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
3915runs on BSC_ConnHdlr {
3916 f_init_handler(pars);
3917 f_sgs_perform_lu();
3918 f_sleep(3.0);
3919
3920 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3921 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
3922 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
3923 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3924
3925 f_sgsap_bssmap_screening();
3926
3927 setverdict(pass);
3928}
3929testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003930 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003931 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003932 f_init(1, true);
3933 pars := f_init_pars(11814, true);
3934 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003935 vc_conn.done;
3936}
3937
Philipp Maierfc19f172019-03-21 11:17:54 +01003938private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
3939runs on BSC_ConnHdlr {
3940 f_init_handler(pars);
3941 f_sgs_perform_lu();
3942 f_sleep(3.0);
3943
3944 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3945 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
3946 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
3947 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3948
3949 f_sgsap_bssmap_screening();
3950
3951 setverdict(pass);
3952}
3953testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
3954 var BSC_ConnHdlrPars pars;
3955 var BSC_ConnHdlr vc_conn;
3956 f_init(1, true);
3957 pars := f_init_pars(11814, true);
3958 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
3959 vc_conn.done;
3960}
3961
Harald Welte4263c522018-12-06 11:56:27 +01003962private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
3963runs on BSC_ConnHdlr {
3964 f_init_handler(pars);
3965 f_sgs_perform_lu();
3966 f_sleep(3.0);
3967
3968 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3969 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
3970 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02003971
3972 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
3973 setverdict(fail, "subscriber not removed from VLR");
3974 }
Harald Welte4263c522018-12-06 11:56:27 +01003975
3976 f_sgsap_bssmap_screening();
3977
3978 setverdict(pass);
3979}
3980testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003981 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003982 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003983 f_init(1, true);
3984 pars := f_init_pars(11815, true);
3985 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003986 vc_conn.done;
3987}
3988
Philipp Maier5d812702019-03-21 10:51:26 +01003989private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
3990runs on BSC_ConnHdlr {
3991 f_init_handler(pars);
3992 f_sgs_perform_lu();
3993 f_sleep(3.0);
3994
3995 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3996 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
3997 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
3998
3999 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4000 setverdict(fail, "subscriber not removed from VLR");
4001 }
4002
4003 f_sgsap_bssmap_screening();
4004
4005 setverdict(pass);
4006}
4007testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4008 var BSC_ConnHdlrPars pars;
4009 var BSC_ConnHdlr vc_conn;
4010 f_init(1, true);
4011 pars := f_init_pars(11815, true);
4012 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4013 vc_conn.done;
4014}
4015
Harald Welte4263c522018-12-06 11:56:27 +01004016/* Trigger a paging request via VTY and send a paging reject in response */
4017private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4018runs on BSC_ConnHdlr {
4019 f_init_handler(pars);
4020 f_sgs_perform_lu();
4021 f_sleep(1.0);
4022
4023 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4024 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4025 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4026 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4027
4028 /* Initiate paging via VTY */
4029 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4030 alt {
4031 [] SGsAP.receive(exp_resp) {
4032 setverdict(pass);
4033 }
4034 [] SGsAP.receive {
4035 setverdict(fail, "Received unexpected message on SGs");
4036 }
4037 }
4038
4039 /* Now reject the paging */
4040 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4041
4042 /* Wait for the states inside the MSC to settle and check the state
4043 * of the SGs Association */
4044 f_sleep(1.0);
4045 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4046
4047 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4048 * but we also need to cover tha case where the cause code indicates an
4049 * "IMSI detached for EPS services". In those cases the VLR is expected to
4050 * try paging on tha A/Iu interface. This will be another testcase similar to
4051 * this one, but extended with checks for the presence of the A/Iu paging
4052 * messages. */
4053
4054 f_sgsap_bssmap_screening();
4055
4056 setverdict(pass);
4057}
4058testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004059 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004060 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004061 f_init(1, true);
4062 pars := f_init_pars(11816, true);
4063 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004064 vc_conn.done;
4065}
4066
4067/* Trigger a paging request via VTY and send a paging reject that indicates
4068 * that the subscriber intentionally rejected the call. */
4069private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4070runs on BSC_ConnHdlr {
4071 f_init_handler(pars);
4072 f_sgs_perform_lu();
4073 f_sleep(1.0);
4074
4075 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4076 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4077 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4078 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4079
4080 /* Initiate paging via VTY */
4081 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4082 alt {
4083 [] SGsAP.receive(exp_resp) {
4084 setverdict(pass);
4085 }
4086 [] SGsAP.receive {
4087 setverdict(fail, "Received unexpected message on SGs");
4088 }
4089 }
4090
4091 /* Now reject the paging */
4092 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4093
4094 /* Wait for the states inside the MSC to settle and check the state
4095 * of the SGs Association */
4096 f_sleep(1.0);
4097 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4098
4099 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4100 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4101 * to check back how this works and how it can be tested */
4102
4103 f_sgsap_bssmap_screening();
4104
4105 setverdict(pass);
4106}
4107testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004108 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004109 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004110 f_init(1, true);
4111 pars := f_init_pars(11817, true);
4112 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004113 vc_conn.done;
4114}
4115
4116/* Trigger a paging request via VTY and send an UE unreacable messge in response */
4117private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
4118runs on BSC_ConnHdlr {
4119 f_init_handler(pars);
4120 f_sgs_perform_lu();
4121 f_sleep(1.0);
4122
4123 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4124 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4125 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4126 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4127
4128 /* Initiate paging via VTY */
4129 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4130 alt {
4131 [] SGsAP.receive(exp_resp) {
4132 setverdict(pass);
4133 }
4134 [] SGsAP.receive {
4135 setverdict(fail, "Received unexpected message on SGs");
4136 }
4137 }
4138
4139 /* Now pretend that the UE is unreachable */
4140 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
4141
4142 /* Wait for the states inside the MSC to settle and check the state
4143 * of the SGs Association. */
4144 f_sleep(1.0);
4145 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4146
4147 f_sgsap_bssmap_screening();
4148
4149 setverdict(pass);
4150}
4151testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004152 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004153 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004154 f_init(1, true);
4155 pars := f_init_pars(11818, true);
4156 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004157 vc_conn.done;
4158}
4159
4160/* Trigger a paging request via VTY but don't respond to it */
4161private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
4162runs on BSC_ConnHdlr {
4163 f_init_handler(pars);
4164 f_sgs_perform_lu();
4165 f_sleep(1.0);
4166
4167 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4168 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4169 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4170 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4171
4172 /* Initiate paging via VTY */
4173 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4174 alt {
4175 [] SGsAP.receive(exp_resp) {
4176 setverdict(pass);
4177 }
4178 [] SGsAP.receive {
4179 setverdict(fail, "Received unexpected message on SGs");
4180 }
4181 }
4182
4183 /* Now do nothing, the MSC/VLR should fail silently to page after a
4184 * few seconds, The SGs association must remain unchanged. */
4185 f_sleep(15.0);
4186 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4187
4188 f_sgsap_bssmap_screening();
4189
4190 setverdict(pass);
4191}
4192testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004193 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004194 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004195 f_init(1, true);
4196 pars := f_init_pars(11819, true);
4197 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004198 vc_conn.done;
4199}
4200
4201/* Trigger a paging request via VTY and slip in an LU */
4202private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4203runs on BSC_ConnHdlr {
4204 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4205 f_init_handler(pars);
4206
4207 /* First we prepar the situation, where the SGs association is in state
4208 * NULL and the confirmed by radio contact indicator is set to false
4209 * as well. This can be archived by performing an SGs LU and then
4210 * resetting the VLR */
4211 f_sgs_perform_lu();
4212 f_sgsap_reset_mme(mp_mme_name);
4213 f_sleep(1.0);
4214 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4215
4216 /* Perform a paging, expect the paging messages on the SGs interface */
4217 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4218 alt {
4219 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4220 setverdict(pass);
4221 }
4222 [] SGsAP.receive {
4223 setverdict(fail, "Received unexpected message on SGs");
4224 }
4225 }
4226
4227 /* Perform the LU as normal */
4228 f_sgs_perform_lu();
4229 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4230
4231 /* Expect a new paging request right after the LU */
4232 alt {
4233 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4234 setverdict(pass);
4235 }
4236 [] SGsAP.receive {
4237 setverdict(fail, "Received unexpected message on SGs");
4238 }
4239 }
4240
4241 /* Test is done now, lets round everything up by rejecting the paging
4242 * cleanly. */
4243 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4244 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4245
4246 f_sgsap_bssmap_screening();
4247
4248 setverdict(pass);
4249}
4250testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004251 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004252 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004253 f_init(1, true);
4254 pars := f_init_pars(11820, true);
4255 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004256 vc_conn.done;
4257}
4258
4259/* Send unexpected unit-data through the SGs interface */
4260private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4261 f_init_handler(pars);
4262 f_sleep(1.0);
4263
4264 /* This simulates what happens when a subscriber without SGs
4265 * association gets unitdata via the SGs interface. */
4266
4267 /* Make sure the subscriber exists and the SGs association
4268 * is in NULL state */
4269 f_perform_lu();
4270 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4271
4272 /* Send some random unit data, the MSC/VLR should send a release
4273 * immediately. */
4274 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4275 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
4276
4277 f_sgsap_bssmap_screening();
4278
4279 setverdict(pass);
4280}
4281testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004282 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004283 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004284 f_init(1, true);
4285 pars := f_init_pars(11821, true);
4286 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004287 vc_conn.done;
4288}
4289
4290/* Send unsolicited unit-data through the SGs interface */
4291private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4292 f_init_handler(pars);
4293 f_sleep(1.0);
4294
4295 /* This simulates what happens when the MME attempts to send unitdata
4296 * to a subscriber that is completely unknown to the VLR */
4297
4298 /* Send some random unit data, the MSC/VLR should send a release
4299 * immediately. */
4300 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4301 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
4302
4303 f_sgsap_bssmap_screening();
4304
4305 setverdict(pass);
4306}
4307testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004308 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004309 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004310 f_init(1, true);
4311 pars := f_init_pars(11822, true);
4312 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004313 vc_conn.done;
4314}
4315
4316private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
4317 /* FIXME: Match an actual payload (second questionmark), the type is
4318 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
4319 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
4320 setverdict(fail, "Unexpected SMS related PDU from MSC");
4321 mtc.stop;
4322 }
4323}
4324
4325/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
4326function f_mt_sms_sgs(inout SmsParameters spars)
4327runs on BSC_ConnHdlr {
4328 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4329 var template (value) RPDU_MS_SGSN rp_mo;
4330 var template (value) PDU_ML3_MS_NW l3_mo;
4331
4332 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4333 var template RPDU_SGSN_MS rp_mt;
4334 var template PDU_ML3_NW_MS l3_mt;
4335
4336 var PDU_ML3_NW_MS sgsap_l3_mt;
4337
4338 var default d := activate(as_other_sms_sgs());
4339
4340 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
4341 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
4342 rp_mt := tr_RP_DATA_MT(?, ?, omit, tp_mt);
4343 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
4344
4345 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
4346
4347 /* Extract relevant identifiers */
4348 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
4349 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
4350
4351 /* send CP-ACK for CP-DATA just received */
4352 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
4353
4354 SGsAP.send(l3_mo);
4355
4356 /* send RP-ACK for RP-DATA */
4357 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
4358 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
4359
4360 SGsAP.send(l3_mo);
4361
4362 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
4363 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
4364
4365 SGsAP.receive(l3_mt);
4366
4367 deactivate(d);
4368
4369 setverdict(pass);
4370}
4371
4372/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
4373function f_mo_sms_sgs(inout SmsParameters spars)
4374runs on BSC_ConnHdlr {
4375 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4376 var template (value) RPDU_MS_SGSN rp_mo;
4377 var template (value) PDU_ML3_MS_NW l3_mo;
4378
4379 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4380 var template RPDU_SGSN_MS rp_mt;
4381 var template PDU_ML3_NW_MS l3_mt;
4382
4383 var default d := activate(as_other_sms_sgs());
4384
4385 /* just in case this is routed to SMPP.. */
4386 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
4387
4388 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
4389 spars.tp.udl, spars.tp.ud);
4390 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, spars.rp.orig, spars.rp.dest, tp_mo);
4391 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
4392
4393 SGsAP.send(l3_mo);
4394
4395 /* receive CP-ACK for CP-DATA above */
4396 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
4397
4398 if (ispresent(spars.exp_rp_err)) {
4399 /* expect an RP-ERROR message from MSC with given cause */
4400 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
4401 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4402 SGsAP.receive(l3_mt);
4403 /* send CP-ACK for CP-DATA just received */
4404 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4405 SGsAP.send(l3_mo);
4406 } else {
4407 /* expect RP-ACK for RP-DATA */
4408 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
4409 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4410 SGsAP.receive(l3_mt);
4411 /* send CP-ACO for CP-DATA just received */
4412 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4413 SGsAP.send(l3_mo);
4414 }
4415
4416 deactivate(d);
4417
4418 setverdict(pass);
4419}
4420
4421private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
4422runs on BSC_ConnHdlr {
4423 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
4424}
4425
4426/* Send a MT SMS via SGs interface */
4427private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4428 f_init_handler(pars);
4429 f_sgs_perform_lu();
4430 f_sleep(1.0);
4431 var SmsParameters spars := valueof(t_SmsPars);
4432 spars.tp.ud := 'C8329BFD064D9B53'O;
4433
4434 /* Trigger SMS via VTY */
4435 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4436 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4437
4438 /* Expect a paging request and respond accordingly with a service request */
4439 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
4440 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
4441
4442 /* Connection is now live, receive the MT-SMS */
4443 f_mt_sms_sgs(spars);
4444
4445 /* Expect a concluding release from the MSC */
4446 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4447
4448 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4449 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4450
4451 f_sgsap_bssmap_screening();
4452
4453 setverdict(pass);
4454}
4455testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004456 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004457 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004458 f_init(1, true);
4459 pars := f_init_pars(11823, true);
4460 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004461 vc_conn.done;
4462}
4463
4464/* Send a MO SMS via SGs interface */
4465private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4466 f_init_handler(pars);
4467 f_sgs_perform_lu();
4468 f_sleep(1.0);
4469 var SmsParameters spars := valueof(t_SmsPars);
4470 spars.tp.ud := 'C8329BFD064D9B53'O;
4471
4472 /* Send the MO-SMS */
4473 f_mo_sms_sgs(spars);
4474
4475 /* Expect a concluding release from the MSC/VLR */
4476 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4477
4478 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4479 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4480
4481 setverdict(pass);
4482
4483 f_sgsap_bssmap_screening()
4484}
4485testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004486 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004487 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004488 f_init(1, true);
4489 pars := f_init_pars(11824, true);
4490 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004491 vc_conn.done;
4492}
4493
4494/* Trigger sending of an MT sms via VTY but never respond to anything */
4495private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4496 f_init_handler(pars, 170.0);
4497 f_sgs_perform_lu();
4498 f_sleep(1.0);
4499
4500 var SmsParameters spars := valueof(t_SmsPars);
4501 spars.tp.ud := 'C8329BFD064D9B53'O;
4502 var integer page_count := 0;
4503 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4504 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4505 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4506 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4507
4508 /* Trigger SMS via VTY */
4509 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4510
Neels Hofmeyr16237742019-03-06 15:34:01 +01004511 /* Expect the MSC/VLR to page exactly once */
4512 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01004513
4514 /* Wait some time to make sure the MSC is not delivering any further
4515 * paging messages or anything else that could be unexpected. */
4516 timer T := 20.0;
4517 T.start
4518 alt {
4519 [] SGsAP.receive(exp_pag_req)
4520 {
4521 setverdict(fail, "paging seems not to stop!");
4522 mtc.stop;
4523 }
4524 [] SGsAP.receive {
4525 setverdict(fail, "unexpected SGsAP message received");
4526 self.stop;
4527 }
4528 [] T.timeout {
4529 setverdict(pass);
4530 }
4531 }
4532
4533 /* Even on a failed paging the SGs Association should stay intact */
4534 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4535
4536 /* Note: We do not execute f_sgsap_bssmap_screening() here since the
4537 * MSC/VLR would re-try to deliver the test SMS trigered above and
4538 * so the screening would fail. */
4539
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01004540 f_vty_sms_clear(hex2str(g_pars.imsi));
4541
Harald Welte4263c522018-12-06 11:56:27 +01004542 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
4543
4544 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01004545
4546 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01004547}
4548testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004549 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004550 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004551 f_init(1, true);
4552 pars := f_init_pars(11825, true);
4553 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004554 vc_conn.done;
4555}
4556
4557/* Trigger sending of an MT sms via VTY but reject the paging immediately */
4558private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4559 f_init_handler(pars, 150.0);
4560 f_sgs_perform_lu();
4561 f_sleep(1.0);
4562
4563 var SmsParameters spars := valueof(t_SmsPars);
4564 spars.tp.ud := 'C8329BFD064D9B53'O;
4565 var integer page_count := 0;
4566 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4567 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4568 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4569 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4570
4571 /* Trigger SMS via VTY */
4572 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4573
4574 /* Expect a paging request and reject it immediately */
4575 SGsAP.receive(exp_pag_req);
4576 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4577
4578 /* The MSC/VLR should no longer try to page once the paging has been
4579 * rejected. Wait some time and check if there are no unexpected
4580 * messages on the SGs interface. */
4581 timer T := 20.0;
4582 T.start
4583 alt {
4584 [] SGsAP.receive(exp_pag_req)
4585 {
4586 setverdict(fail, "paging seems not to stop!");
4587 mtc.stop;
4588 }
4589 [] SGsAP.receive {
4590 setverdict(fail, "unexpected SGsAP message received");
4591 self.stop;
4592 }
4593 [] T.timeout {
4594 setverdict(pass);
4595 }
4596 }
4597
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01004598 f_vty_sms_clear(hex2str(g_pars.imsi));
4599
Harald Welte4263c522018-12-06 11:56:27 +01004600 /* A rejected paging with IMSI_unknown (see above) should always send
4601 * the SGs association to NULL. */
4602 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4603
4604 f_sgsap_bssmap_screening();
4605
Harald Welte4263c522018-12-06 11:56:27 +01004606 setverdict(pass);
4607}
4608testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004609 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004610 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004611 f_init(1, true);
4612 pars := f_init_pars(11826, true);
4613 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004614 vc_conn.done;
4615}
4616
4617/* Perform an MT CSDB call including LU */
4618private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
4619 f_init_handler(pars);
4620
4621 /* Be sure that the BSSMAP reset is done before we begin. */
4622 f_sleep(2.0);
4623
4624 /* Testcase variation: See what happens when we do a regular BSSMAP
4625 * LU first (this should not hurt in any way!) */
4626 if (bssmap_lu) {
4627 f_perform_lu();
4628 }
4629
4630 f_sgs_perform_lu();
4631 f_sleep(1.0);
4632
4633 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4634 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
4635 cpars.bss_rtp_port := 1110;
4636 cpars.mgcp_connection_id_bss := '10004'H;
4637 cpars.mgcp_connection_id_mss := '10005'H;
4638
4639 /* Note: This is an optional parameter. When the call-agent (MSC) does
4640 * supply a full endpoint name this setting will be overwritten. */
4641 cpars.mgcp_ep := "rtpbridge/1@mgw";
4642
4643 /* Initiate a call via MNCC interface */
4644 f_mt_call_initate(cpars);
4645
4646 /* Expect a paging request and respond accordingly with a service request */
4647 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
4648 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
4649
4650 /* Complete the call, hold it for some time and then tear it down */
4651 f_mt_call_complete(cpars);
4652 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01004653 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01004654
4655 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4656 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4657
4658 /* Finally simulate the return of the UE to the 4G network */
4659 SGsAP.send(ts_SGsAP_MO_CSFB_IND(pars.imsi));
4660
4661 /* Test for successful return by triggering a paging, when the paging
4662 * request is received via SGs, we can be sure that the MSC/VLR has
4663 * recognized that the UE is now back on 4G */
4664 f_sleep(1.0);
4665 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4666 alt {
4667 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4668 setverdict(pass);
4669 }
4670 [] SGsAP.receive {
4671 setverdict(fail, "Received unexpected message on SGs");
4672 }
4673 }
4674
4675 f_sgsap_bssmap_screening();
4676
4677 setverdict(pass);
4678}
4679
4680/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
4681private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4682 f_mt_lu_and_csfb_call(id, pars, true);
4683}
4684testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004685 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004686 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004687 f_init(1, true);
4688 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01004689
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004690 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004691 vc_conn.done;
4692}
4693
4694
4695/* Perform a SGSAP LU and then make a CSFB call */
4696private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4697 f_mt_lu_and_csfb_call(id, pars, false);
4698}
4699testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004700 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004701 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004702 f_init(1, true);
4703 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01004704
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004705 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004706 vc_conn.done;
4707}
4708
Philipp Maier628c0052019-04-09 17:36:57 +02004709/* Simulate an HLR/VLR failure */
4710private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4711 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4712 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4713
4714 var PDU_SGsAP lur;
4715
4716 f_init_handler(pars);
4717
4718 /* Attempt location update (which is expected to fail) */
4719 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4720 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4721 SGsAP.send(lur);
4722
4723 /* Respond to SGsAP-RESET-INDICATION from VLR */
4724 alt {
4725 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
4726 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
4727 setverdict(pass);
4728 }
4729 [] SGsAP.receive {
4730 setverdict(fail, "Received unexpected message on SGs");
4731 }
4732 }
4733
4734 f_sleep(1.0);
4735 setverdict(pass);
4736}
4737testcase TC_sgsap_vlr_failure() runs on MTC_CT {
4738 var BSC_ConnHdlrPars pars;
4739 var BSC_ConnHdlr vc_conn;
4740 f_init(1, true, false);
4741 pars := f_init_pars(11811, true, false);
4742 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
4743 vc_conn.done;
4744}
4745
Harald Welte4263c522018-12-06 11:56:27 +01004746/* SGs TODO:
4747 * LU attempt for IMSI without NAM_PS in HLR
4748 * LU attempt with AUTH FAIL due to invalid RES/SRES
4749 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
4750 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
4751 * implicit IMSI detach from EPS
4752 * implicit IMSI detach from non-EPS
4753 * MM INFO
4754 *
4755 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004756
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02004757private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4758 f_init_handler(pars);
4759 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
4760 cpars.bss_rtp_port := 1110;
4761 cpars.mgcp_connection_id_bss := '22222'H;
4762 cpars.mgcp_connection_id_mss := '33333'H;
4763 cpars.mgcp_ep := "rtpbridge/1@mgw";
4764 cpars.mo_call := true;
4765
4766 f_perform_lu();
4767 f_mo_call_establish(cpars);
4768
4769 f_sleep(1.0);
4770
4771 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
4772 var BssmapCause cause := enum2int(cause_val);
4773
4774 var template BSSMAP_FIELD_CellIdentificationList cil;
4775 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
4776
4777 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
4778 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
4779
4780 f_call_hangup(cpars, true);
4781}
4782testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
4783 var BSC_ConnHdlr vc_conn;
4784 f_init();
4785
4786 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
4787 vc_conn.done;
4788}
4789
4790private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
4791 var MgcpCommand mgcp_cmd;
4792 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
4793 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_rtp_ip_mss, cpars.mgw_rtp_ip_mss,
4794 hex2str(cpars.mgcp_call_id), "42",
4795 cpars.mgw_rtp_port_mss,
4796 { int2str(cpars.rtp_payload_type) },
4797 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
4798 cpars.rtp_sdp_format)),
4799 valueof(ts_SDP_ptime(20)) }));
4800 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgcp_connection_id_mss, sdp));
4801 repeat;
4802 }
4803}
4804
4805private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4806 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
4807 cpars.bss_rtp_port := 1110;
4808 cpars.mgcp_connection_id_bss := '22222'H;
4809 cpars.mgcp_connection_id_mss := '33333'H;
4810 cpars.mgcp_ep := "rtpbridge/1@mgw";
4811 cpars.mo_call := true;
4812
4813 f_init_handler(pars);
4814
4815 f_vty_transceive(MSCVTY, "configure terminal");
4816 f_vty_transceive(MSCVTY, "msc");
4817 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
4818 f_vty_transceive(MSCVTY, "neighbor a lac 5 ran-pc 0.24.2");
4819 f_vty_transceive(MSCVTY, "exit");
4820 f_vty_transceive(MSCVTY, "exit");
4821
4822 f_perform_lu();
4823 f_mo_call_establish(cpars);
4824
4825 f_sleep(1.0);
4826
4827 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
4828
4829 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
4830 var BssmapCause cause := enum2int(cause_val);
4831
4832 var template BSSMAP_FIELD_CellIdentificationList cil;
4833 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 5) } };
4834
4835 /* old BSS sends Handover Required */
4836 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
4837
4838 /* Now the action goes on in f_tc_ho_inter_bsc1() */
4839
4840 /* MSC forwards the RR Handover Command to old BSS */
4841 var PDU_BSSAP ho_command;
4842 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
4843
4844 log("GOT HandoverCommand", ho_command);
4845
4846 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
4847
4848 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
4849 f_expect_clear();
4850
4851 log("FIRST inter-BSC Handover done");
4852
4853
4854 /* ------------------------ */
4855
4856 /* Ok, that went well, now the other BSC is handovering back here --
4857 * from now on this here is the new BSS. */
4858 f_create_bssmap_exp_handoverRequest(193);
4859
4860 var PDU_BSSAP ho_request;
4861 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
4862
4863 /* new BSS composes a RR Handover Command */
4864 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
4865 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
4866 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
4867 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
4868 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
4869
4870 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
4871
4872 f_sleep(0.5);
4873
4874 /* Notify that the MS is now over here */
4875
4876 BSSAP.send(ts_BSSMAP_HandoverDetect);
4877 f_sleep(0.1);
4878 BSSAP.send(ts_BSSMAP_HandoverComplete);
4879
4880 f_sleep(3.0);
4881
4882 deactivate(ack_mdcx);
4883
4884 var default ccrel := activate(as_optional_cc_rel(cpars, true));
4885
4886 /* blatant cheating */
4887 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
4888 last_n_sd[0] := 3;
4889 f_bssmap_continue_after_n_sd(last_n_sd);
4890
4891 f_call_hangup(cpars, true);
4892 f_sleep(1.0);
4893 deactivate(ccrel);
4894
4895 setverdict(pass);
4896}
4897private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4898 f_init_handler(pars);
4899 f_create_bssmap_exp_handoverRequest(194);
4900
4901 var PDU_BSSAP ho_request;
4902 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
4903
4904 /* new BSS composes a RR Handover Command */
4905 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
4906 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
4907 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
4908 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
4909 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
4910
4911 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
4912
4913 f_sleep(0.5);
4914
4915 /* Notify that the MS is now over here */
4916
4917 BSSAP.send(ts_BSSMAP_HandoverDetect);
4918 f_sleep(0.1);
4919 BSSAP.send(ts_BSSMAP_HandoverComplete);
4920
4921 f_sleep(3.0);
4922
4923 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
4924 * ... handover back to the first BSC :P */
4925
4926 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
4927 var BssmapCause cause := enum2int(cause_val);
4928
4929 var template BSSMAP_FIELD_CellIdentificationList cil;
4930 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('262'H, '42'H, 23) } };
4931
4932 /* old BSS sends Handover Required */
4933 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
4934
4935 /* Now the action goes on in f_tc_ho_inter_bsc0() */
4936
4937 /* MSC forwards the RR Handover Command to old BSS */
4938 var PDU_BSSAP ho_command;
4939 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
4940
4941 log("GOT HandoverCommand", ho_command);
4942
4943 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
4944
4945 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
4946 f_expect_clear();
4947 setverdict(pass);
4948}
4949testcase TC_ho_inter_bsc() runs on MTC_CT {
4950 var BSC_ConnHdlr vc_conn0;
4951 var BSC_ConnHdlr vc_conn1;
4952 f_init(2);
4953
4954 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
4955 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
4956
4957 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0, 0);
4958 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1, 1);
4959 vc_conn0.done;
4960 vc_conn1.done;
4961}
4962
4963function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
4964 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
4965 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
4966 log("MS_NW patched enc_l3: ", enc_l3);
4967}
4968
4969private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4970 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
4971 cpars.bss_rtp_port := 1110;
4972 cpars.mgcp_connection_id_bss := '22222'H;
4973 cpars.mgcp_connection_id_mss := '33333'H;
4974 cpars.mgcp_ep := "rtpbridge/1@mgw";
4975 cpars.mo_call := true;
4976 var hexstring ho_number := f_gen_msisdn(99999);
4977
4978 f_init_handler(pars);
4979
4980 f_create_mncc_expect(hex2str(ho_number));
4981
4982 f_vty_transceive(MSCVTY, "configure terminal");
4983 f_vty_transceive(MSCVTY, "msc");
4984 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
4985 f_vty_transceive(MSCVTY, "exit");
4986 f_vty_transceive(MSCVTY, "exit");
4987
4988 f_perform_lu();
4989 f_mo_call_establish(cpars);
4990
4991 f_sleep(1.0);
4992
4993 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
4994
4995 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
4996 var BssmapCause cause := enum2int(cause_val);
4997
4998 var template BSSMAP_FIELD_CellIdentificationList cil;
4999 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('017'H, '017'H, 1) } };
5000
5001 /* old BSS sends Handover Required */
5002 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5003
5004 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
5005 * This MSC tries to reach the other MSC via GSUP. */
5006
5007 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
5008 var GSUP_PDU prep_ho_req;
5009 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
5010 pars.imsi, destination_name := remote_msc_name)) -> value prep_ho_req;
5011
5012 var GSUP_IeValue source_name_ie;
5013 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
5014 var octetstring local_msc_name := source_name_ie.source_name;
5015
5016 /* Remote MSC has figured out its BSC and signals success */
5017 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5018 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5019 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5020 aoIPTransportLayer := omit,
5021 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5022 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
5023 pars.imsi,
5024 ho_number,
5025 remote_msc_name, local_msc_name,
5026 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
5027
5028 /* MSC forwards the RR Handover Command to old BSS */
5029 BSSAP.receive(tr_BSSMAP_HandoverCommand);
5030
5031 /* The MS shows up at remote new BSS */
5032
5033 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5034 pars.imsi, remote_msc_name, local_msc_name,
5035 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5036 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
5037 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5038 f_sleep(0.1);
5039
5040 /* Save the MS sequence counters for use on the other connection */
5041 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5042
5043 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
5044 pars.imsi, remote_msc_name, local_msc_name,
5045 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5046 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
5047
5048 /* The local BSS conn clears, all communication goes via remote MSC now */
5049 f_expect_clear();
5050
5051 /**********************************/
5052 /* Play through some signalling across the inter-MSC link.
5053 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
5054
5055 if (false) {
5056 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
5057 invoke_id := 5, /* Phone may not start from 0 or 1 */
5058 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5059 ussd_string := "*#100#"
5060 );
5061
5062 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
5063 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
5064 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5065 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
5066 )
5067
5068 /* Compose a new SS/REGISTER message with request */
5069 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
5070 tid := 1, /* We just need a single transaction */
5071 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
5072 facility := valueof(facility_req)
5073 );
5074 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
5075
5076 /* Compose SS/RELEASE_COMPLETE template with expected response */
5077 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
5078 tid := 1, /* Response should arrive within the same transaction */
5079 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
5080 facility := valueof(facility_rsp)
5081 );
5082
5083 /* Compose expected MSC -> HLR message */
5084 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
5085 imsi := g_pars.imsi,
5086 state := OSMO_GSUP_SESSION_STATE_BEGIN,
5087 ss := valueof(facility_req)
5088 );
5089
5090 /* To be used for sending response with correct session ID */
5091 var GSUP_PDU gsup_req_complete;
5092
5093 /* Request own number */
5094 /* From remote MSC instead of BSSAP directly */
5095 /* Patch the correct N_SD value into the message. */
5096 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
5097 var RAN_Emulation.ConnectionData cd;
5098 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
5099 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5100 pars.imsi, remote_msc_name, local_msc_name,
5101 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5102 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
5103 ))
5104 ));
5105
5106 /* Expect GSUP message containing the SS payload */
5107 gsup_req_complete := f_expect_gsup_msg(gsup_req);
5108
5109 /* Compose the response from HLR using received session ID */
5110 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
5111 imsi := g_pars.imsi,
5112 sid := gsup_req_complete.ies[1].val.session_id,
5113 state := OSMO_GSUP_SESSION_STATE_END,
5114 ss := valueof(facility_rsp)
5115 );
5116
5117 /* Finally, HLR terminates the session */
5118 GSUP.send(gsup_rsp);
5119
5120 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
5121 var GSUP_PDU gsup_ussd_rsp;
5122 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5123 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
5124
5125 var GSUP_IeValue an_apdu;
5126 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
5127 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5128 mtc.stop;
5129 }
5130 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
5131 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
5132 log("Expecting", ussd_rsp);
5133 log("Got", dtap_mt);
5134 if (not match(dtap_mt, ussd_rsp)) {
5135 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5136 mtc.stop;
5137 }
5138 }
5139 /**********************************/
5140
5141
5142 /* inter-MSC handover back to the first MSC */
5143 f_create_bssmap_exp_handoverRequest(193);
5144 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
5145
5146 /* old BSS sends Handover Required, via inter-MSC E link: like
5147 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5148 * but via GSUP */
5149 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
5150 pars.imsi, remote_msc_name, local_msc_name,
5151 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5152 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
5153 ))
5154 ));
5155
5156 /* MSC asks local BSS to prepare Handover to it */
5157 BSSAP.receive(tr_BSSMAP_HandoverRequest);
5158
5159 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
5160 f_bssmap_continue_after_n_sd(last_n_sd);
5161
5162 /* new BSS composes a RR Handover Command */
5163 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5164 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5165 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5166 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5167 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5168
5169 /* HandoverCommand goes out via remote MSC-I */
5170 var GSUP_PDU prep_subsq_ho_res;
5171 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
5172 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
5173
5174 /* MS shows up at the local BSS */
5175 BSSAP.send(ts_BSSMAP_HandoverDetect);
5176 f_sleep(0.1);
5177 BSSAP.send(ts_BSSMAP_HandoverComplete);
5178
5179 /* Handover Succeeded message */
5180 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5181 pars.imsi, destination_name := remote_msc_name));
5182
5183 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
5184 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
5185 pars.imsi, destination_name := remote_msc_name));
5186
5187 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
5188
5189 f_sleep(1.0);
5190 deactivate(ack_mdcx);
5191
5192 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
5193 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
5194 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
5195 MNCC.clear;
5196
5197 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5198 f_call_hangup(cpars, true);
5199 f_sleep(1.0);
5200 deactivate(ccrel);
5201
5202 setverdict(pass);
5203}
5204testcase TC_ho_inter_msc_out() runs on MTC_CT {
5205 var BSC_ConnHdlr vc_conn;
5206 f_init(1);
5207
5208 var BSC_ConnHdlrPars pars := f_init_pars(54);
5209
5210 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5211 vc_conn.done;
5212}
5213
5214
Harald Weltef6dd64d2017-11-19 12:09:51 +01005215control {
Philipp Maier328d1662018-03-07 10:40:27 +01005216 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01005217 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01005218 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01005219 execute( TC_lu_imsi_reject() );
5220 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01005221 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02005222 execute( TC_lu_imsi_auth3g_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01005223 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01005224 execute( TC_lu_and_mo_call() );
Harald Welte071ed732018-01-23 19:53:52 +01005225 execute( TC_lu_auth_sai_timeout() );
5226 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01005227 execute( TC_lu_clear_request() );
5228 execute( TC_lu_disconnect() );
5229 execute( TC_lu_by_imei() );
5230 execute( TC_lu_by_tmsi_noauth_unknown() );
5231 execute( TC_imsi_detach_by_imsi() );
5232 execute( TC_imsi_detach_by_tmsi() );
5233 execute( TC_imsi_detach_by_imei() );
5234 execute( TC_emerg_call_imei_reject() );
5235 execute( TC_emerg_call_imsi() );
5236 execute( TC_cm_serv_req_vgcs_reject() );
5237 execute( TC_cm_serv_req_vbs_reject() );
5238 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01005239 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01005240 execute( TC_lu_auth_2G_fail() );
5241 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
5242 execute( TC_cl3_no_payload() );
5243 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01005244 execute( TC_establish_and_nothing() );
5245 execute( TC_mo_setup_and_nothing() );
5246 execute( TC_mo_crcx_ran_timeout() );
5247 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01005248 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01005249 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01005250 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01005251 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01005252 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
5253 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
5254 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01005255 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01005256 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
5257 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01005258 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01005259 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02005260 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01005261
5262 execute( TC_lu_and_mt_call() );
5263
Harald Weltef45efeb2018-04-09 18:19:24 +02005264 execute( TC_lu_and_mo_sms() );
5265 execute( TC_lu_and_mt_sms() );
Philipp Maier3983e702018-11-22 19:01:33 +01005266 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Harald Weltef640a012018-04-14 17:49:21 +02005267 execute( TC_smpp_mo_sms() );
5268 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02005269
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07005270 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07005271 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07005272 execute( TC_gsup_mt_sms_ack() );
5273 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07005274 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07005275 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07005276
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07005277 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07005278 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07005279 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07005280 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07005281 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07005282 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07005283
Stefan Sperling89eb1f32018-12-17 15:06:20 +01005284 execute( TC_cipher_complete_with_invalid_cipher() );
5285
Harald Welte4263c522018-12-06 11:56:27 +01005286 execute( TC_sgsap_reset() );
5287 execute( TC_sgsap_lu() );
5288 execute( TC_sgsap_lu_imsi_reject() );
5289 execute( TC_sgsap_lu_and_nothing() );
5290 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01005291 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01005292 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01005293 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01005294 execute( TC_sgsap_paging_rej() );
5295 execute( TC_sgsap_paging_subscr_rej() );
5296 execute( TC_sgsap_paging_ue_unr() );
5297 execute( TC_sgsap_paging_and_nothing() );
5298 execute( TC_sgsap_paging_and_lu() );
5299 execute( TC_sgsap_mt_sms() );
5300 execute( TC_sgsap_mo_sms() );
5301 execute( TC_sgsap_mt_sms_and_nothing() );
5302 execute( TC_sgsap_mt_sms_and_reject() );
5303 execute( TC_sgsap_unexp_ud() );
5304 execute( TC_sgsap_unsol_ud() );
5305 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
5306 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02005307 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01005308
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005309 execute( TC_ho_inter_bsc_unknown_cell() );
5310 execute( TC_ho_inter_bsc() );
5311
5312 execute( TC_ho_inter_msc_out() );
5313
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01005314 /* Run this last: at the time of writing this test crashes the MSC */
5315 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Philipp Maierdb7fb8d2019-02-11 10:50:13 +01005316 execute( TC_gsup_mt_multi_part_sms() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02005317 execute( TC_mo_cc_bssmap_clear() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01005318}
5319
5320
5321}