blob: b00e032eda94ab55deb507dee3bbafd2b6ef12b5 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
19
20import from M3UA_Types all;
21import from M3UA_Emulation all;
22
23import from MTP3asp_Types all;
24import from MTP3asp_PortType all;
25
26import from SCCPasp_Types all;
27import from SCCP_Types all;
28import from SCCP_Emulation all;
29
30import from SCTPasp_Types all;
31import from SCTPasp_PortType all;
32
Harald Weltea49e36e2018-01-21 19:29:33 +010033import from Osmocom_CTRL_Functions all;
34import from Osmocom_CTRL_Types all;
35import from Osmocom_CTRL_Adapter all;
36
Harald Welte3ca1c902018-01-24 18:51:27 +010037import from TELNETasp_PortType all;
38import from Osmocom_VTY_Functions all;
39
Harald Weltea49e36e2018-01-21 19:29:33 +010040import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010041import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010042
Harald Welte4aa970c2018-01-26 10:38:09 +010043import from MGCP_Emulation all;
44import from MGCP_Types all;
45import from MGCP_Templates all;
46import from SDP_Types all;
47
Harald Weltea49e36e2018-01-21 19:29:33 +010048import from GSUP_Emulation all;
49import from GSUP_Types all;
50import from IPA_Emulation all;
51
Harald Weltef6dd64d2017-11-19 12:09:51 +010052import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020053import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010054import from BSSAP_CodecPort all;
55import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020056import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010057import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020058import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010059
Harald Welte4263c522018-12-06 11:56:27 +010060import from SGsAP_Templates all;
61import from SGsAP_Types all;
62import from SGsAP_Emulation all;
63
Harald Weltea49e36e2018-01-21 19:29:33 +010064import from MobileL3_Types all;
65import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070066import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010067import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010068import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010069
Harald Weltef640a012018-04-14 17:49:21 +020070import from SMPP_Types all;
71import from SMPP_Templates all;
72import from SMPP_Emulation all;
73
Stefan Sperlingc307e682018-06-14 15:15:46 +020074import from SCCP_Templates all;
75
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070076import from SS_Types all;
77import from SS_Templates all;
78import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010079import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070080
Philipp Maier948747b2019-04-02 15:22:33 +020081import from TCCConversion_Functions all;
82
Harald Welte9b751a62019-04-14 17:39:29 +020083const integer NUM_BSC := 3;
Harald Welte6811d102019-04-14 22:23:14 +020084type record of RAN_Configuration RAN_Configurations;
Harald Weltef6dd64d2017-11-19 12:09:51 +010085
Harald Welte4263c522018-12-06 11:56:27 +010086/* Needed for SGsAP SMS */
87import from MobileL3_SMS_Types all;
88
Harald Weltea4ca4462018-02-09 00:17:14 +010089type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010090 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010091
Harald Welte6811d102019-04-14 22:23:14 +020092 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010093
Harald Weltea49e36e2018-01-21 19:29:33 +010094 /* no 'adapter_CT' for MNCC or GSUP */
95 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010096 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010097 var GSUP_Emulation_CT vc_GSUP;
98 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020099 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +0100100 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100101
102 /* only to get events from IPA underneath GSUP */
103 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100104 /* VTY to MSC */
105 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100106
107 /* A port to directly send BSSAP messages. This port is used for
108 * tests that require low level access to sen arbitrary BSSAP
109 * messages. Run f_init_bssap_direct() to connect and initialize */
110 port BSSAP_CODEC_PT BSSAP_DIRECT;
111
112 /* When BSSAP messages are directly sent, then the connection
113 * handler is not active, which means that also no guard timer is
114 * set up. The following timer will serve as a replacement */
115 timer Tguard_direct := 60.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100116}
117
118modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100119 /* remote parameters of IUT */
120 charstring mp_msc_ip := "127.0.0.1";
121 integer mp_msc_ctrl_port := 4255;
122 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100123
Harald Weltea49e36e2018-01-21 19:29:33 +0100124 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100125 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100126 charstring mp_hlr_ip := "127.0.0.1";
127 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100128 charstring mp_mgw_ip := "127.0.0.1";
129 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100130
Harald Weltea49e36e2018-01-21 19:29:33 +0100131 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100132
Harald Weltef640a012018-04-14 17:49:21 +0200133 integer mp_msc_smpp_port := 2775;
134 charstring mp_smpp_system_id := "msc_tester";
135 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100136 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
137 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200138
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200139 /* Whether to enable osmux tests. Can be dropped completely and enable
140 unconditionally once new version of osmo-msc is released (current
141 version: 1.3.1) */
142 boolean mp_enable_osmux_test := true;
143
Harald Welte6811d102019-04-14 22:23:14 +0200144 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200145 {
146 sccp_service_type := "mtp3_itu",
147 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
148 own_pc := 185,
149 own_ssn := 254,
150 peer_pc := 187,
151 peer_ssn := 254,
152 sio := '83'O,
153 rctx := 0
154 },
155 {
156 sccp_service_type := "mtp3_itu",
157 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
158 own_pc := 186,
159 own_ssn := 254,
160 peer_pc := 187,
161 peer_ssn := 254,
162 sio := '83'O,
163 rctx := 1
164 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100165 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100166}
167
Philipp Maier328d1662018-03-07 10:40:27 +0100168/* altstep for the global guard timer (only used when BSSAP_DIRECT
169 * is used for communication */
170private altstep as_Tguard_direct() runs on MTC_CT {
171 [] Tguard_direct.timeout {
172 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200173 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100174 }
175}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100176
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100177private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
178 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
179 if (respond) {
180 var BIT1 tid_remote := '1'B;
181 if (cpars.mo_call) {
182 tid_remote := '0'B;
183 }
184 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
185 }
186 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100187}
188
Harald Weltef640a012018-04-14 17:49:21 +0200189function f_init_smpp(charstring id) runs on MTC_CT {
190 id := id & "-SMPP";
191 var EsmePars pars := {
192 mode := MODE_TRANSCEIVER,
193 bind := {
194 system_id := mp_smpp_system_id,
195 password := mp_smpp_password,
196 system_type := "MSC_Tests",
197 interface_version := hex2int('34'H),
198 addr_ton := unknown,
199 addr_npi := unknown,
200 address_range := ""
201 },
202 esme_role := true
203 }
204
205 vc_SMPP := SMPP_Emulation_CT.create(id);
206 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
207 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", -1));
208}
209
210
Harald Weltea49e36e2018-01-21 19:29:33 +0100211function f_init_mncc(charstring id) runs on MTC_CT {
212 id := id & "-MNCC";
213 var MnccOps ops := {
214 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
215 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
216 }
217
218 vc_MNCC := MNCC_Emulation_CT.create(id);
219 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
220 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100221}
222
Harald Welte4aa970c2018-01-26 10:38:09 +0100223function f_init_mgcp(charstring id) runs on MTC_CT {
224 id := id & "-MGCP";
225 var MGCPOps ops := {
226 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
227 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
228 }
229 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100230 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100231 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100232 mgw_ip := mp_mgw_ip,
233 mgw_udp_port := mp_mgw_port
Harald Welte4aa970c2018-01-26 10:38:09 +0100234 }
235
236 vc_MGCP := MGCP_Emulation_CT.create(id);
237 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
238 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
239}
240
Philipp Maierc09a1312019-04-09 16:05:26 +0200241function ForwardUnitdataCallback(PDU_SGsAP msg)
242runs on SGsAP_Emulation_CT return template PDU_SGsAP {
243 SGsAP_CLIENT.send(msg);
244 return omit;
245}
246
Harald Welte4263c522018-12-06 11:56:27 +0100247function f_init_sgsap(charstring id) runs on MTC_CT {
248 id := id & "-SGsAP";
249 var SGsAPOps ops := {
250 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200251 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100252 }
253 var SGsAP_conn_parameters pars := {
254 remote_ip := mp_msc_ip,
255 remote_sctp_port := 29118,
256 local_ip := "",
257 local_sctp_port := -1
258 }
259
260 vc_SGsAP := SGsAP_Emulation_CT.create(id);
261 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
262 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
263}
264
265
Harald Weltea49e36e2018-01-21 19:29:33 +0100266function f_init_gsup(charstring id) runs on MTC_CT {
267 id := id & "-GSUP";
268 var GsupOps ops := {
269 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
270 }
271
272 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
273 vc_GSUP := GSUP_Emulation_CT.create(id);
274
275 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
276 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
277 /* we use this hack to get events like ASP_IPA_EVENT_UP */
278 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
279
280 vc_GSUP.start(GSUP_Emulation.main(ops, id));
281 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
282
283 /* wait for incoming connection to GSUP port before proceeding */
284 timer T := 10.0;
285 T.start;
286 alt {
287 [] GSUP_IPA_EVENT.receive(t_ASP_IPA_EVT_UD(ASP_IPA_EVENT_UP)) { }
288 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100289 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200290 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100291 }
292 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100293}
294
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200295function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100296
297 if (g_initialized == true) {
298 return;
299 }
300 g_initialized := true;
301
Philipp Maier75932982018-03-27 14:52:35 +0200302 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200303 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200304 }
305
306 for (var integer i := 0; i < num_bsc; i := i + 1) {
307 if (isbound(mp_bssap_cfg[i])) {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200308 var RanOps ranops := BSC_RanOps;
309 ranops.use_osmux := osmux;
310 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
Harald Welte3ca0ce12019-04-23 17:18:48 +0200311 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200312 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200313 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200314 }
315 }
316
Harald Weltea49e36e2018-01-21 19:29:33 +0100317 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
318 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100319 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200320
321 if (gsup == true) {
322 f_init_gsup("MSC_Test");
323 }
Harald Weltef640a012018-04-14 17:49:21 +0200324 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100325
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100326 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100327 f_init_sgsap("MSC_Test");
328 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100329
330 map(self:MSCVTY, system:MSCVTY);
331 f_vty_set_prompts(MSCVTY);
332 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100333
334 /* set some defaults */
335 f_vty_config(MSCVTY, "network", "authentication optional");
336 f_vty_config(MSCVTY, "msc", "assign-tmsi");
337 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200338 if (mp_enable_osmux_test) {
339 if (osmux) {
340 f_vty_config(MSCVTY, "msc", "osmux on");
341 } else {
342 f_vty_config(MSCVTY, "msc", "osmux off");
343 }
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200344 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100345}
346
Philipp Maier328d1662018-03-07 10:40:27 +0100347/* Initialize for a direct connection to BSSAP. This function is an alternative
348 * to f_init() when the high level functions of the BSC_ConnectionHandler are
349 * not needed. */
350function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200351 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200352 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100353
354 /* Start guard timer and activate it as default */
355 Tguard_direct.start
356 activate(as_Tguard_direct());
357}
358
Harald Weltea49e36e2018-01-21 19:29:33 +0100359type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100360
Harald Weltea49e36e2018-01-21 19:29:33 +0100361/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200362function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200363 boolean ran_is_geran := true, boolean use_osmux := false)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200364runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100365 var BSC_ConnHdlrNetworkPars net_pars := {
366 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
367 expect_tmsi := true,
368 expect_auth := false,
369 expect_ciph := false
370 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100371 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200372 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
373 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100374 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100375 imei := f_gen_imei(imsi_suffix),
376 imsi := f_gen_imsi(imsi_suffix),
377 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100378 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100379 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100380 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100381 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100382 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100383 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100384 send_early_cm := true,
385 ipa_ctrl_ip := mp_msc_ip,
386 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100387 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100388 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200389 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200390 gsup_enable := gsup,
Harald Weltec1f937a2019-04-21 21:19:23 +0200391 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200392 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200393 ran_is_geran := ran_is_geran,
394 use_osmux := use_osmux
Harald Weltea49e36e2018-01-21 19:29:33 +0100395 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200396 if (not ran_is_geran) {
397 pars.use_umts_aka := true;
398 pars.net.expect_auth := true;
399 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100400 return pars;
401}
402
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200403function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars, integer bssap_idx := 0) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100404 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200405 var charstring id := testcasename() & int2str(bssap_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100406
407 vc_conn := BSC_ConnHdlr.create(id);
408 /* BSSMAP part / A interface */
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200409 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:CLIENT);
410 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100411 /* MNCC part */
412 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
413 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100414 /* MGCP part */
415 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
416 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100417 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200418 if (pars.gsup_enable == true) {
419 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
420 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
421 }
Harald Weltef640a012018-04-14 17:49:21 +0200422 /* SMPP part */
423 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
424 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100425 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100426 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100427 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
428 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
429 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100430
Harald Weltea10db902018-01-27 12:44:49 +0100431 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
432 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100433 vc_conn.start(derefers(fn)(id, pars));
434 return vc_conn;
435}
436
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200437function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false)
Harald Welte9b751a62019-04-14 17:39:29 +0200438runs on MTC_CT return BSC_ConnHdlr {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200439 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100440}
441
Harald Weltea49e36e2018-01-21 19:29:33 +0100442private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100443 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100444 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100445}
Harald Weltea49e36e2018-01-21 19:29:33 +0100446testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
447 var BSC_ConnHdlr vc_conn;
448 f_init();
449
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100450 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100451 vc_conn.done;
452}
453
454private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100455 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100456 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100457 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100458}
Harald Weltea49e36e2018-01-21 19:29:33 +0100459testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
460 var BSC_ConnHdlr vc_conn;
461 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100462 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100463
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100464 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100465 vc_conn.done;
466}
467
468/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200469friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100470 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100471 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
472
473 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200474 f_cl3_or_initial_ue(l3_lu);
Harald Welteb7817992019-05-09 13:15:39 +0200475 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100476 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
477 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
478 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100479 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
480 f_expect_clear();
481 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100482 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
483 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200484 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100485 }
486 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100487}
488testcase TC_lu_imsi_reject() runs on MTC_CT {
489 var BSC_ConnHdlr vc_conn;
490 f_init();
491
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100492 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3);
Harald Weltea49e36e2018-01-21 19:29:33 +0100493 vc_conn.done;
494}
495
Harald Weltee13cfb22019-04-23 16:52:02 +0200496
497
Harald Weltea49e36e2018-01-21 19:29:33 +0100498/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200499friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100500 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100501 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
502
503 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200504 f_cl3_or_initial_ue(l3_lu);
Harald Welteb7817992019-05-09 13:15:39 +0200505 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100506 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
507 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
508 alt {
509 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100510 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
511 f_expect_clear();
512 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100513 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
514 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200515 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100516 }
517 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100518}
519testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
520 var BSC_ConnHdlr vc_conn;
521 f_init();
522
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100523 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4);
Harald Weltea49e36e2018-01-21 19:29:33 +0100524 vc_conn.done;
525}
526
Harald Weltee13cfb22019-04-23 16:52:02 +0200527
Harald Welte7b1b2812018-01-22 21:23:06 +0100528private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100529 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100530 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100531 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100532}
533testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
534 var BSC_ConnHdlr vc_conn;
535 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100536 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100537
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100538 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100539 vc_conn.done;
540}
541
Harald Weltee13cfb22019-04-23 16:52:02 +0200542
543friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200544 pars.net.expect_auth := true;
545 pars.use_umts_aka := true;
546 f_init_handler(pars);
547 f_perform_lu();
548}
549testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
550 var BSC_ConnHdlr vc_conn;
551 f_init();
552 f_vty_config(MSCVTY, "network", "authentication required");
553
554 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
555 vc_conn.done;
556}
Harald Weltea49e36e2018-01-21 19:29:33 +0100557
Harald Weltee13cfb22019-04-23 16:52:02 +0200558
Harald Weltea49e36e2018-01-21 19:29:33 +0100559/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200560friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100561runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100562 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100563
564 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100565 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100566 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100567
568 f_create_gsup_expect(hex2str(g_pars.imsi));
569
570 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200571 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200572 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100573
574 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100575 T.start;
576 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100577 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
578 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200579 [] BSSAP.receive {
580 setverdict(fail, "Received unexpected BSSAP");
581 mtc.stop;
582 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100583 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
584 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200585 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100586 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200587 [] T.timeout {
588 setverdict(fail, "Timeout waiting for CM SERV REQ");
589 mtc.stop;
590 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100591 }
592
Harald Welte1ddc7162018-01-27 14:25:46 +0100593 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100594}
Harald Weltea49e36e2018-01-21 19:29:33 +0100595testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
596 var BSC_ConnHdlr vc_conn;
597 f_init();
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100598 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6);
Harald Weltea49e36e2018-01-21 19:29:33 +0100599 vc_conn.done;
600}
601
Harald Weltee13cfb22019-04-23 16:52:02 +0200602
603friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100604 f_init_handler(pars);
Harald Welteb71901a2018-01-26 19:16:05 +0100605 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
606 cpars.bss_rtp_port := 1110;
607 cpars.mgcp_connection_id_bss := '22222'H;
608 cpars.mgcp_connection_id_mss := '33333'H;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100609 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte2bb825f2018-01-22 11:31:18 +0100610
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100611 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100612 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100613}
614testcase TC_lu_and_mo_call() runs on MTC_CT {
615 var BSC_ConnHdlr vc_conn;
616 f_init();
617
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100618 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100619 vc_conn.done;
620}
621
Harald Weltee13cfb22019-04-23 16:52:02 +0200622
Harald Welte071ed732018-01-23 19:53:52 +0100623/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200624friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100625 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100626
627 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
628 var PDU_DTAP_MT dtap_mt;
629
630 /* tell GSUP dispatcher to send this IMSI to us */
631 f_create_gsup_expect(hex2str(g_pars.imsi));
632
633 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200634 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100635
636 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200637 if (pars.ran_is_geran) {
638 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
639 }
Harald Welte071ed732018-01-23 19:53:52 +0100640
641 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
642 /* The HLR would normally return an auth vector here, but we fail to do so. */
643
644 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100645 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100646}
647testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
648 var BSC_ConnHdlr vc_conn;
649 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100650 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100651
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100652 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8);
Harald Welte071ed732018-01-23 19:53:52 +0100653 vc_conn.done;
654}
655
Harald Weltee13cfb22019-04-23 16:52:02 +0200656
Harald Welte071ed732018-01-23 19:53:52 +0100657/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200658friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100659 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100660
661 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
662 var PDU_DTAP_MT dtap_mt;
663
664 /* tell GSUP dispatcher to send this IMSI to us */
665 f_create_gsup_expect(hex2str(g_pars.imsi));
666
667 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200668 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100669
670 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200671 if (pars.ran_is_geran) {
672 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
673 }
Harald Welte071ed732018-01-23 19:53:52 +0100674
675 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
676 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
677
678 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100679 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100680}
681testcase TC_lu_auth_sai_err() runs on MTC_CT {
682 var BSC_ConnHdlr vc_conn;
683 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100684 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100685
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100686 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9);
Harald Welte2bb825f2018-01-22 11:31:18 +0100687 vc_conn.done;
688}
Harald Weltea49e36e2018-01-21 19:29:33 +0100689
Harald Weltee13cfb22019-04-23 16:52:02 +0200690
Harald Weltebc881782018-01-23 20:09:15 +0100691/* Test LU but BSC will send a clear request in the middle */
692private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100693 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100694
695 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
696 var PDU_DTAP_MT dtap_mt;
697
698 /* tell GSUP dispatcher to send this IMSI to us */
699 f_create_gsup_expect(hex2str(g_pars.imsi));
700
701 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200702 f_cl3_or_initial_ue(l3_lu);
Harald Weltebc881782018-01-23 20:09:15 +0100703
704 /* Send Early Classmark, just for the fun of it */
705 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
706
707 f_sleep(1.0);
708 /* send clear request in the middle of the LU */
709 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200710 alt {
711 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
712 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
713 }
Harald Weltebc881782018-01-23 20:09:15 +0100714 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100715 alt {
716 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200717 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
718 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200719 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200720 repeat;
721 }
Harald Welte6811d102019-04-14 22:23:14 +0200722 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100723 }
Harald Weltebc881782018-01-23 20:09:15 +0100724 setverdict(pass);
725}
726testcase TC_lu_clear_request() runs on MTC_CT {
727 var BSC_ConnHdlr vc_conn;
728 f_init();
729
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100730 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100731 vc_conn.done;
732}
733
Harald Welte66af9e62018-01-24 17:28:21 +0100734/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200735friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100736 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100737
738 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
739 var PDU_DTAP_MT dtap_mt;
740
741 /* tell GSUP dispatcher to send this IMSI to us */
742 f_create_gsup_expect(hex2str(g_pars.imsi));
743
744 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200745 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +0100746
747 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200748 if (pars.ran_is_geran) {
749 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
750 }
Harald Welte66af9e62018-01-24 17:28:21 +0100751
752 f_sleep(1.0);
753 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +0200754 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +0100755 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +0100756 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +0100757}
758testcase TC_lu_disconnect() runs on MTC_CT {
759 var BSC_ConnHdlr vc_conn;
760 f_init();
761
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100762 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100763 vc_conn.done;
764}
765
Harald Welteba7b6d92018-01-23 21:32:34 +0100766/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +0200767friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100768 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100769
Harald Welte256571e2018-01-24 18:47:19 +0100770 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100771 var PDU_DTAP_MT dtap_mt;
772
773 /* tell GSUP dispatcher to send this IMSI to us */
774 f_create_gsup_expect(hex2str(g_pars.imsi));
775
776 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200777 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100778
779 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200780 if (pars.ran_is_geran) {
781 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
782 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100783 /* wait for LU reject, ignore any ID REQ */
784 alt {
785 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
786 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
787 }
788 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100789 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100790}
791testcase TC_lu_by_imei() runs on MTC_CT {
792 var BSC_ConnHdlr vc_conn;
793 f_init();
794
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100795 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12);
Harald Welteba7b6d92018-01-23 21:32:34 +0100796 vc_conn.done;
797}
798
Harald Weltee13cfb22019-04-23 16:52:02 +0200799
Harald Welteba7b6d92018-01-23 21:32:34 +0100800/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
801private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200802 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
803 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100804 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100805
806 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
807 var PDU_DTAP_MT dtap_mt;
808
809 /* tell GSUP dispatcher to send this IMSI to us */
810 f_create_gsup_expect(hex2str(g_pars.imsi));
811
812 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200813 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100814
815 /* Send Early Classmark, just for the fun of it */
816 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
817
818 /* Wait for + respond to ID REQ (IMSI) */
819 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req('001'B)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200820 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100821 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
822
823 /* Expect MSC to do UpdateLocation to HLR; respond to it */
824 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
825 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
826 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
827 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
828
829 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100830 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
831 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
832 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100833 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
834 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200835 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +0100836 }
837 }
838
Philipp Maier9b690e42018-12-21 11:50:03 +0100839 /* Wait for MM-Information (if enabled) */
840 f_expect_mm_info();
841
Harald Welteba7b6d92018-01-23 21:32:34 +0100842 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100843 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100844}
845testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
846 var BSC_ConnHdlr vc_conn;
847 f_init();
848
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100849 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100850 vc_conn.done;
851}
852
853
Harald Welte45164da2018-01-24 12:51:27 +0100854/* Test IMSI DETACH (MI=IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200855friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100856 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100857
858 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
859
860 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200861 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100862
863 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200864 if (pars.ran_is_geran) {
865 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
866 }
Harald Welte45164da2018-01-24 12:51:27 +0100867
868 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100869 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100870}
871testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
872 var BSC_ConnHdlr vc_conn;
873 f_init();
874
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100875 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14);
Harald Welte45164da2018-01-24 12:51:27 +0100876 vc_conn.done;
877}
878
Harald Weltee13cfb22019-04-23 16:52:02 +0200879
Harald Welte45164da2018-01-24 12:51:27 +0100880/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200881friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100882 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100883
884 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
885
886 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200887 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100888
889 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200890 if (pars.ran_is_geran) {
891 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
892 }
Harald Welte45164da2018-01-24 12:51:27 +0100893
894 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100895 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100896}
897testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
898 var BSC_ConnHdlr vc_conn;
899 f_init();
900
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100901 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15);
Harald Welte45164da2018-01-24 12:51:27 +0100902 vc_conn.done;
903}
904
Harald Weltee13cfb22019-04-23 16:52:02 +0200905
Harald Welte45164da2018-01-24 12:51:27 +0100906/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +0200907friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100908 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100909
Harald Welte256571e2018-01-24 18:47:19 +0100910 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +0100911
912 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200913 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100914
915 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200916 if (pars.ran_is_geran) {
917 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
918 }
Harald Welte45164da2018-01-24 12:51:27 +0100919
920 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100921 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100922}
923testcase TC_imsi_detach_by_imei() runs on MTC_CT {
924 var BSC_ConnHdlr vc_conn;
925 f_init();
926
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100927 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16);
Harald Welte45164da2018-01-24 12:51:27 +0100928 vc_conn.done;
929}
930
931
932/* helper function for an emergency call. caller passes in mobile identity to use */
933private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +0100934 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
935 cpars.emergency := true;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100936 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte45164da2018-01-24 12:51:27 +0100937
Harald Welte0bef21e2018-02-10 09:48:23 +0100938 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +0100939}
940
941/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200942friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100943 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100944
Harald Welte256571e2018-01-24 18:47:19 +0100945 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100946 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +0200947 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +0100948 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +0100949 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100950}
951testcase TC_emerg_call_imei_reject() runs on MTC_CT {
952 var BSC_ConnHdlr vc_conn;
953 f_init();
954
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100955 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17);
Harald Welte45164da2018-01-24 12:51:27 +0100956 vc_conn.done;
957}
958
Harald Weltee13cfb22019-04-23 16:52:02 +0200959
Harald Welted5b91402018-01-24 18:48:16 +0100960/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200961friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100962 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100963 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100964 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +0100965 /* Then issue emergency call identified by IMSI */
966 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
967}
968testcase TC_emerg_call_imsi() runs on MTC_CT {
969 var BSC_ConnHdlr vc_conn;
970 f_init();
971
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100972 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +0100973 vc_conn.done;
974}
975
Harald Weltee13cfb22019-04-23 16:52:02 +0200976
Harald Welte45164da2018-01-24 12:51:27 +0100977/* CM Service Request for VGCS -> reject */
978private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100979 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100980
981 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100982 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +0100983
984 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100985 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +0200986 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +0100987 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +0100988 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100989}
990testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
991 var BSC_ConnHdlr vc_conn;
992 f_init();
993
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100994 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +0100995 vc_conn.done;
996}
997
998/* CM Service Request for VBS -> reject */
999private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001000 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001001
1002 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001003 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001004
1005 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001006 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001007 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001008 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001009 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001010}
1011testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1012 var BSC_ConnHdlr vc_conn;
1013 f_init();
1014
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001015 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001016 vc_conn.done;
1017}
1018
1019/* CM Service Request for LCS -> reject */
1020private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001021 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001022
1023 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001024 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001025
1026 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001027 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001028 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001029 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001030 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001031}
1032testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1033 var BSC_ConnHdlr vc_conn;
1034 f_init();
1035
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001036 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001037 vc_conn.done;
1038}
1039
Harald Welte0195ab12018-01-24 21:50:20 +01001040/* CM Re-Establishment Request */
1041private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001042 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001043
1044 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001045 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001046
1047 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1048 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001049 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001050 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001051 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001052}
1053testcase TC_cm_reest_req_reject() runs on MTC_CT {
1054 var BSC_ConnHdlr vc_conn;
1055 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001056
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001057 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001058 vc_conn.done;
1059}
1060
Harald Weltec638f4d2018-01-24 22:00:36 +01001061/* Test LU (with authentication enabled), with wrong response from MS */
1062private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001063 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001064
1065 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1066
1067 /* tell GSUP dispatcher to send this IMSI to us */
1068 f_create_gsup_expect(hex2str(g_pars.imsi));
1069
1070 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001071 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001072
1073 /* Send Early Classmark, just for the fun of it */
1074 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1075
1076 var AuthVector vec := f_gen_auth_vec_2g();
1077 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1078 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1079 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1080
1081 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1082 /* Send back wrong auth response */
1083 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1084
1085 /* Expect GSUP AUTH FAIL REP to HLR */
1086 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1087
1088 /* Expect LU REJECT with Cause == Illegal MS */
1089 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001090 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001091}
1092testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1093 var BSC_ConnHdlr vc_conn;
1094 f_init();
1095 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001096
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001097 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23);
Harald Weltec638f4d2018-01-24 22:00:36 +01001098 vc_conn.done;
1099}
1100
Harald Weltede371492018-01-27 23:44:41 +01001101/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001102private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001103 pars.net.expect_auth := true;
1104 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001105 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001106 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001107}
1108testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1109 var BSC_ConnHdlr vc_conn;
1110 f_init();
1111 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001112 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1113
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001114 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001115 vc_conn.done;
1116}
1117
Harald Welte1af6ea82018-01-25 18:33:15 +01001118/* Test Complete L3 without payload */
1119private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001120 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001121
1122 /* Send Complete L3 Info with empty L3 frame */
1123 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1124 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1125
Harald Weltef466eb42018-01-27 14:26:54 +01001126 timer T := 5.0;
1127 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001128 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001129 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001130 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001131 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001132 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001133 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001134 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001135 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001136 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001137 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001138 }
1139 setverdict(pass);
1140}
1141testcase TC_cl3_no_payload() runs on MTC_CT {
1142 var BSC_ConnHdlr vc_conn;
1143 f_init();
1144
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001145 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001146 vc_conn.done;
1147}
1148
1149/* Test Complete L3 with random payload */
1150private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001151 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001152
Daniel Willmannaa14a382018-07-26 08:29:45 +02001153 /* length is limited by PDU_BSSAP length field which includes some
1154 * other fields beside l3info payload. So payl can only be 240 bytes
1155 * Since rnd() returns values < 1 multiply with 241
1156 */
1157 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001158 var octetstring payl := f_rnd_octstring(len);
1159
1160 /* Send Complete L3 Info with empty L3 frame */
1161 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1162 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1163
Harald Weltef466eb42018-01-27 14:26:54 +01001164 timer T := 5.0;
1165 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001166 alt {
1167 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001168 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001169 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001170 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001171 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001172 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001173 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001174 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001175 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001176 }
1177 setverdict(pass);
1178}
1179testcase TC_cl3_rnd_payload() runs on MTC_CT {
1180 var BSC_ConnHdlr vc_conn;
1181 f_init();
1182
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001183 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001184 vc_conn.done;
1185}
1186
Harald Welte116e4332018-01-26 22:17:48 +01001187/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001188friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001189 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001190
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001191 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001192
Harald Welteb9e86fa2018-04-09 18:18:31 +02001193 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001194 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001195}
1196testcase TC_establish_and_nothing() runs on MTC_CT {
1197 var BSC_ConnHdlr vc_conn;
1198 f_init();
1199
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001200 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001201 vc_conn.done;
1202}
1203
Harald Weltee13cfb22019-04-23 16:52:02 +02001204
Harald Welte12510c52018-01-26 22:26:24 +01001205/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001206friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001207 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001208
Harald Welte12510c52018-01-26 22:26:24 +01001209 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1210
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001211 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001212
Harald Welteb9e86fa2018-04-09 18:18:31 +02001213 f_establish_fully();
Harald Welte12510c52018-01-26 22:26:24 +01001214 f_create_mncc_expect(hex2str(cpars.called_party));
1215 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1216
1217 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1218
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001219 var default ccrel := activate(as_optional_cc_rel(cpars));
1220
Philipp Maier109e6aa2018-10-17 10:53:32 +02001221 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001222
1223 deactivate(ccrel);
1224
1225 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001226}
1227testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1228 var BSC_ConnHdlr vc_conn;
1229 f_init();
1230
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001231 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001232 vc_conn.done;
1233}
1234
Harald Weltee13cfb22019-04-23 16:52:02 +02001235
Harald Welte3ab88002018-01-26 22:37:25 +01001236/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001237friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001238 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001239 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1240 var MNCC_PDU mncc;
1241 var MgcpCommand mgcp_cmd;
1242
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001243 f_perform_lu();
Harald Welte3ab88002018-01-26 22:37:25 +01001244
Harald Welteb9e86fa2018-04-09 18:18:31 +02001245 f_establish_fully();
Harald Welte3ab88002018-01-26 22:37:25 +01001246 f_create_mncc_expect(hex2str(cpars.called_party));
1247 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1248
1249 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1250 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1251 cpars.mncc_callref := mncc.u.signal.callref;
1252 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1253 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1254
1255 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Harald Welte1852a842018-01-26 22:53:36 +01001256 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1257 cpars.mgcp_ep := mgcp_cmd.line.ep;
Harald Welte3ab88002018-01-26 22:37:25 +01001258 /* never respond to this */
1259
Philipp Maier8e58f592018-03-14 11:10:56 +01001260 /* When the connection with the MGW fails, the MSC will first request
1261 * a release via call control. We will answer this request normally. */
1262 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1263 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1264
Harald Welte1ddc7162018-01-27 14:25:46 +01001265 f_expect_clear(30.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001266}
1267testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1268 var BSC_ConnHdlr vc_conn;
1269 f_init();
1270
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001271 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001272 vc_conn.done;
1273}
1274
Harald Weltee13cfb22019-04-23 16:52:02 +02001275
Harald Welte0cc82d92018-01-26 22:52:34 +01001276/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001277friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001278 f_init_handler(pars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001279 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1280 var MNCC_PDU mncc;
1281 var MgcpCommand mgcp_cmd;
1282
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001283 f_perform_lu();
Harald Welte0cc82d92018-01-26 22:52:34 +01001284
Harald Welteb9e86fa2018-04-09 18:18:31 +02001285 f_establish_fully();
Harald Welte0cc82d92018-01-26 22:52:34 +01001286 f_create_mncc_expect(hex2str(cpars.called_party));
1287 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1288
1289 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1290 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1291 cpars.mncc_callref := mncc.u.signal.callref;
1292 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1293 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1294
1295 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001296
1297 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1298 * set an endpoint name that fits the pattern. If not, just use the
1299 * endpoint name from the request */
1300 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1301 cpars.mgcp_ep := "rtpbridge/1@mgw";
1302 } else {
1303 cpars.mgcp_ep := mgcp_cmd.line.ep;
1304 }
1305
Harald Welte0cc82d92018-01-26 22:52:34 +01001306 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001307
Harald Welte0cc82d92018-01-26 22:52:34 +01001308 /* Respond to CRCX with error */
1309 var MgcpResponse mgcp_rsp := {
1310 line := {
1311 code := "542",
1312 trans_id := mgcp_cmd.line.trans_id,
1313 string := "FORCED_FAIL"
1314 },
Harald Welte0cc82d92018-01-26 22:52:34 +01001315 sdp := omit
1316 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001317 var MgcpParameter mgcp_rsp_param := {
1318 code := "Z",
1319 val := cpars.mgcp_ep
1320 };
1321 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte0cc82d92018-01-26 22:52:34 +01001322 MGCP.send(mgcp_rsp);
1323
1324 timer T := 30.0;
1325 T.start;
1326 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001327 [] T.timeout {
1328 setverdict(fail, "Timeout waiting for channel release");
1329 mtc.stop;
1330 }
Daniel Willmann5868e622018-02-15 17:42:59 +01001331 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
1332 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1333 repeat;
1334 }
Harald Welte0cc82d92018-01-26 22:52:34 +01001335 [] MNCC.receive { repeat; }
1336 [] GSUP.receive { repeat; }
Philipp Maierc6e06f72018-04-11 18:12:23 +02001337 /* Note: As we did not respond properly to the CRCX from the MSC we
1338 * expect the MSC to omit any further MGCP operation (At least in the
1339 * the current implementation, there is no recovery mechanism implemented
1340 * and a DLCX can not be performed as the MSC does not know a specific
1341 * endpoint yet. */
Daniel Willmannafce8662018-07-06 23:11:32 +02001342 [] MGCP.receive {
1343 setverdict(fail, "Unexpected MGCP message");
1344 mtc.stop;
1345 }
Harald Welte5946b332018-03-18 23:32:21 +01001346 [] as_clear_cmd_compl_disc();
Harald Welte0cc82d92018-01-26 22:52:34 +01001347 }
1348}
1349testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1350 var BSC_ConnHdlr vc_conn;
1351 f_init();
1352
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001353 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001354 vc_conn.done;
1355}
1356
Harald Welte3ab88002018-01-26 22:37:25 +01001357
Harald Welte812f7a42018-01-27 00:49:18 +01001358/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1359private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1360 var MNCC_PDU mncc;
1361 var MgcpCommand mgcp_cmd;
1362 var OCT4 tmsi;
1363
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001364 f_perform_lu();
Harald Welte812f7a42018-01-27 00:49:18 +01001365 if (isvalue(g_pars.tmsi)) {
1366 tmsi := g_pars.tmsi;
1367 } else {
1368 tmsi := 'FFFFFFFF'O;
1369 }
Harald Welte6811d102019-04-14 22:23:14 +02001370 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001371
1372 /* Allocate call reference and send SETUP via MNCC to MSC */
1373 cpars.mncc_callref := f_rnd_int(2147483648);
1374 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1375 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1376
1377 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001378 f_expect_paging();
1379
Harald Welte812f7a42018-01-27 00:49:18 +01001380 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001381 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001382
1383 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1384
1385 /* MSC->MS: SETUP */
1386 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1387}
1388
1389/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001390friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001391 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001392 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1393 var MNCC_PDU mncc;
1394 var MgcpCommand mgcp_cmd;
1395
1396 f_mt_call_start(cpars);
1397
1398 /* MS->MSC: CALL CONFIRMED */
1399 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1400
1401 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1402
1403 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1404 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001405
1406 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1407 * set an endpoint name that fits the pattern. If not, just use the
1408 * endpoint name from the request */
1409 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1410 cpars.mgcp_ep := "rtpbridge/1@mgw";
1411 } else {
1412 cpars.mgcp_ep := mgcp_cmd.line.ep;
1413 }
1414
Harald Welte812f7a42018-01-27 00:49:18 +01001415 /* Respond to CRCX with error */
1416 var MgcpResponse mgcp_rsp := {
1417 line := {
1418 code := "542",
1419 trans_id := mgcp_cmd.line.trans_id,
1420 string := "FORCED_FAIL"
1421 },
Harald Welte812f7a42018-01-27 00:49:18 +01001422 sdp := omit
1423 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001424 var MgcpParameter mgcp_rsp_param := {
1425 code := "Z",
1426 val := cpars.mgcp_ep
1427 };
1428 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001429 MGCP.send(mgcp_rsp);
1430
1431 timer T := 30.0;
1432 T.start;
1433 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001434 [] T.timeout {
1435 setverdict(fail, "Timeout waiting for channel release");
1436 mtc.stop;
1437 }
Harald Welte812f7a42018-01-27 00:49:18 +01001438 [] MNCC.receive { repeat; }
1439 [] GSUP.receive { repeat; }
1440 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1441 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1442 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1443 repeat;
1444 }
1445 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001446 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001447 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001448 }
1449}
1450testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1451 var BSC_ConnHdlr vc_conn;
1452 f_init();
1453
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001454 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001455 vc_conn.done;
1456}
1457
1458
Harald Weltee13cfb22019-04-23 16:52:02 +02001459
Harald Welte812f7a42018-01-27 00:49:18 +01001460/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001461friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001462 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001463 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1464 var MNCC_PDU mncc;
1465 var MgcpCommand mgcp_cmd;
1466
1467 f_mt_call_start(cpars);
1468
1469 /* MS->MSC: CALL CONFIRMED */
1470 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1471 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1472
1473 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1474 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1475 cpars.mgcp_ep := mgcp_cmd.line.ep;
1476 /* FIXME: Respond to CRCX */
1477
1478 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1479 timer T := 190.0;
1480 T.start;
1481 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001482 [] T.timeout {
1483 setverdict(fail, "Timeout waiting for T310");
1484 mtc.stop;
1485 }
Harald Welte812f7a42018-01-27 00:49:18 +01001486 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1487 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1488 }
1489 }
1490 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1491 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1492 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1493 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1494
1495 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001496 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1497 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1498 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1499 repeat;
1500 }
Harald Welte5946b332018-03-18 23:32:21 +01001501 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001502 }
1503}
1504testcase TC_mt_t310() runs on MTC_CT {
1505 var BSC_ConnHdlr vc_conn;
1506 f_init();
1507
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001508 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001509 vc_conn.done;
1510}
1511
Harald Weltee13cfb22019-04-23 16:52:02 +02001512
Harald Welte167458a2018-01-27 15:58:16 +01001513/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001514friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001515 f_init_handler(pars);
1516 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1517 cpars.bss_rtp_port := 1110;
1518 cpars.mgcp_connection_id_bss := '22222'H;
1519 cpars.mgcp_connection_id_mss := '33333'H;
Daniel Willmann9b0235b2018-07-24 12:13:34 +02001520 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte167458a2018-01-27 15:58:16 +01001521
1522 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001523 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001524
1525 /* First MO call should succeed */
1526 f_mo_call(cpars);
1527
1528 /* Cancel the subscriber in the VLR */
1529 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1530 alt {
1531 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1532 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1533 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001534 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001535 }
1536 }
1537
1538 /* Follow-up transactions should fail */
1539 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1540 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001541 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001542 alt {
1543 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1544 [] BSSAP.receive {
1545 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001546 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001547 }
1548 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001549
1550 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001551 setverdict(pass);
1552}
1553testcase TC_gsup_cancel() runs on MTC_CT {
1554 var BSC_ConnHdlr vc_conn;
1555 f_init();
1556
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001557 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33);
Harald Welte167458a2018-01-27 15:58:16 +01001558 vc_conn.done;
1559}
1560
Harald Weltee13cfb22019-04-23 16:52:02 +02001561
Harald Welte9de84792018-01-28 01:06:35 +01001562/* A5/1 only permitted on network side, and MS capable to do it */
1563private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1564 pars.net.expect_auth := true;
1565 pars.net.expect_ciph := true;
1566 pars.net.kc_support := '02'O; /* A5/1 only */
1567 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001568 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001569}
1570testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1571 var BSC_ConnHdlr vc_conn;
1572 f_init();
1573 f_vty_config(MSCVTY, "network", "authentication required");
1574 f_vty_config(MSCVTY, "network", "encryption a5 1");
1575
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001576 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001577 vc_conn.done;
1578}
1579
1580/* A5/3 only permitted on network side, and MS capable to do it */
1581private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1582 pars.net.expect_auth := true;
1583 pars.net.expect_ciph := true;
1584 pars.net.kc_support := '08'O; /* A5/3 only */
1585 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001586 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001587}
1588testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1589 var BSC_ConnHdlr vc_conn;
1590 f_init();
1591 f_vty_config(MSCVTY, "network", "authentication required");
1592 f_vty_config(MSCVTY, "network", "encryption a5 3");
1593
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001594 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001595 vc_conn.done;
1596}
1597
1598/* A5/3 only permitted on network side, and MS with only A5/1 support */
1599private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1600 pars.net.expect_auth := true;
1601 pars.net.expect_ciph := true;
1602 pars.net.kc_support := '08'O; /* A5/3 only */
1603 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1604 f_init_handler(pars, 15.0);
1605
1606 /* cannot use f_perform_lu() as we expect a reject */
1607 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1608 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001609 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001610 if (pars.send_early_cm) {
1611 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1612 } else {
1613 pars.cm1.esind := '0'B;
1614 }
Harald Welte9de84792018-01-28 01:06:35 +01001615 f_mm_auth();
1616 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001617 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1618 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1619 repeat;
1620 }
Harald Welte5946b332018-03-18 23:32:21 +01001621 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1622 f_expect_clear();
1623 }
Harald Welte9de84792018-01-28 01:06:35 +01001624 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1625 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001626 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001627 }
1628 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001629 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001630 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001631 }
1632 }
1633 setverdict(pass);
1634}
1635testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1636 var BSC_ConnHdlr vc_conn;
1637 f_init();
1638 f_vty_config(MSCVTY, "network", "authentication required");
1639 f_vty_config(MSCVTY, "network", "encryption a5 3");
1640
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001641 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360);
1642 vc_conn.done;
1643}
1644testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1645 var BSC_ConnHdlrPars pars;
1646 var BSC_ConnHdlr vc_conn;
1647 f_init();
1648 f_vty_config(MSCVTY, "network", "authentication required");
1649 f_vty_config(MSCVTY, "network", "encryption a5 3");
1650
1651 pars := f_init_pars(361);
1652 pars.send_early_cm := false;
1653 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001654 vc_conn.done;
1655}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001656testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1657 var BSC_ConnHdlr vc_conn;
1658 f_init();
1659 f_vty_config(MSCVTY, "network", "authentication required");
1660 f_vty_config(MSCVTY, "network", "encryption a5 3");
1661
1662 /* Make sure the MSC category is on DEBUG level to trigger the log
1663 * message that is reported in OS#2947 to trigger the segfault */
1664 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1665
1666 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362);
1667 vc_conn.done;
1668}
Harald Welte9de84792018-01-28 01:06:35 +01001669
1670/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1671private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1672 pars.net.expect_auth := true;
1673 pars.net.expect_ciph := true;
1674 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1675 pars.cm1.a5_1 := '1'B;
1676 pars.cm2.a5_1 := '1'B;
1677 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1678 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1679 f_init_handler(pars, 15.0);
1680
1681 /* cannot use f_perform_lu() as we expect a reject */
1682 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1683 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001684 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001685 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1686 f_mm_auth();
1687 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001688 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1689 f_expect_clear();
1690 }
Harald Welte9de84792018-01-28 01:06:35 +01001691 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1692 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001693 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001694 }
1695 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001696 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001697 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001698 }
1699 }
1700 setverdict(pass);
1701}
1702testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1703 var BSC_ConnHdlr vc_conn;
1704 f_init();
1705 f_vty_config(MSCVTY, "network", "authentication required");
1706 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1707
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001708 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37);
Harald Welte9de84792018-01-28 01:06:35 +01001709 vc_conn.done;
1710}
1711
1712/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1713private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1714 pars.net.expect_auth := true;
1715 pars.net.expect_ciph := true;
1716 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1717 pars.cm1.a5_1 := '1'B;
1718 pars.cm2.a5_1 := '1'B;
1719 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1720 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1721 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001722 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001723}
1724testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1725 var BSC_ConnHdlr vc_conn;
1726 f_init();
1727 f_vty_config(MSCVTY, "network", "authentication required");
1728 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1729
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001730 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001731 vc_conn.done;
1732}
1733
Harald Welte33ec09b2018-02-10 15:34:46 +01001734/* LU followed by MT call (including paging) */
1735private function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1736 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001737 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte33ec09b2018-02-10 15:34:46 +01001738 cpars.bss_rtp_port := 1110;
1739 cpars.mgcp_connection_id_bss := '10004'H;
1740 cpars.mgcp_connection_id_mss := '10005'H;
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001741 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01001742
Philipp Maier4b2692d2018-03-14 16:37:48 +01001743 /* Note: This is an optional parameter. When the call-agent (MSC) does
1744 * supply a full endpoint name this setting will be overwritten. */
1745 cpars.mgcp_ep := "rtpbridge/1@mgw";
1746
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001747 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001748 f_mt_call(cpars);
1749}
1750testcase TC_lu_and_mt_call() runs on MTC_CT {
1751 var BSC_ConnHdlr vc_conn;
1752 f_init();
1753
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001754 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001755 vc_conn.done;
1756}
1757
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001758testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
1759 var BSC_ConnHdlr vc_conn;
1760 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001761
1762 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
1763 vc_conn.done;
1764}
1765
Daniel Willmann8b084372018-02-04 13:35:26 +01001766/* Test MO Call SETUP with DTMF */
1767private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1768 f_init_handler(pars);
1769 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1770 cpars.bss_rtp_port := 1110;
1771 cpars.mgcp_connection_id_bss := '22222'H;
1772 cpars.mgcp_connection_id_mss := '33333'H;
1773
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001774 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001775 f_mo_seq_dtmf_dup(cpars);
1776}
1777testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1778 var BSC_ConnHdlr vc_conn;
1779 f_init();
1780
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001781 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001782 vc_conn.done;
1783}
Harald Welte9de84792018-01-28 01:06:35 +01001784
Philipp Maier328d1662018-03-07 10:40:27 +01001785testcase TC_cr_before_reset() runs on MTC_CT {
1786 timer T := 4.0;
1787 var boolean reset_ack_seen := false;
1788 f_init_bssap_direct();
1789
Harald Welte3ca0ce12019-04-23 17:18:48 +02001790 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02001791
Daniel Willmanne8018962018-08-21 14:18:00 +02001792 f_sleep(3.0);
1793
Philipp Maier328d1662018-03-07 10:40:27 +01001794 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001795 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001796
1797 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001798 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001799 T.start
1800 alt {
1801 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1802 reset_ack_seen := true;
1803 repeat;
1804 }
1805
1806 /* Acknowledge MSC sided reset requests */
1807 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001808 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001809 repeat;
1810 }
1811
1812 /* Ignore all other messages (e.g CR from the connection request) */
1813 [] BSSAP_DIRECT.receive { repeat }
1814
1815 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1816 * deadlock situation. The MSC is then unable to respond to any
1817 * further BSSMAP RESET or any other sort of traffic. */
1818 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1819 [reset_ack_seen == false] T.timeout {
1820 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02001821 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01001822 }
1823 }
1824}
Harald Welte9de84792018-01-28 01:06:35 +01001825
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001826/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02001827friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001828 f_init_handler(pars);
1829 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1830 var MNCC_PDU mncc;
1831 var MgcpCommand mgcp_cmd;
1832
1833 f_perform_lu();
1834
Harald Welteb9e86fa2018-04-09 18:18:31 +02001835 f_establish_fully();
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001836 f_create_mncc_expect(hex2str(cpars.called_party));
1837 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1838
1839 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1840 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1841 cpars.mncc_callref := mncc.u.signal.callref;
1842 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1843 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1844
1845 /* Drop CRCX */
1846 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1847
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001848 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001849
1850 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001851
1852 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001853}
1854testcase TC_mo_release_timeout() runs on MTC_CT {
1855 var BSC_ConnHdlr vc_conn;
1856 f_init();
1857
1858 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1859 vc_conn.done;
1860}
1861
Harald Welte12510c52018-01-26 22:26:24 +01001862
Philipp Maier2a98a732018-03-19 16:06:12 +01001863/* LU followed by MT call (including paging) */
1864private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1865 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001866 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01001867 cpars.bss_rtp_port := 1110;
1868 cpars.mgcp_connection_id_bss := '10004'H;
1869 cpars.mgcp_connection_id_mss := '10005'H;
1870
1871 /* Note: This is an optional parameter. When the call-agent (MSC) does
1872 * supply a full endpoint name this setting will be overwritten. */
1873 cpars.mgcp_ep := "rtpbridge/1@mgw";
1874
1875 /* Intentionally disable the CRCX response */
1876 cpars.mgw_drop_dlcx := true;
1877
1878 /* Perform location update and call */
1879 f_perform_lu();
1880 f_mt_call(cpars);
1881}
1882testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
1883 var BSC_ConnHdlr vc_conn;
1884 f_init();
1885
1886 /* Perform an almost normal looking locationupdate + mt-call, but do
1887 * not respond to the DLCX at the end of the call */
1888 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
1889 vc_conn.done;
1890
1891 /* Wait a guard period until the MGCP layer in the MSC times out,
1892 * if the MSC is vulnerable to the use-after-free situation that is
1893 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
1894 * segfault now */
1895 f_sleep(6.0);
1896
1897 /* Run the init procedures once more. If the MSC has crashed, this
1898 * this will fail */
1899 f_init();
1900}
Harald Welte45164da2018-01-24 12:51:27 +01001901
Philipp Maier75932982018-03-27 14:52:35 +02001902/* Two BSSMAP resets from two different BSCs */
1903testcase TC_reset_two() runs on MTC_CT {
1904 var BSC_ConnHdlr vc_conn;
1905 f_init(2);
1906 f_sleep(2.0);
1907 setverdict(pass);
1908}
1909
Harald Weltee13cfb22019-04-23 16:52:02 +02001910/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
1911testcase TC_reset_two_1iu() runs on MTC_CT {
1912 var BSC_ConnHdlr vc_conn;
1913 f_init(3);
1914 f_sleep(2.0);
1915 setverdict(pass);
1916}
1917
Harald Weltef640a012018-04-14 17:49:21 +02001918/***********************************************************************
1919 * SMS Testing
1920 ***********************************************************************/
1921
Harald Weltef45efeb2018-04-09 18:19:24 +02001922/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02001923friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02001924 var SmsParameters spars := valueof(t_SmsPars);
1925
1926 f_init_handler(pars);
1927
1928 /* Perform location update and call */
1929 f_perform_lu();
1930
1931 f_establish_fully(EST_TYPE_MO_SMS);
1932
1933 //spars.exp_rp_err := 96; /* invalid mandatory information */
1934 f_mo_sms(spars);
1935
1936 f_expect_clear();
1937}
1938testcase TC_lu_and_mo_sms() runs on MTC_CT {
1939 var BSC_ConnHdlr vc_conn;
1940 f_init();
1941 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
1942 vc_conn.done;
1943}
1944
Harald Weltee13cfb22019-04-23 16:52:02 +02001945
Harald Weltef45efeb2018-04-09 18:19:24 +02001946private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01001947runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02001948 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
1949}
1950
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01001951/* Remove still pending SMS */
1952private function f_vty_sms_clear(charstring imsi)
1953runs on BSC_ConnHdlr {
1954 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
1955 f_vty_transceive(MSCVTY, "sms-queue clear");
1956}
1957
Harald Weltef45efeb2018-04-09 18:19:24 +02001958/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02001959friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02001960 var SmsParameters spars := valueof(t_SmsPars);
1961 var OCT4 tmsi;
1962
1963 f_init_handler(pars);
1964
1965 /* Perform location update and call */
1966 f_perform_lu();
1967
1968 /* register an 'expect' for given IMSI (+TMSI) */
1969 if (isvalue(g_pars.tmsi)) {
1970 tmsi := g_pars.tmsi;
1971 } else {
1972 tmsi := 'FFFFFFFF'O;
1973 }
Harald Welte6811d102019-04-14 22:23:14 +02001974 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02001975
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01001976 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02001977
1978 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001979 f_expect_paging();
1980
Harald Weltef45efeb2018-04-09 18:19:24 +02001981 /* Establish DTAP / BSSAP / SCCP connection */
1982 f_establish_fully(EST_TYPE_PAG_RESP);
1983
1984 spars.tp.ud := 'C8329BFD064D9B53'O;
1985 f_mt_sms(spars);
1986
1987 f_expect_clear();
1988}
1989testcase TC_lu_and_mt_sms() runs on MTC_CT {
1990 var BSC_ConnHdlrPars pars;
1991 var BSC_ConnHdlr vc_conn;
1992 f_init();
1993 pars := f_init_pars(43);
1994 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02001995 vc_conn.done;
1996}
1997
Harald Weltee13cfb22019-04-23 16:52:02 +02001998
Philipp Maier3983e702018-11-22 19:01:33 +01001999/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002000friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002001 var SmsParameters spars := valueof(t_SmsPars);
2002 var OCT4 tmsi;
Philipp Maier3983e702018-11-22 19:01:33 +01002003 f_init_handler(pars, 150.0);
2004
2005 /* Perform location update */
2006 f_perform_lu();
2007
2008 /* register an 'expect' for given IMSI (+TMSI) */
2009 if (isvalue(g_pars.tmsi)) {
2010 tmsi := g_pars.tmsi;
2011 } else {
2012 tmsi := 'FFFFFFFF'O;
2013 }
Harald Welte6811d102019-04-14 22:23:14 +02002014 f_ran_register_imsi(g_pars.imsi, tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002015
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002016 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2017
Neels Hofmeyr16237742019-03-06 15:34:01 +01002018 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002019 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002020
2021 /* Wait some time to make sure the MSC is not delivering any further
2022 * paging messages or anything else that could be unexpected. */
2023 timer T := 20.0;
2024 T.start
2025 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02002026 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi))
Philipp Maier3983e702018-11-22 19:01:33 +01002027 {
2028 setverdict(fail, "paging seems not to stop!");
2029 mtc.stop;
2030 }
Harald Welte62113fc2019-05-09 13:04:02 +02002031 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Weltee13cfb22019-04-23 16:52:02 +02002032 setverdict(fail, "paging seems not to stop!");
2033 mtc.stop;
2034 }
Philipp Maier3983e702018-11-22 19:01:33 +01002035 [] BSSAP.receive {
2036 setverdict(fail, "unexpected BSSAP message received");
2037 self.stop;
2038 }
2039 [] T.timeout {
2040 setverdict(pass);
2041 }
2042 }
2043
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002044 f_vty_sms_clear(hex2str(g_pars.imsi));
2045
Philipp Maier3983e702018-11-22 19:01:33 +01002046 setverdict(pass);
2047}
2048testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2049 var BSC_ConnHdlrPars pars;
2050 var BSC_ConnHdlr vc_conn;
2051 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002052 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002053 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002054 vc_conn.done;
2055}
2056
Harald Weltee13cfb22019-04-23 16:52:02 +02002057
Harald Weltef640a012018-04-14 17:49:21 +02002058/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002059friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002060 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002061
Harald Weltef640a012018-04-14 17:49:21 +02002062 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002063
Harald Weltef640a012018-04-14 17:49:21 +02002064 /* Perform location update so IMSI is known + registered in MSC/VLR */
2065 f_perform_lu();
2066 f_establish_fully(EST_TYPE_MO_SMS);
2067
2068 f_mo_sms(spars);
2069
2070 var SMPP_PDU smpp;
2071 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2072 tr_smpp.body.deliver_sm := {
2073 service_type := "CMT",
2074 source_addr_ton := network_specific,
2075 source_addr_npi := isdn,
2076 source_addr := hex2str(pars.msisdn),
2077 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2078 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2079 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2080 esm_class := '00000001'B,
2081 protocol_id := 0,
2082 priority_flag := 0,
2083 schedule_delivery_time := "",
2084 replace_if_present := 0,
2085 data_coding := '00000001'B,
2086 sm_default_msg_id := 0,
2087 sm_length := ?,
2088 short_message := spars.tp.ud,
2089 opt_pars := {
2090 {
2091 tag := user_message_reference,
2092 len := 2,
2093 opt_value := {
2094 int2_val := oct2int(spars.tp.msg_ref)
2095 }
2096 }
2097 }
2098 };
2099 alt {
2100 [] SMPP.receive(tr_smpp) -> value smpp {
2101 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2102 }
2103 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2104 }
2105
2106 f_expect_clear();
2107}
2108testcase TC_smpp_mo_sms() runs on MTC_CT {
2109 var BSC_ConnHdlr vc_conn;
2110 f_init();
2111 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2112 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2113 vc_conn.done;
2114 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2115}
2116
Harald Weltee13cfb22019-04-23 16:52:02 +02002117
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002118/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002119friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002120runs on BSC_ConnHdlr {
2121 var SmsParameters spars := valueof(t_SmsPars);
2122 var GSUP_PDU gsup_msg_rx;
2123 var octetstring sm_tpdu;
2124
2125 f_init_handler(pars);
2126
2127 /* We need to inspect GSUP activity */
2128 f_create_gsup_expect(hex2str(g_pars.imsi));
2129
2130 /* Perform location update */
2131 f_perform_lu();
2132
2133 /* Send CM Service Request for SMS */
2134 f_establish_fully(EST_TYPE_MO_SMS);
2135
2136 /* Prepare expected SM-RP-UI (SM TPDU) */
2137 enc_TPDU_RP_DATA_MS_SGSN_fast(
2138 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2139 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2140 spars.tp.udl, spars.tp.ud)),
2141 sm_tpdu);
2142
2143 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2144 imsi := g_pars.imsi,
2145 sm_rp_mr := spars.rp.msg_ref,
2146 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2147 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(?),
2148 /* FIXME: MSISDN coding troubles */
2149 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(?),
2150 /* TODO: can we use decmatch here? */
2151 sm_rp_ui := sm_tpdu
2152 );
2153
2154 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2155 f_mo_sms_submit(spars);
2156 alt {
2157 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
2158 log("RX MO-forwardSM-Req");
2159 log(gsup_msg_rx);
2160 setverdict(pass);
2161 }
2162 [] GSUP.receive {
2163 log("RX unexpected GSUP message");
2164 setverdict(fail);
2165 mtc.stop;
2166 }
2167 }
2168
2169 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2170 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2171 imsi := g_pars.imsi,
2172 sm_rp_mr := spars.rp.msg_ref)));
2173 /* Expect RP-ACK on DTAP */
2174 f_mo_sms_wait_rp_ack(spars);
2175
2176 f_expect_clear();
2177}
2178testcase TC_gsup_mo_sms() runs on MTC_CT {
2179 var BSC_ConnHdlr vc_conn;
2180 f_init();
2181 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2182 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2183 vc_conn.done;
2184 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2185}
2186
Harald Weltee13cfb22019-04-23 16:52:02 +02002187
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002188/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002189friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002190runs on BSC_ConnHdlr {
2191 var SmsParameters spars := valueof(t_SmsPars);
2192 var GSUP_PDU gsup_msg_rx;
2193
2194 f_init_handler(pars);
2195
2196 /* We need to inspect GSUP activity */
2197 f_create_gsup_expect(hex2str(g_pars.imsi));
2198
2199 /* Perform location update */
2200 f_perform_lu();
2201
2202 /* Send CM Service Request for SMS */
2203 f_establish_fully(EST_TYPE_MO_SMS);
2204
2205 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2206 imsi := g_pars.imsi,
2207 sm_rp_mr := spars.rp.msg_ref,
2208 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2209 );
2210
2211 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2212 f_mo_smma(spars);
2213 alt {
2214 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
2215 log("RX MO-ReadyForSM-Req");
2216 log(gsup_msg_rx);
2217 setverdict(pass);
2218 }
2219 [] GSUP.receive {
2220 log("RX unexpected GSUP message");
2221 setverdict(fail);
2222 mtc.stop;
2223 }
2224 }
2225
2226 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2227 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2228 imsi := g_pars.imsi,
2229 sm_rp_mr := spars.rp.msg_ref)));
2230 /* Expect RP-ACK on DTAP */
2231 f_mo_sms_wait_rp_ack(spars);
2232
2233 f_expect_clear();
2234}
2235testcase TC_gsup_mo_smma() runs on MTC_CT {
2236 var BSC_ConnHdlr vc_conn;
2237 f_init();
2238 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2239 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2240 vc_conn.done;
2241 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2242}
2243
Harald Weltee13cfb22019-04-23 16:52:02 +02002244
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002245/* Helper for sending MT SMS over GSUP */
2246private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2247runs on BSC_ConnHdlr {
2248 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2249 imsi := g_pars.imsi,
2250 /* NOTE: MSC should assign RP-MR itself */
2251 sm_rp_mr := 'FF'O,
2252 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2253 /* TODO: fix encoding of ts_GSUP_SM_RP_DA_IMSI */
2254 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(g_pars.msisdn)),
2255 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(g_pars.msisdn)),
2256 /* Encoded SMS TPDU (taken from Wireshark)
2257 * FIXME: we should encode spars somehow */
2258 sm_rp_ui := '00068021436500008111328130858200'O,
2259 sm_rp_mms := mms
2260 ));
2261}
2262
2263/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002264friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002265runs on BSC_ConnHdlr {
2266 var SmsParameters spars := valueof(t_SmsPars);
2267
2268 f_init_handler(pars);
2269
2270 /* We need to inspect GSUP activity */
2271 f_create_gsup_expect(hex2str(g_pars.imsi));
2272
2273 /* Perform location update */
2274 f_perform_lu();
2275
2276 /* Register an 'expect' for given IMSI (+TMSI) */
2277 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002278 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002279 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002280 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002281 }
2282
2283 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2284 imsi := g_pars.imsi,
2285 /* NOTE: MSC should assign RP-MR itself */
2286 sm_rp_mr := ?
2287 );
2288
2289 /* Submit a MT SMS on GSUP */
2290 f_gsup_forwardSM_req(spars);
2291
2292 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002293 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002294 f_establish_fully(EST_TYPE_PAG_RESP);
2295
2296 /* Wait for MT SMS on DTAP */
2297 f_mt_sms_expect(spars);
2298
2299 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2300 f_mt_sms_send_rp_ack(spars);
2301 alt {
2302 [] GSUP.receive(mt_forwardSM_res) {
2303 log("RX MT-forwardSM-Res (RP-ACK)");
2304 setverdict(pass);
2305 }
2306 [] GSUP.receive {
2307 log("RX unexpected GSUP message");
2308 setverdict(fail);
2309 mtc.stop;
2310 }
2311 }
2312
2313 f_expect_clear();
2314}
2315testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2316 var BSC_ConnHdlrPars pars;
2317 var BSC_ConnHdlr vc_conn;
2318 f_init();
2319 pars := f_init_pars(90);
2320 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2321 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2322 vc_conn.done;
2323 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2324}
2325
Harald Weltee13cfb22019-04-23 16:52:02 +02002326
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002327/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002328friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002329runs on BSC_ConnHdlr {
2330 var SmsParameters spars := valueof(t_SmsPars);
2331 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2332
2333 f_init_handler(pars);
2334
2335 /* We need to inspect GSUP activity */
2336 f_create_gsup_expect(hex2str(g_pars.imsi));
2337
2338 /* Perform location update */
2339 f_perform_lu();
2340
2341 /* Register an 'expect' for given IMSI (+TMSI) */
2342 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002343 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002344 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002345 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002346 }
2347
2348 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2349 imsi := g_pars.imsi,
2350 /* NOTE: MSC should assign RP-MR itself */
2351 sm_rp_mr := ?,
2352 sm_rp_cause := sm_rp_cause
2353 );
2354
2355 /* Submit a MT SMS on GSUP */
2356 f_gsup_forwardSM_req(spars);
2357
2358 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002359 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002360 f_establish_fully(EST_TYPE_PAG_RESP);
2361
2362 /* Wait for MT SMS on DTAP */
2363 f_mt_sms_expect(spars);
2364
2365 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2366 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2367 alt {
2368 [] GSUP.receive(mt_forwardSM_err) {
2369 log("RX MT-forwardSM-Err (RP-ERROR)");
2370 setverdict(pass);
2371 mtc.stop;
2372 }
2373 [] GSUP.receive {
2374 log("RX unexpected GSUP message");
2375 setverdict(fail);
2376 mtc.stop;
2377 }
2378 }
2379
2380 f_expect_clear();
2381}
2382testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2383 var BSC_ConnHdlrPars pars;
2384 var BSC_ConnHdlr vc_conn;
2385 f_init();
2386 pars := f_init_pars(91);
2387 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2388 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2389 vc_conn.done;
2390 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2391}
2392
Harald Weltee13cfb22019-04-23 16:52:02 +02002393
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002394/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002395friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002396runs on BSC_ConnHdlr {
2397 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2398 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2399
2400 f_init_handler(pars);
2401
2402 /* We need to inspect GSUP activity */
2403 f_create_gsup_expect(hex2str(g_pars.imsi));
2404
2405 /* Perform location update */
2406 f_perform_lu();
2407
2408 /* Register an 'expect' for given IMSI (+TMSI) */
2409 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002410 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002411 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002412 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002413 }
2414
2415 /* Submit the 1st MT SMS on GSUP */
2416 log("TX MT-forwardSM-Req for the 1st SMS");
2417 f_gsup_forwardSM_req(spars1);
2418
2419 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002420 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002421 f_establish_fully(EST_TYPE_PAG_RESP);
2422
2423 /* Wait for 1st MT SMS on DTAP */
2424 f_mt_sms_expect(spars1);
2425 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2426 ", SM-RP-MR is ", spars1.rp.msg_ref);
2427
2428 /* Submit the 2nd MT SMS on GSUP */
2429 log("TX MT-forwardSM-Req for the 2nd SMS");
2430 f_gsup_forwardSM_req(spars2);
2431
2432 /* Wait for 2nd MT SMS on DTAP */
2433 f_mt_sms_expect(spars2);
2434 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2435 ", SM-RP-MR is ", spars2.rp.msg_ref);
2436
2437 /* Both transaction IDs shall be different */
2438 if (spars1.tid == spars2.tid) {
2439 log("Both DTAP transaction IDs shall be different");
2440 setverdict(fail);
2441 }
2442
2443 /* Both SM-RP-MR values shall be different */
2444 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2445 log("Both SM-RP-MR values shall be different");
2446 setverdict(fail);
2447 }
2448
2449 /* Both SM-RP-MR values shall be assigned */
2450 if (spars1.rp.msg_ref == 'FF'O) {
2451 log("Unassigned SM-RP-MR value for the 1st SMS");
2452 setverdict(fail);
2453 }
2454 if (spars2.rp.msg_ref == 'FF'O) {
2455 log("Unassigned SM-RP-MR value for the 2nd SMS");
2456 setverdict(fail);
2457 }
2458
2459 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2460 f_mt_sms_send_rp_ack(spars1);
2461 alt {
2462 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2463 imsi := g_pars.imsi,
2464 sm_rp_mr := spars1.rp.msg_ref
2465 )) {
2466 log("RX MT-forwardSM-Res (RP-ACK)");
2467 setverdict(pass);
2468 }
2469 [] GSUP.receive {
2470 log("RX unexpected GSUP message");
2471 setverdict(fail);
2472 mtc.stop;
2473 }
2474 }
2475
2476 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2477 f_mt_sms_send_rp_ack(spars2);
2478 alt {
2479 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2480 imsi := g_pars.imsi,
2481 sm_rp_mr := spars2.rp.msg_ref
2482 )) {
2483 log("RX MT-forwardSM-Res (RP-ACK)");
2484 setverdict(pass);
2485 }
2486 [] GSUP.receive {
2487 log("RX unexpected GSUP message");
2488 setverdict(fail);
2489 mtc.stop;
2490 }
2491 }
2492
2493 f_expect_clear();
2494}
2495testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2496 var BSC_ConnHdlrPars pars;
2497 var BSC_ConnHdlr vc_conn;
2498 f_init();
2499 pars := f_init_pars(92);
2500 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2501 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2502 vc_conn.done;
2503 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2504}
2505
Harald Weltee13cfb22019-04-23 16:52:02 +02002506
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002507/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002508friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002509runs on BSC_ConnHdlr {
2510 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2511 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2512
2513 f_init_handler(pars);
2514
2515 /* We need to inspect GSUP activity */
2516 f_create_gsup_expect(hex2str(g_pars.imsi));
2517
2518 /* Perform location update */
2519 f_perform_lu();
2520
2521 /* Register an 'expect' for given IMSI (+TMSI) */
2522 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002523 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002524 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002525 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002526 }
2527
2528 /* Send CM Service Request for MO SMMA */
2529 f_establish_fully(EST_TYPE_MO_SMS);
2530
2531 /* Submit MO SMMA on DTAP */
2532 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2533 spars_mo.rp.msg_ref := '00'O;
2534 f_mo_smma(spars_mo);
2535
2536 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2537 alt {
2538 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2539 imsi := g_pars.imsi,
2540 sm_rp_mr := spars_mo.rp.msg_ref,
2541 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2542 )) {
2543 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2544 setverdict(pass);
2545 }
2546 [] GSUP.receive {
2547 log("RX unexpected GSUP message");
2548 setverdict(fail);
2549 mtc.stop;
2550 }
2551 }
2552
2553 /* Submit MT SMS on GSUP */
2554 log("TX MT-forwardSM-Req for the MT SMS");
2555 f_gsup_forwardSM_req(spars_mt);
2556
2557 /* Wait for MT SMS on DTAP */
2558 f_mt_sms_expect(spars_mt);
2559 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2560 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2561
2562 /* Both SM-RP-MR values shall be different */
2563 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2564 log("Both SM-RP-MR values shall be different");
2565 setverdict(fail);
2566 }
2567
2568 /* SM-RP-MR value for MT SMS shall be assigned */
2569 if (spars_mt.rp.msg_ref == 'FF'O) {
2570 log("Unassigned SM-RP-MR value for the MT SMS");
2571 setverdict(fail);
2572 }
2573
2574 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2575 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2576 imsi := g_pars.imsi,
2577 sm_rp_mr := spars_mo.rp.msg_ref)));
2578 /* Expect RP-ACK for MO SMMA on DTAP */
2579 f_mo_sms_wait_rp_ack(spars_mo);
2580
2581 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2582 f_mt_sms_send_rp_ack(spars_mt);
2583 alt {
2584 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2585 imsi := g_pars.imsi,
2586 sm_rp_mr := spars_mt.rp.msg_ref
2587 )) {
2588 log("RX MT-forwardSM-Res (RP-ACK)");
2589 setverdict(pass);
2590 }
2591 [] GSUP.receive {
2592 log("RX unexpected GSUP message");
2593 setverdict(fail);
2594 mtc.stop;
2595 }
2596 }
2597
2598 f_expect_clear();
2599}
2600testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
2601 var BSC_ConnHdlrPars pars;
2602 var BSC_ConnHdlr vc_conn;
2603 f_init();
2604 pars := f_init_pars(93);
2605 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2606 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
2607 vc_conn.done;
2608 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2609}
2610
Harald Weltee13cfb22019-04-23 16:52:02 +02002611
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002612/* Test multi-part MT-SMS over GSUP */
2613private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
2614runs on BSC_ConnHdlr {
2615 var SmsParameters spars := valueof(t_SmsPars);
2616
2617 f_init_handler(pars);
2618
2619 /* We need to inspect GSUP activity */
2620 f_create_gsup_expect(hex2str(g_pars.imsi));
2621
2622 /* Perform location update */
2623 f_perform_lu();
2624
2625 /* Register an 'expect' for given IMSI (+TMSI) */
2626 if (isvalue(g_pars.tmsi)) {
Harald Welte6811d102019-04-14 22:23:14 +02002627 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002628 } else {
Harald Welte6811d102019-04-14 22:23:14 +02002629 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002630 }
2631
2632 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2633 imsi := g_pars.imsi,
2634 /* NOTE: MSC should assign RP-MR itself */
2635 sm_rp_mr := ?
2636 );
2637
2638 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
2639 for (var integer i := 3; i >= 0; i := i-1) {
2640 /* Submit a MT SMS on GSUP (MMS is decremented) */
2641 f_gsup_forwardSM_req(spars, int2oct(i, 1));
2642
2643 /* Expect Paging Request and Establish connection */
2644 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02002645 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002646 f_establish_fully(EST_TYPE_PAG_RESP);
2647 }
2648
2649 /* Wait for MT SMS on DTAP */
2650 f_mt_sms_expect(spars);
2651
2652 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2653 f_mt_sms_send_rp_ack(spars);
2654 alt {
2655 [] GSUP.receive(mt_forwardSM_res) {
2656 log("RX MT-forwardSM-Res (RP-ACK)");
2657 setverdict(pass);
2658 }
2659 [] GSUP.receive {
2660 log("RX unexpected GSUP message");
2661 setverdict(fail);
2662 mtc.stop;
2663 }
2664 }
2665
2666 /* Keep some 'distance' between transmissions */
2667 f_sleep(1.5);
2668 }
2669
2670 f_expect_clear();
2671}
2672testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
2673 var BSC_ConnHdlrPars pars;
2674 var BSC_ConnHdlr vc_conn;
2675 f_init();
2676 pars := f_init_pars(91);
2677 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2678 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
2679 vc_conn.done;
2680 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2681}
2682
Harald Weltef640a012018-04-14 17:49:21 +02002683/* convert GSM L3 TON to SMPP_TON enum */
2684function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
2685 select (ton) {
2686 case ('000'B) { return unknown; }
2687 case ('001'B) { return international; }
2688 case ('010'B) { return national; }
2689 case ('011'B) { return network_specific; }
2690 case ('100'B) { return subscriber_number; }
2691 case ('101'B) { return alphanumeric; }
2692 case ('110'B) { return abbreviated; }
2693 }
2694 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02002695 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002696}
2697/* convert GSM L3 NPI to SMPP_NPI enum */
2698function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2699 select (npi) {
2700 case ('0000'B) { return unknown; }
2701 case ('0001'B) { return isdn; }
2702 case ('0011'B) { return data; }
2703 case ('0100'B) { return telex; }
2704 case ('0110'B) { return land_mobile; }
2705 case ('1000'B) { return national; }
2706 case ('1001'B) { return private_; }
2707 case ('1010'B) { return ermes; }
2708 }
2709 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02002710 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002711}
2712
2713/* build a SMPP_SM from SmsParameters */
2714function f_mt_sm_from_spars(SmsParameters spars)
2715runs on BSC_ConnHdlr return SMPP_SM {
2716 var SMPP_SM sm := {
2717 service_type := "CMT",
2718 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2719 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2720 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2721 dest_addr_ton := international,
2722 dest_addr_npi := isdn,
2723 destination_addr := hex2str(g_pars.msisdn),
2724 esm_class := '00000001'B,
2725 protocol_id := 0,
2726 priority_flag := 0,
2727 schedule_delivery_time := "",
2728 validity_period := "",
2729 registered_delivery := '00000000'B,
2730 replace_if_present := 0,
2731 data_coding := '00000001'B,
2732 sm_default_msg_id := 0,
2733 sm_length := spars.tp.udl,
2734 short_message := spars.tp.ud,
2735 opt_pars := {}
2736 };
2737 return sm;
2738}
2739
2740/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2741private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2742 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2743 if (trans_mode) {
2744 sm.esm_class := '00000010'B;
2745 }
2746
2747 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2748 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2749 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2750 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2751 * before we expect the SMS delivery on the BSC/radio side */
2752 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2753 }
2754
2755 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002756 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02002757 /* Establish DTAP / BSSAP / SCCP connection */
2758 f_establish_fully(EST_TYPE_PAG_RESP);
2759 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2760
2761 f_mt_sms(spars);
2762
2763 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2764 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2765 }
2766 f_expect_clear();
2767}
2768
2769/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2770private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2771 f_init_handler(pars);
2772
2773 /* Perform location update so IMSI is known + registered in MSC/VLR */
2774 f_perform_lu();
2775 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2776
2777 /* register an 'expect' for given IMSI (+TMSI) */
2778 var OCT4 tmsi;
2779 if (isvalue(g_pars.tmsi)) {
2780 tmsi := g_pars.tmsi;
2781 } else {
2782 tmsi := 'FFFFFFFF'O;
2783 }
Harald Welte6811d102019-04-14 22:23:14 +02002784 f_ran_register_imsi(g_pars.imsi, tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02002785
2786 var SmsParameters spars := valueof(t_SmsPars);
2787 /* TODO: test with more intelligent user data; test different coding schemes */
2788 spars.tp.ud := '00'O;
2789 spars.tp.udl := 1;
2790
2791 /* first test the non-transaction store+forward mode */
2792 f_smpp_mt_sms(spars, false);
2793
2794 /* then test the transaction mode */
2795 f_smpp_mt_sms(spars, true);
2796}
2797testcase TC_smpp_mt_sms() runs on MTC_CT {
2798 var BSC_ConnHdlr vc_conn;
2799 f_init();
2800 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
2801 vc_conn.done;
2802}
2803
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002804/***********************************************************************
2805 * USSD Testing
2806 ***********************************************************************/
2807
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002808private altstep as_unexp_gsup_or_bssap_msg()
2809runs on BSC_ConnHdlr {
2810 [] GSUP.receive {
2811 setverdict(fail, "Unknown/unexpected GSUP received");
2812 self.stop;
2813 }
2814 [] BSSAP.receive {
2815 setverdict(fail, "Unknown/unexpected BSSAP message received");
2816 self.stop;
2817 }
2818}
2819
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07002820private function f_expect_gsup_msg(template GSUP_PDU msg,
2821 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002822runs on BSC_ConnHdlr return GSUP_PDU {
2823 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07002824 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002825
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002826 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002827 alt {
2828 [] GSUP.receive(msg) -> value gsup_msg_complete {
2829 setverdict(pass);
2830 }
2831 /* We don't expect anything else */
2832 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002833 [] T.timeout {
2834 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
2835 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002836 }
2837
2838 return gsup_msg_complete;
2839}
2840
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07002841private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
2842 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002843runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
2844 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07002845 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002846
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002847 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002848 alt {
2849 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
2850 setverdict(pass);
2851 }
2852 /* We don't expect anything else */
2853 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002854 [] T.timeout {
2855 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
2856 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002857 }
2858
2859 return bssap_msg_complete.dtap;
2860}
2861
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002862/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02002863friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002864runs on BSC_ConnHdlr {
2865 f_init_handler(pars);
2866
2867 /* Perform location update */
2868 f_perform_lu();
2869
2870 /* Send CM Service Request for SS/USSD */
2871 f_establish_fully(EST_TYPE_SS_ACT);
2872
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002873 /* We need to inspect GSUP activity */
2874 f_create_gsup_expect(hex2str(g_pars.imsi));
2875
2876 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2877 invoke_id := 5, /* Phone may not start from 0 or 1 */
2878 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2879 ussd_string := "*#100#"
2880 );
2881
2882 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
2883 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
2884 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2885 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
2886 )
2887
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002888 /* Compose a new SS/REGISTER message with request */
2889 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
2890 tid := 1, /* We just need a single transaction */
2891 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002892 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002893 );
2894
2895 /* Compose SS/RELEASE_COMPLETE template with expected response */
2896 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
2897 tid := 1, /* Response should arrive within the same transaction */
2898 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002899 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002900 );
2901
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002902 /* Compose expected MSC -> HLR message */
2903 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
2904 imsi := g_pars.imsi,
2905 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2906 ss := valueof(facility_req)
2907 );
2908
2909 /* To be used for sending response with correct session ID */
2910 var GSUP_PDU gsup_req_complete;
2911
2912 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002913 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002914 /* Expect GSUP message containing the SS payload */
2915 gsup_req_complete := f_expect_gsup_msg(gsup_req);
2916
2917 /* Compose the response from HLR using received session ID */
2918 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
2919 imsi := g_pars.imsi,
2920 sid := gsup_req_complete.ies[1].val.session_id,
2921 state := OSMO_GSUP_SESSION_STATE_END,
2922 ss := valueof(facility_rsp)
2923 );
2924
2925 /* Finally, HLR terminates the session */
2926 GSUP.send(gsup_rsp);
2927 /* Expect RELEASE_COMPLETE message with the response */
2928 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002929
2930 f_expect_clear();
2931}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002932testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002933 var BSC_ConnHdlr vc_conn;
2934 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002935 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002936 vc_conn.done;
2937}
2938
Harald Weltee13cfb22019-04-23 16:52:02 +02002939
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002940/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02002941friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002942runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002943 timer T := 5.0;
2944
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002945 f_init_handler(pars);
2946
2947 /* Perform location update */
2948 f_perform_lu();
2949
Harald Welte6811d102019-04-14 22:23:14 +02002950 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002951
2952 /* We need to inspect GSUP activity */
2953 f_create_gsup_expect(hex2str(g_pars.imsi));
2954
2955 /* Facility IE with network-originated USSD notification */
2956 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2957 op_code := SS_OP_CODE_USS_NOTIFY,
2958 ussd_string := "Mahlzeit!"
2959 );
2960
2961 /* Facility IE with acknowledgment to the USSD notification */
2962 var template OCTN facility_rsp := enc_SS_FacilityInformation(
2963 /* In case of USSD notification, Return Result is empty */
2964 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
2965 );
2966
2967 /* Compose a new MT SS/REGISTER message with USSD notification */
2968 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
2969 tid := 0, /* FIXME: most likely, it should be 0 */
2970 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
2971 facility := valueof(facility_req)
2972 );
2973
2974 /* Compose HLR -> MSC GSUP message */
2975 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
2976 imsi := g_pars.imsi,
2977 sid := '20000101'O,
2978 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2979 ss := valueof(facility_req)
2980 );
2981
2982 /* Send it to MSC and expect Paging Request */
2983 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002984 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002985 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02002986 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2987 setverdict(pass);
2988 }
Harald Welte62113fc2019-05-09 13:04:02 +02002989 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002990 setverdict(pass);
2991 }
2992 /* We don't expect anything else */
2993 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07002994 [] T.timeout {
2995 setverdict(fail, "Timeout waiting for Paging Request");
2996 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002997 }
2998
2999 /* Send Paging Response and expect USSD notification */
3000 f_establish_fully(EST_TYPE_PAG_RESP);
3001 /* Expect MT REGISTER message with USSD notification */
3002 f_expect_mt_dtap_msg(ussd_ntf);
3003
3004 /* Compose a new MO SS/FACILITY message with empty response */
3005 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3006 tid := 0, /* FIXME: it shall match the request tid */
3007 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3008 facility := valueof(facility_rsp)
3009 );
3010
3011 /* Compose expected MSC -> HLR GSUP message */
3012 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3013 imsi := g_pars.imsi,
3014 sid := '20000101'O,
3015 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3016 ss := valueof(facility_rsp)
3017 );
3018
3019 /* MS sends response to the notification */
3020 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3021 /* Expect GSUP message containing the SS payload */
3022 f_expect_gsup_msg(gsup_rsp);
3023
3024 /* Compose expected MT SS/RELEASE COMPLETE message */
3025 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3026 tid := 0, /* FIXME: it shall match the request tid */
3027 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3028 facility := omit
3029 );
3030
3031 /* Compose MSC -> HLR GSUP message */
3032 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3033 imsi := g_pars.imsi,
3034 sid := '20000101'O,
3035 state := OSMO_GSUP_SESSION_STATE_END
3036 );
3037
3038 /* Finally, HLR terminates the session */
3039 GSUP.send(gsup_term)
3040 /* Expect MT RELEASE COMPLETE without Facility IE */
3041 f_expect_mt_dtap_msg(ussd_term);
3042
3043 f_expect_clear();
3044}
3045testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3046 var BSC_ConnHdlr vc_conn;
3047 f_init();
3048 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3049 vc_conn.done;
3050}
3051
Harald Weltee13cfb22019-04-23 16:52:02 +02003052
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003053/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003054friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003055runs on BSC_ConnHdlr {
3056 f_init_handler(pars);
3057
3058 /* Call parameters taken from f_tc_lu_and_mt_call */
3059 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3060 cpars.mgcp_connection_id_bss := '10004'H;
3061 cpars.mgcp_connection_id_mss := '10005'H;
3062 cpars.mgcp_ep := "rtpbridge/1@mgw";
3063 cpars.bss_rtp_port := 1110;
3064
3065 /* Perform location update */
3066 f_perform_lu();
3067
3068 /* Establish a MT call */
3069 f_mt_call_establish(cpars);
3070
3071 /* Hold the call for some time */
3072 f_sleep(1.0);
3073
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003074 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3075 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3076 ussd_string := "*#100#"
3077 );
3078
3079 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3080 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3081 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3082 )
3083
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003084 /* Compose a new SS/REGISTER message with request */
3085 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3086 tid := 1, /* We just need a single transaction */
3087 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003088 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003089 );
3090
3091 /* Compose SS/RELEASE_COMPLETE template with expected response */
3092 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3093 tid := 1, /* Response should arrive within the same transaction */
3094 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003095 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003096 );
3097
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003098 /* Compose expected MSC -> HLR message */
3099 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3100 imsi := g_pars.imsi,
3101 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3102 ss := valueof(facility_req)
3103 );
3104
3105 /* To be used for sending response with correct session ID */
3106 var GSUP_PDU gsup_req_complete;
3107
3108 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003109 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003110 /* Expect GSUP message containing the SS payload */
3111 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3112
3113 /* Compose the response from HLR using received session ID */
3114 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3115 imsi := g_pars.imsi,
3116 sid := gsup_req_complete.ies[1].val.session_id,
3117 state := OSMO_GSUP_SESSION_STATE_END,
3118 ss := valueof(facility_rsp)
3119 );
3120
3121 /* Finally, HLR terminates the session */
3122 GSUP.send(gsup_rsp);
3123 /* Expect RELEASE_COMPLETE message with the response */
3124 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003125
3126 /* Hold the call for some time */
3127 f_sleep(1.0);
3128
3129 /* Release the call (does Clear Complete itself) */
3130 f_call_hangup(cpars, true);
3131}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003132testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003133 var BSC_ConnHdlr vc_conn;
3134 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003135 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003136 vc_conn.done;
3137}
3138
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003139/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003140friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003141 f_init_handler(pars);
3142 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
3143 var MNCC_PDU mncc;
3144 var MgcpCommand mgcp_cmd;
3145
3146 f_perform_lu();
3147
3148 f_establish_fully();
3149 f_create_mncc_expect(hex2str(cpars.called_party));
3150 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
3151
3152 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
3153 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
3154 cpars.mncc_callref := mncc.u.signal.callref;
3155 log("mncc_callref=", cpars.mncc_callref);
3156 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
3157 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
3158
3159 MNCC.send(ts_MNCC_ALERT_req(cpars.mncc_callref));
3160 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_ALERTING(cpars.transaction_id)));
3161 MGCP.receive(tr_CRCX);
3162
3163 f_sleep(1.0);
Harald Weltee13cfb22019-04-23 16:52:02 +02003164 if (pars.ran_is_geran) {
3165 BSSAP.send(ts_BSSMAP_ClearRequest(0));
3166 } else {
3167 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
3168 }
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003169
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003170 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003171
Harald Weltee13cfb22019-04-23 16:52:02 +02003172 if (pars.ran_is_geran) {
3173 interleave {
3174 [] MNCC.receive(tr_MNCC_REL_ind(?, ?)) { };
3175 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003176 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Weltee13cfb22019-04-23 16:52:02 +02003177 };
3178 }
3179 } else {
3180 interleave {
3181 [] MNCC.receive(tr_MNCC_REL_ind(?, ?)) { };
3182 [] BSSAP.receive(tr_RANAP_IuReleaseCommand(?)) {
3183 BSSAP.send(ts_RANAP_IuReleaseComplete);
3184 };
3185 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003186 }
3187
3188 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003189
3190 f_sleep(1.0);
3191}
3192testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3193 var BSC_ConnHdlr vc_conn;
3194 f_init();
3195
3196 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3197 vc_conn.done;
3198}
3199
Harald Weltee13cfb22019-04-23 16:52:02 +02003200
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003201/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003202friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003203runs on BSC_ConnHdlr {
3204 f_init_handler(pars);
3205
3206 /* Call parameters taken from f_tc_lu_and_mt_call */
3207 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3208 cpars.mgcp_connection_id_bss := '10004'H;
3209 cpars.mgcp_connection_id_mss := '10005'H;
3210 cpars.mgcp_ep := "rtpbridge/1@mgw";
3211 cpars.bss_rtp_port := 1110;
3212
3213 /* Perform location update */
3214 f_perform_lu();
3215
3216 /* Establish a MT call */
3217 f_mt_call_establish(cpars);
3218
3219 /* Hold the call for some time */
3220 f_sleep(1.0);
3221
3222 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3223 op_code := SS_OP_CODE_USS_REQUEST,
3224 ussd_string := "Please type anything..."
3225 );
3226
3227 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3228 op_code := SS_OP_CODE_USS_REQUEST,
3229 ussd_string := "Nope."
3230 )
3231
3232 /* Compose MT SS/REGISTER message with network-originated request */
3233 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3234 tid := 0, /* FIXME: most likely, it should be 0 */
3235 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3236 facility := valueof(facility_req)
3237 );
3238
3239 /* Compose HLR -> MSC GSUP message */
3240 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3241 imsi := g_pars.imsi,
3242 sid := '20000101'O,
3243 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3244 ss := valueof(facility_req)
3245 );
3246
3247 /* Send it to MSC */
3248 GSUP.send(gsup_req);
3249 /* Expect MT REGISTER message with USSD request */
3250 f_expect_mt_dtap_msg(ussd_req);
3251
3252 /* Compose a new MO SS/FACILITY message with response */
3253 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3254 tid := 0, /* FIXME: it shall match the request tid */
3255 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3256 facility := valueof(facility_rsp)
3257 );
3258
3259 /* Compose expected MSC -> HLR GSUP message */
3260 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3261 imsi := g_pars.imsi,
3262 sid := '20000101'O,
3263 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3264 ss := valueof(facility_rsp)
3265 );
3266
3267 /* MS sends response */
3268 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3269 f_expect_gsup_msg(gsup_rsp);
3270
3271 /* Compose expected MT SS/RELEASE COMPLETE message */
3272 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3273 tid := 0, /* FIXME: it shall match the request tid */
3274 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3275 facility := omit
3276 );
3277
3278 /* Compose MSC -> HLR GSUP message */
3279 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3280 imsi := g_pars.imsi,
3281 sid := '20000101'O,
3282 state := OSMO_GSUP_SESSION_STATE_END
3283 );
3284
3285 /* Finally, HLR terminates the session */
3286 GSUP.send(gsup_term);
3287 /* Expect MT RELEASE COMPLETE without Facility IE */
3288 f_expect_mt_dtap_msg(ussd_term);
3289
3290 /* Hold the call for some time */
3291 f_sleep(1.0);
3292
3293 /* Release the call (does Clear Complete itself) */
3294 f_call_hangup(cpars, true);
3295}
3296testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3297 var BSC_ConnHdlr vc_conn;
3298 f_init();
3299 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3300 vc_conn.done;
3301}
3302
Harald Weltee13cfb22019-04-23 16:52:02 +02003303
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003304/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003305friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003306runs on BSC_ConnHdlr {
3307 f_init_handler(pars);
3308
3309 /* Perform location update */
3310 f_perform_lu();
3311
3312 /* Send CM Service Request for SS/USSD */
3313 f_establish_fully(EST_TYPE_SS_ACT);
3314
3315 /* We need to inspect GSUP activity */
3316 f_create_gsup_expect(hex2str(g_pars.imsi));
3317
3318 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3319 invoke_id := 1, /* Initial request */
3320 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3321 ussd_string := "*6766*266#"
3322 );
3323
3324 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3325 invoke_id := 2, /* Counter request */
3326 op_code := SS_OP_CODE_USS_REQUEST,
3327 ussd_string := "Password?!?"
3328 )
3329
3330 /* Compose MO SS/REGISTER message with request */
3331 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3332 tid := 1, /* We just need a single transaction */
3333 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3334 facility := valueof(facility_ms_req)
3335 );
3336
3337 /* Compose expected MSC -> HLR message */
3338 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3339 imsi := g_pars.imsi,
3340 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3341 ss := valueof(facility_ms_req)
3342 );
3343
3344 /* To be used for sending response with correct session ID */
3345 var GSUP_PDU gsup_ms_req_complete;
3346
3347 /* Initiate a new transaction */
3348 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3349 /* Expect GSUP request with original Facility IE */
3350 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3351
3352 /* Compose the response from HLR using received session ID */
3353 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3354 imsi := g_pars.imsi,
3355 sid := gsup_ms_req_complete.ies[1].val.session_id,
3356 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3357 ss := valueof(facility_net_req)
3358 );
3359
3360 /* Compose expected MT SS/FACILITY template with counter request */
3361 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3362 tid := 1, /* Response should arrive within the same transaction */
3363 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3364 facility := valueof(facility_net_req)
3365 );
3366
3367 /* Send response over GSUP */
3368 GSUP.send(gsup_net_req);
3369 /* Expect MT SS/FACILITY message with counter request */
3370 f_expect_mt_dtap_msg(ussd_net_req);
3371
3372 /* Compose MO SS/RELEASE COMPLETE */
3373 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3374 tid := 1, /* Response should arrive within the same transaction */
3375 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3376 facility := omit
3377 /* TODO: cause? */
3378 );
3379
3380 /* Compose expected HLR -> MSC abort message */
3381 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3382 imsi := g_pars.imsi,
3383 sid := gsup_ms_req_complete.ies[1].val.session_id,
3384 state := OSMO_GSUP_SESSION_STATE_END
3385 );
3386
3387 /* Abort transaction */
3388 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3389 /* Expect GSUP message indicating abort */
3390 f_expect_gsup_msg(gsup_abort);
3391
3392 f_expect_clear();
3393}
3394testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3395 var BSC_ConnHdlr vc_conn;
3396 f_init();
3397 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3398 vc_conn.done;
3399}
3400
Harald Weltee13cfb22019-04-23 16:52:02 +02003401
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003402/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003403friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003404runs on BSC_ConnHdlr {
3405 f_init_handler(pars);
3406
3407 /* Perform location update */
3408 f_perform_lu();
3409
3410 /* Send CM Service Request for SS/USSD */
3411 f_establish_fully(EST_TYPE_SS_ACT);
3412
3413 /* We need to inspect GSUP activity */
3414 f_create_gsup_expect(hex2str(g_pars.imsi));
3415
3416 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3417 invoke_id := 1,
3418 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3419 ussd_string := "#release_me");
3420
3421 /* Compose MO SS/REGISTER message with request */
3422 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3423 tid := 1, /* An arbitrary transaction identifier */
3424 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3425 facility := valueof(facility_ms_req));
3426
3427 /* Compose expected MSC -> HLR message */
3428 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3429 imsi := g_pars.imsi,
3430 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3431 ss := valueof(facility_ms_req));
3432
3433 /* To be used for sending response with correct session ID */
3434 var GSUP_PDU gsup_ms_req_complete;
3435
3436 /* Initiate a new SS transaction */
3437 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3438 /* Expect GSUP request with original Facility IE */
3439 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3440
3441 /* Don't respond, wait for timeout */
3442 f_sleep(3.0);
3443
3444 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3445 tid := 1, /* Should match the request's tid */
3446 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3447 cause := *, /* TODO: expect some specific value */
3448 facility := omit);
3449
3450 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3451 imsi := g_pars.imsi,
3452 sid := gsup_ms_req_complete.ies[1].val.session_id,
3453 state := OSMO_GSUP_SESSION_STATE_END,
3454 cause := ?); /* TODO: expect some specific value */
3455
3456 /* Expect release on both interfaces */
3457 interleave {
3458 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3459 [] GSUP.receive(gsup_rel) { };
3460 }
3461
3462 f_expect_clear();
3463 setverdict(pass);
3464}
3465testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3466 var BSC_ConnHdlr vc_conn;
3467 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003468 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003469 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3470 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003471 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003472}
3473
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003474/* MT (network-originated) USSD for unknown subscriber */
3475friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
3476runs on BSC_ConnHdlr {
3477 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
3478 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003479
3480 f_init_handler(pars);
3481 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
3482 f_create_gsup_expect(hex2str(imsi));
3483
3484 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3485 imsi := imsi,
3486 sid := sid,
3487 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3488 ss := f_rnd_octstring(23)
3489 );
3490
3491 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
3492 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3493 imsi := imsi,
3494 sid := sid,
3495 state := OSMO_GSUP_SESSION_STATE_END,
3496 cause := 2 /* FIXME: introduce an enumerated type! */
3497 );
3498
3499 /* Initiate a MT USSD notification */
3500 GSUP.send(gsup_req);
3501
3502 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07003503 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003504}
3505testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
3506 var BSC_ConnHdlr vc_conn;
3507 f_init();
3508 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
3509 vc_conn.done;
3510}
3511
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003512/* MO (mobile-originated) SS/USSD for unknown transaction */
3513friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
3514runs on BSC_ConnHdlr {
3515 f_init_handler(pars);
3516
3517 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
3518 f_create_gsup_expect(hex2str(g_pars.imsi));
3519
3520 /* Perform location update */
3521 f_perform_lu();
3522
3523 /* Send CM Service Request for SS/USSD */
3524 f_establish_fully(EST_TYPE_SS_ACT);
3525
3526 /* GSM 04.80 FACILITY message for a non-existing transaction */
3527 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
3528 tid := 1, /* An arbitrary transaction identifier */
3529 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3530 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3531 );
3532
3533 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
3534 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
3535 tid := 1, /* An arbitrary transaction identifier */
3536 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3537 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3538 );
3539
3540 /* Expected response from the network */
3541 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3542 tid := 1, /* Same as in the FACILITY message */
3543 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3544 facility := omit
3545 );
3546
3547 /* Send GSM 04.80 FACILITY for non-existing transaction */
3548 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
3549
3550 /* Expect GSM 04.80 RELEASE COMPLETE message */
3551 f_expect_mt_dtap_msg(mt_ss_rel);
3552 f_expect_clear();
3553
3554 /* Send another CM Service Request for SS/USSD */
3555 f_establish_fully(EST_TYPE_SS_ACT);
3556
3557 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
3558 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
3559
3560 /* Expect GSM 04.80 RELEASE COMPLETE message */
3561 f_expect_mt_dtap_msg(mt_ss_rel);
3562 f_expect_clear();
3563}
3564testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
3565 var BSC_ConnHdlr vc_conn;
3566 f_init();
3567 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
3568 vc_conn.done;
3569}
3570
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003571/* MT (network-originated) USSD for unknown session */
3572friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
3573runs on BSC_ConnHdlr {
3574 var OCT4 sid := '20000333'O;
3575
3576 f_init_handler(pars);
3577
3578 /* Perform location update */
3579 f_perform_lu();
3580
3581 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
3582 f_create_gsup_expect(hex2str(g_pars.imsi));
3583
3584 /* Request referencing a non-existing SS session */
3585 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3586 imsi := g_pars.imsi,
3587 sid := sid,
3588 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3589 ss := f_rnd_octstring(23)
3590 );
3591
3592 /* Error with some cause value */
3593 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3594 imsi := g_pars.imsi,
3595 sid := sid,
3596 state := OSMO_GSUP_SESSION_STATE_END,
3597 cause := ? /* FIXME: introduce an enumerated type! */
3598 );
3599
3600 /* Initiate a MT USSD notification */
3601 GSUP.send(gsup_req);
3602
3603 /* Expect GSUP PROC_SS_ERROR message */
3604 f_expect_gsup_msg(gsup_rsp);
3605}
3606testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
3607 var BSC_ConnHdlr vc_conn;
3608 f_init();
3609 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
3610 vc_conn.done;
3611}
3612
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003613/* MT (network-originated) USSD and no response to Paging Request */
3614friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
3615runs on BSC_ConnHdlr {
3616 timer TP := 2.0; /* Paging timer */
3617
3618 f_init_handler(pars);
3619
3620 /* Perform location update */
3621 f_perform_lu();
3622
3623 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
3624 f_create_gsup_expect(hex2str(g_pars.imsi));
3625
3626 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3627 imsi := g_pars.imsi,
3628 sid := '20000444'O,
3629 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3630 ss := f_rnd_octstring(23)
3631 );
3632
3633 /* Error with some cause value */
3634 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3635 imsi := g_pars.imsi,
3636 sid := '20000444'O,
3637 state := OSMO_GSUP_SESSION_STATE_END,
3638 cause := ? /* FIXME: introduce an enumerated type! */
3639 );
3640
3641 /* Initiate a MT USSD notification */
3642 GSUP.send(gsup_req);
3643
3644 /* Send it to MSC and expect Paging Request */
3645 TP.start;
3646 alt {
3647 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3648 setverdict(pass);
3649 }
3650 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
3651 setverdict(pass);
3652 }
3653 /* We don't expect anything else */
3654 [] as_unexp_gsup_or_bssap_msg();
3655 [] TP.timeout {
3656 setverdict(fail, "Timeout waiting for Paging Request");
3657 }
3658 }
3659
3660 /* Expect GSUP PROC_SS_ERROR message */
3661 f_expect_gsup_msg(gsup_rsp, T_val := 10.0);
3662}
3663testcase TC_proc_ss_paging_fail() runs on MTC_CT {
3664 var BSC_ConnHdlr vc_conn;
3665 f_init();
3666 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
3667 vc_conn.done;
3668}
3669
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07003670/* MT (network-originated) USSD followed by immediate abort */
3671friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
3672runs on BSC_ConnHdlr {
3673 var octetstring facility := f_rnd_octstring(23);
3674 var OCT4 sid := '20000555'O;
3675 timer TP := 2.0;
3676
3677 f_init_handler(pars);
3678
3679 /* Perform location update */
3680 f_perform_lu();
3681
3682 f_ran_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
3683 f_create_gsup_expect(hex2str(g_pars.imsi));
3684
3685 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
3686 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3687 imsi := g_pars.imsi, sid := sid,
3688 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3689 ss := facility
3690 );
3691
3692 /* On the MS side, we expect GSM 04.80 REGISTER message */
3693 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
3694 tid := 0, /* Most likely, it should be 0 */
3695 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3696 facility := facility
3697 );
3698
3699 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
3700 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
3701 imsi := g_pars.imsi, sid := sid,
3702 state := OSMO_GSUP_SESSION_STATE_END,
3703 cause := 0 /* FIXME: introduce an enumerated type! */
3704 );
3705
3706 /* On the MS side, we expect GSM 04.80 REGISTER message */
3707 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3708 tid := 0, /* Most likely, it should be 0 */
3709 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3710 cause := *, /* FIXME: expect some specific cause value */
3711 facility := omit
3712 );
3713
3714 /* Initiate a MT USSD with random payload */
3715 GSUP.send(gsup_req);
3716
3717 /* Expect Paging Request */
3718 TP.start;
3719 alt {
3720 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3721 setverdict(pass);
3722 }
3723 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
3724 setverdict(pass);
3725 }
3726 /* We don't expect anything else */
3727 [] as_unexp_gsup_or_bssap_msg();
3728 [] TP.timeout {
3729 setverdict(fail, "Timeout waiting for Paging Request");
3730 }
3731 }
3732
3733 /* Send Paging Response and establish connection */
3734 f_establish_fully(EST_TYPE_PAG_RESP);
3735 /* Expect MT REGISTER message with random facility */
3736 f_expect_mt_dtap_msg(dtap_reg);
3737
3738 /* HLR/EUSE decides to abort the session even
3739 * before getting any response from the MS */
3740 /* Initiate a MT USSD with random payload */
3741 GSUP.send(gsup_abort);
3742
3743 /* Expect RELEASE COMPLETE on ths MS side */
3744 f_expect_mt_dtap_msg(dtap_rel);
3745
3746 f_expect_clear();
3747}
3748testcase TC_proc_ss_abort() runs on MTC_CT {
3749 var BSC_ConnHdlr vc_conn;
3750 f_init();
3751 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
3752 vc_conn.done;
3753}
3754
Harald Weltee13cfb22019-04-23 16:52:02 +02003755
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003756/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
3757private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3758 pars.net.expect_auth := true;
3759 pars.net.expect_ciph := true;
3760 pars.net.kc_support := '02'O; /* A5/1 only */
3761 f_init_handler(pars);
3762
3763 g_pars.vec := f_gen_auth_vec_2g();
3764
3765 /* Can't use f_perform_lu() directly. Code below is based on it. */
3766
3767 /* tell GSUP dispatcher to send this IMSI to us */
3768 f_create_gsup_expect(hex2str(g_pars.imsi));
3769
3770 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3771 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02003772 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003773
3774 f_mm_auth();
3775
3776 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3777 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3778 alt {
3779 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3780 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
3781 }
3782 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3783 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3784 mtc.stop;
3785 }
3786 [] BSSAP.receive {
3787 setverdict(fail, "Unknown/unexpected BSSAP received");
3788 mtc.stop;
3789 }
3790 }
3791
3792 /* Expect LU reject from MSC. */
3793 alt {
3794 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3795 setverdict(pass);
3796 }
3797 [] BSSAP.receive {
3798 setverdict(fail, "Unknown/unexpected BSSAP received");
3799 mtc.stop;
3800 }
3801 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01003802 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003803}
3804
3805testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
3806 var BSC_ConnHdlr vc_conn;
3807 f_init();
3808 f_vty_config(MSCVTY, "network", "encryption a5 1");
3809
3810 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52);
3811 vc_conn.done;
3812}
3813
Harald Welteb2284bd2019-05-10 11:30:43 +02003814/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
3815friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3816 f_init_handler(pars);
3817
3818 /* tell GSUP dispatcher to send this IMSI to us */
3819 f_create_gsup_expect(hex2str(g_pars.imsi));
3820
3821 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
3822 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
3823
3824 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3825 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
3826 f_cl3_or_initial_ue(l3_lu);
3827
3828 /* Expect LU reject from MSC. */
3829 alt {
3830 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3831 setverdict(pass);
3832 }
3833 [] BSSAP.receive {
3834 setverdict(fail, "Unknown/unexpected BSSAP received");
3835 mtc.stop;
3836 }
3837 }
3838 f_expect_clear();
3839}
3840testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
3841 var BSC_ConnHdlr vc_conn;
3842 f_init();
3843 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
3844 vc_conn.done;
3845}
3846
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01003847private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
3848 pars.net.expect_auth := true;
3849 pars.net.expect_ciph := true;
3850 pars.net.kc_support := kc_support;
3851 f_init_handler(pars);
3852
3853 g_pars.vec := f_gen_auth_vec_2g();
3854
3855 /* Can't use f_perform_lu() directly. Code below is based on it. */
3856
3857 /* tell GSUP dispatcher to send this IMSI to us */
3858 f_create_gsup_expect(hex2str(g_pars.imsi));
3859
3860 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3861 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
3862 f_cl3_or_initial_ue(l3_lu);
3863
3864 f_mm_auth();
3865
3866 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3867 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3868 alt {
3869 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3870 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
3871 }
3872 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
3873 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
3874 repeat;
3875 }
3876 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3877 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3878 mtc.stop;
3879 }
3880 [] BSSAP.receive {
3881 setverdict(fail, "Unknown/unexpected BSSAP received");
3882 mtc.stop;
3883 }
3884 }
3885
3886 /* TODO: Verify MSC is using the best cipher available! How? */
3887
3888 f_msc_lu_hlr();
3889 f_accept_reject_lu();
3890 f_expect_clear();
3891 setverdict(pass);
3892}
3893
3894/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
3895private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3896 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
3897}
3898
3899/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
3900private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3901 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
3902}
3903
3904/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
3905private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3906 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
3907}
3908
3909testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
3910 var BSC_ConnHdlr vc_conn;
3911 f_init();
3912 f_vty_config(MSCVTY, "network", "encryption a5 1");
3913
3914 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
3915 vc_conn.done;
3916}
3917
3918testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
3919 var BSC_ConnHdlr vc_conn;
3920 f_init();
3921 f_vty_config(MSCVTY, "network", "encryption a5 3");
3922
3923 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
3924 vc_conn.done;
3925}
3926
3927testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
3928 var BSC_ConnHdlr vc_conn;
3929 f_init();
3930 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
3931
3932 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
3933 vc_conn.done;
3934}
Harald Welteb2284bd2019-05-10 11:30:43 +02003935
Harald Weltef640a012018-04-14 17:49:21 +02003936/* TODO (SMS):
3937 * different user data lengths
3938 * SMPP transaction mode with unsuccessful delivery
3939 * queued MT-SMS with no paging response + later delivery
3940 * different data coding schemes
3941 * multi-part SMS
3942 * user-data headers
3943 * TP-PID for SMS to SIM
3944 * behavior if SMS memory is full + RP-SMMA
3945 * delivery reports
3946 * SMPP osmocom extensions
3947 * more-messages-to-send
3948 * SMS during ongoing call (SACCH/SAPI3)
3949 */
3950
3951/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01003952 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
3953 * malformed messages (missing IE, invalid message type): properly rejected?
3954 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
3955 * 3G/2G auth permutations
3956 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01003957 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01003958 * too long L3 INFO in DTAP
3959 * too long / padded BSSAP
3960 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01003961 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01003962
Harald Weltee13cfb22019-04-23 16:52:02 +02003963/***********************************************************************
3964 * SGsAP Testing
3965 ***********************************************************************/
3966
Philipp Maier948747b2019-04-02 15:22:33 +02003967/* Check if a subscriber exists in the VLR */
3968private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
3969
3970 var CtrlValue active_subsribers;
3971 var integer rc;
3972 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
3973
3974 rc := f_strstr(active_subsribers, imsi_or_msisdn);
3975 if (rc < 0) {
3976 return false;
3977 }
3978
3979 return true;
3980}
3981
Harald Welte4263c522018-12-06 11:56:27 +01003982/* Perform a location updatye at the A-Interface and run some checks to confirm
3983 * that everything is back to normal. */
3984private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
3985 var SmsParameters spars := valueof(t_SmsPars);
3986
3987 /* Perform a location update, the SGs association is expected to fall
3988 * back to NULL */
3989 f_perform_lu();
3990 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3991
3992 /* Trigger a paging request and expect the paging on BSSMAP, this is
3993 * to make sure that pagings are sent throught the A-Interface again
3994 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02003995 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01003996 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3997
3998 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003999 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4000 setverdict(pass);
4001 }
Harald Welte62113fc2019-05-09 13:04:02 +02004002 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004003 setverdict(pass);
4004 }
4005 [] SGsAP.receive {
4006 setverdict(fail, "Received unexpected message on SGs");
4007 }
4008 }
4009
4010 /* Send an SMS to make sure that also payload messages are routed
4011 * throught the A-Interface again */
4012 f_establish_fully(EST_TYPE_MO_SMS);
4013 f_mo_sms(spars);
4014 f_expect_clear();
4015}
4016
4017private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4018 var charstring vlr_name;
4019 f_init_handler(pars);
4020
4021 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4022 log("VLR name: ", vlr_name);
4023 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004024 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004025}
4026
4027testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004028 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004029 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004030 f_init(1, true);
4031 pars := f_init_pars(11810, true);
4032 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004033 vc_conn.done;
4034}
4035
4036/* like f_mm_auth() but for SGs */
4037function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4038 if (g_pars.net.expect_auth) {
4039 g_pars.vec := f_gen_auth_vec_3g();
4040 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4041 g_pars.vec.sres,
4042 g_pars.vec.kc,
4043 g_pars.vec.ik,
4044 g_pars.vec.ck,
4045 g_pars.vec.autn,
4046 g_pars.vec.res));
4047 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4048 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4049 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4050 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4051 }
4052}
4053
4054/* like f_perform_lu(), but on SGs rather than BSSAP */
4055function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4056 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4057 var PDU_SGsAP lur;
4058 var PDU_SGsAP lua;
4059 var PDU_SGsAP mm_info;
4060 var octetstring mm_info_dtap;
4061
4062 /* tell GSUP dispatcher to send this IMSI to us */
4063 f_create_gsup_expect(hex2str(g_pars.imsi));
4064
4065 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4066 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4067 /* Old LAI, if MS sends it */
4068 /* TMSI status, if MS has no valid TMSI */
4069 /* IMEISV, if it supports "automatic device detection" */
4070 /* TAI, if available in MME */
4071 /* E-CGI, if available in MME */
4072 SGsAP.send(lur);
4073
4074 /* FIXME: is this really done over SGs? The Ue is already authenticated
4075 * via the MME ... */
4076 f_mm_auth_sgs();
4077
4078 /* Expect MSC to perform LU with HLR */
4079 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4080 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4081 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4082 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4083
4084 alt {
4085 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4086 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4087 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4088 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4089 }
4090 setverdict(pass);
4091 }
4092 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4093 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4094 }
4095 [] SGsAP.receive {
4096 setverdict(fail, "Received unexpected message on SGs");
4097 }
4098 }
4099
4100 /* Check MM information */
4101 if (mp_mm_info == true) {
4102 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4103 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4104 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4105 setverdict(fail, "Unexpected MM Information");
4106 }
4107 }
4108
4109 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4110}
4111
4112private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4113 f_init_handler(pars);
4114 f_sgs_perform_lu();
4115 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4116
4117 f_sgsap_bssmap_screening();
4118
4119 setverdict(pass);
4120}
4121testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004122 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004123 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004124 f_init(1, true);
4125 pars := f_init_pars(11811, true);
4126 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004127 vc_conn.done;
4128}
4129
4130/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4131private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4132 f_init_handler(pars);
4133 var PDU_SGsAP lur;
4134
4135 f_create_gsup_expect(hex2str(g_pars.imsi));
4136 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4137 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4138 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4139 SGsAP.send(lur);
4140
4141 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4142 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4143 alt {
4144 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4145 setverdict(pass);
4146 }
4147 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4148 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4149 mtc.stop;
4150 }
4151 [] SGsAP.receive {
4152 setverdict(fail, "Received unexpected message on SGs");
4153 }
4154 }
4155
4156 f_sgsap_bssmap_screening();
4157
4158 setverdict(pass);
4159}
4160testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004161 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004162 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004163 f_init(1, true);
4164 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004165
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004166 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004167 vc_conn.done;
4168}
4169
4170/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4171private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4172 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4173 var PDU_SGsAP lur;
4174
4175 f_init_handler(pars);
4176
4177 /* tell GSUP dispatcher to send this IMSI to us */
4178 f_create_gsup_expect(hex2str(g_pars.imsi));
4179
4180 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4181 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4182 /* Old LAI, if MS sends it */
4183 /* TMSI status, if MS has no valid TMSI */
4184 /* IMEISV, if it supports "automatic device detection" */
4185 /* TAI, if available in MME */
4186 /* E-CGI, if available in MME */
4187 SGsAP.send(lur);
4188
4189 /* FIXME: is this really done over SGs? The Ue is already authenticated
4190 * via the MME ... */
4191 f_mm_auth_sgs();
4192
4193 /* Expect MSC to perform LU with HLR */
4194 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4195 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4196 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4197 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4198
4199 alt {
4200 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4201 setverdict(pass);
4202 }
4203 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4204 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4205 }
4206 [] SGsAP.receive {
4207 setverdict(fail, "Received unexpected message on SGs");
4208 }
4209 }
4210
4211 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4212
4213 /* Wait until the VLR has abort the TMSI reallocation procedure */
4214 f_sleep(45.0);
4215
4216 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4217 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4218
4219 f_sgsap_bssmap_screening();
4220
4221 setverdict(pass);
4222}
4223testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004224 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004225 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004226 f_init(1, true);
4227 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004228
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004229 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004230 vc_conn.done;
4231}
4232
4233private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4234runs on BSC_ConnHdlr {
4235 f_init_handler(pars);
4236 f_sgs_perform_lu();
4237 f_sleep(3.0);
4238
4239 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4240 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4241 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4242 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4243
4244 f_sgsap_bssmap_screening();
4245
4246 setverdict(pass);
4247}
4248testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004249 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004250 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004251 f_init(1, true);
4252 pars := f_init_pars(11814, true);
4253 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004254 vc_conn.done;
4255}
4256
Philipp Maierfc19f172019-03-21 11:17:54 +01004257private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4258runs on BSC_ConnHdlr {
4259 f_init_handler(pars);
4260 f_sgs_perform_lu();
4261 f_sleep(3.0);
4262
4263 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4264 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4265 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4266 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4267
4268 f_sgsap_bssmap_screening();
4269
4270 setverdict(pass);
4271}
4272testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4273 var BSC_ConnHdlrPars pars;
4274 var BSC_ConnHdlr vc_conn;
4275 f_init(1, true);
4276 pars := f_init_pars(11814, true);
4277 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4278 vc_conn.done;
4279}
4280
Harald Welte4263c522018-12-06 11:56:27 +01004281private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4282runs on BSC_ConnHdlr {
4283 f_init_handler(pars);
4284 f_sgs_perform_lu();
4285 f_sleep(3.0);
4286
4287 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4288 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4289 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004290
4291 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4292 setverdict(fail, "subscriber not removed from VLR");
4293 }
Harald Welte4263c522018-12-06 11:56:27 +01004294
4295 f_sgsap_bssmap_screening();
4296
4297 setverdict(pass);
4298}
4299testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004300 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004301 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004302 f_init(1, true);
4303 pars := f_init_pars(11815, true);
4304 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004305 vc_conn.done;
4306}
4307
Philipp Maier5d812702019-03-21 10:51:26 +01004308private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4309runs on BSC_ConnHdlr {
4310 f_init_handler(pars);
4311 f_sgs_perform_lu();
4312 f_sleep(3.0);
4313
4314 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4315 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4316 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4317
4318 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4319 setverdict(fail, "subscriber not removed from VLR");
4320 }
4321
4322 f_sgsap_bssmap_screening();
4323
4324 setverdict(pass);
4325}
4326testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4327 var BSC_ConnHdlrPars pars;
4328 var BSC_ConnHdlr vc_conn;
4329 f_init(1, true);
4330 pars := f_init_pars(11815, true);
4331 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4332 vc_conn.done;
4333}
4334
Harald Welte4263c522018-12-06 11:56:27 +01004335/* Trigger a paging request via VTY and send a paging reject in response */
4336private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4337runs on BSC_ConnHdlr {
4338 f_init_handler(pars);
4339 f_sgs_perform_lu();
4340 f_sleep(1.0);
4341
4342 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4343 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4344 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4345 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4346
4347 /* Initiate paging via VTY */
4348 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4349 alt {
4350 [] SGsAP.receive(exp_resp) {
4351 setverdict(pass);
4352 }
4353 [] SGsAP.receive {
4354 setverdict(fail, "Received unexpected message on SGs");
4355 }
4356 }
4357
4358 /* Now reject the paging */
4359 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4360
4361 /* Wait for the states inside the MSC to settle and check the state
4362 * of the SGs Association */
4363 f_sleep(1.0);
4364 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4365
4366 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4367 * but we also need to cover tha case where the cause code indicates an
4368 * "IMSI detached for EPS services". In those cases the VLR is expected to
4369 * try paging on tha A/Iu interface. This will be another testcase similar to
4370 * this one, but extended with checks for the presence of the A/Iu paging
4371 * messages. */
4372
4373 f_sgsap_bssmap_screening();
4374
4375 setverdict(pass);
4376}
4377testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004378 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004379 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004380 f_init(1, true);
4381 pars := f_init_pars(11816, true);
4382 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004383 vc_conn.done;
4384}
4385
4386/* Trigger a paging request via VTY and send a paging reject that indicates
4387 * that the subscriber intentionally rejected the call. */
4388private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4389runs on BSC_ConnHdlr {
4390 f_init_handler(pars);
4391 f_sgs_perform_lu();
4392 f_sleep(1.0);
4393
4394 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4395 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4396 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4397 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4398
4399 /* Initiate paging via VTY */
4400 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4401 alt {
4402 [] SGsAP.receive(exp_resp) {
4403 setverdict(pass);
4404 }
4405 [] SGsAP.receive {
4406 setverdict(fail, "Received unexpected message on SGs");
4407 }
4408 }
4409
4410 /* Now reject the paging */
4411 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4412
4413 /* Wait for the states inside the MSC to settle and check the state
4414 * of the SGs Association */
4415 f_sleep(1.0);
4416 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4417
4418 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4419 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4420 * to check back how this works and how it can be tested */
4421
4422 f_sgsap_bssmap_screening();
4423
4424 setverdict(pass);
4425}
4426testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004427 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004428 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004429 f_init(1, true);
4430 pars := f_init_pars(11817, true);
4431 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004432 vc_conn.done;
4433}
4434
4435/* Trigger a paging request via VTY and send an UE unreacable messge in response */
4436private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
4437runs on BSC_ConnHdlr {
4438 f_init_handler(pars);
4439 f_sgs_perform_lu();
4440 f_sleep(1.0);
4441
4442 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4443 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4444 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4445 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4446
4447 /* Initiate paging via VTY */
4448 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4449 alt {
4450 [] SGsAP.receive(exp_resp) {
4451 setverdict(pass);
4452 }
4453 [] SGsAP.receive {
4454 setverdict(fail, "Received unexpected message on SGs");
4455 }
4456 }
4457
4458 /* Now pretend that the UE is unreachable */
4459 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
4460
4461 /* Wait for the states inside the MSC to settle and check the state
4462 * of the SGs Association. */
4463 f_sleep(1.0);
4464 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4465
4466 f_sgsap_bssmap_screening();
4467
4468 setverdict(pass);
4469}
4470testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004471 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004472 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004473 f_init(1, true);
4474 pars := f_init_pars(11818, true);
4475 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004476 vc_conn.done;
4477}
4478
4479/* Trigger a paging request via VTY but don't respond to it */
4480private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
4481runs on BSC_ConnHdlr {
4482 f_init_handler(pars);
4483 f_sgs_perform_lu();
4484 f_sleep(1.0);
4485
4486 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4487 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4488 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4489 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4490
4491 /* Initiate paging via VTY */
4492 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4493 alt {
4494 [] SGsAP.receive(exp_resp) {
4495 setverdict(pass);
4496 }
4497 [] SGsAP.receive {
4498 setverdict(fail, "Received unexpected message on SGs");
4499 }
4500 }
4501
4502 /* Now do nothing, the MSC/VLR should fail silently to page after a
4503 * few seconds, The SGs association must remain unchanged. */
4504 f_sleep(15.0);
4505 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4506
4507 f_sgsap_bssmap_screening();
4508
4509 setverdict(pass);
4510}
4511testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004512 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004513 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004514 f_init(1, true);
4515 pars := f_init_pars(11819, true);
4516 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004517 vc_conn.done;
4518}
4519
4520/* Trigger a paging request via VTY and slip in an LU */
4521private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4522runs on BSC_ConnHdlr {
4523 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4524 f_init_handler(pars);
4525
4526 /* First we prepar the situation, where the SGs association is in state
4527 * NULL and the confirmed by radio contact indicator is set to false
4528 * as well. This can be archived by performing an SGs LU and then
4529 * resetting the VLR */
4530 f_sgs_perform_lu();
4531 f_sgsap_reset_mme(mp_mme_name);
4532 f_sleep(1.0);
4533 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4534
4535 /* Perform a paging, expect the paging messages on the SGs interface */
4536 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4537 alt {
4538 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4539 setverdict(pass);
4540 }
4541 [] SGsAP.receive {
4542 setverdict(fail, "Received unexpected message on SGs");
4543 }
4544 }
4545
4546 /* Perform the LU as normal */
4547 f_sgs_perform_lu();
4548 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4549
4550 /* Expect a new paging request right after the LU */
4551 alt {
4552 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4553 setverdict(pass);
4554 }
4555 [] SGsAP.receive {
4556 setverdict(fail, "Received unexpected message on SGs");
4557 }
4558 }
4559
4560 /* Test is done now, lets round everything up by rejecting the paging
4561 * cleanly. */
4562 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4563 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4564
4565 f_sgsap_bssmap_screening();
4566
4567 setverdict(pass);
4568}
4569testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004570 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004571 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004572 f_init(1, true);
4573 pars := f_init_pars(11820, true);
4574 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004575 vc_conn.done;
4576}
4577
4578/* Send unexpected unit-data through the SGs interface */
4579private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4580 f_init_handler(pars);
4581 f_sleep(1.0);
4582
4583 /* This simulates what happens when a subscriber without SGs
4584 * association gets unitdata via the SGs interface. */
4585
4586 /* Make sure the subscriber exists and the SGs association
4587 * is in NULL state */
4588 f_perform_lu();
4589 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4590
4591 /* Send some random unit data, the MSC/VLR should send a release
4592 * immediately. */
4593 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4594 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
4595
4596 f_sgsap_bssmap_screening();
4597
4598 setverdict(pass);
4599}
4600testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004601 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004602 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004603 f_init(1, true);
4604 pars := f_init_pars(11821, true);
4605 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004606 vc_conn.done;
4607}
4608
4609/* Send unsolicited unit-data through the SGs interface */
4610private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4611 f_init_handler(pars);
4612 f_sleep(1.0);
4613
4614 /* This simulates what happens when the MME attempts to send unitdata
4615 * to a subscriber that is completely unknown to the VLR */
4616
4617 /* Send some random unit data, the MSC/VLR should send a release
4618 * immediately. */
4619 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4620 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
4621
4622 f_sgsap_bssmap_screening();
4623
4624 setverdict(pass);
4625}
4626testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004627 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004628 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004629 f_init(1, true);
4630 pars := f_init_pars(11822, true);
4631 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004632 vc_conn.done;
4633}
4634
4635private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
4636 /* FIXME: Match an actual payload (second questionmark), the type is
4637 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
4638 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
4639 setverdict(fail, "Unexpected SMS related PDU from MSC");
4640 mtc.stop;
4641 }
4642}
4643
4644/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
4645function f_mt_sms_sgs(inout SmsParameters spars)
4646runs on BSC_ConnHdlr {
4647 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4648 var template (value) RPDU_MS_SGSN rp_mo;
4649 var template (value) PDU_ML3_MS_NW l3_mo;
4650
4651 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4652 var template RPDU_SGSN_MS rp_mt;
4653 var template PDU_ML3_NW_MS l3_mt;
4654
4655 var PDU_ML3_NW_MS sgsap_l3_mt;
4656
4657 var default d := activate(as_other_sms_sgs());
4658
4659 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
4660 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
4661 rp_mt := tr_RP_DATA_MT(?, ?, omit, tp_mt);
4662 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
4663
4664 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
4665
4666 /* Extract relevant identifiers */
4667 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
4668 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
4669
4670 /* send CP-ACK for CP-DATA just received */
4671 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
4672
4673 SGsAP.send(l3_mo);
4674
4675 /* send RP-ACK for RP-DATA */
4676 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
4677 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
4678
4679 SGsAP.send(l3_mo);
4680
4681 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
4682 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
4683
4684 SGsAP.receive(l3_mt);
4685
4686 deactivate(d);
4687
4688 setverdict(pass);
4689}
4690
4691/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
4692function f_mo_sms_sgs(inout SmsParameters spars)
4693runs on BSC_ConnHdlr {
4694 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4695 var template (value) RPDU_MS_SGSN rp_mo;
4696 var template (value) PDU_ML3_MS_NW l3_mo;
4697
4698 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4699 var template RPDU_SGSN_MS rp_mt;
4700 var template PDU_ML3_NW_MS l3_mt;
4701
4702 var default d := activate(as_other_sms_sgs());
4703
4704 /* just in case this is routed to SMPP.. */
4705 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
4706
4707 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
4708 spars.tp.udl, spars.tp.ud);
4709 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, spars.rp.orig, spars.rp.dest, tp_mo);
4710 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
4711
4712 SGsAP.send(l3_mo);
4713
4714 /* receive CP-ACK for CP-DATA above */
4715 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
4716
4717 if (ispresent(spars.exp_rp_err)) {
4718 /* expect an RP-ERROR message from MSC with given cause */
4719 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
4720 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4721 SGsAP.receive(l3_mt);
4722 /* send CP-ACK for CP-DATA just received */
4723 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4724 SGsAP.send(l3_mo);
4725 } else {
4726 /* expect RP-ACK for RP-DATA */
4727 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
4728 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4729 SGsAP.receive(l3_mt);
4730 /* send CP-ACO for CP-DATA just received */
4731 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4732 SGsAP.send(l3_mo);
4733 }
4734
4735 deactivate(d);
4736
4737 setverdict(pass);
4738}
4739
4740private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
4741runs on BSC_ConnHdlr {
4742 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
4743}
4744
4745/* Send a MT SMS via SGs interface */
4746private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4747 f_init_handler(pars);
4748 f_sgs_perform_lu();
4749 f_sleep(1.0);
4750 var SmsParameters spars := valueof(t_SmsPars);
4751 spars.tp.ud := 'C8329BFD064D9B53'O;
4752
4753 /* Trigger SMS via VTY */
4754 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4755 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4756
4757 /* Expect a paging request and respond accordingly with a service request */
4758 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
4759 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
4760
4761 /* Connection is now live, receive the MT-SMS */
4762 f_mt_sms_sgs(spars);
4763
4764 /* Expect a concluding release from the MSC */
4765 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4766
4767 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4768 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4769
4770 f_sgsap_bssmap_screening();
4771
4772 setverdict(pass);
4773}
4774testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004775 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004776 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004777 f_init(1, true);
4778 pars := f_init_pars(11823, true);
4779 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004780 vc_conn.done;
4781}
4782
4783/* Send a MO SMS via SGs interface */
4784private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4785 f_init_handler(pars);
4786 f_sgs_perform_lu();
4787 f_sleep(1.0);
4788 var SmsParameters spars := valueof(t_SmsPars);
4789 spars.tp.ud := 'C8329BFD064D9B53'O;
4790
4791 /* Send the MO-SMS */
4792 f_mo_sms_sgs(spars);
4793
4794 /* Expect a concluding release from the MSC/VLR */
4795 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4796
4797 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4798 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4799
4800 setverdict(pass);
4801
4802 f_sgsap_bssmap_screening()
4803}
4804testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004805 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004806 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004807 f_init(1, true);
4808 pars := f_init_pars(11824, true);
4809 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004810 vc_conn.done;
4811}
4812
4813/* Trigger sending of an MT sms via VTY but never respond to anything */
4814private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4815 f_init_handler(pars, 170.0);
4816 f_sgs_perform_lu();
4817 f_sleep(1.0);
4818
4819 var SmsParameters spars := valueof(t_SmsPars);
4820 spars.tp.ud := 'C8329BFD064D9B53'O;
4821 var integer page_count := 0;
4822 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4823 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4824 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4825 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4826
4827 /* Trigger SMS via VTY */
4828 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4829
Neels Hofmeyr16237742019-03-06 15:34:01 +01004830 /* Expect the MSC/VLR to page exactly once */
4831 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01004832
4833 /* Wait some time to make sure the MSC is not delivering any further
4834 * paging messages or anything else that could be unexpected. */
4835 timer T := 20.0;
4836 T.start
4837 alt {
4838 [] SGsAP.receive(exp_pag_req)
4839 {
4840 setverdict(fail, "paging seems not to stop!");
4841 mtc.stop;
4842 }
4843 [] SGsAP.receive {
4844 setverdict(fail, "unexpected SGsAP message received");
4845 self.stop;
4846 }
4847 [] T.timeout {
4848 setverdict(pass);
4849 }
4850 }
4851
4852 /* Even on a failed paging the SGs Association should stay intact */
4853 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4854
4855 /* Note: We do not execute f_sgsap_bssmap_screening() here since the
4856 * MSC/VLR would re-try to deliver the test SMS trigered above and
4857 * so the screening would fail. */
4858
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01004859 f_vty_sms_clear(hex2str(g_pars.imsi));
4860
Harald Welte4263c522018-12-06 11:56:27 +01004861 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
4862
4863 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01004864
4865 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01004866}
4867testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004868 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004869 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004870 f_init(1, true);
4871 pars := f_init_pars(11825, true);
4872 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004873 vc_conn.done;
4874}
4875
4876/* Trigger sending of an MT sms via VTY but reject the paging immediately */
4877private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4878 f_init_handler(pars, 150.0);
4879 f_sgs_perform_lu();
4880 f_sleep(1.0);
4881
4882 var SmsParameters spars := valueof(t_SmsPars);
4883 spars.tp.ud := 'C8329BFD064D9B53'O;
4884 var integer page_count := 0;
4885 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4886 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4887 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4888 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4889
4890 /* Trigger SMS via VTY */
4891 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4892
4893 /* Expect a paging request and reject it immediately */
4894 SGsAP.receive(exp_pag_req);
4895 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4896
4897 /* The MSC/VLR should no longer try to page once the paging has been
4898 * rejected. Wait some time and check if there are no unexpected
4899 * messages on the SGs interface. */
4900 timer T := 20.0;
4901 T.start
4902 alt {
4903 [] SGsAP.receive(exp_pag_req)
4904 {
4905 setverdict(fail, "paging seems not to stop!");
4906 mtc.stop;
4907 }
4908 [] SGsAP.receive {
4909 setverdict(fail, "unexpected SGsAP message received");
4910 self.stop;
4911 }
4912 [] T.timeout {
4913 setverdict(pass);
4914 }
4915 }
4916
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01004917 f_vty_sms_clear(hex2str(g_pars.imsi));
4918
Harald Welte4263c522018-12-06 11:56:27 +01004919 /* A rejected paging with IMSI_unknown (see above) should always send
4920 * the SGs association to NULL. */
4921 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4922
4923 f_sgsap_bssmap_screening();
4924
Harald Welte4263c522018-12-06 11:56:27 +01004925 setverdict(pass);
4926}
4927testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004928 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004929 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004930 f_init(1, true);
4931 pars := f_init_pars(11826, true);
4932 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004933 vc_conn.done;
4934}
4935
4936/* Perform an MT CSDB call including LU */
4937private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
4938 f_init_handler(pars);
4939
4940 /* Be sure that the BSSMAP reset is done before we begin. */
4941 f_sleep(2.0);
4942
4943 /* Testcase variation: See what happens when we do a regular BSSMAP
4944 * LU first (this should not hurt in any way!) */
4945 if (bssmap_lu) {
4946 f_perform_lu();
4947 }
4948
4949 f_sgs_perform_lu();
4950 f_sleep(1.0);
4951
4952 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4953 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
4954 cpars.bss_rtp_port := 1110;
4955 cpars.mgcp_connection_id_bss := '10004'H;
4956 cpars.mgcp_connection_id_mss := '10005'H;
4957
4958 /* Note: This is an optional parameter. When the call-agent (MSC) does
4959 * supply a full endpoint name this setting will be overwritten. */
4960 cpars.mgcp_ep := "rtpbridge/1@mgw";
4961
4962 /* Initiate a call via MNCC interface */
4963 f_mt_call_initate(cpars);
4964
4965 /* Expect a paging request and respond accordingly with a service request */
4966 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
4967 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
4968
4969 /* Complete the call, hold it for some time and then tear it down */
4970 f_mt_call_complete(cpars);
4971 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01004972 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01004973
4974 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4975 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4976
4977 /* Finally simulate the return of the UE to the 4G network */
4978 SGsAP.send(ts_SGsAP_MO_CSFB_IND(pars.imsi));
4979
4980 /* Test for successful return by triggering a paging, when the paging
4981 * request is received via SGs, we can be sure that the MSC/VLR has
4982 * recognized that the UE is now back on 4G */
4983 f_sleep(1.0);
4984 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4985 alt {
4986 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4987 setverdict(pass);
4988 }
4989 [] SGsAP.receive {
4990 setverdict(fail, "Received unexpected message on SGs");
4991 }
4992 }
4993
4994 f_sgsap_bssmap_screening();
4995
4996 setverdict(pass);
4997}
4998
4999/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5000private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5001 f_mt_lu_and_csfb_call(id, pars, true);
5002}
5003testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005004 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005005 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005006 f_init(1, true);
5007 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005008
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005009 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005010 vc_conn.done;
5011}
5012
5013
5014/* Perform a SGSAP LU and then make a CSFB call */
5015private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5016 f_mt_lu_and_csfb_call(id, pars, false);
5017}
5018testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005019 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005020 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005021 f_init(1, true);
5022 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005023
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005024 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005025 vc_conn.done;
5026}
5027
Philipp Maier628c0052019-04-09 17:36:57 +02005028/* Simulate an HLR/VLR failure */
5029private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5030 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5031 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5032
5033 var PDU_SGsAP lur;
5034
5035 f_init_handler(pars);
5036
5037 /* Attempt location update (which is expected to fail) */
5038 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5039 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5040 SGsAP.send(lur);
5041
5042 /* Respond to SGsAP-RESET-INDICATION from VLR */
5043 alt {
5044 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5045 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5046 setverdict(pass);
5047 }
5048 [] SGsAP.receive {
5049 setverdict(fail, "Received unexpected message on SGs");
5050 }
5051 }
5052
5053 f_sleep(1.0);
5054 setverdict(pass);
5055}
5056testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5057 var BSC_ConnHdlrPars pars;
5058 var BSC_ConnHdlr vc_conn;
5059 f_init(1, true, false);
5060 pars := f_init_pars(11811, true, false);
5061 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5062 vc_conn.done;
5063}
5064
Harald Welte4263c522018-12-06 11:56:27 +01005065/* SGs TODO:
5066 * LU attempt for IMSI without NAM_PS in HLR
5067 * LU attempt with AUTH FAIL due to invalid RES/SRES
5068 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5069 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5070 * implicit IMSI detach from EPS
5071 * implicit IMSI detach from non-EPS
5072 * MM INFO
5073 *
5074 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005075
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005076private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5077 f_init_handler(pars);
5078 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
5079 cpars.bss_rtp_port := 1110;
5080 cpars.mgcp_connection_id_bss := '22222'H;
5081 cpars.mgcp_connection_id_mss := '33333'H;
5082 cpars.mgcp_ep := "rtpbridge/1@mgw";
5083 cpars.mo_call := true;
5084
5085 f_perform_lu();
5086 f_mo_call_establish(cpars);
5087
5088 f_sleep(1.0);
5089
5090 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5091 var BssmapCause cause := enum2int(cause_val);
5092
5093 var template BSSMAP_FIELD_CellIdentificationList cil;
5094 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5095
5096 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5097 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5098
5099 f_call_hangup(cpars, true);
5100}
5101testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5102 var BSC_ConnHdlr vc_conn;
5103 f_init();
5104
5105 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5106 vc_conn.done;
5107}
5108
5109private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5110 var MgcpCommand mgcp_cmd;
5111 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
5112 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_rtp_ip_mss, cpars.mgw_rtp_ip_mss,
5113 hex2str(cpars.mgcp_call_id), "42",
5114 cpars.mgw_rtp_port_mss,
5115 { int2str(cpars.rtp_payload_type) },
5116 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5117 cpars.rtp_sdp_format)),
5118 valueof(ts_SDP_ptime(20)) }));
5119 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgcp_connection_id_mss, sdp));
5120 repeat;
5121 }
5122}
5123
5124private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5125 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
5126 cpars.bss_rtp_port := 1110;
5127 cpars.mgcp_connection_id_bss := '22222'H;
5128 cpars.mgcp_connection_id_mss := '33333'H;
5129 cpars.mgcp_ep := "rtpbridge/1@mgw";
5130 cpars.mo_call := true;
5131
5132 f_init_handler(pars);
5133
5134 f_vty_transceive(MSCVTY, "configure terminal");
5135 f_vty_transceive(MSCVTY, "msc");
5136 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
5137 f_vty_transceive(MSCVTY, "neighbor a lac 5 ran-pc 0.24.2");
5138 f_vty_transceive(MSCVTY, "exit");
5139 f_vty_transceive(MSCVTY, "exit");
5140
5141 f_perform_lu();
5142 f_mo_call_establish(cpars);
5143
5144 f_sleep(1.0);
5145
5146 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5147
5148 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5149 var BssmapCause cause := enum2int(cause_val);
5150
5151 var template BSSMAP_FIELD_CellIdentificationList cil;
5152 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 5) } };
5153
5154 /* old BSS sends Handover Required */
5155 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5156
5157 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5158
5159 /* MSC forwards the RR Handover Command to old BSS */
5160 var PDU_BSSAP ho_command;
5161 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5162
5163 log("GOT HandoverCommand", ho_command);
5164
5165 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5166
5167 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5168 f_expect_clear();
5169
5170 log("FIRST inter-BSC Handover done");
5171
5172
5173 /* ------------------------ */
5174
5175 /* Ok, that went well, now the other BSC is handovering back here --
5176 * from now on this here is the new BSS. */
5177 f_create_bssmap_exp_handoverRequest(193);
5178
5179 var PDU_BSSAP ho_request;
5180 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5181
5182 /* new BSS composes a RR Handover Command */
5183 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5184 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5185 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5186 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5187 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5188
5189 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5190
5191 f_sleep(0.5);
5192
5193 /* Notify that the MS is now over here */
5194
5195 BSSAP.send(ts_BSSMAP_HandoverDetect);
5196 f_sleep(0.1);
5197 BSSAP.send(ts_BSSMAP_HandoverComplete);
5198
5199 f_sleep(3.0);
5200
5201 deactivate(ack_mdcx);
5202
5203 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5204
5205 /* blatant cheating */
5206 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5207 last_n_sd[0] := 3;
5208 f_bssmap_continue_after_n_sd(last_n_sd);
5209
5210 f_call_hangup(cpars, true);
5211 f_sleep(1.0);
5212 deactivate(ccrel);
5213
5214 setverdict(pass);
5215}
5216private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5217 f_init_handler(pars);
5218 f_create_bssmap_exp_handoverRequest(194);
5219
5220 var PDU_BSSAP ho_request;
5221 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5222
5223 /* new BSS composes a RR Handover Command */
5224 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5225 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5226 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5227 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5228 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5229
5230 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5231
5232 f_sleep(0.5);
5233
5234 /* Notify that the MS is now over here */
5235
5236 BSSAP.send(ts_BSSMAP_HandoverDetect);
5237 f_sleep(0.1);
5238 BSSAP.send(ts_BSSMAP_HandoverComplete);
5239
5240 f_sleep(3.0);
5241
5242 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5243 * ... handover back to the first BSC :P */
5244
5245 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5246 var BssmapCause cause := enum2int(cause_val);
5247
5248 var template BSSMAP_FIELD_CellIdentificationList cil;
5249 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('262'H, '42'H, 23) } };
5250
5251 /* old BSS sends Handover Required */
5252 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5253
5254 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5255
5256 /* MSC forwards the RR Handover Command to old BSS */
5257 var PDU_BSSAP ho_command;
5258 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5259
5260 log("GOT HandoverCommand", ho_command);
5261
5262 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5263
5264 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5265 f_expect_clear();
5266 setverdict(pass);
5267}
5268testcase TC_ho_inter_bsc() runs on MTC_CT {
5269 var BSC_ConnHdlr vc_conn0;
5270 var BSC_ConnHdlr vc_conn1;
5271 f_init(2);
5272
5273 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
5274 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
5275
5276 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0, 0);
5277 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1, 1);
5278 vc_conn0.done;
5279 vc_conn1.done;
5280}
5281
5282function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5283 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5284 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5285 log("MS_NW patched enc_l3: ", enc_l3);
5286}
5287
5288private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5289 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
5290 cpars.bss_rtp_port := 1110;
5291 cpars.mgcp_connection_id_bss := '22222'H;
5292 cpars.mgcp_connection_id_mss := '33333'H;
5293 cpars.mgcp_ep := "rtpbridge/1@mgw";
5294 cpars.mo_call := true;
5295 var hexstring ho_number := f_gen_msisdn(99999);
5296
5297 f_init_handler(pars);
5298
5299 f_create_mncc_expect(hex2str(ho_number));
5300
5301 f_vty_transceive(MSCVTY, "configure terminal");
5302 f_vty_transceive(MSCVTY, "msc");
5303 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
5304 f_vty_transceive(MSCVTY, "exit");
5305 f_vty_transceive(MSCVTY, "exit");
5306
5307 f_perform_lu();
5308 f_mo_call_establish(cpars);
5309
5310 f_sleep(1.0);
5311
5312 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5313
5314 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5315 var BssmapCause cause := enum2int(cause_val);
5316
5317 var template BSSMAP_FIELD_CellIdentificationList cil;
5318 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('017'H, '017'H, 1) } };
5319
5320 /* old BSS sends Handover Required */
5321 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5322
5323 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
5324 * This MSC tries to reach the other MSC via GSUP. */
5325
5326 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
5327 var GSUP_PDU prep_ho_req;
5328 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
5329 pars.imsi, destination_name := remote_msc_name)) -> value prep_ho_req;
5330
5331 var GSUP_IeValue source_name_ie;
5332 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
5333 var octetstring local_msc_name := source_name_ie.source_name;
5334
5335 /* Remote MSC has figured out its BSC and signals success */
5336 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5337 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5338 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5339 aoIPTransportLayer := omit,
5340 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5341 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
5342 pars.imsi,
5343 ho_number,
5344 remote_msc_name, local_msc_name,
5345 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
5346
5347 /* MSC forwards the RR Handover Command to old BSS */
5348 BSSAP.receive(tr_BSSMAP_HandoverCommand);
5349
5350 /* The MS shows up at remote new BSS */
5351
5352 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5353 pars.imsi, remote_msc_name, local_msc_name,
5354 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5355 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
5356 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5357 f_sleep(0.1);
5358
5359 /* Save the MS sequence counters for use on the other connection */
5360 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5361
5362 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
5363 pars.imsi, remote_msc_name, local_msc_name,
5364 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5365 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
5366
5367 /* The local BSS conn clears, all communication goes via remote MSC now */
5368 f_expect_clear();
5369
5370 /**********************************/
5371 /* Play through some signalling across the inter-MSC link.
5372 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
5373
5374 if (false) {
5375 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
5376 invoke_id := 5, /* Phone may not start from 0 or 1 */
5377 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5378 ussd_string := "*#100#"
5379 );
5380
5381 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
5382 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
5383 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5384 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
5385 )
5386
5387 /* Compose a new SS/REGISTER message with request */
5388 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
5389 tid := 1, /* We just need a single transaction */
5390 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
5391 facility := valueof(facility_req)
5392 );
5393 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
5394
5395 /* Compose SS/RELEASE_COMPLETE template with expected response */
5396 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
5397 tid := 1, /* Response should arrive within the same transaction */
5398 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
5399 facility := valueof(facility_rsp)
5400 );
5401
5402 /* Compose expected MSC -> HLR message */
5403 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
5404 imsi := g_pars.imsi,
5405 state := OSMO_GSUP_SESSION_STATE_BEGIN,
5406 ss := valueof(facility_req)
5407 );
5408
5409 /* To be used for sending response with correct session ID */
5410 var GSUP_PDU gsup_req_complete;
5411
5412 /* Request own number */
5413 /* From remote MSC instead of BSSAP directly */
5414 /* Patch the correct N_SD value into the message. */
5415 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
5416 var RAN_Emulation.ConnectionData cd;
5417 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
5418 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5419 pars.imsi, remote_msc_name, local_msc_name,
5420 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5421 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
5422 ))
5423 ));
5424
5425 /* Expect GSUP message containing the SS payload */
5426 gsup_req_complete := f_expect_gsup_msg(gsup_req);
5427
5428 /* Compose the response from HLR using received session ID */
5429 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
5430 imsi := g_pars.imsi,
5431 sid := gsup_req_complete.ies[1].val.session_id,
5432 state := OSMO_GSUP_SESSION_STATE_END,
5433 ss := valueof(facility_rsp)
5434 );
5435
5436 /* Finally, HLR terminates the session */
5437 GSUP.send(gsup_rsp);
5438
5439 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
5440 var GSUP_PDU gsup_ussd_rsp;
5441 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5442 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
5443
5444 var GSUP_IeValue an_apdu;
5445 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
5446 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5447 mtc.stop;
5448 }
5449 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
5450 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
5451 log("Expecting", ussd_rsp);
5452 log("Got", dtap_mt);
5453 if (not match(dtap_mt, ussd_rsp)) {
5454 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5455 mtc.stop;
5456 }
5457 }
5458 /**********************************/
5459
5460
5461 /* inter-MSC handover back to the first MSC */
5462 f_create_bssmap_exp_handoverRequest(193);
5463 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
5464
5465 /* old BSS sends Handover Required, via inter-MSC E link: like
5466 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5467 * but via GSUP */
5468 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
5469 pars.imsi, remote_msc_name, local_msc_name,
5470 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5471 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
5472 ))
5473 ));
5474
5475 /* MSC asks local BSS to prepare Handover to it */
5476 BSSAP.receive(tr_BSSMAP_HandoverRequest);
5477
5478 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
5479 f_bssmap_continue_after_n_sd(last_n_sd);
5480
5481 /* new BSS composes a RR Handover Command */
5482 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5483 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5484 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5485 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5486 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5487
5488 /* HandoverCommand goes out via remote MSC-I */
5489 var GSUP_PDU prep_subsq_ho_res;
5490 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
5491 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
5492
5493 /* MS shows up at the local BSS */
5494 BSSAP.send(ts_BSSMAP_HandoverDetect);
5495 f_sleep(0.1);
5496 BSSAP.send(ts_BSSMAP_HandoverComplete);
5497
5498 /* Handover Succeeded message */
5499 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5500 pars.imsi, destination_name := remote_msc_name));
5501
5502 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
5503 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
5504 pars.imsi, destination_name := remote_msc_name));
5505
5506 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
5507
5508 f_sleep(1.0);
5509 deactivate(ack_mdcx);
5510
5511 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
5512 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
5513 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
5514 MNCC.clear;
5515
5516 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5517 f_call_hangup(cpars, true);
5518 f_sleep(1.0);
5519 deactivate(ccrel);
5520
5521 setverdict(pass);
5522}
5523testcase TC_ho_inter_msc_out() runs on MTC_CT {
5524 var BSC_ConnHdlr vc_conn;
5525 f_init(1);
5526
5527 var BSC_ConnHdlrPars pars := f_init_pars(54);
5528
5529 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5530 vc_conn.done;
5531}
5532
5533
Harald Weltef6dd64d2017-11-19 12:09:51 +01005534control {
Philipp Maier328d1662018-03-07 10:40:27 +01005535 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01005536 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01005537 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01005538 execute( TC_lu_imsi_reject() );
5539 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01005540 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02005541 execute( TC_lu_imsi_auth3g_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01005542 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01005543 execute( TC_lu_and_mo_call() );
Harald Welte071ed732018-01-23 19:53:52 +01005544 execute( TC_lu_auth_sai_timeout() );
5545 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01005546 execute( TC_lu_clear_request() );
5547 execute( TC_lu_disconnect() );
5548 execute( TC_lu_by_imei() );
5549 execute( TC_lu_by_tmsi_noauth_unknown() );
5550 execute( TC_imsi_detach_by_imsi() );
5551 execute( TC_imsi_detach_by_tmsi() );
5552 execute( TC_imsi_detach_by_imei() );
5553 execute( TC_emerg_call_imei_reject() );
5554 execute( TC_emerg_call_imsi() );
5555 execute( TC_cm_serv_req_vgcs_reject() );
5556 execute( TC_cm_serv_req_vbs_reject() );
5557 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01005558 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01005559 execute( TC_lu_auth_2G_fail() );
5560 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
5561 execute( TC_cl3_no_payload() );
5562 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01005563 execute( TC_establish_and_nothing() );
5564 execute( TC_mo_setup_and_nothing() );
5565 execute( TC_mo_crcx_ran_timeout() );
5566 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01005567 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01005568 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01005569 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01005570 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01005571 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
5572 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
5573 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01005574 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01005575 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
5576 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01005577 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01005578 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02005579 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01005580
5581 execute( TC_lu_and_mt_call() );
5582
Harald Weltef45efeb2018-04-09 18:19:24 +02005583 execute( TC_lu_and_mo_sms() );
5584 execute( TC_lu_and_mt_sms() );
Philipp Maier3983e702018-11-22 19:01:33 +01005585 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Harald Weltef640a012018-04-14 17:49:21 +02005586 execute( TC_smpp_mo_sms() );
5587 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02005588
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07005589 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07005590 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07005591 execute( TC_gsup_mt_sms_ack() );
5592 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07005593 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07005594 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07005595
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07005596 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07005597 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07005598 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07005599 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07005600 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07005601 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07005602
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07005603 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07005604 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07005605 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07005606 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07005607 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07005608
Stefan Sperling89eb1f32018-12-17 15:06:20 +01005609 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01005610 execute( TC_cipher_complete_1_without_cipher() );
5611 execute( TC_cipher_complete_3_without_cipher() );
5612 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02005613 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01005614
Harald Welte4263c522018-12-06 11:56:27 +01005615 execute( TC_sgsap_reset() );
5616 execute( TC_sgsap_lu() );
5617 execute( TC_sgsap_lu_imsi_reject() );
5618 execute( TC_sgsap_lu_and_nothing() );
5619 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01005620 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01005621 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01005622 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01005623 execute( TC_sgsap_paging_rej() );
5624 execute( TC_sgsap_paging_subscr_rej() );
5625 execute( TC_sgsap_paging_ue_unr() );
5626 execute( TC_sgsap_paging_and_nothing() );
5627 execute( TC_sgsap_paging_and_lu() );
5628 execute( TC_sgsap_mt_sms() );
5629 execute( TC_sgsap_mo_sms() );
5630 execute( TC_sgsap_mt_sms_and_nothing() );
5631 execute( TC_sgsap_mt_sms_and_reject() );
5632 execute( TC_sgsap_unexp_ud() );
5633 execute( TC_sgsap_unsol_ud() );
5634 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
5635 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02005636 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01005637
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005638 execute( TC_ho_inter_bsc_unknown_cell() );
5639 execute( TC_ho_inter_bsc() );
5640
5641 execute( TC_ho_inter_msc_out() );
5642
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01005643 /* Run this last: at the time of writing this test crashes the MSC */
5644 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Philipp Maierdb7fb8d2019-02-11 10:50:13 +01005645 execute( TC_gsup_mt_multi_part_sms() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02005646 execute( TC_mo_cc_bssmap_clear() );
Pau Espin Pedrol690d6592019-05-31 17:56:32 +02005647 if (mp_enable_osmux_test) {
5648 execute( TC_lu_and_mt_call_osmux() );
5649 }
Harald Weltef6dd64d2017-11-19 12:09:51 +01005650}
5651
5652
5653}