blob: 35ca84a7e7de936697e3b6cbf6520ebae782f9f6 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
19
20import from M3UA_Types all;
21import from M3UA_Emulation all;
22
23import from MTP3asp_Types all;
24import from MTP3asp_PortType all;
25
26import from SCCPasp_Types all;
27import from SCCP_Types all;
28import from SCCP_Emulation all;
29
30import from SCTPasp_Types all;
31import from SCTPasp_PortType all;
32
Harald Weltea49e36e2018-01-21 19:29:33 +010033import from Osmocom_CTRL_Functions all;
34import from Osmocom_CTRL_Types all;
35import from Osmocom_CTRL_Adapter all;
36
Harald Welte3ca1c902018-01-24 18:51:27 +010037import from TELNETasp_PortType all;
38import from Osmocom_VTY_Functions all;
39
Harald Weltea49e36e2018-01-21 19:29:33 +010040import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010041import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010042
Harald Welte4aa970c2018-01-26 10:38:09 +010043import from MGCP_Emulation all;
44import from MGCP_Types all;
45import from MGCP_Templates all;
46import from SDP_Types all;
47
Harald Weltea49e36e2018-01-21 19:29:33 +010048import from GSUP_Emulation all;
49import from GSUP_Types all;
50import from IPA_Emulation all;
51
Harald Weltef6dd64d2017-11-19 12:09:51 +010052import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020053import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010054import from BSSAP_CodecPort all;
55import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020056import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010057import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020058import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010059
Harald Welte4263c522018-12-06 11:56:27 +010060import from SGsAP_Templates all;
61import from SGsAP_Types all;
62import from SGsAP_Emulation all;
63
Harald Weltea49e36e2018-01-21 19:29:33 +010064import from MobileL3_Types all;
65import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070066import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010067import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010068import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010069
Harald Weltef640a012018-04-14 17:49:21 +020070import from SMPP_Types all;
71import from SMPP_Templates all;
72import from SMPP_Emulation all;
73
Stefan Sperlingc307e682018-06-14 15:15:46 +020074import from SCCP_Templates all;
75
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070076import from SS_Types all;
77import from SS_Templates all;
78import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010079import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070080
Philipp Maier948747b2019-04-02 15:22:33 +020081import from TCCConversion_Functions all;
82
Harald Welte9b751a62019-04-14 17:39:29 +020083const integer NUM_BSC := 3;
Harald Welte6811d102019-04-14 22:23:14 +020084type record of RAN_Configuration RAN_Configurations;
Harald Weltef6dd64d2017-11-19 12:09:51 +010085
Harald Welte4263c522018-12-06 11:56:27 +010086/* Needed for SGsAP SMS */
87import from MobileL3_SMS_Types all;
88
Harald Weltea4ca4462018-02-09 00:17:14 +010089type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010090 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010091
Harald Welte6811d102019-04-14 22:23:14 +020092 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010093
Harald Weltea49e36e2018-01-21 19:29:33 +010094 /* no 'adapter_CT' for MNCC or GSUP */
95 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010096 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010097 var GSUP_Emulation_CT vc_GSUP;
98 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020099 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +0100100 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100101
102 /* only to get events from IPA underneath GSUP */
103 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100104 /* VTY to MSC */
105 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100106
107 /* A port to directly send BSSAP messages. This port is used for
108 * tests that require low level access to sen arbitrary BSSAP
109 * messages. Run f_init_bssap_direct() to connect and initialize */
110 port BSSAP_CODEC_PT BSSAP_DIRECT;
111
112 /* When BSSAP messages are directly sent, then the connection
113 * handler is not active, which means that also no guard timer is
114 * set up. The following timer will serve as a replacement */
115 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100116
117 /* Configure T(tias) over VTY, seconds */
118 var integer g_msc_sccp_timer_ias := 7 * 60;
119 /* Configure T(tiar) over VTY, seconds */
120 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100121}
122
123modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100124 /* remote parameters of IUT */
125 charstring mp_msc_ip := "127.0.0.1";
126 integer mp_msc_ctrl_port := 4255;
127 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100128
Harald Weltea49e36e2018-01-21 19:29:33 +0100129 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100130 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100131 charstring mp_hlr_ip := "127.0.0.1";
132 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100133 charstring mp_mgw_ip := "127.0.0.1";
134 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100135
Harald Weltea49e36e2018-01-21 19:29:33 +0100136 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100137
Harald Weltef640a012018-04-14 17:49:21 +0200138 integer mp_msc_smpp_port := 2775;
139 charstring mp_smpp_system_id := "msc_tester";
140 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100141 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
142 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200143
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200144 /* Whether to enable osmux tests. Can be dropped completely and enable
145 unconditionally once new version of osmo-msc is released (current
146 version: 1.3.1) */
147 boolean mp_enable_osmux_test := true;
148
Harald Welte6811d102019-04-14 22:23:14 +0200149 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200150 {
151 sccp_service_type := "mtp3_itu",
152 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
153 own_pc := 185,
154 own_ssn := 254,
155 peer_pc := 187,
156 peer_ssn := 254,
157 sio := '83'O,
158 rctx := 0
159 },
160 {
161 sccp_service_type := "mtp3_itu",
162 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
163 own_pc := 186,
164 own_ssn := 254,
165 peer_pc := 187,
166 peer_ssn := 254,
167 sio := '83'O,
168 rctx := 1
169 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100170 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100171}
172
Philipp Maier328d1662018-03-07 10:40:27 +0100173/* altstep for the global guard timer (only used when BSSAP_DIRECT
174 * is used for communication */
175private altstep as_Tguard_direct() runs on MTC_CT {
176 [] Tguard_direct.timeout {
177 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200178 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100179 }
180}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100181
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100182private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
183 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
184 if (respond) {
185 var BIT1 tid_remote := '1'B;
186 if (cpars.mo_call) {
187 tid_remote := '0'B;
188 }
189 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
190 }
191 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100192}
193
Harald Weltef640a012018-04-14 17:49:21 +0200194function f_init_smpp(charstring id) runs on MTC_CT {
195 id := id & "-SMPP";
196 var EsmePars pars := {
197 mode := MODE_TRANSCEIVER,
198 bind := {
199 system_id := mp_smpp_system_id,
200 password := mp_smpp_password,
201 system_type := "MSC_Tests",
202 interface_version := hex2int('34'H),
203 addr_ton := unknown,
204 addr_npi := unknown,
205 address_range := ""
206 },
207 esme_role := true
208 }
209
210 vc_SMPP := SMPP_Emulation_CT.create(id);
211 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
212 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", -1));
213}
214
215
Harald Weltea49e36e2018-01-21 19:29:33 +0100216function f_init_mncc(charstring id) runs on MTC_CT {
217 id := id & "-MNCC";
218 var MnccOps ops := {
219 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
220 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
221 }
222
223 vc_MNCC := MNCC_Emulation_CT.create(id);
224 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
225 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100226}
227
Harald Welte4aa970c2018-01-26 10:38:09 +0100228function f_init_mgcp(charstring id) runs on MTC_CT {
229 id := id & "-MGCP";
230 var MGCPOps ops := {
231 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
232 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
233 }
234 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100235 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100236 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100237 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200238 mgw_udp_port := mp_mgw_port,
239 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100240 }
241
242 vc_MGCP := MGCP_Emulation_CT.create(id);
243 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
244 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
245}
246
Philipp Maierc09a1312019-04-09 16:05:26 +0200247function ForwardUnitdataCallback(PDU_SGsAP msg)
248runs on SGsAP_Emulation_CT return template PDU_SGsAP {
249 SGsAP_CLIENT.send(msg);
250 return omit;
251}
252
Harald Welte4263c522018-12-06 11:56:27 +0100253function f_init_sgsap(charstring id) runs on MTC_CT {
254 id := id & "-SGsAP";
255 var SGsAPOps ops := {
256 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200257 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100258 }
259 var SGsAP_conn_parameters pars := {
260 remote_ip := mp_msc_ip,
261 remote_sctp_port := 29118,
262 local_ip := "",
263 local_sctp_port := -1
264 }
265
266 vc_SGsAP := SGsAP_Emulation_CT.create(id);
267 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
268 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
269}
270
271
Harald Weltea49e36e2018-01-21 19:29:33 +0100272function f_init_gsup(charstring id) runs on MTC_CT {
273 id := id & "-GSUP";
274 var GsupOps ops := {
275 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
276 }
277
278 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
279 vc_GSUP := GSUP_Emulation_CT.create(id);
280
281 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
282 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
283 /* we use this hack to get events like ASP_IPA_EVENT_UP */
284 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
285
286 vc_GSUP.start(GSUP_Emulation.main(ops, id));
287 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
288
289 /* wait for incoming connection to GSUP port before proceeding */
290 timer T := 10.0;
291 T.start;
292 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700293 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100294 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100295 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200296 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100297 }
298 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100299}
300
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200301function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100302
303 if (g_initialized == true) {
304 return;
305 }
306 g_initialized := true;
307
Philipp Maier75932982018-03-27 14:52:35 +0200308 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200309 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200310 }
311
312 for (var integer i := 0; i < num_bsc; i := i + 1) {
313 if (isbound(mp_bssap_cfg[i])) {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200314 var RanOps ranops := BSC_RanOps;
315 ranops.use_osmux := osmux;
316 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
Harald Welte3ca0ce12019-04-23 17:18:48 +0200317 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200318 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200319 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200320 }
321 }
322
Harald Weltea49e36e2018-01-21 19:29:33 +0100323 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
324 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100325 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200326
327 if (gsup == true) {
328 f_init_gsup("MSC_Test");
329 }
Harald Weltef640a012018-04-14 17:49:21 +0200330 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100331
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100332 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100333 f_init_sgsap("MSC_Test");
334 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100335
336 map(self:MSCVTY, system:MSCVTY);
337 f_vty_set_prompts(MSCVTY);
338 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100339
340 /* set some defaults */
341 f_vty_config(MSCVTY, "network", "authentication optional");
342 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200343 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100344 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100345 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
346 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200347 if (mp_enable_osmux_test) {
348 if (osmux) {
349 f_vty_config(MSCVTY, "msc", "osmux on");
350 } else {
351 f_vty_config(MSCVTY, "msc", "osmux off");
352 }
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200353 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100354}
355
Philipp Maier328d1662018-03-07 10:40:27 +0100356/* Initialize for a direct connection to BSSAP. This function is an alternative
357 * to f_init() when the high level functions of the BSC_ConnectionHandler are
358 * not needed. */
359function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200360 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200361 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100362
363 /* Start guard timer and activate it as default */
364 Tguard_direct.start
365 activate(as_Tguard_direct());
366}
367
Harald Weltea49e36e2018-01-21 19:29:33 +0100368type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100369
Harald Weltea49e36e2018-01-21 19:29:33 +0100370/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200371function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100372 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200373runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100374 var BSC_ConnHdlrNetworkPars net_pars := {
375 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
376 expect_tmsi := true,
377 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200378 expect_ciph := false,
379 expect_imei := false,
380 expect_imei_early := false,
381 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
382 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100383 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100384 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200385 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
386 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100387 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100388 imei := f_gen_imei(imsi_suffix),
389 imsi := f_gen_imsi(imsi_suffix),
390 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100391 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100392 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100393 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100394 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100395 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100396 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100397 send_early_cm := true,
398 ipa_ctrl_ip := mp_msc_ip,
399 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100400 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100401 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200402 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200403 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100404 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200405 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200406 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200407 ran_is_geran := ran_is_geran,
408 use_osmux := use_osmux
Harald Weltea49e36e2018-01-21 19:29:33 +0100409 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200410 if (not ran_is_geran) {
411 pars.use_umts_aka := true;
412 pars.net.expect_auth := true;
413 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100414 return pars;
415}
416
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200417function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars, integer bssap_idx := 0) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100418 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200419 var charstring id := testcasename() & int2str(bssap_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100420
421 vc_conn := BSC_ConnHdlr.create(id);
422 /* BSSMAP part / A interface */
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200423 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:CLIENT);
424 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100425 /* MNCC part */
426 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
427 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100428 /* MGCP part */
429 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
430 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100431 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200432 if (pars.gsup_enable == true) {
433 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
434 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
435 }
Harald Weltef640a012018-04-14 17:49:21 +0200436 /* SMPP part */
437 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
438 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100439 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100440 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100441 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
442 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
443 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100444
Harald Weltea10db902018-01-27 12:44:49 +0100445 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
446 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100447 vc_conn.start(derefers(fn)(id, pars));
448 return vc_conn;
449}
450
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200451function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false)
Harald Welte9b751a62019-04-14 17:39:29 +0200452runs on MTC_CT return BSC_ConnHdlr {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200453 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100454}
455
Harald Weltea49e36e2018-01-21 19:29:33 +0100456private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100457 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100458 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100459}
Harald Weltea49e36e2018-01-21 19:29:33 +0100460testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
461 var BSC_ConnHdlr vc_conn;
462 f_init();
463
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100464 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100465 vc_conn.done;
466}
467
468private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100469 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100470 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100471 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100472}
Harald Weltea49e36e2018-01-21 19:29:33 +0100473testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
474 var BSC_ConnHdlr vc_conn;
475 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100476 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100477
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100478 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100479 vc_conn.done;
480}
481
482/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200483friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100484 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100485 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
486
487 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200488 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100489 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100490 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
491 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
492 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100493 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
494 f_expect_clear();
495 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100496 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
497 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200498 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100499 }
500 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100501}
502testcase TC_lu_imsi_reject() runs on MTC_CT {
503 var BSC_ConnHdlr vc_conn;
504 f_init();
505
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100506 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3);
Harald Weltea49e36e2018-01-21 19:29:33 +0100507 vc_conn.done;
508}
509
Harald Weltee13cfb22019-04-23 16:52:02 +0200510
511
Harald Weltea49e36e2018-01-21 19:29:33 +0100512/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200513friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100514 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100515 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
516
517 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200518 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100519 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100520 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
521 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
522 alt {
523 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100524 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
525 f_expect_clear();
526 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100527 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
528 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200529 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100530 }
531 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100532}
533testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
534 var BSC_ConnHdlr vc_conn;
535 f_init();
536
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100537 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4);
Harald Weltea49e36e2018-01-21 19:29:33 +0100538 vc_conn.done;
539}
540
Harald Weltee13cfb22019-04-23 16:52:02 +0200541
Harald Welte7b1b2812018-01-22 21:23:06 +0100542private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100543 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100544 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100545 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100546}
547testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
548 var BSC_ConnHdlr vc_conn;
549 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100550 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100551
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100552 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100553 vc_conn.done;
554}
555
Harald Weltee13cfb22019-04-23 16:52:02 +0200556
557friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200558 pars.net.expect_auth := true;
559 pars.use_umts_aka := true;
560 f_init_handler(pars);
561 f_perform_lu();
562}
563testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
564 var BSC_ConnHdlr vc_conn;
565 f_init();
566 f_vty_config(MSCVTY, "network", "authentication required");
567
568 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
569 vc_conn.done;
570}
Harald Weltea49e36e2018-01-21 19:29:33 +0100571
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100572/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
573 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
574 */
575friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
576
577 f_init_handler(pars);
578
579 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
580 var PDU_DTAP_MT dtap_mt;
581
582 /* tell GSUP dispatcher to send this IMSI to us */
583 f_create_gsup_expect(hex2str(g_pars.imsi));
584
585 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
586 if (g_pars.ran_is_geran) {
587 f_bssap_compl_l3(l3_lu);
588 if (g_pars.send_early_cm) {
589 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
590 }
591 } else {
592 f_ranap_initial_ue(l3_lu);
593 }
594
595 f_mm_imei_early();
596 f_mm_common();
597 f_msc_lu_hlr();
598 f_mm_imei();
599
600 alt {
601 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
602 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
603 setverdict(fail, "Expected LU ACK, but received LU REJ");
604 mtc.stop;
605 }
606 }
607
608 /* currently (due to bug OS#4337), an extra LU reject is received before
609 terminating the connection. Enabling following line makes the test
610 pass: */
611 //f_expect_lu_reject('16'O); /* Cause: congestion */
612
613 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
614 extra time to avoid race conditons... */
615 f_expect_clear(7.0);
616
617 setverdict(pass);
618}
619testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
620 var BSC_ConnHdlr vc_conn;
621 f_init();
622
623 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
624 vc_conn.done;
625}
626
Harald Weltee13cfb22019-04-23 16:52:02 +0200627
Harald Weltea49e36e2018-01-21 19:29:33 +0100628/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200629friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100630runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100631 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100632
633 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100634 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100635 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100636
637 f_create_gsup_expect(hex2str(g_pars.imsi));
638
639 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200640 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200641 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100642
643 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100644 T.start;
645 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100646 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
647 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200648 [] BSSAP.receive {
649 setverdict(fail, "Received unexpected BSSAP");
650 mtc.stop;
651 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100652 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
653 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200654 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100655 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200656 [] T.timeout {
657 setverdict(fail, "Timeout waiting for CM SERV REQ");
658 mtc.stop;
659 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100660 }
661
Harald Welte1ddc7162018-01-27 14:25:46 +0100662 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100663}
Harald Weltea49e36e2018-01-21 19:29:33 +0100664testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
665 var BSC_ConnHdlr vc_conn;
666 f_init();
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100667 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6);
Harald Weltea49e36e2018-01-21 19:29:33 +0100668 vc_conn.done;
669}
670
Harald Weltee13cfb22019-04-23 16:52:02 +0200671
672friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100673 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200674 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100675 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100676 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100677}
678testcase TC_lu_and_mo_call() runs on MTC_CT {
679 var BSC_ConnHdlr vc_conn;
680 f_init();
681
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100682 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100683 vc_conn.done;
684}
685
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100686/* Verify T(iar) triggers and releases the channel */
687friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
688 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
689 f_init_handler(pars);
690 var CallParameters cpars := valueof(t_CallParams);
691 f_perform_lu();
692 f_mo_call_establish(cpars);
693
694 /* Expect the channel cleared upon T(iar) triggered: */
695 T_wait_iar.start;
696 alt {
697 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
698 T_wait_iar.stop
699 setverdict(pass);
700 }
701 [] MGCP.receive(tr_DLCX(?)) { repeat; }
702 [] T_wait_iar.timeout {
703 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
704 mtc.stop;
705 }
706 }
707
708 setverdict(pass);
709}
710testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
711 var BSC_ConnHdlr vc_conn;
712
713 /* Set T(iar) in MSC low enough that it will trigger before other side
714 has time to keep alive with a T(ias). Keep recommended ratio of
715 T(iar) >= T(ias)*2 */
716 g_msc_sccp_timer_ias := 2;
717 g_msc_sccp_timer_iar := 5;
718
719 f_init();
720
721 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
722 vc_conn.done;
723}
724
Harald Weltee13cfb22019-04-23 16:52:02 +0200725
Harald Welte071ed732018-01-23 19:53:52 +0100726/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200727friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100728 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100729
730 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
731 var PDU_DTAP_MT dtap_mt;
732
733 /* tell GSUP dispatcher to send this IMSI to us */
734 f_create_gsup_expect(hex2str(g_pars.imsi));
735
736 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200737 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100738
739 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200740 if (pars.ran_is_geran) {
741 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
742 }
Harald Welte071ed732018-01-23 19:53:52 +0100743
744 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
745 /* The HLR would normally return an auth vector here, but we fail to do so. */
746
747 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100748 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100749}
750testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
751 var BSC_ConnHdlr vc_conn;
752 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100753 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100754
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100755 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8);
Harald Welte071ed732018-01-23 19:53:52 +0100756 vc_conn.done;
757}
758
Harald Weltee13cfb22019-04-23 16:52:02 +0200759
Harald Welte071ed732018-01-23 19:53:52 +0100760/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200761friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100762 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100763
764 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
765 var PDU_DTAP_MT dtap_mt;
766
767 /* tell GSUP dispatcher to send this IMSI to us */
768 f_create_gsup_expect(hex2str(g_pars.imsi));
769
770 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200771 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100772
773 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200774 if (pars.ran_is_geran) {
775 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
776 }
Harald Welte071ed732018-01-23 19:53:52 +0100777
778 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
779 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
780
781 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100782 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100783}
784testcase TC_lu_auth_sai_err() runs on MTC_CT {
785 var BSC_ConnHdlr vc_conn;
786 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100787 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100788
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100789 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9);
Harald Welte2bb825f2018-01-22 11:31:18 +0100790 vc_conn.done;
791}
Harald Weltea49e36e2018-01-21 19:29:33 +0100792
Harald Weltee13cfb22019-04-23 16:52:02 +0200793
Harald Weltebc881782018-01-23 20:09:15 +0100794/* Test LU but BSC will send a clear request in the middle */
795private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100796 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100797
798 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
799 var PDU_DTAP_MT dtap_mt;
800
801 /* tell GSUP dispatcher to send this IMSI to us */
802 f_create_gsup_expect(hex2str(g_pars.imsi));
803
804 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200805 f_cl3_or_initial_ue(l3_lu);
Harald Weltebc881782018-01-23 20:09:15 +0100806
807 /* Send Early Classmark, just for the fun of it */
808 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
809
810 f_sleep(1.0);
811 /* send clear request in the middle of the LU */
812 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200813 alt {
814 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
815 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
816 }
Harald Weltebc881782018-01-23 20:09:15 +0100817 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100818 alt {
819 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200820 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
821 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200822 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200823 repeat;
824 }
Harald Welte6811d102019-04-14 22:23:14 +0200825 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100826 }
Harald Weltebc881782018-01-23 20:09:15 +0100827 setverdict(pass);
828}
829testcase TC_lu_clear_request() runs on MTC_CT {
830 var BSC_ConnHdlr vc_conn;
831 f_init();
832
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100833 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100834 vc_conn.done;
835}
836
Harald Welte66af9e62018-01-24 17:28:21 +0100837/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200838friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100839 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100840
841 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
842 var PDU_DTAP_MT dtap_mt;
843
844 /* tell GSUP dispatcher to send this IMSI to us */
845 f_create_gsup_expect(hex2str(g_pars.imsi));
846
847 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200848 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +0100849
850 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200851 if (pars.ran_is_geran) {
852 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
853 }
Harald Welte66af9e62018-01-24 17:28:21 +0100854
855 f_sleep(1.0);
856 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +0200857 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +0100858 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +0100859 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +0100860}
861testcase TC_lu_disconnect() runs on MTC_CT {
862 var BSC_ConnHdlr vc_conn;
863 f_init();
864
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100865 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100866 vc_conn.done;
867}
868
Harald Welteba7b6d92018-01-23 21:32:34 +0100869/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +0200870friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100871 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100872
Harald Welte256571e2018-01-24 18:47:19 +0100873 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100874 var PDU_DTAP_MT dtap_mt;
875
876 /* tell GSUP dispatcher to send this IMSI to us */
877 f_create_gsup_expect(hex2str(g_pars.imsi));
878
879 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200880 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100881
882 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200883 if (pars.ran_is_geran) {
884 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
885 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100886 /* wait for LU reject, ignore any ID REQ */
887 alt {
888 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
889 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
890 }
891 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100892 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100893}
894testcase TC_lu_by_imei() runs on MTC_CT {
895 var BSC_ConnHdlr vc_conn;
896 f_init();
897
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100898 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12);
Harald Welteba7b6d92018-01-23 21:32:34 +0100899 vc_conn.done;
900}
901
Harald Weltee13cfb22019-04-23 16:52:02 +0200902
Harald Welteba7b6d92018-01-23 21:32:34 +0100903/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
904private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200905 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
906 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100907 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100908
909 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
910 var PDU_DTAP_MT dtap_mt;
911
912 /* tell GSUP dispatcher to send this IMSI to us */
913 f_create_gsup_expect(hex2str(g_pars.imsi));
914
915 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200916 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100917
918 /* Send Early Classmark, just for the fun of it */
919 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
920
921 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +0200922 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200923 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100924 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
925
926 /* Expect MSC to do UpdateLocation to HLR; respond to it */
927 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
928 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
929 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
930 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
931
932 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100933 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
934 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
935 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100936 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
937 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200938 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +0100939 }
940 }
941
Philipp Maier9b690e42018-12-21 11:50:03 +0100942 /* Wait for MM-Information (if enabled) */
943 f_expect_mm_info();
944
Harald Welteba7b6d92018-01-23 21:32:34 +0100945 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100946 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100947}
948testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
949 var BSC_ConnHdlr vc_conn;
950 f_init();
951
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100952 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100953 vc_conn.done;
954}
955
956
Harald Welte45164da2018-01-24 12:51:27 +0100957/* Test IMSI DETACH (MI=IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200958friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100959 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100960
961 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
962
963 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200964 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100965
966 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200967 if (pars.ran_is_geran) {
968 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
969 }
Harald Welte45164da2018-01-24 12:51:27 +0100970
971 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100972 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100973}
974testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
975 var BSC_ConnHdlr vc_conn;
976 f_init();
977
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100978 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14);
Harald Welte45164da2018-01-24 12:51:27 +0100979 vc_conn.done;
980}
981
Harald Weltee13cfb22019-04-23 16:52:02 +0200982
Harald Welte45164da2018-01-24 12:51:27 +0100983/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200984friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100985 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100986
987 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
988
989 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200990 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100991
992 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200993 if (pars.ran_is_geran) {
994 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
995 }
Harald Welte45164da2018-01-24 12:51:27 +0100996
997 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100998 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100999}
1000testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1001 var BSC_ConnHdlr vc_conn;
1002 f_init();
1003
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001004 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15);
Harald Welte45164da2018-01-24 12:51:27 +01001005 vc_conn.done;
1006}
1007
Harald Weltee13cfb22019-04-23 16:52:02 +02001008
Harald Welte45164da2018-01-24 12:51:27 +01001009/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001010friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001011 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001012
Harald Welte256571e2018-01-24 18:47:19 +01001013 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001014
1015 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001016 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001017
1018 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001019 if (pars.ran_is_geran) {
1020 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1021 }
Harald Welte45164da2018-01-24 12:51:27 +01001022
1023 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001024 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001025}
1026testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1027 var BSC_ConnHdlr vc_conn;
1028 f_init();
1029
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001030 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16);
Harald Welte45164da2018-01-24 12:51:27 +01001031 vc_conn.done;
1032}
1033
1034
1035/* helper function for an emergency call. caller passes in mobile identity to use */
1036private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001037 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1038 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001039
Harald Welte0bef21e2018-02-10 09:48:23 +01001040 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001041}
1042
1043/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001044friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001045 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001046
Harald Welte256571e2018-01-24 18:47:19 +01001047 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001048 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001049 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001050 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001051 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001052}
1053testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1054 var BSC_ConnHdlr vc_conn;
1055 f_init();
1056
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001057 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17);
Harald Welte45164da2018-01-24 12:51:27 +01001058 vc_conn.done;
1059}
1060
Harald Weltee13cfb22019-04-23 16:52:02 +02001061
Harald Welted5b91402018-01-24 18:48:16 +01001062/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001063friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001064 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001065 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001066 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001067 /* Then issue emergency call identified by IMSI */
1068 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1069}
1070testcase TC_emerg_call_imsi() runs on MTC_CT {
1071 var BSC_ConnHdlr vc_conn;
1072 f_init();
1073
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001074 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001075 vc_conn.done;
1076}
1077
Harald Weltee13cfb22019-04-23 16:52:02 +02001078
Harald Welte45164da2018-01-24 12:51:27 +01001079/* CM Service Request for VGCS -> reject */
1080private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001081 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001082
1083 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001084 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001085
1086 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001087 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001088 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001089 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001090 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001091}
1092testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1093 var BSC_ConnHdlr vc_conn;
1094 f_init();
1095
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001096 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001097 vc_conn.done;
1098}
1099
1100/* CM Service Request for VBS -> reject */
1101private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001102 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001103
1104 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001105 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001106
1107 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001108 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001109 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001110 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001111 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001112}
1113testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1114 var BSC_ConnHdlr vc_conn;
1115 f_init();
1116
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001117 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001118 vc_conn.done;
1119}
1120
1121/* CM Service Request for LCS -> reject */
1122private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001123 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001124
1125 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001126 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001127
1128 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001129 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001130 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001131 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001132 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001133}
1134testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1135 var BSC_ConnHdlr vc_conn;
1136 f_init();
1137
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001138 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001139 vc_conn.done;
1140}
1141
Harald Welte0195ab12018-01-24 21:50:20 +01001142/* CM Re-Establishment Request */
1143private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001144 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001145
1146 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001147 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001148
1149 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1150 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001151 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001152 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001153 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001154}
1155testcase TC_cm_reest_req_reject() runs on MTC_CT {
1156 var BSC_ConnHdlr vc_conn;
1157 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001158
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001159 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001160 vc_conn.done;
1161}
1162
Harald Weltec638f4d2018-01-24 22:00:36 +01001163/* Test LU (with authentication enabled), with wrong response from MS */
1164private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001165 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001166
1167 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1168
1169 /* tell GSUP dispatcher to send this IMSI to us */
1170 f_create_gsup_expect(hex2str(g_pars.imsi));
1171
1172 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001173 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001174
1175 /* Send Early Classmark, just for the fun of it */
1176 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1177
1178 var AuthVector vec := f_gen_auth_vec_2g();
1179 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1180 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1181 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1182
1183 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1184 /* Send back wrong auth response */
1185 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1186
1187 /* Expect GSUP AUTH FAIL REP to HLR */
1188 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1189
1190 /* Expect LU REJECT with Cause == Illegal MS */
1191 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001192 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001193}
1194testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1195 var BSC_ConnHdlr vc_conn;
1196 f_init();
1197 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001198
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001199 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23);
Harald Weltec638f4d2018-01-24 22:00:36 +01001200 vc_conn.done;
1201}
1202
Harald Weltede371492018-01-27 23:44:41 +01001203/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001204private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001205 pars.net.expect_auth := true;
1206 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001207 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001208 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001209}
1210testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1211 var BSC_ConnHdlr vc_conn;
1212 f_init();
1213 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001214 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1215
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001216 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001217 vc_conn.done;
1218}
1219
Harald Welte1af6ea82018-01-25 18:33:15 +01001220/* Test Complete L3 without payload */
1221private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001222 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001223
1224 /* Send Complete L3 Info with empty L3 frame */
1225 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1226 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1227
Harald Weltef466eb42018-01-27 14:26:54 +01001228 timer T := 5.0;
1229 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001230 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001231 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001232 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001233 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001234 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001235 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001236 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001237 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001238 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001239 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001240 }
1241 setverdict(pass);
1242}
1243testcase TC_cl3_no_payload() runs on MTC_CT {
1244 var BSC_ConnHdlr vc_conn;
1245 f_init();
1246
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001247 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001248 vc_conn.done;
1249}
1250
1251/* Test Complete L3 with random payload */
1252private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001253 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001254
Daniel Willmannaa14a382018-07-26 08:29:45 +02001255 /* length is limited by PDU_BSSAP length field which includes some
1256 * other fields beside l3info payload. So payl can only be 240 bytes
1257 * Since rnd() returns values < 1 multiply with 241
1258 */
1259 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001260 var octetstring payl := f_rnd_octstring(len);
1261
1262 /* Send Complete L3 Info with empty L3 frame */
1263 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1264 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1265
Harald Weltef466eb42018-01-27 14:26:54 +01001266 timer T := 5.0;
1267 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001268 alt {
1269 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001270 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001271 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001272 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001273 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001274 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001275 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001276 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001277 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001278 }
1279 setverdict(pass);
1280}
1281testcase TC_cl3_rnd_payload() runs on MTC_CT {
1282 var BSC_ConnHdlr vc_conn;
1283 f_init();
1284
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001285 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001286 vc_conn.done;
1287}
1288
Harald Welte116e4332018-01-26 22:17:48 +01001289/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001290friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001291 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001292
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001293 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001294
Harald Welteb9e86fa2018-04-09 18:18:31 +02001295 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001296 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001297}
1298testcase TC_establish_and_nothing() runs on MTC_CT {
1299 var BSC_ConnHdlr vc_conn;
1300 f_init();
1301
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001302 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001303 vc_conn.done;
1304}
1305
Harald Weltee13cfb22019-04-23 16:52:02 +02001306
Harald Welte12510c52018-01-26 22:26:24 +01001307/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001308friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001309 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001310
Harald Welte12510c52018-01-26 22:26:24 +01001311 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001312 cpars.mgw_conn_2.resp := 0;
1313 cpars.stop_after_cc_setup := true;
1314
1315 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001316
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001317 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001318
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001319 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001320
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001321 var default ccrel := activate(as_optional_cc_rel(cpars));
1322
Philipp Maier109e6aa2018-10-17 10:53:32 +02001323 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001324
1325 deactivate(ccrel);
1326
1327 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001328}
1329testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1330 var BSC_ConnHdlr vc_conn;
1331 f_init();
1332
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001333 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001334 vc_conn.done;
1335}
1336
Harald Weltee13cfb22019-04-23 16:52:02 +02001337
Harald Welte3ab88002018-01-26 22:37:25 +01001338/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001339friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001340 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001341 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1342 var MNCC_PDU mncc;
1343 var MgcpCommand mgcp_cmd;
1344
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001345 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001346 /* Do not respond to the second CRCX */
1347 cpars.mgw_conn_2.resp := 0;
1348 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001349
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001350 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001351
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001352 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001353
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001354 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001355}
1356testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1357 var BSC_ConnHdlr vc_conn;
1358 f_init();
1359
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001360 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001361 vc_conn.done;
1362}
1363
Harald Weltee13cfb22019-04-23 16:52:02 +02001364
Harald Welte0cc82d92018-01-26 22:52:34 +01001365/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001366friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001367 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001368
Harald Welte0cc82d92018-01-26 22:52:34 +01001369 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001370
1371 /* Respond with error for the first CRCX */
1372 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001373
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001374 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001375 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001376
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001377 var default ccrel := activate(as_optional_cc_rel(cpars));
1378 f_expect_clear(60.0);
1379 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001380}
1381testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1382 var BSC_ConnHdlr vc_conn;
1383 f_init();
1384
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001385 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001386 vc_conn.done;
1387}
1388
Harald Welte3ab88002018-01-26 22:37:25 +01001389
Harald Welte812f7a42018-01-27 00:49:18 +01001390/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1391private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1392 var MNCC_PDU mncc;
1393 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001394
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001395 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001396 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001397
1398 /* Allocate call reference and send SETUP via MNCC to MSC */
1399 cpars.mncc_callref := f_rnd_int(2147483648);
1400 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1401 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1402
1403 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001404 f_expect_paging();
1405
Harald Welte812f7a42018-01-27 00:49:18 +01001406 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001407 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001408
1409 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1410
1411 /* MSC->MS: SETUP */
1412 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1413}
1414
1415/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001416friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001417 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001418 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1419 var MNCC_PDU mncc;
1420 var MgcpCommand mgcp_cmd;
1421
1422 f_mt_call_start(cpars);
1423
1424 /* MS->MSC: CALL CONFIRMED */
1425 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1426
1427 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1428
1429 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1430 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001431
1432 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1433 * set an endpoint name that fits the pattern. If not, just use the
1434 * endpoint name from the request */
1435 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1436 cpars.mgcp_ep := "rtpbridge/1@mgw";
1437 } else {
1438 cpars.mgcp_ep := mgcp_cmd.line.ep;
1439 }
1440
Harald Welte812f7a42018-01-27 00:49:18 +01001441 /* Respond to CRCX with error */
1442 var MgcpResponse mgcp_rsp := {
1443 line := {
1444 code := "542",
1445 trans_id := mgcp_cmd.line.trans_id,
1446 string := "FORCED_FAIL"
1447 },
Harald Welte812f7a42018-01-27 00:49:18 +01001448 sdp := omit
1449 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001450 var MgcpParameter mgcp_rsp_param := {
1451 code := "Z",
1452 val := cpars.mgcp_ep
1453 };
1454 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001455 MGCP.send(mgcp_rsp);
1456
1457 timer T := 30.0;
1458 T.start;
1459 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001460 [] T.timeout {
1461 setverdict(fail, "Timeout waiting for channel release");
1462 mtc.stop;
1463 }
Harald Welte812f7a42018-01-27 00:49:18 +01001464 [] MNCC.receive { repeat; }
1465 [] GSUP.receive { repeat; }
1466 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1467 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1468 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1469 repeat;
1470 }
1471 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001472 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001473 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001474 }
1475}
1476testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1477 var BSC_ConnHdlr vc_conn;
1478 f_init();
1479
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001480 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001481 vc_conn.done;
1482}
1483
1484
Harald Weltee13cfb22019-04-23 16:52:02 +02001485
Harald Welte812f7a42018-01-27 00:49:18 +01001486/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001487friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001488 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001489 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1490 var MNCC_PDU mncc;
1491 var MgcpCommand mgcp_cmd;
1492
1493 f_mt_call_start(cpars);
1494
1495 /* MS->MSC: CALL CONFIRMED */
1496 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1497 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1498
1499 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1500 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1501 cpars.mgcp_ep := mgcp_cmd.line.ep;
1502 /* FIXME: Respond to CRCX */
1503
1504 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1505 timer T := 190.0;
1506 T.start;
1507 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001508 [] T.timeout {
1509 setverdict(fail, "Timeout waiting for T310");
1510 mtc.stop;
1511 }
Harald Welte812f7a42018-01-27 00:49:18 +01001512 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1513 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1514 }
1515 }
1516 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1517 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1518 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1519 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1520
1521 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001522 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1523 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1524 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1525 repeat;
1526 }
Harald Welte5946b332018-03-18 23:32:21 +01001527 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001528 }
1529}
1530testcase TC_mt_t310() runs on MTC_CT {
1531 var BSC_ConnHdlr vc_conn;
1532 f_init();
1533
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001534 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001535 vc_conn.done;
1536}
1537
Harald Weltee13cfb22019-04-23 16:52:02 +02001538
Harald Welte167458a2018-01-27 15:58:16 +01001539/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001540friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001541 f_init_handler(pars);
1542 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001543
1544 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001545 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001546
1547 /* First MO call should succeed */
1548 f_mo_call(cpars);
1549
1550 /* Cancel the subscriber in the VLR */
1551 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1552 alt {
1553 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1554 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1555 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001556 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001557 }
1558 }
1559
1560 /* Follow-up transactions should fail */
1561 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1562 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001563 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001564 alt {
1565 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1566 [] BSSAP.receive {
1567 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001568 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001569 }
1570 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001571
1572 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001573 setverdict(pass);
1574}
1575testcase TC_gsup_cancel() runs on MTC_CT {
1576 var BSC_ConnHdlr vc_conn;
1577 f_init();
1578
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001579 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33);
Harald Welte167458a2018-01-27 15:58:16 +01001580 vc_conn.done;
1581}
1582
Harald Weltee13cfb22019-04-23 16:52:02 +02001583
Harald Welte9de84792018-01-28 01:06:35 +01001584/* A5/1 only permitted on network side, and MS capable to do it */
1585private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1586 pars.net.expect_auth := true;
1587 pars.net.expect_ciph := true;
1588 pars.net.kc_support := '02'O; /* A5/1 only */
1589 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001590 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001591}
1592testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1593 var BSC_ConnHdlr vc_conn;
1594 f_init();
1595 f_vty_config(MSCVTY, "network", "authentication required");
1596 f_vty_config(MSCVTY, "network", "encryption a5 1");
1597
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001598 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001599 vc_conn.done;
1600}
1601
1602/* A5/3 only permitted on network side, and MS capable to do it */
1603private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1604 pars.net.expect_auth := true;
1605 pars.net.expect_ciph := true;
1606 pars.net.kc_support := '08'O; /* A5/3 only */
1607 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001608 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001609}
1610testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1611 var BSC_ConnHdlr vc_conn;
1612 f_init();
1613 f_vty_config(MSCVTY, "network", "authentication required");
1614 f_vty_config(MSCVTY, "network", "encryption a5 3");
1615
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001616 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001617 vc_conn.done;
1618}
1619
1620/* A5/3 only permitted on network side, and MS with only A5/1 support */
1621private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1622 pars.net.expect_auth := true;
1623 pars.net.expect_ciph := true;
1624 pars.net.kc_support := '08'O; /* A5/3 only */
1625 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1626 f_init_handler(pars, 15.0);
1627
1628 /* cannot use f_perform_lu() as we expect a reject */
1629 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1630 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001631 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001632 if (pars.send_early_cm) {
1633 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1634 } else {
1635 pars.cm1.esind := '0'B;
1636 }
Harald Welte9de84792018-01-28 01:06:35 +01001637 f_mm_auth();
1638 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001639 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1640 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1641 repeat;
1642 }
Harald Welte5946b332018-03-18 23:32:21 +01001643 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1644 f_expect_clear();
1645 }
Harald Welte9de84792018-01-28 01:06:35 +01001646 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1647 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001648 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001649 }
1650 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001651 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001652 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001653 }
1654 }
1655 setverdict(pass);
1656}
1657testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1658 var BSC_ConnHdlr vc_conn;
1659 f_init();
1660 f_vty_config(MSCVTY, "network", "authentication required");
1661 f_vty_config(MSCVTY, "network", "encryption a5 3");
1662
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001663 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360);
1664 vc_conn.done;
1665}
1666testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1667 var BSC_ConnHdlrPars pars;
1668 var BSC_ConnHdlr vc_conn;
1669 f_init();
1670 f_vty_config(MSCVTY, "network", "authentication required");
1671 f_vty_config(MSCVTY, "network", "encryption a5 3");
1672
1673 pars := f_init_pars(361);
1674 pars.send_early_cm := false;
1675 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001676 vc_conn.done;
1677}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001678testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1679 var BSC_ConnHdlr vc_conn;
1680 f_init();
1681 f_vty_config(MSCVTY, "network", "authentication required");
1682 f_vty_config(MSCVTY, "network", "encryption a5 3");
1683
1684 /* Make sure the MSC category is on DEBUG level to trigger the log
1685 * message that is reported in OS#2947 to trigger the segfault */
1686 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1687
1688 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362);
1689 vc_conn.done;
1690}
Harald Welte9de84792018-01-28 01:06:35 +01001691
1692/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1693private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1694 pars.net.expect_auth := true;
1695 pars.net.expect_ciph := true;
1696 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1697 pars.cm1.a5_1 := '1'B;
1698 pars.cm2.a5_1 := '1'B;
1699 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1700 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1701 f_init_handler(pars, 15.0);
1702
1703 /* cannot use f_perform_lu() as we expect a reject */
1704 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1705 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001706 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001707 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1708 f_mm_auth();
1709 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001710 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1711 f_expect_clear();
1712 }
Harald Welte9de84792018-01-28 01:06:35 +01001713 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1714 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001715 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001716 }
1717 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001718 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001719 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001720 }
1721 }
1722 setverdict(pass);
1723}
1724testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1725 var BSC_ConnHdlr vc_conn;
1726 f_init();
1727 f_vty_config(MSCVTY, "network", "authentication required");
1728 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1729
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001730 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37);
Harald Welte9de84792018-01-28 01:06:35 +01001731 vc_conn.done;
1732}
1733
1734/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1735private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1736 pars.net.expect_auth := true;
1737 pars.net.expect_ciph := true;
1738 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1739 pars.cm1.a5_1 := '1'B;
1740 pars.cm2.a5_1 := '1'B;
1741 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1742 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1743 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001744 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001745}
1746testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1747 var BSC_ConnHdlr vc_conn;
1748 f_init();
1749 f_vty_config(MSCVTY, "network", "authentication required");
1750 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1751
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001752 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001753 vc_conn.done;
1754}
1755
Harald Welte33ec09b2018-02-10 15:34:46 +01001756/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01001757friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01001758 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001759 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001760 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01001761
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001762 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001763 f_mt_call(cpars);
1764}
1765testcase TC_lu_and_mt_call() runs on MTC_CT {
1766 var BSC_ConnHdlr vc_conn;
1767 f_init();
1768
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001769 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001770 vc_conn.done;
1771}
1772
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001773testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
1774 var BSC_ConnHdlr vc_conn;
1775 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001776
1777 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
1778 vc_conn.done;
1779}
1780
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01001781/* MT call while already Paging */
1782friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1783 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1784 var SmsParameters spars := valueof(t_SmsPars);
1785 var OCT4 tmsi;
1786
1787 f_init_handler(pars);
1788
1789 /* Perform location update */
1790 f_perform_lu();
1791
1792 /* register an 'expect' for given IMSI (+TMSI) */
1793 if (isvalue(g_pars.tmsi)) {
1794 tmsi := g_pars.tmsi;
1795 } else {
1796 tmsi := 'FFFFFFFF'O;
1797 }
1798 f_ran_register_imsi(g_pars.imsi, tmsi);
1799
1800 log("start Paging by an SMS");
1801 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
1802
1803 /* MSC->BSC: expect PAGING from MSC */
1804 f_expect_paging();
1805
1806 log("MNCC signals MT call, before Paging Response");
1807 f_mt_call_initate(cpars);
1808 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
1809
1810 f_sleep(0.5);
1811 log("phone answers Paging, expecting both SMS and MT call to be established");
1812 f_establish_fully(EST_TYPE_PAG_RESP);
1813 spars.tp.ud := 'C8329BFD064D9B53'O;
1814 interleave {
1815 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
1816 log("Got SMS-DELIVER");
1817 };
1818 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
1819 log("Got CC Setup");
1820 };
1821 }
1822 setverdict(pass);
1823 log("success, tear down");
1824 var default ccrel := activate(as_optional_cc_rel(cpars));
1825 if (g_pars.ran_is_geran) {
1826 BSSAP.send(ts_BSSMAP_ClearRequest(0));
1827 } else {
1828 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
1829 }
1830 f_expect_clear();
1831 deactivate(ccrel);
1832 f_vty_sms_clear(hex2str(g_pars.imsi));
1833}
1834testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
1835 var BSC_ConnHdlrPars pars;
1836 var BSC_ConnHdlr vc_conn;
1837 f_init();
1838 pars := f_init_pars(391);
1839 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
1840 vc_conn.done;
1841}
1842
Daniel Willmann8b084372018-02-04 13:35:26 +01001843/* Test MO Call SETUP with DTMF */
1844private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1845 f_init_handler(pars);
1846 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01001847
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001848 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001849 f_mo_seq_dtmf_dup(cpars);
1850}
1851testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1852 var BSC_ConnHdlr vc_conn;
1853 f_init();
1854
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001855 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001856 vc_conn.done;
1857}
Harald Welte9de84792018-01-28 01:06:35 +01001858
Philipp Maier328d1662018-03-07 10:40:27 +01001859testcase TC_cr_before_reset() runs on MTC_CT {
1860 timer T := 4.0;
1861 var boolean reset_ack_seen := false;
1862 f_init_bssap_direct();
1863
Harald Welte3ca0ce12019-04-23 17:18:48 +02001864 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02001865
Daniel Willmanne8018962018-08-21 14:18:00 +02001866 f_sleep(3.0);
1867
Philipp Maier328d1662018-03-07 10:40:27 +01001868 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001869 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001870
1871 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001872 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001873 T.start
1874 alt {
1875 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1876 reset_ack_seen := true;
1877 repeat;
1878 }
1879
1880 /* Acknowledge MSC sided reset requests */
1881 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001882 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001883 repeat;
1884 }
1885
1886 /* Ignore all other messages (e.g CR from the connection request) */
1887 [] BSSAP_DIRECT.receive { repeat }
1888
1889 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1890 * deadlock situation. The MSC is then unable to respond to any
1891 * further BSSMAP RESET or any other sort of traffic. */
1892 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1893 [reset_ack_seen == false] T.timeout {
1894 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02001895 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01001896 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01001897 }
Philipp Maier328d1662018-03-07 10:40:27 +01001898}
Harald Welte9de84792018-01-28 01:06:35 +01001899
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001900/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02001901friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001902 f_init_handler(pars);
1903 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1904 var MNCC_PDU mncc;
1905 var MgcpCommand mgcp_cmd;
1906
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001907 /* Do not respond to the second CRCX */
1908 cpars.mgw_conn_2.resp := 0;
1909
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001910 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001911 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001912
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001913 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001914
1915 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001916
1917 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001918}
1919testcase TC_mo_release_timeout() runs on MTC_CT {
1920 var BSC_ConnHdlr vc_conn;
1921 f_init();
1922
1923 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1924 vc_conn.done;
1925}
1926
Harald Welte12510c52018-01-26 22:26:24 +01001927
Philipp Maier2a98a732018-03-19 16:06:12 +01001928/* LU followed by MT call (including paging) */
1929private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1930 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001931 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01001932
1933 /* Intentionally disable the CRCX response */
1934 cpars.mgw_drop_dlcx := true;
1935
1936 /* Perform location update and call */
1937 f_perform_lu();
1938 f_mt_call(cpars);
1939}
1940testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
1941 var BSC_ConnHdlr vc_conn;
1942 f_init();
1943
1944 /* Perform an almost normal looking locationupdate + mt-call, but do
1945 * not respond to the DLCX at the end of the call */
1946 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
1947 vc_conn.done;
1948
1949 /* Wait a guard period until the MGCP layer in the MSC times out,
1950 * if the MSC is vulnerable to the use-after-free situation that is
1951 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
1952 * segfault now */
1953 f_sleep(6.0);
1954
1955 /* Run the init procedures once more. If the MSC has crashed, this
1956 * this will fail */
1957 f_init();
1958}
Harald Welte45164da2018-01-24 12:51:27 +01001959
Philipp Maier75932982018-03-27 14:52:35 +02001960/* Two BSSMAP resets from two different BSCs */
1961testcase TC_reset_two() runs on MTC_CT {
1962 var BSC_ConnHdlr vc_conn;
1963 f_init(2);
1964 f_sleep(2.0);
1965 setverdict(pass);
1966}
1967
Harald Weltee13cfb22019-04-23 16:52:02 +02001968/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
1969testcase TC_reset_two_1iu() runs on MTC_CT {
1970 var BSC_ConnHdlr vc_conn;
1971 f_init(3);
1972 f_sleep(2.0);
1973 setverdict(pass);
1974}
1975
Harald Weltef640a012018-04-14 17:49:21 +02001976/***********************************************************************
1977 * SMS Testing
1978 ***********************************************************************/
1979
Harald Weltef45efeb2018-04-09 18:19:24 +02001980/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02001981friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02001982 var SmsParameters spars := valueof(t_SmsPars);
1983
1984 f_init_handler(pars);
1985
1986 /* Perform location update and call */
1987 f_perform_lu();
1988
1989 f_establish_fully(EST_TYPE_MO_SMS);
1990
1991 //spars.exp_rp_err := 96; /* invalid mandatory information */
1992 f_mo_sms(spars);
1993
1994 f_expect_clear();
1995}
1996testcase TC_lu_and_mo_sms() runs on MTC_CT {
1997 var BSC_ConnHdlr vc_conn;
1998 f_init();
1999 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2000 vc_conn.done;
2001}
2002
Harald Weltee13cfb22019-04-23 16:52:02 +02002003
Harald Weltef45efeb2018-04-09 18:19:24 +02002004private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002005runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002006 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2007}
2008
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002009/* Remove still pending SMS */
2010private function f_vty_sms_clear(charstring imsi)
2011runs on BSC_ConnHdlr {
2012 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2013 f_vty_transceive(MSCVTY, "sms-queue clear");
2014}
2015
Harald Weltef45efeb2018-04-09 18:19:24 +02002016/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002017friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002018 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002019
2020 f_init_handler(pars);
2021
2022 /* Perform location update and call */
2023 f_perform_lu();
2024
2025 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002026 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002027
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002028 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002029
2030 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002031 f_expect_paging();
2032
Harald Weltef45efeb2018-04-09 18:19:24 +02002033 /* Establish DTAP / BSSAP / SCCP connection */
2034 f_establish_fully(EST_TYPE_PAG_RESP);
2035
2036 spars.tp.ud := 'C8329BFD064D9B53'O;
2037 f_mt_sms(spars);
2038
2039 f_expect_clear();
2040}
2041testcase TC_lu_and_mt_sms() runs on MTC_CT {
2042 var BSC_ConnHdlrPars pars;
2043 var BSC_ConnHdlr vc_conn;
2044 f_init();
2045 pars := f_init_pars(43);
2046 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002047 vc_conn.done;
2048}
2049
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002050/* SMS added while already Paging */
2051friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2052 var SmsParameters spars := valueof(t_SmsPars);
2053 var OCT4 tmsi;
2054
2055 f_init_handler(pars);
2056
2057 f_perform_lu();
2058
2059 /* register an 'expect' for given IMSI (+TMSI) */
2060 if (isvalue(g_pars.tmsi)) {
2061 tmsi := g_pars.tmsi;
2062 } else {
2063 tmsi := 'FFFFFFFF'O;
2064 }
2065 f_ran_register_imsi(g_pars.imsi, tmsi);
2066
2067 log("first SMS");
2068 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2069
2070 /* MSC->BSC: expect PAGING from MSC */
2071 f_expect_paging();
2072
2073 log("second SMS");
2074 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2075 * with the pending paging. Another SMS: */
2076 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2077
2078 /* Establish DTAP / BSSAP / SCCP connection */
2079 f_establish_fully(EST_TYPE_PAG_RESP);
2080
2081 spars.tp.ud := 'C8329BFD064D9B53'O;
2082 f_mt_sms(spars);
2083
2084 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2085 f_mt_sms(spars);
2086
2087 f_expect_clear();
2088}
2089testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2090 var BSC_ConnHdlrPars pars;
2091 var BSC_ConnHdlr vc_conn;
2092 f_init();
2093 pars := f_init_pars(44);
2094 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2095 vc_conn.done;
2096}
Harald Weltee13cfb22019-04-23 16:52:02 +02002097
Philipp Maier3983e702018-11-22 19:01:33 +01002098/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002099friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002100 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002101
Philipp Maier3983e702018-11-22 19:01:33 +01002102 f_init_handler(pars, 150.0);
2103
2104 /* Perform location update */
2105 f_perform_lu();
2106
2107 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002108 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002109
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002110 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2111
Neels Hofmeyr16237742019-03-06 15:34:01 +01002112 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002113 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002114
2115 /* Wait some time to make sure the MSC is not delivering any further
2116 * paging messages or anything else that could be unexpected. */
2117 timer T := 20.0;
2118 T.start
2119 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002120 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2121 setverdict(fail, "paging seems not to stop!");
2122 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002123 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002124 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2125 setverdict(fail, "paging seems not to stop!");
2126 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002127 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002128 [] BSSAP.receive {
2129 setverdict(fail, "unexpected BSSAP message received");
2130 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002131 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002132 [] T.timeout {
2133 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002134 }
2135 }
2136
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002137 f_vty_sms_clear(hex2str(g_pars.imsi));
2138
Philipp Maier3983e702018-11-22 19:01:33 +01002139 setverdict(pass);
2140}
2141testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2142 var BSC_ConnHdlrPars pars;
2143 var BSC_ConnHdlr vc_conn;
2144 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002145 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002146 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002147 vc_conn.done;
2148}
2149
Alexander Couzensfc02f242019-09-12 03:43:18 +02002150/* LU followed by MT SMS with repeated paging */
2151friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2152 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002153
2154 f_init_handler(pars);
2155
2156 /* Perform location update and call */
2157 f_perform_lu();
2158
2159 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002160 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002161
2162 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2163
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002164 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002165 /* MSC->BSC: expect PAGING from MSC */
2166 f_expect_paging();
2167
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002168 if (g_pars.ran_is_geran) {
2169 log("GERAN: expect no further Paging");
2170 } else {
2171 log("UTRAN: expect more Paging");
2172 }
2173
2174 timer T := 5.0;
2175 T.start;
2176 alt {
2177 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2178 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2179 mtc.stop;
2180 }
2181 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2182 log("UTRAN: second Paging received, as expected");
2183 setverdict(pass);
2184 }
2185 [] T.timeout {
2186 if (g_pars.ran_is_geran) {
2187 log("GERAN: No further Paging received, as expected");
2188 setverdict(pass);
2189 } else {
2190 setverdict(fail, "UTRAN: Expected a second Paging");
2191 mtc.stop;
2192 }
2193 }
2194 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002195
2196 /* Establish DTAP / BSSAP / SCCP connection */
2197 f_establish_fully(EST_TYPE_PAG_RESP);
2198
2199 spars.tp.ud := 'C8329BFD064D9B53'O;
2200 f_mt_sms(spars);
2201
2202 f_expect_clear();
2203}
2204testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2205 var BSC_ConnHdlrPars pars;
2206 var BSC_ConnHdlr vc_conn;
2207 f_init();
2208 pars := f_init_pars(1844);
2209 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2210 vc_conn.done;
2211}
Harald Weltee13cfb22019-04-23 16:52:02 +02002212
Harald Weltef640a012018-04-14 17:49:21 +02002213/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002214friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002215 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002216
Harald Weltef640a012018-04-14 17:49:21 +02002217 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002218
Harald Weltef640a012018-04-14 17:49:21 +02002219 /* Perform location update so IMSI is known + registered in MSC/VLR */
2220 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002221
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002222 /* MS/UE submits a MO SMS */
2223 f_establish_fully(EST_TYPE_MO_SMS);
2224 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002225
2226 var SMPP_PDU smpp;
2227 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2228 tr_smpp.body.deliver_sm := {
2229 service_type := "CMT",
2230 source_addr_ton := network_specific,
2231 source_addr_npi := isdn,
2232 source_addr := hex2str(pars.msisdn),
2233 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2234 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2235 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2236 esm_class := '00000001'B,
2237 protocol_id := 0,
2238 priority_flag := 0,
2239 schedule_delivery_time := "",
2240 replace_if_present := 0,
2241 data_coding := '00000001'B,
2242 sm_default_msg_id := 0,
2243 sm_length := ?,
2244 short_message := spars.tp.ud,
2245 opt_pars := {
2246 {
2247 tag := user_message_reference,
2248 len := 2,
2249 opt_value := {
2250 int2_val := oct2int(spars.tp.msg_ref)
2251 }
2252 }
2253 }
2254 };
2255 alt {
2256 [] SMPP.receive(tr_smpp) -> value smpp {
2257 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2258 }
2259 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2260 }
2261
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002262 /* MSC terminates the SMS transaction with RP-ACK */
2263 f_mo_sms_wait_rp_ack(spars);
2264
Harald Weltef640a012018-04-14 17:49:21 +02002265 f_expect_clear();
2266}
2267testcase TC_smpp_mo_sms() runs on MTC_CT {
2268 var BSC_ConnHdlr vc_conn;
2269 f_init();
2270 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2271 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2272 vc_conn.done;
2273 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2274}
2275
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002276/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2277friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2278runs on BSC_ConnHdlr {
2279 var SmsParameters spars := valueof(t_SmsPars);
2280 var SMPP_PDU smpp_pdu;
2281 timer T := 3.0;
2282
2283 f_init_handler(pars);
2284
2285 /* Perform location update */
2286 f_perform_lu();
2287
2288 /* MS/UE submits a MO SMS */
2289 f_establish_fully(EST_TYPE_MO_SMS);
2290 f_mo_sms_submit(spars);
2291
2292 /* ESME responds with an error (Invalid Destination Address) */
2293 T.start;
2294 alt {
2295 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2296 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2297 }
2298 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2299 [] T.timeout {
2300 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2301 mtc.stop;
2302 }
2303 }
2304
2305 /* Expect RP-ERROR on BSSAP interface */
2306 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2307 f_mo_sms_wait_rp_ack(spars);
2308
2309 f_expect_clear();
2310}
2311testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2312 var BSC_ConnHdlr vc_conn;
2313 f_init();
2314 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2315 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2316 vc_conn.done;
2317 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2318}
2319
Harald Weltee13cfb22019-04-23 16:52:02 +02002320
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002321/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002322friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002323runs on BSC_ConnHdlr {
2324 var SmsParameters spars := valueof(t_SmsPars);
2325 var GSUP_PDU gsup_msg_rx;
2326 var octetstring sm_tpdu;
2327
2328 f_init_handler(pars);
2329
2330 /* We need to inspect GSUP activity */
2331 f_create_gsup_expect(hex2str(g_pars.imsi));
2332
2333 /* Perform location update */
2334 f_perform_lu();
2335
2336 /* Send CM Service Request for SMS */
2337 f_establish_fully(EST_TYPE_MO_SMS);
2338
2339 /* Prepare expected SM-RP-UI (SM TPDU) */
2340 enc_TPDU_RP_DATA_MS_SGSN_fast(
2341 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2342 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2343 spars.tp.udl, spars.tp.ud)),
2344 sm_tpdu);
2345
2346 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2347 imsi := g_pars.imsi,
2348 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002349 /* SM-RP-DA: SMSC address */
2350 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2351 number := spars.rp.smsc_addr.rP_NumberDigits,
2352 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2353 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2354 ext := spars.rp.smsc_addr.rP_Ext)),
2355 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2356 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2357 number := g_pars.msisdn,
2358 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2359 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002360 /* TODO: can we use decmatch here? */
2361 sm_rp_ui := sm_tpdu
2362 );
2363
2364 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2365 f_mo_sms_submit(spars);
2366 alt {
2367 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002368 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002369 setverdict(pass);
2370 }
2371 [] GSUP.receive {
2372 log("RX unexpected GSUP message");
2373 setverdict(fail);
2374 mtc.stop;
2375 }
2376 }
2377
2378 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2379 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2380 imsi := g_pars.imsi,
2381 sm_rp_mr := spars.rp.msg_ref)));
2382 /* Expect RP-ACK on DTAP */
2383 f_mo_sms_wait_rp_ack(spars);
2384
2385 f_expect_clear();
2386}
2387testcase TC_gsup_mo_sms() runs on MTC_CT {
2388 var BSC_ConnHdlr vc_conn;
2389 f_init();
2390 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2391 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2392 vc_conn.done;
2393 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2394}
2395
Harald Weltee13cfb22019-04-23 16:52:02 +02002396
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002397/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002398friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002399runs on BSC_ConnHdlr {
2400 var SmsParameters spars := valueof(t_SmsPars);
2401 var GSUP_PDU gsup_msg_rx;
2402
2403 f_init_handler(pars);
2404
2405 /* We need to inspect GSUP activity */
2406 f_create_gsup_expect(hex2str(g_pars.imsi));
2407
2408 /* Perform location update */
2409 f_perform_lu();
2410
2411 /* Send CM Service Request for SMS */
2412 f_establish_fully(EST_TYPE_MO_SMS);
2413
2414 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2415 imsi := g_pars.imsi,
2416 sm_rp_mr := spars.rp.msg_ref,
2417 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2418 );
2419
2420 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2421 f_mo_smma(spars);
2422 alt {
2423 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002424 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002425 setverdict(pass);
2426 }
2427 [] GSUP.receive {
2428 log("RX unexpected GSUP message");
2429 setverdict(fail);
2430 mtc.stop;
2431 }
2432 }
2433
2434 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2435 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2436 imsi := g_pars.imsi,
2437 sm_rp_mr := spars.rp.msg_ref)));
2438 /* Expect RP-ACK on DTAP */
2439 f_mo_sms_wait_rp_ack(spars);
2440
2441 f_expect_clear();
2442}
2443testcase TC_gsup_mo_smma() runs on MTC_CT {
2444 var BSC_ConnHdlr vc_conn;
2445 f_init();
2446 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2447 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2448 vc_conn.done;
2449 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2450}
2451
Harald Weltee13cfb22019-04-23 16:52:02 +02002452
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002453/* Helper for sending MT SMS over GSUP */
2454private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2455runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002456 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002457 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2458 number := spars.rp.smsc_addr.rP_NumberDigits,
2459 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2460 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2461 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002462
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002463 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2464 imsi := g_pars.imsi,
2465 /* NOTE: MSC should assign RP-MR itself */
2466 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002467 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002468 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002469 /* Encoded SMS TPDU (taken from Wireshark)
2470 * FIXME: we should encode spars somehow */
2471 sm_rp_ui := '00068021436500008111328130858200'O,
2472 sm_rp_mms := mms
2473 ));
2474}
2475
2476/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002477friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002478runs on BSC_ConnHdlr {
2479 var SmsParameters spars := valueof(t_SmsPars);
2480
2481 f_init_handler(pars);
2482
2483 /* We need to inspect GSUP activity */
2484 f_create_gsup_expect(hex2str(g_pars.imsi));
2485
2486 /* Perform location update */
2487 f_perform_lu();
2488
2489 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002490 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002491
2492 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2493 imsi := g_pars.imsi,
2494 /* NOTE: MSC should assign RP-MR itself */
2495 sm_rp_mr := ?
2496 );
2497
2498 /* Submit a MT SMS on GSUP */
2499 f_gsup_forwardSM_req(spars);
2500
2501 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002502 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002503 f_establish_fully(EST_TYPE_PAG_RESP);
2504
2505 /* Wait for MT SMS on DTAP */
2506 f_mt_sms_expect(spars);
2507
2508 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2509 f_mt_sms_send_rp_ack(spars);
2510 alt {
2511 [] GSUP.receive(mt_forwardSM_res) {
2512 log("RX MT-forwardSM-Res (RP-ACK)");
2513 setverdict(pass);
2514 }
2515 [] GSUP.receive {
2516 log("RX unexpected GSUP message");
2517 setverdict(fail);
2518 mtc.stop;
2519 }
2520 }
2521
2522 f_expect_clear();
2523}
2524testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2525 var BSC_ConnHdlrPars pars;
2526 var BSC_ConnHdlr vc_conn;
2527 f_init();
2528 pars := f_init_pars(90);
2529 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2530 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2531 vc_conn.done;
2532 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2533}
2534
Harald Weltee13cfb22019-04-23 16:52:02 +02002535
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002536/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002537friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002538runs on BSC_ConnHdlr {
2539 var SmsParameters spars := valueof(t_SmsPars);
2540 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2541
2542 f_init_handler(pars);
2543
2544 /* We need to inspect GSUP activity */
2545 f_create_gsup_expect(hex2str(g_pars.imsi));
2546
2547 /* Perform location update */
2548 f_perform_lu();
2549
2550 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002551 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002552
2553 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2554 imsi := g_pars.imsi,
2555 /* NOTE: MSC should assign RP-MR itself */
2556 sm_rp_mr := ?,
2557 sm_rp_cause := sm_rp_cause
2558 );
2559
2560 /* Submit a MT SMS on GSUP */
2561 f_gsup_forwardSM_req(spars);
2562
2563 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002564 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002565 f_establish_fully(EST_TYPE_PAG_RESP);
2566
2567 /* Wait for MT SMS on DTAP */
2568 f_mt_sms_expect(spars);
2569
2570 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2571 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2572 alt {
2573 [] GSUP.receive(mt_forwardSM_err) {
2574 log("RX MT-forwardSM-Err (RP-ERROR)");
2575 setverdict(pass);
2576 mtc.stop;
2577 }
2578 [] GSUP.receive {
2579 log("RX unexpected GSUP message");
2580 setverdict(fail);
2581 mtc.stop;
2582 }
2583 }
2584
2585 f_expect_clear();
2586}
2587testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2588 var BSC_ConnHdlrPars pars;
2589 var BSC_ConnHdlr vc_conn;
2590 f_init();
2591 pars := f_init_pars(91);
2592 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2593 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2594 vc_conn.done;
2595 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2596}
2597
Harald Weltee13cfb22019-04-23 16:52:02 +02002598
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002599/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002600friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002601runs on BSC_ConnHdlr {
2602 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2603 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2604
2605 f_init_handler(pars);
2606
2607 /* We need to inspect GSUP activity */
2608 f_create_gsup_expect(hex2str(g_pars.imsi));
2609
2610 /* Perform location update */
2611 f_perform_lu();
2612
2613 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002614 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002615
2616 /* Submit the 1st MT SMS on GSUP */
2617 log("TX MT-forwardSM-Req for the 1st SMS");
2618 f_gsup_forwardSM_req(spars1);
2619
2620 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002621 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002622 f_establish_fully(EST_TYPE_PAG_RESP);
2623
2624 /* Wait for 1st MT SMS on DTAP */
2625 f_mt_sms_expect(spars1);
2626 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2627 ", SM-RP-MR is ", spars1.rp.msg_ref);
2628
2629 /* Submit the 2nd MT SMS on GSUP */
2630 log("TX MT-forwardSM-Req for the 2nd SMS");
2631 f_gsup_forwardSM_req(spars2);
2632
2633 /* Wait for 2nd MT SMS on DTAP */
2634 f_mt_sms_expect(spars2);
2635 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2636 ", SM-RP-MR is ", spars2.rp.msg_ref);
2637
2638 /* Both transaction IDs shall be different */
2639 if (spars1.tid == spars2.tid) {
2640 log("Both DTAP transaction IDs shall be different");
2641 setverdict(fail);
2642 }
2643
2644 /* Both SM-RP-MR values shall be different */
2645 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2646 log("Both SM-RP-MR values shall be different");
2647 setverdict(fail);
2648 }
2649
2650 /* Both SM-RP-MR values shall be assigned */
2651 if (spars1.rp.msg_ref == 'FF'O) {
2652 log("Unassigned SM-RP-MR value for the 1st SMS");
2653 setverdict(fail);
2654 }
2655 if (spars2.rp.msg_ref == 'FF'O) {
2656 log("Unassigned SM-RP-MR value for the 2nd SMS");
2657 setverdict(fail);
2658 }
2659
2660 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2661 f_mt_sms_send_rp_ack(spars1);
2662 alt {
2663 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2664 imsi := g_pars.imsi,
2665 sm_rp_mr := spars1.rp.msg_ref
2666 )) {
2667 log("RX MT-forwardSM-Res (RP-ACK)");
2668 setverdict(pass);
2669 }
2670 [] GSUP.receive {
2671 log("RX unexpected GSUP message");
2672 setverdict(fail);
2673 mtc.stop;
2674 }
2675 }
2676
2677 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2678 f_mt_sms_send_rp_ack(spars2);
2679 alt {
2680 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2681 imsi := g_pars.imsi,
2682 sm_rp_mr := spars2.rp.msg_ref
2683 )) {
2684 log("RX MT-forwardSM-Res (RP-ACK)");
2685 setverdict(pass);
2686 }
2687 [] GSUP.receive {
2688 log("RX unexpected GSUP message");
2689 setverdict(fail);
2690 mtc.stop;
2691 }
2692 }
2693
2694 f_expect_clear();
2695}
2696testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2697 var BSC_ConnHdlrPars pars;
2698 var BSC_ConnHdlr vc_conn;
2699 f_init();
2700 pars := f_init_pars(92);
2701 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2702 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2703 vc_conn.done;
2704 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2705}
2706
Harald Weltee13cfb22019-04-23 16:52:02 +02002707
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002708/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002709friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002710runs on BSC_ConnHdlr {
2711 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2712 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2713
2714 f_init_handler(pars);
2715
2716 /* We need to inspect GSUP activity */
2717 f_create_gsup_expect(hex2str(g_pars.imsi));
2718
2719 /* Perform location update */
2720 f_perform_lu();
2721
2722 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002723 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002724
2725 /* Send CM Service Request for MO SMMA */
2726 f_establish_fully(EST_TYPE_MO_SMS);
2727
2728 /* Submit MO SMMA on DTAP */
2729 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2730 spars_mo.rp.msg_ref := '00'O;
2731 f_mo_smma(spars_mo);
2732
2733 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2734 alt {
2735 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2736 imsi := g_pars.imsi,
2737 sm_rp_mr := spars_mo.rp.msg_ref,
2738 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2739 )) {
2740 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2741 setverdict(pass);
2742 }
2743 [] GSUP.receive {
2744 log("RX unexpected GSUP message");
2745 setverdict(fail);
2746 mtc.stop;
2747 }
2748 }
2749
2750 /* Submit MT SMS on GSUP */
2751 log("TX MT-forwardSM-Req for the MT SMS");
2752 f_gsup_forwardSM_req(spars_mt);
2753
2754 /* Wait for MT SMS on DTAP */
2755 f_mt_sms_expect(spars_mt);
2756 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2757 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2758
2759 /* Both SM-RP-MR values shall be different */
2760 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2761 log("Both SM-RP-MR values shall be different");
2762 setverdict(fail);
2763 }
2764
2765 /* SM-RP-MR value for MT SMS shall be assigned */
2766 if (spars_mt.rp.msg_ref == 'FF'O) {
2767 log("Unassigned SM-RP-MR value for the MT SMS");
2768 setverdict(fail);
2769 }
2770
2771 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2772 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2773 imsi := g_pars.imsi,
2774 sm_rp_mr := spars_mo.rp.msg_ref)));
2775 /* Expect RP-ACK for MO SMMA on DTAP */
2776 f_mo_sms_wait_rp_ack(spars_mo);
2777
2778 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2779 f_mt_sms_send_rp_ack(spars_mt);
2780 alt {
2781 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2782 imsi := g_pars.imsi,
2783 sm_rp_mr := spars_mt.rp.msg_ref
2784 )) {
2785 log("RX MT-forwardSM-Res (RP-ACK)");
2786 setverdict(pass);
2787 }
2788 [] GSUP.receive {
2789 log("RX unexpected GSUP message");
2790 setverdict(fail);
2791 mtc.stop;
2792 }
2793 }
2794
2795 f_expect_clear();
2796}
2797testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
2798 var BSC_ConnHdlrPars pars;
2799 var BSC_ConnHdlr vc_conn;
2800 f_init();
2801 pars := f_init_pars(93);
2802 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2803 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
2804 vc_conn.done;
2805 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2806}
2807
Harald Weltee13cfb22019-04-23 16:52:02 +02002808
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002809/* Test multi-part MT-SMS over GSUP */
2810private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
2811runs on BSC_ConnHdlr {
2812 var SmsParameters spars := valueof(t_SmsPars);
2813
2814 f_init_handler(pars);
2815
2816 /* We need to inspect GSUP activity */
2817 f_create_gsup_expect(hex2str(g_pars.imsi));
2818
2819 /* Perform location update */
2820 f_perform_lu();
2821
2822 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002823 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002824
2825 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2826 imsi := g_pars.imsi,
2827 /* NOTE: MSC should assign RP-MR itself */
2828 sm_rp_mr := ?
2829 );
2830
2831 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
2832 for (var integer i := 3; i >= 0; i := i-1) {
2833 /* Submit a MT SMS on GSUP (MMS is decremented) */
2834 f_gsup_forwardSM_req(spars, int2oct(i, 1));
2835
2836 /* Expect Paging Request and Establish connection */
2837 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02002838 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002839 f_establish_fully(EST_TYPE_PAG_RESP);
2840 }
2841
2842 /* Wait for MT SMS on DTAP */
2843 f_mt_sms_expect(spars);
2844
2845 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2846 f_mt_sms_send_rp_ack(spars);
2847 alt {
2848 [] GSUP.receive(mt_forwardSM_res) {
2849 log("RX MT-forwardSM-Res (RP-ACK)");
2850 setverdict(pass);
2851 }
2852 [] GSUP.receive {
2853 log("RX unexpected GSUP message");
2854 setverdict(fail);
2855 mtc.stop;
2856 }
2857 }
2858
2859 /* Keep some 'distance' between transmissions */
2860 f_sleep(1.5);
2861 }
2862
2863 f_expect_clear();
2864}
2865testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
2866 var BSC_ConnHdlrPars pars;
2867 var BSC_ConnHdlr vc_conn;
2868 f_init();
2869 pars := f_init_pars(91);
2870 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2871 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
2872 vc_conn.done;
2873 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2874}
2875
Harald Weltef640a012018-04-14 17:49:21 +02002876/* convert GSM L3 TON to SMPP_TON enum */
2877function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
2878 select (ton) {
2879 case ('000'B) { return unknown; }
2880 case ('001'B) { return international; }
2881 case ('010'B) { return national; }
2882 case ('011'B) { return network_specific; }
2883 case ('100'B) { return subscriber_number; }
2884 case ('101'B) { return alphanumeric; }
2885 case ('110'B) { return abbreviated; }
2886 }
2887 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02002888 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002889}
2890/* convert GSM L3 NPI to SMPP_NPI enum */
2891function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2892 select (npi) {
2893 case ('0000'B) { return unknown; }
2894 case ('0001'B) { return isdn; }
2895 case ('0011'B) { return data; }
2896 case ('0100'B) { return telex; }
2897 case ('0110'B) { return land_mobile; }
2898 case ('1000'B) { return national; }
2899 case ('1001'B) { return private_; }
2900 case ('1010'B) { return ermes; }
2901 }
2902 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02002903 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002904}
2905
2906/* build a SMPP_SM from SmsParameters */
2907function f_mt_sm_from_spars(SmsParameters spars)
2908runs on BSC_ConnHdlr return SMPP_SM {
2909 var SMPP_SM sm := {
2910 service_type := "CMT",
2911 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2912 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2913 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2914 dest_addr_ton := international,
2915 dest_addr_npi := isdn,
2916 destination_addr := hex2str(g_pars.msisdn),
2917 esm_class := '00000001'B,
2918 protocol_id := 0,
2919 priority_flag := 0,
2920 schedule_delivery_time := "",
2921 validity_period := "",
2922 registered_delivery := '00000000'B,
2923 replace_if_present := 0,
2924 data_coding := '00000001'B,
2925 sm_default_msg_id := 0,
2926 sm_length := spars.tp.udl,
2927 short_message := spars.tp.ud,
2928 opt_pars := {}
2929 };
2930 return sm;
2931}
2932
2933/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2934private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2935 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2936 if (trans_mode) {
2937 sm.esm_class := '00000010'B;
2938 }
2939
2940 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2941 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2942 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2943 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2944 * before we expect the SMS delivery on the BSC/radio side */
2945 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2946 }
2947
2948 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002949 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02002950 /* Establish DTAP / BSSAP / SCCP connection */
2951 f_establish_fully(EST_TYPE_PAG_RESP);
2952 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2953
2954 f_mt_sms(spars);
2955
2956 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2957 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2958 }
2959 f_expect_clear();
2960}
2961
2962/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2963private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2964 f_init_handler(pars);
2965
2966 /* Perform location update so IMSI is known + registered in MSC/VLR */
2967 f_perform_lu();
2968 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2969
2970 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002971 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02002972
2973 var SmsParameters spars := valueof(t_SmsPars);
2974 /* TODO: test with more intelligent user data; test different coding schemes */
2975 spars.tp.ud := '00'O;
2976 spars.tp.udl := 1;
2977
2978 /* first test the non-transaction store+forward mode */
2979 f_smpp_mt_sms(spars, false);
2980
2981 /* then test the transaction mode */
2982 f_smpp_mt_sms(spars, true);
2983}
2984testcase TC_smpp_mt_sms() runs on MTC_CT {
2985 var BSC_ConnHdlr vc_conn;
2986 f_init();
2987 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
2988 vc_conn.done;
2989}
2990
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002991/***********************************************************************
2992 * USSD Testing
2993 ***********************************************************************/
2994
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002995private altstep as_unexp_gsup_or_bssap_msg()
2996runs on BSC_ConnHdlr {
2997 [] GSUP.receive {
2998 setverdict(fail, "Unknown/unexpected GSUP received");
2999 self.stop;
3000 }
3001 [] BSSAP.receive {
3002 setverdict(fail, "Unknown/unexpected BSSAP message received");
3003 self.stop;
3004 }
3005}
3006
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003007private function f_expect_gsup_msg(template GSUP_PDU msg,
3008 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003009runs on BSC_ConnHdlr return GSUP_PDU {
3010 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003011 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003012
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003013 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003014 alt {
3015 [] GSUP.receive(msg) -> value gsup_msg_complete {
3016 setverdict(pass);
3017 }
3018 /* We don't expect anything else */
3019 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003020 [] T.timeout {
3021 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3022 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003023 }
3024
3025 return gsup_msg_complete;
3026}
3027
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003028private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3029 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003030runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3031 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003032 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003033
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003034 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003035 alt {
3036 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3037 setverdict(pass);
3038 }
3039 /* We don't expect anything else */
3040 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003041 [] T.timeout {
3042 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3043 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003044 }
3045
3046 return bssap_msg_complete.dtap;
3047}
3048
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003049/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003050friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003051runs on BSC_ConnHdlr {
3052 f_init_handler(pars);
3053
3054 /* Perform location update */
3055 f_perform_lu();
3056
3057 /* Send CM Service Request for SS/USSD */
3058 f_establish_fully(EST_TYPE_SS_ACT);
3059
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003060 /* We need to inspect GSUP activity */
3061 f_create_gsup_expect(hex2str(g_pars.imsi));
3062
3063 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3064 invoke_id := 5, /* Phone may not start from 0 or 1 */
3065 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3066 ussd_string := "*#100#"
3067 );
3068
3069 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3070 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3071 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3072 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3073 )
3074
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003075 /* Compose a new SS/REGISTER message with request */
3076 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3077 tid := 1, /* We just need a single transaction */
3078 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003079 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003080 );
3081
3082 /* Compose SS/RELEASE_COMPLETE template with expected response */
3083 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3084 tid := 1, /* Response should arrive within the same transaction */
3085 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003086 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003087 );
3088
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003089 /* Compose expected MSC -> HLR message */
3090 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3091 imsi := g_pars.imsi,
3092 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3093 ss := valueof(facility_req)
3094 );
3095
3096 /* To be used for sending response with correct session ID */
3097 var GSUP_PDU gsup_req_complete;
3098
3099 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003100 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003101 /* Expect GSUP message containing the SS payload */
3102 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3103
3104 /* Compose the response from HLR using received session ID */
3105 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3106 imsi := g_pars.imsi,
3107 sid := gsup_req_complete.ies[1].val.session_id,
3108 state := OSMO_GSUP_SESSION_STATE_END,
3109 ss := valueof(facility_rsp)
3110 );
3111
3112 /* Finally, HLR terminates the session */
3113 GSUP.send(gsup_rsp);
3114 /* Expect RELEASE_COMPLETE message with the response */
3115 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003116
3117 f_expect_clear();
3118}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003119testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003120 var BSC_ConnHdlr vc_conn;
3121 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003122 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003123 vc_conn.done;
3124}
3125
Harald Weltee13cfb22019-04-23 16:52:02 +02003126
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003127/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003128friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003129runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003130 timer T := 5.0;
3131
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003132 f_init_handler(pars);
3133
3134 /* Perform location update */
3135 f_perform_lu();
3136
Harald Welte6811d102019-04-14 22:23:14 +02003137 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003138
3139 /* We need to inspect GSUP activity */
3140 f_create_gsup_expect(hex2str(g_pars.imsi));
3141
3142 /* Facility IE with network-originated USSD notification */
3143 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3144 op_code := SS_OP_CODE_USS_NOTIFY,
3145 ussd_string := "Mahlzeit!"
3146 );
3147
3148 /* Facility IE with acknowledgment to the USSD notification */
3149 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3150 /* In case of USSD notification, Return Result is empty */
3151 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3152 );
3153
3154 /* Compose a new MT SS/REGISTER message with USSD notification */
3155 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3156 tid := 0, /* FIXME: most likely, it should be 0 */
3157 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3158 facility := valueof(facility_req)
3159 );
3160
3161 /* Compose HLR -> MSC GSUP message */
3162 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3163 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003164 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003165 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3166 ss := valueof(facility_req)
3167 );
3168
3169 /* Send it to MSC and expect Paging Request */
3170 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003171 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003172 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003173 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3174 setverdict(pass);
3175 }
Harald Welte62113fc2019-05-09 13:04:02 +02003176 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003177 setverdict(pass);
3178 }
3179 /* We don't expect anything else */
3180 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003181 [] T.timeout {
3182 setverdict(fail, "Timeout waiting for Paging Request");
3183 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003184 }
3185
3186 /* Send Paging Response and expect USSD notification */
3187 f_establish_fully(EST_TYPE_PAG_RESP);
3188 /* Expect MT REGISTER message with USSD notification */
3189 f_expect_mt_dtap_msg(ussd_ntf);
3190
3191 /* Compose a new MO SS/FACILITY message with empty response */
3192 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3193 tid := 0, /* FIXME: it shall match the request tid */
3194 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3195 facility := valueof(facility_rsp)
3196 );
3197
3198 /* Compose expected MSC -> HLR GSUP message */
3199 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3200 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003201 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003202 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3203 ss := valueof(facility_rsp)
3204 );
3205
3206 /* MS sends response to the notification */
3207 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3208 /* Expect GSUP message containing the SS payload */
3209 f_expect_gsup_msg(gsup_rsp);
3210
3211 /* Compose expected MT SS/RELEASE COMPLETE message */
3212 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3213 tid := 0, /* FIXME: it shall match the request tid */
3214 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3215 facility := omit
3216 );
3217
3218 /* Compose MSC -> HLR GSUP message */
3219 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3220 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003221 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003222 state := OSMO_GSUP_SESSION_STATE_END
3223 );
3224
3225 /* Finally, HLR terminates the session */
3226 GSUP.send(gsup_term)
3227 /* Expect MT RELEASE COMPLETE without Facility IE */
3228 f_expect_mt_dtap_msg(ussd_term);
3229
3230 f_expect_clear();
3231}
3232testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3233 var BSC_ConnHdlr vc_conn;
3234 f_init();
3235 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3236 vc_conn.done;
3237}
3238
Harald Weltee13cfb22019-04-23 16:52:02 +02003239
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003240/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003241friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003242runs on BSC_ConnHdlr {
3243 f_init_handler(pars);
3244
3245 /* Call parameters taken from f_tc_lu_and_mt_call */
3246 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003247
3248 /* Perform location update */
3249 f_perform_lu();
3250
3251 /* Establish a MT call */
3252 f_mt_call_establish(cpars);
3253
3254 /* Hold the call for some time */
3255 f_sleep(1.0);
3256
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003257 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3258 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3259 ussd_string := "*#100#"
3260 );
3261
3262 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3263 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3264 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3265 )
3266
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003267 /* Compose a new SS/REGISTER message with request */
3268 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3269 tid := 1, /* We just need a single transaction */
3270 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003271 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003272 );
3273
3274 /* Compose SS/RELEASE_COMPLETE template with expected response */
3275 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3276 tid := 1, /* Response should arrive within the same transaction */
3277 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003278 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003279 );
3280
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003281 /* Compose expected MSC -> HLR message */
3282 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3283 imsi := g_pars.imsi,
3284 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3285 ss := valueof(facility_req)
3286 );
3287
3288 /* To be used for sending response with correct session ID */
3289 var GSUP_PDU gsup_req_complete;
3290
3291 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003292 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003293 /* Expect GSUP message containing the SS payload */
3294 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3295
3296 /* Compose the response from HLR using received session ID */
3297 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3298 imsi := g_pars.imsi,
3299 sid := gsup_req_complete.ies[1].val.session_id,
3300 state := OSMO_GSUP_SESSION_STATE_END,
3301 ss := valueof(facility_rsp)
3302 );
3303
3304 /* Finally, HLR terminates the session */
3305 GSUP.send(gsup_rsp);
3306 /* Expect RELEASE_COMPLETE message with the response */
3307 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003308
3309 /* Hold the call for some time */
3310 f_sleep(1.0);
3311
3312 /* Release the call (does Clear Complete itself) */
3313 f_call_hangup(cpars, true);
3314}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003315testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003316 var BSC_ConnHdlr vc_conn;
3317 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003318 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003319 vc_conn.done;
3320}
3321
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003322/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003323friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003324 f_init_handler(pars);
3325 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003326 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003327
3328 f_perform_lu();
3329
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003330 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003331 f_mo_call_establish(cpars);
3332 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003333 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003334
3335 f_sleep(1.0);
3336}
3337testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3338 var BSC_ConnHdlr vc_conn;
3339 f_init();
3340
3341 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3342 vc_conn.done;
3343}
3344
Harald Weltee13cfb22019-04-23 16:52:02 +02003345
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003346/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003347friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003348runs on BSC_ConnHdlr {
3349 f_init_handler(pars);
3350
3351 /* Call parameters taken from f_tc_lu_and_mt_call */
3352 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003353
3354 /* Perform location update */
3355 f_perform_lu();
3356
3357 /* Establish a MT call */
3358 f_mt_call_establish(cpars);
3359
3360 /* Hold the call for some time */
3361 f_sleep(1.0);
3362
3363 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3364 op_code := SS_OP_CODE_USS_REQUEST,
3365 ussd_string := "Please type anything..."
3366 );
3367
3368 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3369 op_code := SS_OP_CODE_USS_REQUEST,
3370 ussd_string := "Nope."
3371 )
3372
3373 /* Compose MT SS/REGISTER message with network-originated request */
3374 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3375 tid := 0, /* FIXME: most likely, it should be 0 */
3376 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3377 facility := valueof(facility_req)
3378 );
3379
3380 /* Compose HLR -> MSC GSUP message */
3381 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3382 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003383 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003384 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3385 ss := valueof(facility_req)
3386 );
3387
3388 /* Send it to MSC */
3389 GSUP.send(gsup_req);
3390 /* Expect MT REGISTER message with USSD request */
3391 f_expect_mt_dtap_msg(ussd_req);
3392
3393 /* Compose a new MO SS/FACILITY message with response */
3394 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3395 tid := 0, /* FIXME: it shall match the request tid */
3396 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3397 facility := valueof(facility_rsp)
3398 );
3399
3400 /* Compose expected MSC -> HLR GSUP message */
3401 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3402 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003403 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003404 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3405 ss := valueof(facility_rsp)
3406 );
3407
3408 /* MS sends response */
3409 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3410 f_expect_gsup_msg(gsup_rsp);
3411
3412 /* Compose expected MT SS/RELEASE COMPLETE message */
3413 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3414 tid := 0, /* FIXME: it shall match the request tid */
3415 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3416 facility := omit
3417 );
3418
3419 /* Compose MSC -> HLR GSUP message */
3420 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3421 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003422 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003423 state := OSMO_GSUP_SESSION_STATE_END
3424 );
3425
3426 /* Finally, HLR terminates the session */
3427 GSUP.send(gsup_term);
3428 /* Expect MT RELEASE COMPLETE without Facility IE */
3429 f_expect_mt_dtap_msg(ussd_term);
3430
3431 /* Hold the call for some time */
3432 f_sleep(1.0);
3433
3434 /* Release the call (does Clear Complete itself) */
3435 f_call_hangup(cpars, true);
3436}
3437testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3438 var BSC_ConnHdlr vc_conn;
3439 f_init();
3440 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3441 vc_conn.done;
3442}
3443
Harald Weltee13cfb22019-04-23 16:52:02 +02003444
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003445/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003446friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003447runs on BSC_ConnHdlr {
3448 f_init_handler(pars);
3449
3450 /* Perform location update */
3451 f_perform_lu();
3452
3453 /* Send CM Service Request for SS/USSD */
3454 f_establish_fully(EST_TYPE_SS_ACT);
3455
3456 /* We need to inspect GSUP activity */
3457 f_create_gsup_expect(hex2str(g_pars.imsi));
3458
3459 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3460 invoke_id := 1, /* Initial request */
3461 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3462 ussd_string := "*6766*266#"
3463 );
3464
3465 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3466 invoke_id := 2, /* Counter request */
3467 op_code := SS_OP_CODE_USS_REQUEST,
3468 ussd_string := "Password?!?"
3469 )
3470
3471 /* Compose MO SS/REGISTER message with request */
3472 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3473 tid := 1, /* We just need a single transaction */
3474 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3475 facility := valueof(facility_ms_req)
3476 );
3477
3478 /* Compose expected MSC -> HLR message */
3479 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3480 imsi := g_pars.imsi,
3481 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3482 ss := valueof(facility_ms_req)
3483 );
3484
3485 /* To be used for sending response with correct session ID */
3486 var GSUP_PDU gsup_ms_req_complete;
3487
3488 /* Initiate a new transaction */
3489 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3490 /* Expect GSUP request with original Facility IE */
3491 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3492
3493 /* Compose the response from HLR using received session ID */
3494 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3495 imsi := g_pars.imsi,
3496 sid := gsup_ms_req_complete.ies[1].val.session_id,
3497 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3498 ss := valueof(facility_net_req)
3499 );
3500
3501 /* Compose expected MT SS/FACILITY template with counter request */
3502 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3503 tid := 1, /* Response should arrive within the same transaction */
3504 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3505 facility := valueof(facility_net_req)
3506 );
3507
3508 /* Send response over GSUP */
3509 GSUP.send(gsup_net_req);
3510 /* Expect MT SS/FACILITY message with counter request */
3511 f_expect_mt_dtap_msg(ussd_net_req);
3512
3513 /* Compose MO SS/RELEASE COMPLETE */
3514 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3515 tid := 1, /* Response should arrive within the same transaction */
3516 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3517 facility := omit
3518 /* TODO: cause? */
3519 );
3520
3521 /* Compose expected HLR -> MSC abort message */
3522 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3523 imsi := g_pars.imsi,
3524 sid := gsup_ms_req_complete.ies[1].val.session_id,
3525 state := OSMO_GSUP_SESSION_STATE_END
3526 );
3527
3528 /* Abort transaction */
3529 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3530 /* Expect GSUP message indicating abort */
3531 f_expect_gsup_msg(gsup_abort);
3532
3533 f_expect_clear();
3534}
3535testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3536 var BSC_ConnHdlr vc_conn;
3537 f_init();
3538 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3539 vc_conn.done;
3540}
3541
Harald Weltee13cfb22019-04-23 16:52:02 +02003542
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003543/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003544friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003545runs on BSC_ConnHdlr {
3546 f_init_handler(pars);
3547
3548 /* Perform location update */
3549 f_perform_lu();
3550
3551 /* Send CM Service Request for SS/USSD */
3552 f_establish_fully(EST_TYPE_SS_ACT);
3553
3554 /* We need to inspect GSUP activity */
3555 f_create_gsup_expect(hex2str(g_pars.imsi));
3556
3557 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3558 invoke_id := 1,
3559 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3560 ussd_string := "#release_me");
3561
3562 /* Compose MO SS/REGISTER message with request */
3563 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3564 tid := 1, /* An arbitrary transaction identifier */
3565 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3566 facility := valueof(facility_ms_req));
3567
3568 /* Compose expected MSC -> HLR message */
3569 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3570 imsi := g_pars.imsi,
3571 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3572 ss := valueof(facility_ms_req));
3573
3574 /* To be used for sending response with correct session ID */
3575 var GSUP_PDU gsup_ms_req_complete;
3576
3577 /* Initiate a new SS transaction */
3578 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3579 /* Expect GSUP request with original Facility IE */
3580 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3581
3582 /* Don't respond, wait for timeout */
3583 f_sleep(3.0);
3584
3585 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3586 tid := 1, /* Should match the request's tid */
3587 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3588 cause := *, /* TODO: expect some specific value */
3589 facility := omit);
3590
3591 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3592 imsi := g_pars.imsi,
3593 sid := gsup_ms_req_complete.ies[1].val.session_id,
3594 state := OSMO_GSUP_SESSION_STATE_END,
3595 cause := ?); /* TODO: expect some specific value */
3596
3597 /* Expect release on both interfaces */
3598 interleave {
3599 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3600 [] GSUP.receive(gsup_rel) { };
3601 }
3602
3603 f_expect_clear();
3604 setverdict(pass);
3605}
3606testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3607 var BSC_ConnHdlr vc_conn;
3608 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003609 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003610 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3611 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003612 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003613}
3614
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003615/* MT (network-originated) USSD for unknown subscriber */
3616friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
3617runs on BSC_ConnHdlr {
3618 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
3619 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003620
3621 f_init_handler(pars);
3622 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
3623 f_create_gsup_expect(hex2str(imsi));
3624
3625 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3626 imsi := imsi,
3627 sid := sid,
3628 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3629 ss := f_rnd_octstring(23)
3630 );
3631
3632 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
3633 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3634 imsi := imsi,
3635 sid := sid,
3636 state := OSMO_GSUP_SESSION_STATE_END,
3637 cause := 2 /* FIXME: introduce an enumerated type! */
3638 );
3639
3640 /* Initiate a MT USSD notification */
3641 GSUP.send(gsup_req);
3642
3643 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07003644 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003645}
3646testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
3647 var BSC_ConnHdlr vc_conn;
3648 f_init();
3649 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
3650 vc_conn.done;
3651}
3652
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003653/* MO (mobile-originated) SS/USSD for unknown transaction */
3654friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
3655runs on BSC_ConnHdlr {
3656 f_init_handler(pars);
3657
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003658 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003659 f_create_gsup_expect(hex2str(g_pars.imsi));
3660
3661 /* Perform location update */
3662 f_perform_lu();
3663
3664 /* Send CM Service Request for SS/USSD */
3665 f_establish_fully(EST_TYPE_SS_ACT);
3666
3667 /* GSM 04.80 FACILITY message for a non-existing transaction */
3668 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
3669 tid := 1, /* An arbitrary transaction identifier */
3670 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3671 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3672 );
3673
3674 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
3675 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
3676 tid := 1, /* An arbitrary transaction identifier */
3677 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3678 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3679 );
3680
3681 /* Expected response from the network */
3682 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3683 tid := 1, /* Same as in the FACILITY message */
3684 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3685 facility := omit
3686 );
3687
3688 /* Send GSM 04.80 FACILITY for non-existing transaction */
3689 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
3690
3691 /* Expect GSM 04.80 RELEASE COMPLETE message */
3692 f_expect_mt_dtap_msg(mt_ss_rel);
3693 f_expect_clear();
3694
3695 /* Send another CM Service Request for SS/USSD */
3696 f_establish_fully(EST_TYPE_SS_ACT);
3697
3698 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
3699 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
3700
3701 /* Expect GSM 04.80 RELEASE COMPLETE message */
3702 f_expect_mt_dtap_msg(mt_ss_rel);
3703 f_expect_clear();
3704}
3705testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
3706 var BSC_ConnHdlr vc_conn;
3707 f_init();
3708 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
3709 vc_conn.done;
3710}
3711
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003712/* MT (network-originated) USSD for unknown session */
3713friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
3714runs on BSC_ConnHdlr {
3715 var OCT4 sid := '20000333'O;
3716
3717 f_init_handler(pars);
3718
3719 /* Perform location update */
3720 f_perform_lu();
3721
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003722 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003723 f_create_gsup_expect(hex2str(g_pars.imsi));
3724
3725 /* Request referencing a non-existing SS session */
3726 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3727 imsi := g_pars.imsi,
3728 sid := sid,
3729 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3730 ss := f_rnd_octstring(23)
3731 );
3732
3733 /* Error with some cause value */
3734 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3735 imsi := g_pars.imsi,
3736 sid := sid,
3737 state := OSMO_GSUP_SESSION_STATE_END,
3738 cause := ? /* FIXME: introduce an enumerated type! */
3739 );
3740
3741 /* Initiate a MT USSD notification */
3742 GSUP.send(gsup_req);
3743
3744 /* Expect GSUP PROC_SS_ERROR message */
3745 f_expect_gsup_msg(gsup_rsp);
3746}
3747testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
3748 var BSC_ConnHdlr vc_conn;
3749 f_init();
3750 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
3751 vc_conn.done;
3752}
3753
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003754/* MT (network-originated) USSD and no response to Paging Request */
3755friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
3756runs on BSC_ConnHdlr {
3757 timer TP := 2.0; /* Paging timer */
3758
3759 f_init_handler(pars);
3760
3761 /* Perform location update */
3762 f_perform_lu();
3763
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003764 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003765 f_create_gsup_expect(hex2str(g_pars.imsi));
3766
3767 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3768 imsi := g_pars.imsi,
3769 sid := '20000444'O,
3770 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3771 ss := f_rnd_octstring(23)
3772 );
3773
3774 /* Error with some cause value */
3775 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3776 imsi := g_pars.imsi,
3777 sid := '20000444'O,
3778 state := OSMO_GSUP_SESSION_STATE_END,
3779 cause := ? /* FIXME: introduce an enumerated type! */
3780 );
3781
3782 /* Initiate a MT USSD notification */
3783 GSUP.send(gsup_req);
3784
3785 /* Send it to MSC and expect Paging Request */
3786 TP.start;
3787 alt {
3788 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3789 setverdict(pass);
3790 }
3791 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
3792 setverdict(pass);
3793 }
3794 /* We don't expect anything else */
3795 [] as_unexp_gsup_or_bssap_msg();
3796 [] TP.timeout {
3797 setverdict(fail, "Timeout waiting for Paging Request");
3798 }
3799 }
3800
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07003801 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
3802 * OsmoMSC waits for Paging Response 10 seconds by default. */
3803 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003804}
3805testcase TC_proc_ss_paging_fail() runs on MTC_CT {
3806 var BSC_ConnHdlr vc_conn;
3807 f_init();
3808 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
3809 vc_conn.done;
3810}
3811
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07003812/* MT (network-originated) USSD followed by immediate abort */
3813friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
3814runs on BSC_ConnHdlr {
3815 var octetstring facility := f_rnd_octstring(23);
3816 var OCT4 sid := '20000555'O;
3817 timer TP := 2.0;
3818
3819 f_init_handler(pars);
3820
3821 /* Perform location update */
3822 f_perform_lu();
3823
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003824 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07003825 f_create_gsup_expect(hex2str(g_pars.imsi));
3826
3827 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
3828 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3829 imsi := g_pars.imsi, sid := sid,
3830 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3831 ss := facility
3832 );
3833
3834 /* On the MS side, we expect GSM 04.80 REGISTER message */
3835 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
3836 tid := 0, /* Most likely, it should be 0 */
3837 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3838 facility := facility
3839 );
3840
3841 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
3842 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
3843 imsi := g_pars.imsi, sid := sid,
3844 state := OSMO_GSUP_SESSION_STATE_END,
3845 cause := 0 /* FIXME: introduce an enumerated type! */
3846 );
3847
3848 /* On the MS side, we expect GSM 04.80 REGISTER message */
3849 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3850 tid := 0, /* Most likely, it should be 0 */
3851 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3852 cause := *, /* FIXME: expect some specific cause value */
3853 facility := omit
3854 );
3855
3856 /* Initiate a MT USSD with random payload */
3857 GSUP.send(gsup_req);
3858
3859 /* Expect Paging Request */
3860 TP.start;
3861 alt {
3862 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3863 setverdict(pass);
3864 }
3865 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
3866 setverdict(pass);
3867 }
3868 /* We don't expect anything else */
3869 [] as_unexp_gsup_or_bssap_msg();
3870 [] TP.timeout {
3871 setverdict(fail, "Timeout waiting for Paging Request");
3872 }
3873 }
3874
3875 /* Send Paging Response and establish connection */
3876 f_establish_fully(EST_TYPE_PAG_RESP);
3877 /* Expect MT REGISTER message with random facility */
3878 f_expect_mt_dtap_msg(dtap_reg);
3879
3880 /* HLR/EUSE decides to abort the session even
3881 * before getting any response from the MS */
3882 /* Initiate a MT USSD with random payload */
3883 GSUP.send(gsup_abort);
3884
3885 /* Expect RELEASE COMPLETE on ths MS side */
3886 f_expect_mt_dtap_msg(dtap_rel);
3887
3888 f_expect_clear();
3889}
3890testcase TC_proc_ss_abort() runs on MTC_CT {
3891 var BSC_ConnHdlr vc_conn;
3892 f_init();
3893 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
3894 vc_conn.done;
3895}
3896
Harald Weltee13cfb22019-04-23 16:52:02 +02003897
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01003898/* Verify multiple concurrent MO SS/USSD transactions
3899 * (one subscriber - one transaction) */
3900testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
3901 var BSC_ConnHdlr vc_conn[16];
3902 var integer i;
3903
3904 f_init();
3905
3906 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3907 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
3908 }
3909
3910 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3911 vc_conn[i].done;
3912 }
3913}
3914
3915/* Verify multiple concurrent MT SS/USSD transactions
3916 * (one subscriber - one transaction) */
3917testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
3918 var BSC_ConnHdlr vc_conn[16];
3919 var integer i;
3920 var OCT4 sid;
3921
3922 f_init();
3923
3924 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3925 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
3926 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
3927 f_init_pars(226 + i, gsup_sid := sid));
3928 }
3929
3930 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3931 vc_conn[i].done;
3932 }
3933}
3934
3935
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003936/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
3937private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3938 pars.net.expect_auth := true;
3939 pars.net.expect_ciph := true;
3940 pars.net.kc_support := '02'O; /* A5/1 only */
3941 f_init_handler(pars);
3942
3943 g_pars.vec := f_gen_auth_vec_2g();
3944
3945 /* Can't use f_perform_lu() directly. Code below is based on it. */
3946
3947 /* tell GSUP dispatcher to send this IMSI to us */
3948 f_create_gsup_expect(hex2str(g_pars.imsi));
3949
3950 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3951 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02003952 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003953
3954 f_mm_auth();
3955
3956 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3957 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3958 alt {
3959 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3960 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
3961 }
3962 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3963 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3964 mtc.stop;
3965 }
3966 [] BSSAP.receive {
3967 setverdict(fail, "Unknown/unexpected BSSAP received");
3968 mtc.stop;
3969 }
3970 }
3971
3972 /* Expect LU reject from MSC. */
3973 alt {
3974 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3975 setverdict(pass);
3976 }
3977 [] BSSAP.receive {
3978 setverdict(fail, "Unknown/unexpected BSSAP received");
3979 mtc.stop;
3980 }
3981 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01003982 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003983}
3984
3985testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
3986 var BSC_ConnHdlr vc_conn;
3987 f_init();
3988 f_vty_config(MSCVTY, "network", "encryption a5 1");
3989
3990 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52);
3991 vc_conn.done;
3992}
3993
Harald Welteb2284bd2019-05-10 11:30:43 +02003994/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
3995friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3996 f_init_handler(pars);
3997
3998 /* tell GSUP dispatcher to send this IMSI to us */
3999 f_create_gsup_expect(hex2str(g_pars.imsi));
4000
4001 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4002 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4003
4004 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4005 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4006 f_cl3_or_initial_ue(l3_lu);
4007
4008 /* Expect LU reject from MSC. */
4009 alt {
4010 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4011 setverdict(pass);
4012 }
4013 [] BSSAP.receive {
4014 setverdict(fail, "Unknown/unexpected BSSAP received");
4015 mtc.stop;
4016 }
4017 }
4018 f_expect_clear();
4019}
4020testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4021 var BSC_ConnHdlr vc_conn;
4022 f_init();
4023 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4024 vc_conn.done;
4025}
4026
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004027private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4028 pars.net.expect_auth := true;
4029 pars.net.expect_ciph := true;
4030 pars.net.kc_support := kc_support;
4031 f_init_handler(pars);
4032
4033 g_pars.vec := f_gen_auth_vec_2g();
4034
4035 /* Can't use f_perform_lu() directly. Code below is based on it. */
4036
4037 /* tell GSUP dispatcher to send this IMSI to us */
4038 f_create_gsup_expect(hex2str(g_pars.imsi));
4039
4040 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4041 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4042 f_cl3_or_initial_ue(l3_lu);
4043
4044 f_mm_auth();
4045
4046 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4047 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4048 alt {
4049 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4050 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4051 }
4052 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4053 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4054 repeat;
4055 }
4056 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4057 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4058 mtc.stop;
4059 }
4060 [] BSSAP.receive {
4061 setverdict(fail, "Unknown/unexpected BSSAP received");
4062 mtc.stop;
4063 }
4064 }
4065
4066 /* TODO: Verify MSC is using the best cipher available! How? */
4067
4068 f_msc_lu_hlr();
4069 f_accept_reject_lu();
4070 f_expect_clear();
4071 setverdict(pass);
4072}
4073
4074/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4075private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4076 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4077}
4078
4079/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4080private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4081 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4082}
4083
4084/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4085private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4086 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4087}
4088
4089testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4090 var BSC_ConnHdlr vc_conn;
4091 f_init();
4092 f_vty_config(MSCVTY, "network", "encryption a5 1");
4093
4094 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4095 vc_conn.done;
4096}
4097
4098testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4099 var BSC_ConnHdlr vc_conn;
4100 f_init();
4101 f_vty_config(MSCVTY, "network", "encryption a5 3");
4102
4103 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4104 vc_conn.done;
4105}
4106
4107testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4108 var BSC_ConnHdlr vc_conn;
4109 f_init();
4110 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4111
4112 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4113 vc_conn.done;
4114}
Harald Welteb2284bd2019-05-10 11:30:43 +02004115
Harald Weltef640a012018-04-14 17:49:21 +02004116/* TODO (SMS):
4117 * different user data lengths
4118 * SMPP transaction mode with unsuccessful delivery
4119 * queued MT-SMS with no paging response + later delivery
4120 * different data coding schemes
4121 * multi-part SMS
4122 * user-data headers
4123 * TP-PID for SMS to SIM
4124 * behavior if SMS memory is full + RP-SMMA
4125 * delivery reports
4126 * SMPP osmocom extensions
4127 * more-messages-to-send
4128 * SMS during ongoing call (SACCH/SAPI3)
4129 */
4130
4131/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004132 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4133 * malformed messages (missing IE, invalid message type): properly rejected?
4134 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4135 * 3G/2G auth permutations
4136 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004137 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004138 * too long L3 INFO in DTAP
4139 * too long / padded BSSAP
4140 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004141 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004142
Harald Weltee13cfb22019-04-23 16:52:02 +02004143/***********************************************************************
4144 * SGsAP Testing
4145 ***********************************************************************/
4146
Philipp Maier948747b2019-04-02 15:22:33 +02004147/* Check if a subscriber exists in the VLR */
4148private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4149
4150 var CtrlValue active_subsribers;
4151 var integer rc;
4152 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4153
4154 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4155 if (rc < 0) {
4156 return false;
4157 }
4158
4159 return true;
4160}
4161
Harald Welte4263c522018-12-06 11:56:27 +01004162/* Perform a location updatye at the A-Interface and run some checks to confirm
4163 * that everything is back to normal. */
4164private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4165 var SmsParameters spars := valueof(t_SmsPars);
4166
4167 /* Perform a location update, the SGs association is expected to fall
4168 * back to NULL */
4169 f_perform_lu();
4170 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4171
4172 /* Trigger a paging request and expect the paging on BSSMAP, this is
4173 * to make sure that pagings are sent throught the A-Interface again
4174 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004175 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004176 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4177
4178 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004179 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4180 setverdict(pass);
4181 }
Harald Welte62113fc2019-05-09 13:04:02 +02004182 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004183 setverdict(pass);
4184 }
4185 [] SGsAP.receive {
4186 setverdict(fail, "Received unexpected message on SGs");
4187 }
4188 }
4189
4190 /* Send an SMS to make sure that also payload messages are routed
4191 * throught the A-Interface again */
4192 f_establish_fully(EST_TYPE_MO_SMS);
4193 f_mo_sms(spars);
4194 f_expect_clear();
4195}
4196
4197private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4198 var charstring vlr_name;
4199 f_init_handler(pars);
4200
4201 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4202 log("VLR name: ", vlr_name);
4203 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004204 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004205}
4206
4207testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004208 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004209 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004210 f_init(1, true);
4211 pars := f_init_pars(11810, true);
4212 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004213 vc_conn.done;
4214}
4215
4216/* like f_mm_auth() but for SGs */
4217function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4218 if (g_pars.net.expect_auth) {
4219 g_pars.vec := f_gen_auth_vec_3g();
4220 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4221 g_pars.vec.sres,
4222 g_pars.vec.kc,
4223 g_pars.vec.ik,
4224 g_pars.vec.ck,
4225 g_pars.vec.autn,
4226 g_pars.vec.res));
4227 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4228 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4229 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4230 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4231 }
4232}
4233
4234/* like f_perform_lu(), but on SGs rather than BSSAP */
4235function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4236 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4237 var PDU_SGsAP lur;
4238 var PDU_SGsAP lua;
4239 var PDU_SGsAP mm_info;
4240 var octetstring mm_info_dtap;
4241
4242 /* tell GSUP dispatcher to send this IMSI to us */
4243 f_create_gsup_expect(hex2str(g_pars.imsi));
4244
4245 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4246 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4247 /* Old LAI, if MS sends it */
4248 /* TMSI status, if MS has no valid TMSI */
4249 /* IMEISV, if it supports "automatic device detection" */
4250 /* TAI, if available in MME */
4251 /* E-CGI, if available in MME */
4252 SGsAP.send(lur);
4253
4254 /* FIXME: is this really done over SGs? The Ue is already authenticated
4255 * via the MME ... */
4256 f_mm_auth_sgs();
4257
4258 /* Expect MSC to perform LU with HLR */
4259 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4260 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4261 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4262 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4263
4264 alt {
4265 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4266 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4267 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4268 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4269 }
4270 setverdict(pass);
4271 }
4272 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4273 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4274 }
4275 [] SGsAP.receive {
4276 setverdict(fail, "Received unexpected message on SGs");
4277 }
4278 }
4279
4280 /* Check MM information */
4281 if (mp_mm_info == true) {
4282 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4283 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4284 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4285 setverdict(fail, "Unexpected MM Information");
4286 }
4287 }
4288
4289 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4290}
4291
4292private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4293 f_init_handler(pars);
4294 f_sgs_perform_lu();
4295 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4296
4297 f_sgsap_bssmap_screening();
4298
4299 setverdict(pass);
4300}
4301testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004302 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004303 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004304 f_init(1, true);
4305 pars := f_init_pars(11811, true);
4306 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004307 vc_conn.done;
4308}
4309
4310/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4311private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4312 f_init_handler(pars);
4313 var PDU_SGsAP lur;
4314
4315 f_create_gsup_expect(hex2str(g_pars.imsi));
4316 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4317 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4318 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4319 SGsAP.send(lur);
4320
4321 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4322 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4323 alt {
4324 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4325 setverdict(pass);
4326 }
4327 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4328 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4329 mtc.stop;
4330 }
4331 [] SGsAP.receive {
4332 setverdict(fail, "Received unexpected message on SGs");
4333 }
4334 }
4335
4336 f_sgsap_bssmap_screening();
4337
4338 setverdict(pass);
4339}
4340testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004341 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004342 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004343 f_init(1, true);
4344 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004345
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004346 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004347 vc_conn.done;
4348}
4349
4350/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4351private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4352 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4353 var PDU_SGsAP lur;
4354
4355 f_init_handler(pars);
4356
4357 /* tell GSUP dispatcher to send this IMSI to us */
4358 f_create_gsup_expect(hex2str(g_pars.imsi));
4359
4360 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4361 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4362 /* Old LAI, if MS sends it */
4363 /* TMSI status, if MS has no valid TMSI */
4364 /* IMEISV, if it supports "automatic device detection" */
4365 /* TAI, if available in MME */
4366 /* E-CGI, if available in MME */
4367 SGsAP.send(lur);
4368
4369 /* FIXME: is this really done over SGs? The Ue is already authenticated
4370 * via the MME ... */
4371 f_mm_auth_sgs();
4372
4373 /* Expect MSC to perform LU with HLR */
4374 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4375 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4376 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4377 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4378
4379 alt {
4380 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4381 setverdict(pass);
4382 }
4383 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4384 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4385 }
4386 [] SGsAP.receive {
4387 setverdict(fail, "Received unexpected message on SGs");
4388 }
4389 }
4390
4391 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4392
4393 /* Wait until the VLR has abort the TMSI reallocation procedure */
4394 f_sleep(45.0);
4395
4396 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4397 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4398
4399 f_sgsap_bssmap_screening();
4400
4401 setverdict(pass);
4402}
4403testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004404 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004405 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004406 f_init(1, true);
4407 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004408
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004409 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004410 vc_conn.done;
4411}
4412
4413private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4414runs on BSC_ConnHdlr {
4415 f_init_handler(pars);
4416 f_sgs_perform_lu();
4417 f_sleep(3.0);
4418
4419 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4420 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4421 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4422 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4423
4424 f_sgsap_bssmap_screening();
4425
4426 setverdict(pass);
4427}
4428testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004429 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004430 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004431 f_init(1, true);
4432 pars := f_init_pars(11814, true);
4433 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004434 vc_conn.done;
4435}
4436
Philipp Maierfc19f172019-03-21 11:17:54 +01004437private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4438runs on BSC_ConnHdlr {
4439 f_init_handler(pars);
4440 f_sgs_perform_lu();
4441 f_sleep(3.0);
4442
4443 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4444 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4445 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4446 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4447
4448 f_sgsap_bssmap_screening();
4449
4450 setverdict(pass);
4451}
4452testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4453 var BSC_ConnHdlrPars pars;
4454 var BSC_ConnHdlr vc_conn;
4455 f_init(1, true);
4456 pars := f_init_pars(11814, true);
4457 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4458 vc_conn.done;
4459}
4460
Harald Welte4263c522018-12-06 11:56:27 +01004461private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4462runs on BSC_ConnHdlr {
4463 f_init_handler(pars);
4464 f_sgs_perform_lu();
4465 f_sleep(3.0);
4466
4467 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4468 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4469 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004470
4471 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4472 setverdict(fail, "subscriber not removed from VLR");
4473 }
Harald Welte4263c522018-12-06 11:56:27 +01004474
4475 f_sgsap_bssmap_screening();
4476
4477 setverdict(pass);
4478}
4479testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004480 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004481 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004482 f_init(1, true);
4483 pars := f_init_pars(11815, true);
4484 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004485 vc_conn.done;
4486}
4487
Philipp Maier5d812702019-03-21 10:51:26 +01004488private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4489runs on BSC_ConnHdlr {
4490 f_init_handler(pars);
4491 f_sgs_perform_lu();
4492 f_sleep(3.0);
4493
4494 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4495 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4496 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4497
4498 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4499 setverdict(fail, "subscriber not removed from VLR");
4500 }
4501
4502 f_sgsap_bssmap_screening();
4503
4504 setverdict(pass);
4505}
4506testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4507 var BSC_ConnHdlrPars pars;
4508 var BSC_ConnHdlr vc_conn;
4509 f_init(1, true);
4510 pars := f_init_pars(11815, true);
4511 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4512 vc_conn.done;
4513}
4514
Harald Welte4263c522018-12-06 11:56:27 +01004515/* Trigger a paging request via VTY and send a paging reject in response */
4516private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4517runs on BSC_ConnHdlr {
4518 f_init_handler(pars);
4519 f_sgs_perform_lu();
4520 f_sleep(1.0);
4521
4522 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4523 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4524 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4525 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4526
4527 /* Initiate paging via VTY */
4528 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4529 alt {
4530 [] SGsAP.receive(exp_resp) {
4531 setverdict(pass);
4532 }
4533 [] SGsAP.receive {
4534 setverdict(fail, "Received unexpected message on SGs");
4535 }
4536 }
4537
4538 /* Now reject the paging */
4539 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4540
4541 /* Wait for the states inside the MSC to settle and check the state
4542 * of the SGs Association */
4543 f_sleep(1.0);
4544 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4545
4546 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4547 * but we also need to cover tha case where the cause code indicates an
4548 * "IMSI detached for EPS services". In those cases the VLR is expected to
4549 * try paging on tha A/Iu interface. This will be another testcase similar to
4550 * this one, but extended with checks for the presence of the A/Iu paging
4551 * messages. */
4552
4553 f_sgsap_bssmap_screening();
4554
4555 setverdict(pass);
4556}
4557testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004558 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004559 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004560 f_init(1, true);
4561 pars := f_init_pars(11816, true);
4562 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004563 vc_conn.done;
4564}
4565
4566/* Trigger a paging request via VTY and send a paging reject that indicates
4567 * that the subscriber intentionally rejected the call. */
4568private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4569runs on BSC_ConnHdlr {
4570 f_init_handler(pars);
4571 f_sgs_perform_lu();
4572 f_sleep(1.0);
4573
4574 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4575 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4576 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4577 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4578
4579 /* Initiate paging via VTY */
4580 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4581 alt {
4582 [] SGsAP.receive(exp_resp) {
4583 setverdict(pass);
4584 }
4585 [] SGsAP.receive {
4586 setverdict(fail, "Received unexpected message on SGs");
4587 }
4588 }
4589
4590 /* Now reject the paging */
4591 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4592
4593 /* Wait for the states inside the MSC to settle and check the state
4594 * of the SGs Association */
4595 f_sleep(1.0);
4596 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4597
4598 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4599 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4600 * to check back how this works and how it can be tested */
4601
4602 f_sgsap_bssmap_screening();
4603
4604 setverdict(pass);
4605}
4606testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004607 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004608 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004609 f_init(1, true);
4610 pars := f_init_pars(11817, true);
4611 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004612 vc_conn.done;
4613}
4614
4615/* Trigger a paging request via VTY and send an UE unreacable messge in response */
4616private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
4617runs on BSC_ConnHdlr {
4618 f_init_handler(pars);
4619 f_sgs_perform_lu();
4620 f_sleep(1.0);
4621
4622 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4623 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4624 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4625 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4626
4627 /* Initiate paging via VTY */
4628 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4629 alt {
4630 [] SGsAP.receive(exp_resp) {
4631 setverdict(pass);
4632 }
4633 [] SGsAP.receive {
4634 setverdict(fail, "Received unexpected message on SGs");
4635 }
4636 }
4637
4638 /* Now pretend that the UE is unreachable */
4639 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
4640
4641 /* Wait for the states inside the MSC to settle and check the state
4642 * of the SGs Association. */
4643 f_sleep(1.0);
4644 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4645
4646 f_sgsap_bssmap_screening();
4647
4648 setverdict(pass);
4649}
4650testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004651 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004652 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004653 f_init(1, true);
4654 pars := f_init_pars(11818, true);
4655 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004656 vc_conn.done;
4657}
4658
4659/* Trigger a paging request via VTY but don't respond to it */
4660private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
4661runs on BSC_ConnHdlr {
4662 f_init_handler(pars);
4663 f_sgs_perform_lu();
4664 f_sleep(1.0);
4665
4666 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4667 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02004668 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01004669 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4670 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4671
4672 /* Initiate paging via VTY */
4673 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4674 alt {
4675 [] SGsAP.receive(exp_resp) {
4676 setverdict(pass);
4677 }
4678 [] SGsAP.receive {
4679 setverdict(fail, "Received unexpected message on SGs");
4680 }
4681 }
4682
Philipp Maier34218102019-09-24 09:15:49 +02004683 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
4684 * after some time */
4685 timer T := 10.0;
4686 T.start
4687 alt {
4688 [] SGsAP.receive(exp_serv_abrt)
4689 {
4690 setverdict(pass);
4691 }
4692 [] SGsAP.receive {
4693 setverdict(fail, "unexpected SGsAP message received");
4694 self.stop;
4695 }
4696 [] T.timeout {
4697 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
4698 self.stop;
4699 }
4700 }
4701
4702 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01004703 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4704
4705 f_sgsap_bssmap_screening();
4706
4707 setverdict(pass);
4708}
4709testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004710 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004711 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004712 f_init(1, true);
4713 pars := f_init_pars(11819, true);
4714 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004715 vc_conn.done;
4716}
4717
4718/* Trigger a paging request via VTY and slip in an LU */
4719private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4720runs on BSC_ConnHdlr {
4721 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4722 f_init_handler(pars);
4723
4724 /* First we prepar the situation, where the SGs association is in state
4725 * NULL and the confirmed by radio contact indicator is set to false
4726 * as well. This can be archived by performing an SGs LU and then
4727 * resetting the VLR */
4728 f_sgs_perform_lu();
4729 f_sgsap_reset_mme(mp_mme_name);
4730 f_sleep(1.0);
4731 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4732
4733 /* Perform a paging, expect the paging messages on the SGs interface */
4734 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4735 alt {
4736 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4737 setverdict(pass);
4738 }
4739 [] SGsAP.receive {
4740 setverdict(fail, "Received unexpected message on SGs");
4741 }
4742 }
4743
4744 /* Perform the LU as normal */
4745 f_sgs_perform_lu();
4746 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4747
4748 /* Expect a new paging request right after the LU */
4749 alt {
4750 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4751 setverdict(pass);
4752 }
4753 [] SGsAP.receive {
4754 setverdict(fail, "Received unexpected message on SGs");
4755 }
4756 }
4757
4758 /* Test is done now, lets round everything up by rejecting the paging
4759 * cleanly. */
4760 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4761 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4762
4763 f_sgsap_bssmap_screening();
4764
4765 setverdict(pass);
4766}
4767testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004768 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004769 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004770 f_init(1, true);
4771 pars := f_init_pars(11820, true);
4772 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004773 vc_conn.done;
4774}
4775
4776/* Send unexpected unit-data through the SGs interface */
4777private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4778 f_init_handler(pars);
4779 f_sleep(1.0);
4780
4781 /* This simulates what happens when a subscriber without SGs
4782 * association gets unitdata via the SGs interface. */
4783
4784 /* Make sure the subscriber exists and the SGs association
4785 * is in NULL state */
4786 f_perform_lu();
4787 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4788
4789 /* Send some random unit data, the MSC/VLR should send a release
4790 * immediately. */
4791 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4792 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
4793
4794 f_sgsap_bssmap_screening();
4795
4796 setverdict(pass);
4797}
4798testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004799 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004800 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004801 f_init(1, true);
4802 pars := f_init_pars(11821, true);
4803 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004804 vc_conn.done;
4805}
4806
4807/* Send unsolicited unit-data through the SGs interface */
4808private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4809 f_init_handler(pars);
4810 f_sleep(1.0);
4811
4812 /* This simulates what happens when the MME attempts to send unitdata
4813 * to a subscriber that is completely unknown to the VLR */
4814
4815 /* Send some random unit data, the MSC/VLR should send a release
4816 * immediately. */
4817 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4818 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
4819
4820 f_sgsap_bssmap_screening();
4821
4822 setverdict(pass);
4823}
4824testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004825 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004826 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004827 f_init(1, true);
4828 pars := f_init_pars(11822, true);
4829 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004830 vc_conn.done;
4831}
4832
4833private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
4834 /* FIXME: Match an actual payload (second questionmark), the type is
4835 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
4836 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
4837 setverdict(fail, "Unexpected SMS related PDU from MSC");
4838 mtc.stop;
4839 }
4840}
4841
4842/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
4843function f_mt_sms_sgs(inout SmsParameters spars)
4844runs on BSC_ConnHdlr {
4845 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4846 var template (value) RPDU_MS_SGSN rp_mo;
4847 var template (value) PDU_ML3_MS_NW l3_mo;
4848
4849 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4850 var template RPDU_SGSN_MS rp_mt;
4851 var template PDU_ML3_NW_MS l3_mt;
4852
4853 var PDU_ML3_NW_MS sgsap_l3_mt;
4854
4855 var default d := activate(as_other_sms_sgs());
4856
4857 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
4858 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09004859 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01004860 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
4861
4862 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
4863
4864 /* Extract relevant identifiers */
4865 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
4866 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
4867
4868 /* send CP-ACK for CP-DATA just received */
4869 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
4870
4871 SGsAP.send(l3_mo);
4872
4873 /* send RP-ACK for RP-DATA */
4874 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
4875 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
4876
4877 SGsAP.send(l3_mo);
4878
4879 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
4880 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
4881
4882 SGsAP.receive(l3_mt);
4883
4884 deactivate(d);
4885
4886 setverdict(pass);
4887}
4888
4889/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
4890function f_mo_sms_sgs(inout SmsParameters spars)
4891runs on BSC_ConnHdlr {
4892 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4893 var template (value) RPDU_MS_SGSN rp_mo;
4894 var template (value) PDU_ML3_MS_NW l3_mo;
4895
4896 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4897 var template RPDU_SGSN_MS rp_mt;
4898 var template PDU_ML3_NW_MS l3_mt;
4899
4900 var default d := activate(as_other_sms_sgs());
4901
4902 /* just in case this is routed to SMPP.. */
4903 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
4904
4905 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
4906 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09004907 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01004908 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
4909
4910 SGsAP.send(l3_mo);
4911
4912 /* receive CP-ACK for CP-DATA above */
4913 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
4914
4915 if (ispresent(spars.exp_rp_err)) {
4916 /* expect an RP-ERROR message from MSC with given cause */
4917 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
4918 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4919 SGsAP.receive(l3_mt);
4920 /* send CP-ACK for CP-DATA just received */
4921 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4922 SGsAP.send(l3_mo);
4923 } else {
4924 /* expect RP-ACK for RP-DATA */
4925 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
4926 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4927 SGsAP.receive(l3_mt);
4928 /* send CP-ACO for CP-DATA just received */
4929 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4930 SGsAP.send(l3_mo);
4931 }
4932
4933 deactivate(d);
4934
4935 setverdict(pass);
4936}
4937
4938private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
4939runs on BSC_ConnHdlr {
4940 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
4941}
4942
4943/* Send a MT SMS via SGs interface */
4944private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4945 f_init_handler(pars);
4946 f_sgs_perform_lu();
4947 f_sleep(1.0);
4948 var SmsParameters spars := valueof(t_SmsPars);
4949 spars.tp.ud := 'C8329BFD064D9B53'O;
4950
4951 /* Trigger SMS via VTY */
4952 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4953 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4954
4955 /* Expect a paging request and respond accordingly with a service request */
4956 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
4957 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
4958
4959 /* Connection is now live, receive the MT-SMS */
4960 f_mt_sms_sgs(spars);
4961
4962 /* Expect a concluding release from the MSC */
4963 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4964
4965 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4966 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4967
4968 f_sgsap_bssmap_screening();
4969
4970 setverdict(pass);
4971}
4972testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004973 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004974 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004975 f_init(1, true);
4976 pars := f_init_pars(11823, true);
4977 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004978 vc_conn.done;
4979}
4980
4981/* Send a MO SMS via SGs interface */
4982private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4983 f_init_handler(pars);
4984 f_sgs_perform_lu();
4985 f_sleep(1.0);
4986 var SmsParameters spars := valueof(t_SmsPars);
4987 spars.tp.ud := 'C8329BFD064D9B53'O;
4988
4989 /* Send the MO-SMS */
4990 f_mo_sms_sgs(spars);
4991
4992 /* Expect a concluding release from the MSC/VLR */
4993 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4994
4995 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4996 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4997
4998 setverdict(pass);
4999
5000 f_sgsap_bssmap_screening()
5001}
5002testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005003 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005004 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005005 f_init(1, true);
5006 pars := f_init_pars(11824, true);
5007 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005008 vc_conn.done;
5009}
5010
5011/* Trigger sending of an MT sms via VTY but never respond to anything */
5012private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5013 f_init_handler(pars, 170.0);
5014 f_sgs_perform_lu();
5015 f_sleep(1.0);
5016
5017 var SmsParameters spars := valueof(t_SmsPars);
5018 spars.tp.ud := 'C8329BFD064D9B53'O;
5019 var integer page_count := 0;
5020 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5021 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5022 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5023 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5024
5025 /* Trigger SMS via VTY */
5026 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5027
Neels Hofmeyr16237742019-03-06 15:34:01 +01005028 /* Expect the MSC/VLR to page exactly once */
5029 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005030
5031 /* Wait some time to make sure the MSC is not delivering any further
5032 * paging messages or anything else that could be unexpected. */
5033 timer T := 20.0;
5034 T.start
5035 alt {
5036 [] SGsAP.receive(exp_pag_req)
5037 {
5038 setverdict(fail, "paging seems not to stop!");
5039 mtc.stop;
5040 }
5041 [] SGsAP.receive {
5042 setverdict(fail, "unexpected SGsAP message received");
5043 self.stop;
5044 }
5045 [] T.timeout {
5046 setverdict(pass);
5047 }
5048 }
5049
5050 /* Even on a failed paging the SGs Association should stay intact */
5051 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5052
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005053 /* Make sure that the SMS we just inserted is cleared and the
5054 * subscriber is expired. This is necessary because otherwise the MSC
5055 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005056
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005057 f_vty_sms_clear(hex2str(g_pars.imsi));
5058
Harald Welte4263c522018-12-06 11:56:27 +01005059 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5060
5061 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005062
5063 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005064}
5065testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005066 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005067 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005068 f_init(1, true);
5069 pars := f_init_pars(11825, true);
5070 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005071 vc_conn.done;
5072}
5073
5074/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5075private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5076 f_init_handler(pars, 150.0);
5077 f_sgs_perform_lu();
5078 f_sleep(1.0);
5079
5080 var SmsParameters spars := valueof(t_SmsPars);
5081 spars.tp.ud := 'C8329BFD064D9B53'O;
5082 var integer page_count := 0;
5083 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5084 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5085 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5086 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5087
5088 /* Trigger SMS via VTY */
5089 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5090
5091 /* Expect a paging request and reject it immediately */
5092 SGsAP.receive(exp_pag_req);
5093 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5094
5095 /* The MSC/VLR should no longer try to page once the paging has been
5096 * rejected. Wait some time and check if there are no unexpected
5097 * messages on the SGs interface. */
5098 timer T := 20.0;
5099 T.start
5100 alt {
5101 [] SGsAP.receive(exp_pag_req)
5102 {
5103 setverdict(fail, "paging seems not to stop!");
5104 mtc.stop;
5105 }
5106 [] SGsAP.receive {
5107 setverdict(fail, "unexpected SGsAP message received");
5108 self.stop;
5109 }
5110 [] T.timeout {
5111 setverdict(pass);
5112 }
5113 }
5114
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005115 f_vty_sms_clear(hex2str(g_pars.imsi));
5116
Harald Welte4263c522018-12-06 11:56:27 +01005117 /* A rejected paging with IMSI_unknown (see above) should always send
5118 * the SGs association to NULL. */
5119 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5120
5121 f_sgsap_bssmap_screening();
5122
Harald Welte4263c522018-12-06 11:56:27 +01005123 setverdict(pass);
5124}
5125testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005126 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005127 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005128 f_init(1, true);
5129 pars := f_init_pars(11826, true);
5130 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005131 vc_conn.done;
5132}
5133
5134/* Perform an MT CSDB call including LU */
5135private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5136 f_init_handler(pars);
5137
5138 /* Be sure that the BSSMAP reset is done before we begin. */
5139 f_sleep(2.0);
5140
5141 /* Testcase variation: See what happens when we do a regular BSSMAP
5142 * LU first (this should not hurt in any way!) */
5143 if (bssmap_lu) {
5144 f_perform_lu();
5145 }
5146
5147 f_sgs_perform_lu();
5148 f_sleep(1.0);
5149
5150 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5151 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005152
5153 /* Initiate a call via MNCC interface */
5154 f_mt_call_initate(cpars);
5155
5156 /* Expect a paging request and respond accordingly with a service request */
5157 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5158 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5159
5160 /* Complete the call, hold it for some time and then tear it down */
5161 f_mt_call_complete(cpars);
5162 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005163 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005164
5165 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5166 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5167
Harald Welte4263c522018-12-06 11:56:27 +01005168 /* Test for successful return by triggering a paging, when the paging
5169 * request is received via SGs, we can be sure that the MSC/VLR has
5170 * recognized that the UE is now back on 4G */
5171 f_sleep(1.0);
5172 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5173 alt {
5174 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5175 setverdict(pass);
5176 }
5177 [] SGsAP.receive {
5178 setverdict(fail, "Received unexpected message on SGs");
5179 }
5180 }
5181
5182 f_sgsap_bssmap_screening();
5183
5184 setverdict(pass);
5185}
5186
5187/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5188private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5189 f_mt_lu_and_csfb_call(id, pars, true);
5190}
5191testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005192 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005193 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005194 f_init(1, true);
5195 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005196
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005197 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005198 vc_conn.done;
5199}
5200
Harald Welte4263c522018-12-06 11:56:27 +01005201/* Perform a SGSAP LU and then make a CSFB call */
5202private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5203 f_mt_lu_and_csfb_call(id, pars, false);
5204}
5205testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005206 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005207 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005208 f_init(1, true);
5209 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005210
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005211 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005212 vc_conn.done;
5213}
5214
Philipp Maier628c0052019-04-09 17:36:57 +02005215/* Simulate an HLR/VLR failure */
5216private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5217 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5218 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5219
5220 var PDU_SGsAP lur;
5221
5222 f_init_handler(pars);
5223
5224 /* Attempt location update (which is expected to fail) */
5225 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5226 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5227 SGsAP.send(lur);
5228
5229 /* Respond to SGsAP-RESET-INDICATION from VLR */
5230 alt {
5231 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5232 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5233 setverdict(pass);
5234 }
5235 [] SGsAP.receive {
5236 setverdict(fail, "Received unexpected message on SGs");
5237 }
5238 }
5239
5240 f_sleep(1.0);
5241 setverdict(pass);
5242}
5243testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5244 var BSC_ConnHdlrPars pars;
5245 var BSC_ConnHdlr vc_conn;
5246 f_init(1, true, false);
5247 pars := f_init_pars(11811, true, false);
5248 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5249 vc_conn.done;
5250}
5251
Harald Welte4263c522018-12-06 11:56:27 +01005252/* SGs TODO:
5253 * LU attempt for IMSI without NAM_PS in HLR
5254 * LU attempt with AUTH FAIL due to invalid RES/SRES
5255 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5256 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5257 * implicit IMSI detach from EPS
5258 * implicit IMSI detach from non-EPS
5259 * MM INFO
5260 *
5261 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005262
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005263private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5264 f_init_handler(pars);
5265 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005266
5267 f_perform_lu();
5268 f_mo_call_establish(cpars);
5269
5270 f_sleep(1.0);
5271
5272 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5273 var BssmapCause cause := enum2int(cause_val);
5274
5275 var template BSSMAP_FIELD_CellIdentificationList cil;
5276 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5277
5278 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5279 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5280
5281 f_call_hangup(cpars, true);
5282}
5283testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5284 var BSC_ConnHdlr vc_conn;
5285 f_init();
5286
5287 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5288 vc_conn.done;
5289}
5290
5291private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5292 var MgcpCommand mgcp_cmd;
5293 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005294 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005295 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005296 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005297 { int2str(cpars.rtp_payload_type) },
5298 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5299 cpars.rtp_sdp_format)),
5300 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005301 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_2.mgcp_connection_id, sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005302 repeat;
5303 }
5304}
5305
5306private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5307 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005308
5309 f_init_handler(pars);
5310
5311 f_vty_transceive(MSCVTY, "configure terminal");
5312 f_vty_transceive(MSCVTY, "msc");
5313 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
5314 f_vty_transceive(MSCVTY, "neighbor a lac 5 ran-pc 0.24.2");
5315 f_vty_transceive(MSCVTY, "exit");
5316 f_vty_transceive(MSCVTY, "exit");
5317
5318 f_perform_lu();
5319 f_mo_call_establish(cpars);
5320
5321 f_sleep(1.0);
5322
5323 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5324
5325 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5326 var BssmapCause cause := enum2int(cause_val);
5327
5328 var template BSSMAP_FIELD_CellIdentificationList cil;
5329 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 5) } };
5330
5331 /* old BSS sends Handover Required */
5332 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5333
5334 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5335
5336 /* MSC forwards the RR Handover Command to old BSS */
5337 var PDU_BSSAP ho_command;
5338 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5339
5340 log("GOT HandoverCommand", ho_command);
5341
5342 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5343
5344 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5345 f_expect_clear();
5346
5347 log("FIRST inter-BSC Handover done");
5348
5349
5350 /* ------------------------ */
5351
5352 /* Ok, that went well, now the other BSC is handovering back here --
5353 * from now on this here is the new BSS. */
5354 f_create_bssmap_exp_handoverRequest(193);
5355
5356 var PDU_BSSAP ho_request;
5357 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5358
5359 /* new BSS composes a RR Handover Command */
5360 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5361 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5362 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5363 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5364 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5365
5366 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5367
5368 f_sleep(0.5);
5369
5370 /* Notify that the MS is now over here */
5371
5372 BSSAP.send(ts_BSSMAP_HandoverDetect);
5373 f_sleep(0.1);
5374 BSSAP.send(ts_BSSMAP_HandoverComplete);
5375
5376 f_sleep(3.0);
5377
5378 deactivate(ack_mdcx);
5379
5380 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5381
5382 /* blatant cheating */
5383 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5384 last_n_sd[0] := 3;
5385 f_bssmap_continue_after_n_sd(last_n_sd);
5386
5387 f_call_hangup(cpars, true);
5388 f_sleep(1.0);
5389 deactivate(ccrel);
5390
5391 setverdict(pass);
5392}
5393private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5394 f_init_handler(pars);
5395 f_create_bssmap_exp_handoverRequest(194);
5396
5397 var PDU_BSSAP ho_request;
5398 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5399
5400 /* new BSS composes a RR Handover Command */
5401 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5402 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5403 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5404 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5405 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5406
5407 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5408
5409 f_sleep(0.5);
5410
5411 /* Notify that the MS is now over here */
5412
5413 BSSAP.send(ts_BSSMAP_HandoverDetect);
5414 f_sleep(0.1);
5415 BSSAP.send(ts_BSSMAP_HandoverComplete);
5416
5417 f_sleep(3.0);
5418
5419 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5420 * ... handover back to the first BSC :P */
5421
5422 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5423 var BssmapCause cause := enum2int(cause_val);
5424
5425 var template BSSMAP_FIELD_CellIdentificationList cil;
5426 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('262'H, '42'H, 23) } };
5427
5428 /* old BSS sends Handover Required */
5429 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5430
5431 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5432
5433 /* MSC forwards the RR Handover Command to old BSS */
5434 var PDU_BSSAP ho_command;
5435 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5436
5437 log("GOT HandoverCommand", ho_command);
5438
5439 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5440
5441 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5442 f_expect_clear();
5443 setverdict(pass);
5444}
5445testcase TC_ho_inter_bsc() runs on MTC_CT {
5446 var BSC_ConnHdlr vc_conn0;
5447 var BSC_ConnHdlr vc_conn1;
5448 f_init(2);
5449
5450 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
5451 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
5452
5453 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0, 0);
5454 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1, 1);
5455 vc_conn0.done;
5456 vc_conn1.done;
5457}
5458
5459function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5460 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5461 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5462 log("MS_NW patched enc_l3: ", enc_l3);
5463}
5464
5465private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5466 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005467 var hexstring ho_number := f_gen_msisdn(99999);
5468
5469 f_init_handler(pars);
5470
5471 f_create_mncc_expect(hex2str(ho_number));
5472
5473 f_vty_transceive(MSCVTY, "configure terminal");
5474 f_vty_transceive(MSCVTY, "msc");
5475 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
5476 f_vty_transceive(MSCVTY, "exit");
5477 f_vty_transceive(MSCVTY, "exit");
5478
5479 f_perform_lu();
5480 f_mo_call_establish(cpars);
5481
5482 f_sleep(1.0);
5483
5484 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5485
5486 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5487 var BssmapCause cause := enum2int(cause_val);
5488
5489 var template BSSMAP_FIELD_CellIdentificationList cil;
5490 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('017'H, '017'H, 1) } };
5491
5492 /* old BSS sends Handover Required */
5493 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5494
5495 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
5496 * This MSC tries to reach the other MSC via GSUP. */
5497
5498 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
5499 var GSUP_PDU prep_ho_req;
5500 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
5501 pars.imsi, destination_name := remote_msc_name)) -> value prep_ho_req;
5502
5503 var GSUP_IeValue source_name_ie;
5504 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
5505 var octetstring local_msc_name := source_name_ie.source_name;
5506
5507 /* Remote MSC has figured out its BSC and signals success */
5508 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5509 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5510 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5511 aoIPTransportLayer := omit,
5512 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5513 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
5514 pars.imsi,
5515 ho_number,
5516 remote_msc_name, local_msc_name,
5517 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
5518
5519 /* MSC forwards the RR Handover Command to old BSS */
5520 BSSAP.receive(tr_BSSMAP_HandoverCommand);
5521
5522 /* The MS shows up at remote new BSS */
5523
5524 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5525 pars.imsi, remote_msc_name, local_msc_name,
5526 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5527 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
5528 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5529 f_sleep(0.1);
5530
5531 /* Save the MS sequence counters for use on the other connection */
5532 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5533
5534 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
5535 pars.imsi, remote_msc_name, local_msc_name,
5536 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5537 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
5538
5539 /* The local BSS conn clears, all communication goes via remote MSC now */
5540 f_expect_clear();
5541
5542 /**********************************/
5543 /* Play through some signalling across the inter-MSC link.
5544 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
5545
5546 if (false) {
5547 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
5548 invoke_id := 5, /* Phone may not start from 0 or 1 */
5549 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5550 ussd_string := "*#100#"
5551 );
5552
5553 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
5554 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
5555 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5556 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
5557 )
5558
5559 /* Compose a new SS/REGISTER message with request */
5560 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
5561 tid := 1, /* We just need a single transaction */
5562 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
5563 facility := valueof(facility_req)
5564 );
5565 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
5566
5567 /* Compose SS/RELEASE_COMPLETE template with expected response */
5568 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
5569 tid := 1, /* Response should arrive within the same transaction */
5570 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
5571 facility := valueof(facility_rsp)
5572 );
5573
5574 /* Compose expected MSC -> HLR message */
5575 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
5576 imsi := g_pars.imsi,
5577 state := OSMO_GSUP_SESSION_STATE_BEGIN,
5578 ss := valueof(facility_req)
5579 );
5580
5581 /* To be used for sending response with correct session ID */
5582 var GSUP_PDU gsup_req_complete;
5583
5584 /* Request own number */
5585 /* From remote MSC instead of BSSAP directly */
5586 /* Patch the correct N_SD value into the message. */
5587 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
5588 var RAN_Emulation.ConnectionData cd;
5589 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
5590 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5591 pars.imsi, remote_msc_name, local_msc_name,
5592 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5593 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
5594 ))
5595 ));
5596
5597 /* Expect GSUP message containing the SS payload */
5598 gsup_req_complete := f_expect_gsup_msg(gsup_req);
5599
5600 /* Compose the response from HLR using received session ID */
5601 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
5602 imsi := g_pars.imsi,
5603 sid := gsup_req_complete.ies[1].val.session_id,
5604 state := OSMO_GSUP_SESSION_STATE_END,
5605 ss := valueof(facility_rsp)
5606 );
5607
5608 /* Finally, HLR terminates the session */
5609 GSUP.send(gsup_rsp);
5610
5611 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
5612 var GSUP_PDU gsup_ussd_rsp;
5613 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5614 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
5615
5616 var GSUP_IeValue an_apdu;
5617 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
5618 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5619 mtc.stop;
5620 }
5621 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
5622 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
5623 log("Expecting", ussd_rsp);
5624 log("Got", dtap_mt);
5625 if (not match(dtap_mt, ussd_rsp)) {
5626 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5627 mtc.stop;
5628 }
5629 }
5630 /**********************************/
5631
5632
5633 /* inter-MSC handover back to the first MSC */
5634 f_create_bssmap_exp_handoverRequest(193);
5635 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
5636
5637 /* old BSS sends Handover Required, via inter-MSC E link: like
5638 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5639 * but via GSUP */
5640 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
5641 pars.imsi, remote_msc_name, local_msc_name,
5642 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5643 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
5644 ))
5645 ));
5646
5647 /* MSC asks local BSS to prepare Handover to it */
5648 BSSAP.receive(tr_BSSMAP_HandoverRequest);
5649
5650 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
5651 f_bssmap_continue_after_n_sd(last_n_sd);
5652
5653 /* new BSS composes a RR Handover Command */
5654 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5655 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5656 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5657 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5658 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5659
5660 /* HandoverCommand goes out via remote MSC-I */
5661 var GSUP_PDU prep_subsq_ho_res;
5662 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
5663 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
5664
5665 /* MS shows up at the local BSS */
5666 BSSAP.send(ts_BSSMAP_HandoverDetect);
5667 f_sleep(0.1);
5668 BSSAP.send(ts_BSSMAP_HandoverComplete);
5669
5670 /* Handover Succeeded message */
5671 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5672 pars.imsi, destination_name := remote_msc_name));
5673
5674 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
5675 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
5676 pars.imsi, destination_name := remote_msc_name));
5677
5678 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
5679
5680 f_sleep(1.0);
5681 deactivate(ack_mdcx);
5682
5683 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
5684 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
5685 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
5686 MNCC.clear;
5687
5688 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5689 f_call_hangup(cpars, true);
5690 f_sleep(1.0);
5691 deactivate(ccrel);
5692
5693 setverdict(pass);
5694}
5695testcase TC_ho_inter_msc_out() runs on MTC_CT {
5696 var BSC_ConnHdlr vc_conn;
5697 f_init(1);
5698
5699 var BSC_ConnHdlrPars pars := f_init_pars(54);
5700
5701 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5702 vc_conn.done;
5703}
5704
Oliver Smith1d118ff2019-07-03 10:57:35 +02005705private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5706 pars.net.expect_auth := true;
5707 pars.net.expect_imei := true;
5708 f_init_handler(pars);
5709 f_perform_lu();
5710}
5711testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
5712 var BSC_ConnHdlr vc_conn;
5713 f_init();
5714 f_vty_config(MSCVTY, "network", "authentication required");
5715 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5716
5717 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
5718 vc_conn.done;
5719}
5720
5721private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5722 pars.net.expect_auth := true;
5723 pars.use_umts_aka := true;
5724 pars.net.expect_imei := true;
5725 f_init_handler(pars);
5726 f_perform_lu();
5727}
5728testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
5729 var BSC_ConnHdlr vc_conn;
5730 f_init();
5731 f_vty_config(MSCVTY, "network", "authentication required");
5732 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5733
5734 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
5735 vc_conn.done;
5736}
5737
5738private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5739 pars.net.expect_imei := true;
5740 f_init_handler(pars);
5741 f_perform_lu();
5742}
5743testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
5744 var BSC_ConnHdlr vc_conn;
5745 f_init();
5746 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5747
5748 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
5749 vc_conn.done;
5750}
5751
5752private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5753 pars.net.expect_tmsi := false;
5754 pars.net.expect_imei := true;
5755 f_init_handler(pars);
5756 f_perform_lu();
5757}
5758testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
5759 var BSC_ConnHdlr vc_conn;
5760 f_init();
5761 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
5762 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5763
5764 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
5765 vc_conn.done;
5766}
5767
5768private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5769 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005770
5771 pars.net.expect_auth := true;
5772 pars.net.expect_imei := true;
5773 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
5774 f_init_handler(pars);
5775
5776 /* Cannot use f_perform_lu() as we expect a reject */
5777 l3_lu := f_build_lu_imsi(g_pars.imsi)
5778 f_create_gsup_expect(hex2str(g_pars.imsi));
5779 f_bssap_compl_l3(l3_lu);
5780 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5781
5782 f_mm_common();
5783 f_msc_lu_hlr();
5784 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005785 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005786 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005787}
5788testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
5789 var BSC_ConnHdlr vc_conn;
5790 f_init();
5791 f_vty_config(MSCVTY, "network", "authentication required");
5792 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5793
5794 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
5795 vc_conn.done;
5796}
5797
5798private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5799 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005800
5801 pars.net.expect_auth := true;
5802 pars.net.expect_imei := true;
5803 pars.net.check_imei_error := true;
5804 f_init_handler(pars);
5805
5806 /* Cannot use f_perform_lu() as we expect a reject */
5807 l3_lu := f_build_lu_imsi(g_pars.imsi)
5808 f_create_gsup_expect(hex2str(g_pars.imsi));
5809 f_bssap_compl_l3(l3_lu);
5810 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5811
5812 f_mm_common();
5813 f_msc_lu_hlr();
5814 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005815 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005816 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005817}
5818testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
5819 var BSC_ConnHdlr vc_conn;
5820 f_init();
5821 f_vty_config(MSCVTY, "network", "authentication required");
5822 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5823
5824 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
5825 vc_conn.done;
5826}
5827
5828private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5829 pars.net.expect_auth := true;
5830 pars.net.expect_imei_early := true;
5831 f_init_handler(pars);
5832 f_perform_lu();
5833}
5834testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
5835 var BSC_ConnHdlr vc_conn;
5836 f_init();
5837 f_vty_config(MSCVTY, "network", "authentication required");
5838 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5839
5840 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
5841 vc_conn.done;
5842}
5843
5844private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5845 pars.net.expect_auth := true;
5846 pars.use_umts_aka := true;
5847 pars.net.expect_imei_early := true;
5848 f_init_handler(pars);
5849 f_perform_lu();
5850}
5851testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
5852 var BSC_ConnHdlr vc_conn;
5853 f_init();
5854 f_vty_config(MSCVTY, "network", "authentication required");
5855 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5856
5857 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
5858 vc_conn.done;
5859}
5860
5861private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5862 pars.net.expect_imei_early := true;
5863 f_init_handler(pars);
5864 f_perform_lu();
5865}
5866testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
5867 var BSC_ConnHdlr vc_conn;
5868 f_init();
5869 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5870
5871 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
5872 vc_conn.done;
5873}
5874
5875private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5876 pars.net.expect_tmsi := false;
5877 pars.net.expect_imei_early := true;
5878 f_init_handler(pars);
5879 f_perform_lu();
5880}
5881testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
5882 var BSC_ConnHdlr vc_conn;
5883 f_init();
5884 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
5885 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5886
5887 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
5888 vc_conn.done;
5889}
5890
5891private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5892 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005893
5894 pars.net.expect_auth := true;
5895 pars.net.expect_imei_early := true;
5896 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
5897 f_init_handler(pars);
5898
5899 /* Cannot use f_perform_lu() as we expect a reject */
5900 l3_lu := f_build_lu_imsi(g_pars.imsi)
5901 f_create_gsup_expect(hex2str(g_pars.imsi));
5902 f_bssap_compl_l3(l3_lu);
5903 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5904
5905 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005906 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005907 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005908}
5909testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
5910 var BSC_ConnHdlr vc_conn;
5911 f_init();
5912 f_vty_config(MSCVTY, "network", "authentication required");
5913 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5914
5915 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
5916 vc_conn.done;
5917}
5918
5919private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5920 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005921
5922 pars.net.expect_auth := true;
5923 pars.net.expect_imei_early := true;
5924 pars.net.check_imei_error := true;
5925 f_init_handler(pars);
5926
5927 /* Cannot use f_perform_lu() as we expect a reject */
5928 l3_lu := f_build_lu_imsi(g_pars.imsi)
5929 f_create_gsup_expect(hex2str(g_pars.imsi));
5930 f_bssap_compl_l3(l3_lu);
5931 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5932
5933 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005934 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005935 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005936}
5937testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
5938 var BSC_ConnHdlr vc_conn;
5939 f_init();
5940 f_vty_config(MSCVTY, "network", "authentication required");
5941 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5942
5943 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
5944 vc_conn.done;
5945}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005946
Neels Hofmeyr8df69622019-11-02 19:16:03 +01005947friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5948 f_init_handler(pars);
5949 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
5950
5951 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
5952 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
5953 * will cause a use-after-free after that event dispatch. */
5954 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
5955 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
5956 cpars.rtp_sdp_format := "FOO/8000";
5957 cpars.expect_release := true;
5958
5959 f_perform_lu();
5960 f_mo_call_establish(cpars);
5961}
5962testcase TC_invalid_mgcp_crash() runs on MTC_CT {
5963 var BSC_ConnHdlr vc_conn;
5964 f_init();
5965
5966 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
5967 vc_conn.done;
5968}
5969
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01005970friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
5971runs on BSC_ConnHdlr {
5972 pars.tmsi := 'FFFFFFFF'O;
5973 f_init_handler(pars);
5974
5975 f_create_gsup_expect(hex2str(g_pars.imsi));
5976
5977 /* Initiate Location Updating using an unknown TMSI */
5978 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
5979
5980 /* Expect an Identity Request, send response with no identity */
5981 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
5982 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
5983 lengthIndicator := 1,
5984 mobileIdentityV := {
5985 typeOfIdentity := '000'B,
5986 oddEvenInd_identity := {
5987 no_identity := {
5988 oddevenIndicator := '0'B,
5989 fillerDigits := '00000'H
5990 }
5991 }
5992 }
5993 })));
5994
5995 f_expect_lu_reject();
5996 f_expect_clear();
5997}
5998testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
5999 var BSC_ConnHdlr vc_conn;
6000
6001 f_init();
6002
6003 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7);
6004 vc_conn.done;
6005}
6006
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006007/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6008 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6009 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6010friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6011runs on BSC_ConnHdlr {
6012 var charstring imsi := hex2str(pars.imsi);
6013
6014 f_init_handler(pars);
6015
6016 /* Perform location update */
6017 f_perform_lu();
6018
6019 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6020 f_create_gsup_expect(hex2str(g_pars.imsi));
6021
6022 /* Initiate paging procedure from the VTY */
6023 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6024 f_expect_paging();
6025
6026 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6027 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6028
6029 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6030 f_establish_fully(EST_TYPE_PAG_RESP);
6031
6032 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6033 * In this case we do not send anything and just wait for a Clear Command. */
6034 f_expect_clear();
6035}
6036testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6037 var BSC_ConnHdlr vc_conn;
6038
6039 f_init();
6040
6041 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6042 vc_conn.done;
6043}
6044
Harald Weltef6dd64d2017-11-19 12:09:51 +01006045control {
Philipp Maier328d1662018-03-07 10:40:27 +01006046 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006047 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01006048 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006049 execute( TC_lu_imsi_reject() );
6050 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01006051 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02006052 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01006053 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01006054 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01006055 execute( TC_lu_and_mo_call() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01006056 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01006057 execute( TC_lu_auth_sai_timeout() );
6058 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006059 execute( TC_lu_clear_request() );
6060 execute( TC_lu_disconnect() );
6061 execute( TC_lu_by_imei() );
6062 execute( TC_lu_by_tmsi_noauth_unknown() );
6063 execute( TC_imsi_detach_by_imsi() );
6064 execute( TC_imsi_detach_by_tmsi() );
6065 execute( TC_imsi_detach_by_imei() );
6066 execute( TC_emerg_call_imei_reject() );
6067 execute( TC_emerg_call_imsi() );
6068 execute( TC_cm_serv_req_vgcs_reject() );
6069 execute( TC_cm_serv_req_vbs_reject() );
6070 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01006071 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01006072 execute( TC_lu_auth_2G_fail() );
6073 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
6074 execute( TC_cl3_no_payload() );
6075 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01006076 execute( TC_establish_and_nothing() );
6077 execute( TC_mo_setup_and_nothing() );
6078 execute( TC_mo_crcx_ran_timeout() );
6079 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01006080 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01006081 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01006082 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01006083 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01006084 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
6085 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
6086 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01006087 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01006088 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
6089 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01006090 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01006091 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02006092 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006093
6094 execute( TC_lu_and_mt_call() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006095 execute( TC_lu_and_mt_call_already_paging() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006096
Harald Weltef45efeb2018-04-09 18:19:24 +02006097 execute( TC_lu_and_mo_sms() );
6098 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006099 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01006100 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02006101 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02006102 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07006103 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02006104 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02006105
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006106 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07006107 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07006108 execute( TC_gsup_mt_sms_ack() );
6109 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07006110 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07006111 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07006112 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006113
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006114 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006115 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006116 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006117 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07006118 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07006119 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07006120
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006121 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07006122 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07006123 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07006124 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07006125 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006126
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01006127 execute( TC_multi_lu_and_mo_ussd() );
6128 execute( TC_multi_lu_and_mt_ussd() );
6129
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006130 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01006131 execute( TC_cipher_complete_1_without_cipher() );
6132 execute( TC_cipher_complete_3_without_cipher() );
6133 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02006134 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006135
Harald Welte4263c522018-12-06 11:56:27 +01006136 execute( TC_sgsap_reset() );
6137 execute( TC_sgsap_lu() );
6138 execute( TC_sgsap_lu_imsi_reject() );
6139 execute( TC_sgsap_lu_and_nothing() );
6140 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01006141 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01006142 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01006143 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01006144 execute( TC_sgsap_paging_rej() );
6145 execute( TC_sgsap_paging_subscr_rej() );
6146 execute( TC_sgsap_paging_ue_unr() );
6147 execute( TC_sgsap_paging_and_nothing() );
6148 execute( TC_sgsap_paging_and_lu() );
6149 execute( TC_sgsap_mt_sms() );
6150 execute( TC_sgsap_mo_sms() );
6151 execute( TC_sgsap_mt_sms_and_nothing() );
6152 execute( TC_sgsap_mt_sms_and_reject() );
6153 execute( TC_sgsap_unexp_ud() );
6154 execute( TC_sgsap_unsol_ud() );
6155 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
6156 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02006157 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01006158
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006159 execute( TC_ho_inter_bsc_unknown_cell() );
6160 execute( TC_ho_inter_bsc() );
6161
6162 execute( TC_ho_inter_msc_out() );
6163
Oliver Smith1d118ff2019-07-03 10:57:35 +02006164 execute( TC_lu_imsi_auth_tmsi_check_imei() );
6165 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
6166 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
6167 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
6168 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
6169 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
6170 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
6171 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
6172 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
6173 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
6174 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
6175 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
6176
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01006177 /* Run this last: at the time of writing this test crashes the MSC */
6178 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02006179 execute( TC_mo_cc_bssmap_clear() );
Pau Espin Pedrol690d6592019-05-31 17:56:32 +02006180 if (mp_enable_osmux_test) {
6181 execute( TC_lu_and_mt_call_osmux() );
6182 }
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006183 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006184 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006185 execute( TC_lu_and_expire_while_paging() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01006186}
6187
6188
6189}