blob: 6b2b2597ac1bb996e9f7fd8b249985d8aadc3896 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
3import from General_Types all;
4import from Osmocom_Types all;
5
6import from M3UA_Types all;
7import from M3UA_Emulation all;
8
9import from MTP3asp_Types all;
10import from MTP3asp_PortType all;
11
12import from SCCPasp_Types all;
13import from SCCP_Types all;
14import from SCCP_Emulation all;
15
16import from SCTPasp_Types all;
17import from SCTPasp_PortType all;
18
Harald Weltea49e36e2018-01-21 19:29:33 +010019import from Osmocom_CTRL_Functions all;
20import from Osmocom_CTRL_Types all;
21import from Osmocom_CTRL_Adapter all;
22
Harald Welte3ca1c902018-01-24 18:51:27 +010023import from TELNETasp_PortType all;
24import from Osmocom_VTY_Functions all;
25
Harald Weltea49e36e2018-01-21 19:29:33 +010026import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010027import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010028
Harald Welte4aa970c2018-01-26 10:38:09 +010029import from MGCP_Emulation all;
30import from MGCP_Types all;
31import from MGCP_Templates all;
32import from SDP_Types all;
33
Harald Weltea49e36e2018-01-21 19:29:33 +010034import from GSUP_Emulation all;
35import from GSUP_Types all;
36import from IPA_Emulation all;
37
Harald Weltef6dd64d2017-11-19 12:09:51 +010038import from BSSAP_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010039import from BSSAP_Adapter all;
40import from BSSAP_CodecPort all;
41import from BSSMAP_Templates all;
42import from BSSMAP_Emulation all;
43import from BSC_ConnectionHandler all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010044
Harald Welte4263c522018-12-06 11:56:27 +010045import from SGsAP_Templates all;
46import from SGsAP_Types all;
47import from SGsAP_Emulation all;
48
Harald Weltea49e36e2018-01-21 19:29:33 +010049import from MobileL3_Types all;
50import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070051import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010052import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010053import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010054
Harald Weltef640a012018-04-14 17:49:21 +020055import from SMPP_Types all;
56import from SMPP_Templates all;
57import from SMPP_Emulation all;
58
Stefan Sperlingc307e682018-06-14 15:15:46 +020059import from SCCP_Templates all;
60
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070061import from SS_Types all;
62import from SS_Templates all;
63import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010064import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070065
Philipp Maier75932982018-03-27 14:52:35 +020066const integer NUM_BSC := 2;
67type record of BSSAP_Configuration BSSAP_Configurations;
Harald Weltef6dd64d2017-11-19 12:09:51 +010068
Harald Welte4263c522018-12-06 11:56:27 +010069/* Needed for SGsAP SMS */
70import from MobileL3_SMS_Types all;
71
Harald Weltea4ca4462018-02-09 00:17:14 +010072type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010073 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010074
Philipp Maier75932982018-03-27 14:52:35 +020075 var BSSAP_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010076
Harald Weltea49e36e2018-01-21 19:29:33 +010077 /* no 'adapter_CT' for MNCC or GSUP */
78 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010079 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010080 var GSUP_Emulation_CT vc_GSUP;
81 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020082 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +010083 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +010084
85 /* only to get events from IPA underneath GSUP */
86 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +010087 /* VTY to MSC */
88 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +010089
90 /* A port to directly send BSSAP messages. This port is used for
91 * tests that require low level access to sen arbitrary BSSAP
92 * messages. Run f_init_bssap_direct() to connect and initialize */
93 port BSSAP_CODEC_PT BSSAP_DIRECT;
94
95 /* When BSSAP messages are directly sent, then the connection
96 * handler is not active, which means that also no guard timer is
97 * set up. The following timer will serve as a replacement */
98 timer Tguard_direct := 60.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +010099}
100
101modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100102 /* remote parameters of IUT */
103 charstring mp_msc_ip := "127.0.0.1";
104 integer mp_msc_ctrl_port := 4255;
105 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100106
Harald Weltea49e36e2018-01-21 19:29:33 +0100107 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100108 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100109 charstring mp_hlr_ip := "127.0.0.1";
110 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100111 charstring mp_mgw_ip := "127.0.0.1";
112 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100113
Harald Weltea49e36e2018-01-21 19:29:33 +0100114 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100115
Harald Weltef640a012018-04-14 17:49:21 +0200116 integer mp_msc_smpp_port := 2775;
117 charstring mp_smpp_system_id := "msc_tester";
118 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100119 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
120 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200121
Philipp Maier75932982018-03-27 14:52:35 +0200122 BSSAP_Configurations mp_bssap_cfg := {
123 {
124 sccp_service_type := "mtp3_itu",
125 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
126 own_pc := 185,
127 own_ssn := 254,
128 peer_pc := 187,
129 peer_ssn := 254,
130 sio := '83'O,
131 rctx := 0
132 },
133 {
134 sccp_service_type := "mtp3_itu",
135 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
136 own_pc := 186,
137 own_ssn := 254,
138 peer_pc := 187,
139 peer_ssn := 254,
140 sio := '83'O,
141 rctx := 1
142 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100143 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100144}
145
Philipp Maier328d1662018-03-07 10:40:27 +0100146/* altstep for the global guard timer (only used when BSSAP_DIRECT
147 * is used for communication */
148private altstep as_Tguard_direct() runs on MTC_CT {
149 [] Tguard_direct.timeout {
150 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200151 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100152 }
153}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100154
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100155private altstep as_optional_cc_rel(CallParameters cpars) runs on BSC_ConnHdlr {
156 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) { repeat; };
157}
158
Harald Weltef640a012018-04-14 17:49:21 +0200159function f_init_smpp(charstring id) runs on MTC_CT {
160 id := id & "-SMPP";
161 var EsmePars pars := {
162 mode := MODE_TRANSCEIVER,
163 bind := {
164 system_id := mp_smpp_system_id,
165 password := mp_smpp_password,
166 system_type := "MSC_Tests",
167 interface_version := hex2int('34'H),
168 addr_ton := unknown,
169 addr_npi := unknown,
170 address_range := ""
171 },
172 esme_role := true
173 }
174
175 vc_SMPP := SMPP_Emulation_CT.create(id);
176 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
177 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", -1));
178}
179
180
Harald Weltea49e36e2018-01-21 19:29:33 +0100181function f_init_mncc(charstring id) runs on MTC_CT {
182 id := id & "-MNCC";
183 var MnccOps ops := {
184 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
185 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
186 }
187
188 vc_MNCC := MNCC_Emulation_CT.create(id);
189 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
190 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100191}
192
Harald Welte4aa970c2018-01-26 10:38:09 +0100193function f_init_mgcp(charstring id) runs on MTC_CT {
194 id := id & "-MGCP";
195 var MGCPOps ops := {
196 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
197 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
198 }
199 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100200 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100201 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100202 mgw_ip := mp_mgw_ip,
203 mgw_udp_port := mp_mgw_port
Harald Welte4aa970c2018-01-26 10:38:09 +0100204 }
205
206 vc_MGCP := MGCP_Emulation_CT.create(id);
207 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
208 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
209}
210
Harald Welte4263c522018-12-06 11:56:27 +0100211function f_init_sgsap(charstring id) runs on MTC_CT {
212 id := id & "-SGsAP";
213 var SGsAPOps ops := {
214 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
215 unitdata_cb := refers(SGsAP_Emulation.DummyUnitdataCallback)
216 }
217 var SGsAP_conn_parameters pars := {
218 remote_ip := mp_msc_ip,
219 remote_sctp_port := 29118,
220 local_ip := "",
221 local_sctp_port := -1
222 }
223
224 vc_SGsAP := SGsAP_Emulation_CT.create(id);
225 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
226 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
227}
228
229
Harald Weltea49e36e2018-01-21 19:29:33 +0100230function f_init_gsup(charstring id) runs on MTC_CT {
231 id := id & "-GSUP";
232 var GsupOps ops := {
233 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
234 }
235
236 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
237 vc_GSUP := GSUP_Emulation_CT.create(id);
238
239 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
240 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
241 /* we use this hack to get events like ASP_IPA_EVENT_UP */
242 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
243
244 vc_GSUP.start(GSUP_Emulation.main(ops, id));
245 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
246
247 /* wait for incoming connection to GSUP port before proceeding */
248 timer T := 10.0;
249 T.start;
250 alt {
251 [] GSUP_IPA_EVENT.receive(t_ASP_IPA_EVT_UD(ASP_IPA_EVENT_UP)) { }
252 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100253 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200254 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100255 }
256 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100257}
258
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100259function f_init(integer num_bsc := 1, boolean sgsap := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100260
261 if (g_initialized == true) {
262 return;
263 }
264 g_initialized := true;
265
Philipp Maier75932982018-03-27 14:52:35 +0200266 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200267 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200268 }
269
270 for (var integer i := 0; i < num_bsc; i := i + 1) {
271 if (isbound(mp_bssap_cfg[i])) {
Philipp Maierdefd9482018-05-16 16:44:37 +0200272 f_bssap_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), BSC_BssmapOps);
Harald Welted5833a82018-05-27 16:52:56 +0200273 f_bssap_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200274 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200275 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200276 }
277 }
278
Harald Weltea49e36e2018-01-21 19:29:33 +0100279 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
280 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100281 f_init_mgcp("MSC_Test");
Harald Weltea49e36e2018-01-21 19:29:33 +0100282 f_init_gsup("MSC_Test");
Harald Weltef640a012018-04-14 17:49:21 +0200283 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100284
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100285 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100286 f_init_sgsap("MSC_Test");
287 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100288
289 map(self:MSCVTY, system:MSCVTY);
290 f_vty_set_prompts(MSCVTY);
291 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100292
293 /* set some defaults */
294 f_vty_config(MSCVTY, "network", "authentication optional");
295 f_vty_config(MSCVTY, "msc", "assign-tmsi");
296 f_vty_config(MSCVTY, "network", "encryption a5 0");
Harald Weltef6dd64d2017-11-19 12:09:51 +0100297}
298
Philipp Maier328d1662018-03-07 10:40:27 +0100299/* Initialize for a direct connection to BSSAP. This function is an alternative
300 * to f_init() when the high level functions of the BSC_ConnectionHandler are
301 * not needed. */
302function f_init_bssap_direct() runs on MTC_CT {
Philipp Maier75932982018-03-27 14:52:35 +0200303 f_bssap_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
304 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100305
306 /* Start guard timer and activate it as default */
307 Tguard_direct.start
308 activate(as_Tguard_direct());
309}
310
Harald Weltef6dd64d2017-11-19 12:09:51 +0100311template PDU_BSSAP ts_BSSAP_BSSMAP := {
312 discriminator := '0'B,
313 spare := '0000000'B,
314 dlci := omit,
315 lengthIndicator := 0, /* overwritten by codec */
316 pdu := ?
317}
318
319template PDU_BSSAP tr_BSSAP_BSSMAP := {
320 discriminator := '0'B,
321 spare := '0000000'B,
322 dlci := omit,
323 lengthIndicator := ?,
324 pdu := {
325 bssmap := ?
326 }
327}
328
329
330type integer BssmapCause;
331
332template (value) BSSMAP_IE_Cause ts_BSSMAP_IE_Cause(BssmapCause val) := {
333 elementIdentifier := '04'O,
334 lengthIndicator := 0,
335 causeValue := int2bit(val, 7),
336 extensionCauseValue := '0'B,
337 spare1 := omit
338}
339
340template (value) PDU_BSSAP ts_BSSMAP_Reset(BssmapCause cause) modifies ts_BSSAP_BSSMAP := {
341 pdu := {
342 bssmap := {
343 reset := {
344 messageType := '30'O,
345 cause := ts_BSSMAP_IE_Cause(cause),
346 a_InterfaceSelectorForReset := omit
347 }
348 }
349 }
350}
351
352template (value) PDU_BSSAP ts_BSSMAP_ResetAck modifies ts_BSSAP_BSSMAP := {
353 pdu := {
354 bssmap := {
355 resetAck := {
356 messageType := '31'O,
357 a_InterfaceSelectorForReset := omit
358 }
359 }
360 }
361}
362
363template PDU_BSSAP tr_BSSMAP_ResetAck modifies tr_BSSAP_BSSMAP := {
364 pdu := {
365 bssmap := {
366 resetAck := {
367 messageType := '31'O,
368 a_InterfaceSelectorForReset := *
369 }
370 }
371 }
372}
373
374template BSSMAP_IE_CellIdentifier ts_BSSMAP_IE_CellID := {
375 elementIdentifier := '05'O,
376 lengthIndicator := 0,
377 cellIdentifierDiscriminator := '0000'B,
378 spare1_4 := '0000'B,
379 cellIdentification := ?
380}
381
382type uint16_t BssmapLAC;
383type uint16_t BssmapCI;
384
385/*
386template BSSMAP_IE_CellIdentifier ts_CellId_CGI(mcc, mnc, lac, ci)
387modifies ts_BSSMAP_IE_CellID := {
388 cellIdentification := {
389 cI_LAC_CGI := {
390 mnc_mcc := FIXME,
391 lac := int2oct(lac, 2),
392 ci := int2oct(ci, 2)
393 }
394 }
395}
396*/
397
398template BSSMAP_IE_CellIdentifier ts_CellID_LAC_CI(BssmapLAC lac, BssmapCI ci)
399modifies ts_BSSMAP_IE_CellID := {
400 cellIdentification := {
401 cI_LAC_CI := {
402 lac := int2oct(lac, 2),
403 ci := int2oct(ci, 2)
404 }
405 }
406}
407
408template BSSMAP_IE_CellIdentifier ts_CellId_CI(BssmapCI ci)
409modifies ts_BSSMAP_IE_CellID := {
410 cellIdentification := {
411 cI_CI := int2oct(ci, 2)
412 }
413}
414
415template BSSMAP_IE_CellIdentifier ts_CellId_none
416modifies ts_BSSMAP_IE_CellID := {
417 cellIdentification := {
418 cI_noCell := ''O
419 }
420}
421
422
423template BSSMAP_IE_Layer3Information ts_BSSMAP_IE_L3Info(octetstring l3info) := {
424 elementIdentifier := '17'O,
425 lengthIndicator := 0,
426 layer3info := l3info
427}
428
429template PDU_BSSAP ts_BSSMAP_ComplL3(BSSMAP_IE_CellIdentifier cell_id, octetstring l3_info)
430modifies ts_BSSAP_BSSMAP := {
431 pdu := {
432 bssmap := {
433 completeLayer3Information := {
434 messageType := '57'O,
435 cellIdentifier := cell_id,
436 layer3Information := ts_BSSMAP_IE_L3Info(l3_info),
437 chosenChannel := omit,
438 lSAIdentifier := omit,
439 aPDU := omit,
440 codecList := omit,
441 redirectAttemptFlag := omit,
442 sendSequenceNumber := omit,
443 iMSI := omit
444 }
445 }
446 }
447}
448
449template PDU_BSSAP ts_BSSMAP_HandoReq(BssmapCause cause, BSSMAP_IE_CellIdentifierList cid_list)
450modifies ts_BSSAP_BSSMAP := {
451 pdu := {
452 bssmap := {
453 handoverRequired := {
454 messageType := '11'O,
455 cause := ts_BSSMAP_IE_Cause(cause),
456 responseRequest := omit,
457 cellIdentifierList := cid_list,
458 circuitPoolList := omit,
459 currentChannelType1 := omit,
460 speechVersion := omit,
461 queueingIndicator := omit,
462 oldToNewBSSInfo := omit,
463 sourceToTargetRNCTransparentInfo := omit,
464 sourceToTargetRNCTransparentInfoCDMA := omit,
465 gERANClassmark := omit,
466 talkerPriority := omit,
467 speechCodec := omit,
468 cSG_Identifier := omit
469 }
470 }
471 }
472}
473
Harald Weltea49e36e2018-01-21 19:29:33 +0100474type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100475
Harald Weltea49e36e2018-01-21 19:29:33 +0100476/* FIXME: move into BSC_ConnectionHandler? */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100477function f_init_pars(integer imsi_suffix, boolean sgsap := false) runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100478 var BSC_ConnHdlrNetworkPars net_pars := {
479 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
480 expect_tmsi := true,
481 expect_auth := false,
482 expect_ciph := false
483 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100484 var BSC_ConnHdlrPars pars := {
Philipp Maier75932982018-03-27 14:52:35 +0200485 sccp_addr_own := g_bssap[0].sccp_addr_own,
486 sccp_addr_peer := g_bssap[0].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100487 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100488 imei := f_gen_imei(imsi_suffix),
489 imsi := f_gen_imsi(imsi_suffix),
490 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100491 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100492 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100493 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100494 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100495 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100496 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100497 send_early_cm := true,
498 ipa_ctrl_ip := mp_msc_ip,
499 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100500 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100501 mm_info := mp_mm_info,
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100502 sgsap_enable := sgsap
Harald Weltea49e36e2018-01-21 19:29:33 +0100503 };
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100504 return pars;
505}
506
507function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
508 var BSC_ConnHdlr vc_conn;
509 var charstring id := testcasename();
Harald Weltea49e36e2018-01-21 19:29:33 +0100510
511 vc_conn := BSC_ConnHdlr.create(id);
512 /* BSSMAP part / A interface */
Philipp Maier75932982018-03-27 14:52:35 +0200513 connect(vc_conn:BSSAP, g_bssap[0].vc_BSSMAP:CLIENT);
514 connect(vc_conn:BSSAP_PROC, g_bssap[0].vc_BSSMAP:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100515 /* MNCC part */
516 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
517 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100518 /* MGCP part */
519 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
520 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100521 /* GSUP part */
522 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
523 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
Harald Weltef640a012018-04-14 17:49:21 +0200524 /* SMPP part */
525 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
526 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100527 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100528 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100529 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
530 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
531 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100532
Harald Weltea10db902018-01-27 12:44:49 +0100533 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
534 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100535 vc_conn.start(derefers(fn)(id, pars));
536 return vc_conn;
537}
538
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100539function f_start_handler(void_fn fn, integer imsi_suffix) runs on MTC_CT return BSC_ConnHdlr {
540 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix));
541}
542
Harald Weltea49e36e2018-01-21 19:29:33 +0100543private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100544 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100545 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100546}
Harald Weltea49e36e2018-01-21 19:29:33 +0100547testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
548 var BSC_ConnHdlr vc_conn;
549 f_init();
550
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100551 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100552 vc_conn.done;
553}
554
555private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100556 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100557 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100558 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100559}
Harald Weltea49e36e2018-01-21 19:29:33 +0100560testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
561 var BSC_ConnHdlr vc_conn;
562 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100563 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100564
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100565 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100566 vc_conn.done;
567}
568
569/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
570private function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100571 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100572 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
573
574 f_create_gsup_expect(hex2str(g_pars.imsi));
575 f_bssap_compl_l3(l3_lu);
576 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
577 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
578 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100579 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
580 f_expect_clear();
581 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100582 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
583 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200584 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100585 }
586 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100587}
588testcase TC_lu_imsi_reject() runs on MTC_CT {
589 var BSC_ConnHdlr vc_conn;
590 f_init();
591
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100592 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3);
Harald Weltea49e36e2018-01-21 19:29:33 +0100593 vc_conn.done;
594}
595
596/* Do LU by IMSI, timeout on GSUP */
597private function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100598 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100599 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
600
601 f_create_gsup_expect(hex2str(g_pars.imsi));
602 f_bssap_compl_l3(l3_lu);
603 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
604 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
605 alt {
606 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100607 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
608 f_expect_clear();
609 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100610 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
611 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200612 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100613 }
614 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100615}
616testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
617 var BSC_ConnHdlr vc_conn;
618 f_init();
619
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100620 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4);
Harald Weltea49e36e2018-01-21 19:29:33 +0100621 vc_conn.done;
622}
623
Harald Welte7b1b2812018-01-22 21:23:06 +0100624private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100625 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100626 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100627 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100628}
629testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
630 var BSC_ConnHdlr vc_conn;
631 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100632 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100633
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100634 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100635 vc_conn.done;
636}
637
Harald Weltea49e36e2018-01-21 19:29:33 +0100638
639/* Send CM SERVICE REQ for IMSI that has never performed LU before */
640private function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
641runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100642 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100643
644 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100645 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100646 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100647
648 f_create_gsup_expect(hex2str(g_pars.imsi));
649
650 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
651 f_bssap_compl_l3(l3_info);
652
653 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100654 T.start;
655 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100656 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
657 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200658 [] BSSAP.receive {
659 setverdict(fail, "Received unexpected BSSAP");
660 mtc.stop;
661 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100662 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
663 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200664 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100665 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200666 [] T.timeout {
667 setverdict(fail, "Timeout waiting for CM SERV REQ");
668 mtc.stop;
669 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100670 }
671
Harald Welte1ddc7162018-01-27 14:25:46 +0100672 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100673}
Harald Weltea49e36e2018-01-21 19:29:33 +0100674testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
675 var BSC_ConnHdlr vc_conn;
676 f_init();
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100677 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6);
Harald Weltea49e36e2018-01-21 19:29:33 +0100678 vc_conn.done;
679}
680
Harald Welte2bb825f2018-01-22 11:31:18 +0100681private function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100682 f_init_handler(pars);
Harald Welteb71901a2018-01-26 19:16:05 +0100683 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
684 cpars.bss_rtp_port := 1110;
685 cpars.mgcp_connection_id_bss := '22222'H;
686 cpars.mgcp_connection_id_mss := '33333'H;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100687 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte2bb825f2018-01-22 11:31:18 +0100688
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100689 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100690 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100691}
692testcase TC_lu_and_mo_call() runs on MTC_CT {
693 var BSC_ConnHdlr vc_conn;
694 f_init();
695
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100696 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100697 vc_conn.done;
698}
699
700/* Test LU (with authentication enabled), where HLR times out sending SAI response */
701private function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100702 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100703
704 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
705 var PDU_DTAP_MT dtap_mt;
706
707 /* tell GSUP dispatcher to send this IMSI to us */
708 f_create_gsup_expect(hex2str(g_pars.imsi));
709
710 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
711 f_bssap_compl_l3(l3_lu);
712
713 /* Send Early Classmark, just for the fun of it */
714 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
715
716 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
717 /* The HLR would normally return an auth vector here, but we fail to do so. */
718
719 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100720 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100721}
722testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
723 var BSC_ConnHdlr vc_conn;
724 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100725 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100726
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100727 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8);
Harald Welte071ed732018-01-23 19:53:52 +0100728 vc_conn.done;
729}
730
731/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
732private function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100733 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100734
735 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
736 var PDU_DTAP_MT dtap_mt;
737
738 /* tell GSUP dispatcher to send this IMSI to us */
739 f_create_gsup_expect(hex2str(g_pars.imsi));
740
741 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
742 f_bssap_compl_l3(l3_lu);
743
744 /* Send Early Classmark, just for the fun of it */
745 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
746
747 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
748 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
749
750 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100751 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100752}
753testcase TC_lu_auth_sai_err() runs on MTC_CT {
754 var BSC_ConnHdlr vc_conn;
755 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100756 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100757
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100758 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9);
Harald Welte2bb825f2018-01-22 11:31:18 +0100759 vc_conn.done;
760}
Harald Weltea49e36e2018-01-21 19:29:33 +0100761
Harald Weltebc881782018-01-23 20:09:15 +0100762/* Test LU but BSC will send a clear request in the middle */
763private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100764 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100765
766 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
767 var PDU_DTAP_MT dtap_mt;
768
769 /* tell GSUP dispatcher to send this IMSI to us */
770 f_create_gsup_expect(hex2str(g_pars.imsi));
771
772 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
773 f_bssap_compl_l3(l3_lu);
774
775 /* Send Early Classmark, just for the fun of it */
776 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
777
778 f_sleep(1.0);
779 /* send clear request in the middle of the LU */
780 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200781 alt {
782 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
783 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
784 }
Harald Weltebc881782018-01-23 20:09:15 +0100785 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100786 alt {
787 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200788 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
789 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200790 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200791 repeat;
792 }
Harald Welte89a32492018-01-27 19:07:28 +0100793 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
794 }
Harald Weltebc881782018-01-23 20:09:15 +0100795 setverdict(pass);
796}
797testcase TC_lu_clear_request() runs on MTC_CT {
798 var BSC_ConnHdlr vc_conn;
799 f_init();
800
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100801 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100802 vc_conn.done;
803}
804
Harald Welte66af9e62018-01-24 17:28:21 +0100805/* Test LU but BSC will send a clear request in the middle */
806private function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100807 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100808
809 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
810 var PDU_DTAP_MT dtap_mt;
811
812 /* tell GSUP dispatcher to send this IMSI to us */
813 f_create_gsup_expect(hex2str(g_pars.imsi));
814
815 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
816 f_bssap_compl_l3(l3_lu);
817
818 /* Send Early Classmark, just for the fun of it */
819 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
820
821 f_sleep(1.0);
822 /* send clear request in the middle of the LU */
823 BSSAP.send(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
824 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +0100825 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +0100826}
827testcase TC_lu_disconnect() runs on MTC_CT {
828 var BSC_ConnHdlr vc_conn;
829 f_init();
830
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100831 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100832 vc_conn.done;
833}
834
835
Harald Welteba7b6d92018-01-23 21:32:34 +0100836/* Test LU but with illegal mobile identity type = IMEI */
837private function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100838 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100839
Harald Welte256571e2018-01-24 18:47:19 +0100840 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100841 var PDU_DTAP_MT dtap_mt;
842
843 /* tell GSUP dispatcher to send this IMSI to us */
844 f_create_gsup_expect(hex2str(g_pars.imsi));
845
846 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
847 f_bssap_compl_l3(l3_lu);
848
849 /* Send Early Classmark, just for the fun of it */
850 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
851 /* wait for LU reject, ignore any ID REQ */
852 alt {
853 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
854 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
855 }
856 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100857 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100858}
859testcase TC_lu_by_imei() runs on MTC_CT {
860 var BSC_ConnHdlr vc_conn;
861 f_init();
862
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100863 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12);
Harald Welteba7b6d92018-01-23 21:32:34 +0100864 vc_conn.done;
865}
866
867/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
868private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200869 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
870 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100871 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100872
873 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
874 var PDU_DTAP_MT dtap_mt;
875
876 /* tell GSUP dispatcher to send this IMSI to us */
877 f_create_gsup_expect(hex2str(g_pars.imsi));
878
879 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
880 f_bssap_compl_l3(l3_lu);
881
882 /* Send Early Classmark, just for the fun of it */
883 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
884
885 /* Wait for + respond to ID REQ (IMSI) */
886 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req('001'B)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200887 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100888 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
889
890 /* Expect MSC to do UpdateLocation to HLR; respond to it */
891 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
892 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
893 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
894 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
895
896 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100897 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
898 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
899 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100900 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
901 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200902 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +0100903 }
904 }
905
Philipp Maier9b690e42018-12-21 11:50:03 +0100906 /* Wait for MM-Information (if enabled) */
907 f_expect_mm_info();
908
Harald Welteba7b6d92018-01-23 21:32:34 +0100909 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100910 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100911}
912testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
913 var BSC_ConnHdlr vc_conn;
914 f_init();
915
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100916 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100917 vc_conn.done;
918}
919
920
Harald Welte45164da2018-01-24 12:51:27 +0100921/* Test IMSI DETACH (MI=IMSI) */
922private function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100923 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100924
925 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
926
927 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
928 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
929
930 /* Send Early Classmark, just for the fun of it? */
931 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
932
933 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100934 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100935}
936testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
937 var BSC_ConnHdlr vc_conn;
938 f_init();
939
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100940 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14);
Harald Welte45164da2018-01-24 12:51:27 +0100941 vc_conn.done;
942}
943
944/* Test IMSI DETACH (MI=TMSI) */
945private function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100946 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100947
948 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
949
950 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
951 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
952
953 /* Send Early Classmark, just for the fun of it? */
954 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
955
956 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100957 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100958}
959testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
960 var BSC_ConnHdlr vc_conn;
961 f_init();
962
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100963 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15);
Harald Welte45164da2018-01-24 12:51:27 +0100964 vc_conn.done;
965}
966
967/* Test IMSI DETACH (MI=IMEI), which is illegal */
968private function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100969 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100970
Harald Welte256571e2018-01-24 18:47:19 +0100971 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +0100972
973 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
974 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
975
976 /* Send Early Classmark, just for the fun of it? */
977 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
978
979 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100980 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100981}
982testcase TC_imsi_detach_by_imei() runs on MTC_CT {
983 var BSC_ConnHdlr vc_conn;
984 f_init();
985
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100986 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16);
Harald Welte45164da2018-01-24 12:51:27 +0100987 vc_conn.done;
988}
989
990
991/* helper function for an emergency call. caller passes in mobile identity to use */
992private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +0100993 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
994 cpars.emergency := true;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100995 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte45164da2018-01-24 12:51:27 +0100996
Harald Welte0bef21e2018-02-10 09:48:23 +0100997 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +0100998}
999
1000/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
1001private function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001002 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001003
Harald Welte256571e2018-01-24 18:47:19 +01001004 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001005 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001006 f_bssap_compl_l3(l3_info);
1007 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001008 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001009}
1010testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1011 var BSC_ConnHdlr vc_conn;
1012 f_init();
1013
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001014 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17);
Harald Welte45164da2018-01-24 12:51:27 +01001015 vc_conn.done;
1016}
1017
Harald Welted5b91402018-01-24 18:48:16 +01001018/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Welte45164da2018-01-24 12:51:27 +01001019private function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001020 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001021 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001022 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001023 /* Then issue emergency call identified by IMSI */
1024 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1025}
1026testcase TC_emerg_call_imsi() runs on MTC_CT {
1027 var BSC_ConnHdlr vc_conn;
1028 f_init();
1029
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001030 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001031 vc_conn.done;
1032}
1033
1034/* CM Service Request for VGCS -> reject */
1035private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001036 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001037
1038 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001039 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001040
1041 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001042 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001043 f_bssap_compl_l3(l3_info);
1044 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001045 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001046}
1047testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1048 var BSC_ConnHdlr vc_conn;
1049 f_init();
1050
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001051 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001052 vc_conn.done;
1053}
1054
1055/* CM Service Request for VBS -> reject */
1056private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001057 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001058
1059 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001060 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001061
1062 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001063 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001064 f_bssap_compl_l3(l3_info);
1065 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001066 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001067}
1068testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1069 var BSC_ConnHdlr vc_conn;
1070 f_init();
1071
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001072 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001073 vc_conn.done;
1074}
1075
1076/* CM Service Request for LCS -> reject */
1077private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001078 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001079
1080 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001081 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001082
1083 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001084 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001085 f_bssap_compl_l3(l3_info);
1086 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001087 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001088}
1089testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1090 var BSC_ConnHdlr vc_conn;
1091 f_init();
1092
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001093 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001094 vc_conn.done;
1095}
1096
Harald Welte0195ab12018-01-24 21:50:20 +01001097/* CM Re-Establishment Request */
1098private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001099 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001100
1101 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001102 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001103
1104 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1105 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
1106 f_bssap_compl_l3(l3_info);
1107 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001108 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001109}
1110testcase TC_cm_reest_req_reject() runs on MTC_CT {
1111 var BSC_ConnHdlr vc_conn;
1112 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001113
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001114 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001115 vc_conn.done;
1116}
1117
Harald Weltec638f4d2018-01-24 22:00:36 +01001118/* Test LU (with authentication enabled), with wrong response from MS */
1119private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001120 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001121
1122 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1123
1124 /* tell GSUP dispatcher to send this IMSI to us */
1125 f_create_gsup_expect(hex2str(g_pars.imsi));
1126
1127 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1128 f_bssap_compl_l3(l3_lu);
1129
1130 /* Send Early Classmark, just for the fun of it */
1131 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1132
1133 var AuthVector vec := f_gen_auth_vec_2g();
1134 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1135 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1136 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1137
1138 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1139 /* Send back wrong auth response */
1140 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1141
1142 /* Expect GSUP AUTH FAIL REP to HLR */
1143 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1144
1145 /* Expect LU REJECT with Cause == Illegal MS */
1146 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001147 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001148}
1149testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1150 var BSC_ConnHdlr vc_conn;
1151 f_init();
1152 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001153
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001154 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23);
Harald Weltec638f4d2018-01-24 22:00:36 +01001155 vc_conn.done;
1156}
1157
Harald Weltede371492018-01-27 23:44:41 +01001158/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001159private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001160 pars.net.expect_auth := true;
1161 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001162 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001163 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001164}
1165testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1166 var BSC_ConnHdlr vc_conn;
1167 f_init();
1168 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001169 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1170
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001171 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001172 vc_conn.done;
1173}
1174
Harald Welte1af6ea82018-01-25 18:33:15 +01001175/* Test Complete L3 without payload */
1176private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001177 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001178
1179 /* Send Complete L3 Info with empty L3 frame */
1180 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1181 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1182
Harald Weltef466eb42018-01-27 14:26:54 +01001183 timer T := 5.0;
1184 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001185 alt {
1186 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
1187 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001188 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
1189 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001190 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001191 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001192 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001193 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001194 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001195 }
1196 setverdict(pass);
1197}
1198testcase TC_cl3_no_payload() runs on MTC_CT {
1199 var BSC_ConnHdlr vc_conn;
1200 f_init();
1201
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001202 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001203 vc_conn.done;
1204}
1205
1206/* Test Complete L3 with random payload */
1207private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001208 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001209
Daniel Willmannaa14a382018-07-26 08:29:45 +02001210 /* length is limited by PDU_BSSAP length field which includes some
1211 * other fields beside l3info payload. So payl can only be 240 bytes
1212 * Since rnd() returns values < 1 multiply with 241
1213 */
1214 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001215 var octetstring payl := f_rnd_octstring(len);
1216
1217 /* Send Complete L3 Info with empty L3 frame */
1218 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1219 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1220
Harald Weltef466eb42018-01-27 14:26:54 +01001221 timer T := 5.0;
1222 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001223 alt {
1224 /* Immediate disconnect */
1225 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001226 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Weltebdb3c452018-03-18 22:43:06 +01001227 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001228 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001229 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001230 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001231 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001232 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001233 }
1234 setverdict(pass);
1235}
1236testcase TC_cl3_rnd_payload() runs on MTC_CT {
1237 var BSC_ConnHdlr vc_conn;
1238 f_init();
1239
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001240 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001241 vc_conn.done;
1242}
1243
Harald Welte116e4332018-01-26 22:17:48 +01001244/* Test Complete L3 with random payload */
1245private function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001246 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001247
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001248 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001249
Harald Welteb9e86fa2018-04-09 18:18:31 +02001250 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001251 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001252}
1253testcase TC_establish_and_nothing() runs on MTC_CT {
1254 var BSC_ConnHdlr vc_conn;
1255 f_init();
1256
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001257 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001258 vc_conn.done;
1259}
1260
Harald Welte12510c52018-01-26 22:26:24 +01001261/* Test MO Call SETUP with no response from MNCC */
1262private function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001263 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001264
Harald Welte12510c52018-01-26 22:26:24 +01001265 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1266
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001267 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001268
Harald Welteb9e86fa2018-04-09 18:18:31 +02001269 f_establish_fully();
Harald Welte12510c52018-01-26 22:26:24 +01001270 f_create_mncc_expect(hex2str(cpars.called_party));
1271 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1272
1273 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1274
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001275 var default ccrel := activate(as_optional_cc_rel(cpars));
1276
Philipp Maier109e6aa2018-10-17 10:53:32 +02001277 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001278
1279 deactivate(ccrel);
1280
1281 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001282}
1283testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1284 var BSC_ConnHdlr vc_conn;
1285 f_init();
1286
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001287 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001288 vc_conn.done;
1289}
1290
Harald Welte3ab88002018-01-26 22:37:25 +01001291/* Test MO Call with no response to RAN-side CRCX */
1292private function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001293 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001294 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1295 var MNCC_PDU mncc;
1296 var MgcpCommand mgcp_cmd;
1297
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001298 f_perform_lu();
Harald Welte3ab88002018-01-26 22:37:25 +01001299
Harald Welteb9e86fa2018-04-09 18:18:31 +02001300 f_establish_fully();
Harald Welte3ab88002018-01-26 22:37:25 +01001301 f_create_mncc_expect(hex2str(cpars.called_party));
1302 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1303
1304 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1305 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1306 cpars.mncc_callref := mncc.u.signal.callref;
1307 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1308 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1309
1310 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Harald Welte1852a842018-01-26 22:53:36 +01001311 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1312 cpars.mgcp_ep := mgcp_cmd.line.ep;
Harald Welte3ab88002018-01-26 22:37:25 +01001313 /* never respond to this */
1314
Philipp Maier8e58f592018-03-14 11:10:56 +01001315 /* When the connection with the MGW fails, the MSC will first request
1316 * a release via call control. We will answer this request normally. */
1317 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1318 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1319
Harald Welte1ddc7162018-01-27 14:25:46 +01001320 f_expect_clear(30.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001321}
1322testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1323 var BSC_ConnHdlr vc_conn;
1324 f_init();
1325
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001326 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001327 vc_conn.done;
1328}
1329
Harald Welte0cc82d92018-01-26 22:52:34 +01001330/* Test MO Call with reject to RAN-side CRCX */
1331private function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001332 f_init_handler(pars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001333 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1334 var MNCC_PDU mncc;
1335 var MgcpCommand mgcp_cmd;
1336
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001337 f_perform_lu();
Harald Welte0cc82d92018-01-26 22:52:34 +01001338
Harald Welteb9e86fa2018-04-09 18:18:31 +02001339 f_establish_fully();
Harald Welte0cc82d92018-01-26 22:52:34 +01001340 f_create_mncc_expect(hex2str(cpars.called_party));
1341 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1342
1343 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1344 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1345 cpars.mncc_callref := mncc.u.signal.callref;
1346 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1347 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1348
1349 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001350
1351 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1352 * set an endpoint name that fits the pattern. If not, just use the
1353 * endpoint name from the request */
1354 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1355 cpars.mgcp_ep := "rtpbridge/1@mgw";
1356 } else {
1357 cpars.mgcp_ep := mgcp_cmd.line.ep;
1358 }
1359
Harald Welte0cc82d92018-01-26 22:52:34 +01001360 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001361
Harald Welte0cc82d92018-01-26 22:52:34 +01001362 /* Respond to CRCX with error */
1363 var MgcpResponse mgcp_rsp := {
1364 line := {
1365 code := "542",
1366 trans_id := mgcp_cmd.line.trans_id,
1367 string := "FORCED_FAIL"
1368 },
Harald Welte0cc82d92018-01-26 22:52:34 +01001369 sdp := omit
1370 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001371 var MgcpParameter mgcp_rsp_param := {
1372 code := "Z",
1373 val := cpars.mgcp_ep
1374 };
1375 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte0cc82d92018-01-26 22:52:34 +01001376 MGCP.send(mgcp_rsp);
1377
1378 timer T := 30.0;
1379 T.start;
1380 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001381 [] T.timeout {
1382 setverdict(fail, "Timeout waiting for channel release");
1383 mtc.stop;
1384 }
Daniel Willmann5868e622018-02-15 17:42:59 +01001385 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
1386 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1387 repeat;
1388 }
Harald Welte0cc82d92018-01-26 22:52:34 +01001389 [] MNCC.receive { repeat; }
1390 [] GSUP.receive { repeat; }
Philipp Maierc6e06f72018-04-11 18:12:23 +02001391 /* Note: As we did not respond properly to the CRCX from the MSC we
1392 * expect the MSC to omit any further MGCP operation (At least in the
1393 * the current implementation, there is no recovery mechanism implemented
1394 * and a DLCX can not be performed as the MSC does not know a specific
1395 * endpoint yet. */
Daniel Willmannafce8662018-07-06 23:11:32 +02001396 [] MGCP.receive {
1397 setverdict(fail, "Unexpected MGCP message");
1398 mtc.stop;
1399 }
Harald Welte5946b332018-03-18 23:32:21 +01001400 [] as_clear_cmd_compl_disc();
Harald Welte0cc82d92018-01-26 22:52:34 +01001401 }
1402}
1403testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1404 var BSC_ConnHdlr vc_conn;
1405 f_init();
1406
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001407 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001408 vc_conn.done;
1409}
1410
Harald Welte3ab88002018-01-26 22:37:25 +01001411
Harald Welte812f7a42018-01-27 00:49:18 +01001412/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1413private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1414 var MNCC_PDU mncc;
1415 var MgcpCommand mgcp_cmd;
1416 var OCT4 tmsi;
1417
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001418 f_perform_lu();
Harald Welte812f7a42018-01-27 00:49:18 +01001419 if (isvalue(g_pars.tmsi)) {
1420 tmsi := g_pars.tmsi;
1421 } else {
1422 tmsi := 'FFFFFFFF'O;
1423 }
1424 f_bssmap_register_imsi(g_pars.imsi, tmsi);
1425
1426 /* Allocate call reference and send SETUP via MNCC to MSC */
1427 cpars.mncc_callref := f_rnd_int(2147483648);
1428 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1429 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1430
1431 /* MSC->BSC: expect PAGING from MSC */
1432 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
1433 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001434 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001435
1436 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1437
1438 /* MSC->MS: SETUP */
1439 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1440}
1441
1442/* Test MT Call */
1443private function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001444 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001445 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1446 var MNCC_PDU mncc;
1447 var MgcpCommand mgcp_cmd;
1448
1449 f_mt_call_start(cpars);
1450
1451 /* MS->MSC: CALL CONFIRMED */
1452 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1453
1454 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1455
1456 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1457 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001458
1459 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1460 * set an endpoint name that fits the pattern. If not, just use the
1461 * endpoint name from the request */
1462 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1463 cpars.mgcp_ep := "rtpbridge/1@mgw";
1464 } else {
1465 cpars.mgcp_ep := mgcp_cmd.line.ep;
1466 }
1467
Harald Welte812f7a42018-01-27 00:49:18 +01001468 /* Respond to CRCX with error */
1469 var MgcpResponse mgcp_rsp := {
1470 line := {
1471 code := "542",
1472 trans_id := mgcp_cmd.line.trans_id,
1473 string := "FORCED_FAIL"
1474 },
Harald Welte812f7a42018-01-27 00:49:18 +01001475 sdp := omit
1476 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001477 var MgcpParameter mgcp_rsp_param := {
1478 code := "Z",
1479 val := cpars.mgcp_ep
1480 };
1481 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001482 MGCP.send(mgcp_rsp);
1483
1484 timer T := 30.0;
1485 T.start;
1486 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001487 [] T.timeout {
1488 setverdict(fail, "Timeout waiting for channel release");
1489 mtc.stop;
1490 }
Harald Welte812f7a42018-01-27 00:49:18 +01001491 [] MNCC.receive { repeat; }
1492 [] GSUP.receive { repeat; }
1493 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1494 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1495 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1496 repeat;
1497 }
1498 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001499 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001500 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001501 }
1502}
1503testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1504 var BSC_ConnHdlr vc_conn;
1505 f_init();
1506
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001507 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001508 vc_conn.done;
1509}
1510
1511
1512/* Test MT Call T310 timer */
1513private function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001514 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001515 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1516 var MNCC_PDU mncc;
1517 var MgcpCommand mgcp_cmd;
1518
1519 f_mt_call_start(cpars);
1520
1521 /* MS->MSC: CALL CONFIRMED */
1522 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1523 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1524
1525 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1526 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1527 cpars.mgcp_ep := mgcp_cmd.line.ep;
1528 /* FIXME: Respond to CRCX */
1529
1530 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1531 timer T := 190.0;
1532 T.start;
1533 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001534 [] T.timeout {
1535 setverdict(fail, "Timeout waiting for T310");
1536 mtc.stop;
1537 }
Harald Welte812f7a42018-01-27 00:49:18 +01001538 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1539 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1540 }
1541 }
1542 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1543 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1544 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1545 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1546
1547 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001548 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1549 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1550 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1551 repeat;
1552 }
Harald Welte5946b332018-03-18 23:32:21 +01001553 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001554 }
1555}
1556testcase TC_mt_t310() runs on MTC_CT {
1557 var BSC_ConnHdlr vc_conn;
1558 f_init();
1559
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001560 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001561 vc_conn.done;
1562}
1563
Harald Welte167458a2018-01-27 15:58:16 +01001564/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
1565private function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1566 f_init_handler(pars);
1567 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1568 cpars.bss_rtp_port := 1110;
1569 cpars.mgcp_connection_id_bss := '22222'H;
1570 cpars.mgcp_connection_id_mss := '33333'H;
Daniel Willmann9b0235b2018-07-24 12:13:34 +02001571 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte167458a2018-01-27 15:58:16 +01001572
1573 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001574 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001575
1576 /* First MO call should succeed */
1577 f_mo_call(cpars);
1578
1579 /* Cancel the subscriber in the VLR */
1580 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1581 alt {
1582 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1583 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1584 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001585 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001586 }
1587 }
1588
1589 /* Follow-up transactions should fail */
1590 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1591 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
1592 f_bssap_compl_l3(l3_info);
1593 alt {
1594 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1595 [] BSSAP.receive {
1596 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001597 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001598 }
1599 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001600
1601 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001602 setverdict(pass);
1603}
1604testcase TC_gsup_cancel() runs on MTC_CT {
1605 var BSC_ConnHdlr vc_conn;
1606 f_init();
1607
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001608 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33);
Harald Welte167458a2018-01-27 15:58:16 +01001609 vc_conn.done;
1610}
1611
Harald Welte9de84792018-01-28 01:06:35 +01001612/* A5/1 only permitted on network side, and MS capable to do it */
1613private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1614 pars.net.expect_auth := true;
1615 pars.net.expect_ciph := true;
1616 pars.net.kc_support := '02'O; /* A5/1 only */
1617 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001618 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001619}
1620testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1621 var BSC_ConnHdlr vc_conn;
1622 f_init();
1623 f_vty_config(MSCVTY, "network", "authentication required");
1624 f_vty_config(MSCVTY, "network", "encryption a5 1");
1625
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001626 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001627 vc_conn.done;
1628}
1629
1630/* A5/3 only permitted on network side, and MS capable to do it */
1631private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1632 pars.net.expect_auth := true;
1633 pars.net.expect_ciph := true;
1634 pars.net.kc_support := '08'O; /* A5/3 only */
1635 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001636 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001637}
1638testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1639 var BSC_ConnHdlr vc_conn;
1640 f_init();
1641 f_vty_config(MSCVTY, "network", "authentication required");
1642 f_vty_config(MSCVTY, "network", "encryption a5 3");
1643
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001644 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001645 vc_conn.done;
1646}
1647
1648/* A5/3 only permitted on network side, and MS with only A5/1 support */
1649private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1650 pars.net.expect_auth := true;
1651 pars.net.expect_ciph := true;
1652 pars.net.kc_support := '08'O; /* A5/3 only */
1653 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1654 f_init_handler(pars, 15.0);
1655
1656 /* cannot use f_perform_lu() as we expect a reject */
1657 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1658 f_create_gsup_expect(hex2str(g_pars.imsi));
1659 f_bssap_compl_l3(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001660 if (pars.send_early_cm) {
1661 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1662 } else {
1663 pars.cm1.esind := '0'B;
1664 }
Harald Welte9de84792018-01-28 01:06:35 +01001665 f_mm_auth();
1666 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001667 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1668 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1669 repeat;
1670 }
Harald Welte5946b332018-03-18 23:32:21 +01001671 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1672 f_expect_clear();
1673 }
Harald Welte9de84792018-01-28 01:06:35 +01001674 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1675 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001676 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001677 }
1678 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001679 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001680 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001681 }
1682 }
1683 setverdict(pass);
1684}
1685testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1686 var BSC_ConnHdlr vc_conn;
1687 f_init();
1688 f_vty_config(MSCVTY, "network", "authentication required");
1689 f_vty_config(MSCVTY, "network", "encryption a5 3");
1690
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001691 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360);
1692 vc_conn.done;
1693}
1694testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1695 var BSC_ConnHdlrPars pars;
1696 var BSC_ConnHdlr vc_conn;
1697 f_init();
1698 f_vty_config(MSCVTY, "network", "authentication required");
1699 f_vty_config(MSCVTY, "network", "encryption a5 3");
1700
1701 pars := f_init_pars(361);
1702 pars.send_early_cm := false;
1703 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001704 vc_conn.done;
1705}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001706testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1707 var BSC_ConnHdlr vc_conn;
1708 f_init();
1709 f_vty_config(MSCVTY, "network", "authentication required");
1710 f_vty_config(MSCVTY, "network", "encryption a5 3");
1711
1712 /* Make sure the MSC category is on DEBUG level to trigger the log
1713 * message that is reported in OS#2947 to trigger the segfault */
1714 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1715
1716 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362);
1717 vc_conn.done;
1718}
Harald Welte9de84792018-01-28 01:06:35 +01001719
1720/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1721private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1722 pars.net.expect_auth := true;
1723 pars.net.expect_ciph := true;
1724 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1725 pars.cm1.a5_1 := '1'B;
1726 pars.cm2.a5_1 := '1'B;
1727 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1728 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1729 f_init_handler(pars, 15.0);
1730
1731 /* cannot use f_perform_lu() as we expect a reject */
1732 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1733 f_create_gsup_expect(hex2str(g_pars.imsi));
1734 f_bssap_compl_l3(l3_lu);
1735 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1736 f_mm_auth();
1737 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001738 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1739 f_expect_clear();
1740 }
Harald Welte9de84792018-01-28 01:06:35 +01001741 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1742 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001743 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001744 }
1745 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001746 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001747 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001748 }
1749 }
1750 setverdict(pass);
1751}
1752testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1753 var BSC_ConnHdlr vc_conn;
1754 f_init();
1755 f_vty_config(MSCVTY, "network", "authentication required");
1756 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1757
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001758 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37);
Harald Welte9de84792018-01-28 01:06:35 +01001759 vc_conn.done;
1760}
1761
1762/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1763private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1764 pars.net.expect_auth := true;
1765 pars.net.expect_ciph := true;
1766 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1767 pars.cm1.a5_1 := '1'B;
1768 pars.cm2.a5_1 := '1'B;
1769 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1770 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1771 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001772 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001773}
1774testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1775 var BSC_ConnHdlr vc_conn;
1776 f_init();
1777 f_vty_config(MSCVTY, "network", "authentication required");
1778 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1779
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001780 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001781 vc_conn.done;
1782}
1783
Harald Welte33ec09b2018-02-10 15:34:46 +01001784/* LU followed by MT call (including paging) */
1785private function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1786 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001787 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte33ec09b2018-02-10 15:34:46 +01001788 cpars.bss_rtp_port := 1110;
1789 cpars.mgcp_connection_id_bss := '10004'H;
1790 cpars.mgcp_connection_id_mss := '10005'H;
1791
Philipp Maier4b2692d2018-03-14 16:37:48 +01001792 /* Note: This is an optional parameter. When the call-agent (MSC) does
1793 * supply a full endpoint name this setting will be overwritten. */
1794 cpars.mgcp_ep := "rtpbridge/1@mgw";
1795
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001796 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001797 f_mt_call(cpars);
1798}
1799testcase TC_lu_and_mt_call() runs on MTC_CT {
1800 var BSC_ConnHdlr vc_conn;
1801 f_init();
1802
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001803 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001804 vc_conn.done;
1805}
1806
Daniel Willmann8b084372018-02-04 13:35:26 +01001807/* Test MO Call SETUP with DTMF */
1808private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1809 f_init_handler(pars);
1810 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1811 cpars.bss_rtp_port := 1110;
1812 cpars.mgcp_connection_id_bss := '22222'H;
1813 cpars.mgcp_connection_id_mss := '33333'H;
1814
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001815 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001816 f_mo_seq_dtmf_dup(cpars);
1817}
1818testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1819 var BSC_ConnHdlr vc_conn;
1820 f_init();
1821
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001822 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001823 vc_conn.done;
1824}
Harald Welte9de84792018-01-28 01:06:35 +01001825
Philipp Maier328d1662018-03-07 10:40:27 +01001826testcase TC_cr_before_reset() runs on MTC_CT {
1827 timer T := 4.0;
1828 var boolean reset_ack_seen := false;
1829 f_init_bssap_direct();
1830
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02001831 f_bssap_start(g_bssap[0]);
1832
Daniel Willmanne8018962018-08-21 14:18:00 +02001833 f_sleep(3.0);
1834
Philipp Maier328d1662018-03-07 10:40:27 +01001835 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001836 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001837
1838 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001839 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001840 T.start
1841 alt {
1842 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1843 reset_ack_seen := true;
1844 repeat;
1845 }
1846
1847 /* Acknowledge MSC sided reset requests */
1848 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001849 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001850 repeat;
1851 }
1852
1853 /* Ignore all other messages (e.g CR from the connection request) */
1854 [] BSSAP_DIRECT.receive { repeat }
1855
1856 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1857 * deadlock situation. The MSC is then unable to respond to any
1858 * further BSSMAP RESET or any other sort of traffic. */
1859 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1860 [reset_ack_seen == false] T.timeout {
1861 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02001862 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01001863 }
1864 }
1865}
Harald Welte9de84792018-01-28 01:06:35 +01001866
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001867/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
1868private function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1869 f_init_handler(pars);
1870 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1871 var MNCC_PDU mncc;
1872 var MgcpCommand mgcp_cmd;
1873
1874 f_perform_lu();
1875
Harald Welteb9e86fa2018-04-09 18:18:31 +02001876 f_establish_fully();
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001877 f_create_mncc_expect(hex2str(cpars.called_party));
1878 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1879
1880 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1881 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1882 cpars.mncc_callref := mncc.u.signal.callref;
1883 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1884 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1885
1886 /* Drop CRCX */
1887 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1888
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001889 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001890
1891 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001892
1893 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001894}
1895testcase TC_mo_release_timeout() runs on MTC_CT {
1896 var BSC_ConnHdlr vc_conn;
1897 f_init();
1898
1899 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1900 vc_conn.done;
1901}
1902
Harald Welte12510c52018-01-26 22:26:24 +01001903
Philipp Maier2a98a732018-03-19 16:06:12 +01001904/* LU followed by MT call (including paging) */
1905private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1906 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001907 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01001908 cpars.bss_rtp_port := 1110;
1909 cpars.mgcp_connection_id_bss := '10004'H;
1910 cpars.mgcp_connection_id_mss := '10005'H;
1911
1912 /* Note: This is an optional parameter. When the call-agent (MSC) does
1913 * supply a full endpoint name this setting will be overwritten. */
1914 cpars.mgcp_ep := "rtpbridge/1@mgw";
1915
1916 /* Intentionally disable the CRCX response */
1917 cpars.mgw_drop_dlcx := true;
1918
1919 /* Perform location update and call */
1920 f_perform_lu();
1921 f_mt_call(cpars);
1922}
1923testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
1924 var BSC_ConnHdlr vc_conn;
1925 f_init();
1926
1927 /* Perform an almost normal looking locationupdate + mt-call, but do
1928 * not respond to the DLCX at the end of the call */
1929 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
1930 vc_conn.done;
1931
1932 /* Wait a guard period until the MGCP layer in the MSC times out,
1933 * if the MSC is vulnerable to the use-after-free situation that is
1934 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
1935 * segfault now */
1936 f_sleep(6.0);
1937
1938 /* Run the init procedures once more. If the MSC has crashed, this
1939 * this will fail */
1940 f_init();
1941}
Harald Welte45164da2018-01-24 12:51:27 +01001942
Philipp Maier75932982018-03-27 14:52:35 +02001943/* Two BSSMAP resets from two different BSCs */
1944testcase TC_reset_two() runs on MTC_CT {
1945 var BSC_ConnHdlr vc_conn;
1946 f_init(2);
1947 f_sleep(2.0);
1948 setverdict(pass);
1949}
1950
Harald Weltef640a012018-04-14 17:49:21 +02001951/***********************************************************************
1952 * SMS Testing
1953 ***********************************************************************/
1954
Harald Weltef45efeb2018-04-09 18:19:24 +02001955/* LU followed by MO SMS */
1956private function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1957 var SmsParameters spars := valueof(t_SmsPars);
1958
1959 f_init_handler(pars);
1960
1961 /* Perform location update and call */
1962 f_perform_lu();
1963
1964 f_establish_fully(EST_TYPE_MO_SMS);
1965
1966 //spars.exp_rp_err := 96; /* invalid mandatory information */
1967 f_mo_sms(spars);
1968
1969 f_expect_clear();
1970}
1971testcase TC_lu_and_mo_sms() runs on MTC_CT {
1972 var BSC_ConnHdlr vc_conn;
1973 f_init();
1974 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
1975 vc_conn.done;
1976}
1977
1978private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01001979runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02001980 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
1981}
1982
1983/* LU followed by MT SMS */
1984private function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1985 var SmsParameters spars := valueof(t_SmsPars);
1986 var OCT4 tmsi;
1987
1988 f_init_handler(pars);
1989
1990 /* Perform location update and call */
1991 f_perform_lu();
1992
1993 /* register an 'expect' for given IMSI (+TMSI) */
1994 if (isvalue(g_pars.tmsi)) {
1995 tmsi := g_pars.tmsi;
1996 } else {
1997 tmsi := 'FFFFFFFF'O;
1998 }
1999 f_bssmap_register_imsi(g_pars.imsi, tmsi);
2000
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002001 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002002
2003 /* MSC->BSC: expect PAGING from MSC */
2004 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2005 /* Establish DTAP / BSSAP / SCCP connection */
2006 f_establish_fully(EST_TYPE_PAG_RESP);
2007
2008 spars.tp.ud := 'C8329BFD064D9B53'O;
2009 f_mt_sms(spars);
2010
2011 f_expect_clear();
2012}
2013testcase TC_lu_and_mt_sms() runs on MTC_CT {
2014 var BSC_ConnHdlrPars pars;
2015 var BSC_ConnHdlr vc_conn;
2016 f_init();
2017 pars := f_init_pars(43);
2018 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002019 vc_conn.done;
2020}
2021
Philipp Maier3983e702018-11-22 19:01:33 +01002022/* Paging for MT SMS but no response */
2023private function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2024 var SmsParameters spars := valueof(t_SmsPars);
2025 var OCT4 tmsi;
2026 var integer page_count := 0;
2027 f_init_handler(pars, 150.0);
2028
2029 /* Perform location update */
2030 f_perform_lu();
2031
2032 /* register an 'expect' for given IMSI (+TMSI) */
2033 if (isvalue(g_pars.tmsi)) {
2034 tmsi := g_pars.tmsi;
2035 } else {
2036 tmsi := 'FFFFFFFF'O;
2037 }
2038 f_bssmap_register_imsi(g_pars.imsi, tmsi);
2039
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002040 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2041
Philipp Maier3983e702018-11-22 19:01:33 +01002042 /* Expect the MSC to page exactly 10 times before giving up */
2043 alt {
2044 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi))
2045 {
2046 page_count := page_count + 1;
2047
2048 if (page_count < 10) {
2049 repeat;
2050 }
2051 }
2052 [] BSSAP.receive {
2053 setverdict(fail, "unexpected BSSAP message received");
2054 self.stop;
2055 }
2056 }
2057
2058 /* Wait some time to make sure the MSC is not delivering any further
2059 * paging messages or anything else that could be unexpected. */
2060 timer T := 20.0;
2061 T.start
2062 alt {
2063 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi))
2064 {
2065 setverdict(fail, "paging seems not to stop!");
2066 mtc.stop;
2067 }
2068 [] BSSAP.receive {
2069 setverdict(fail, "unexpected BSSAP message received");
2070 self.stop;
2071 }
2072 [] T.timeout {
2073 setverdict(pass);
2074 }
2075 }
2076
2077 setverdict(pass);
2078}
2079testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2080 var BSC_ConnHdlrPars pars;
2081 var BSC_ConnHdlr vc_conn;
2082 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002083 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002084 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002085 vc_conn.done;
2086}
2087
Harald Weltef640a012018-04-14 17:49:21 +02002088/* mobile originated SMS from MS/BTS/BSC side to SMPP */
2089private function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2090 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002091
Harald Weltef640a012018-04-14 17:49:21 +02002092 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002093
Harald Weltef640a012018-04-14 17:49:21 +02002094 /* Perform location update so IMSI is known + registered in MSC/VLR */
2095 f_perform_lu();
2096 f_establish_fully(EST_TYPE_MO_SMS);
2097
2098 f_mo_sms(spars);
2099
2100 var SMPP_PDU smpp;
2101 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2102 tr_smpp.body.deliver_sm := {
2103 service_type := "CMT",
2104 source_addr_ton := network_specific,
2105 source_addr_npi := isdn,
2106 source_addr := hex2str(pars.msisdn),
2107 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2108 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2109 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2110 esm_class := '00000001'B,
2111 protocol_id := 0,
2112 priority_flag := 0,
2113 schedule_delivery_time := "",
2114 replace_if_present := 0,
2115 data_coding := '00000001'B,
2116 sm_default_msg_id := 0,
2117 sm_length := ?,
2118 short_message := spars.tp.ud,
2119 opt_pars := {
2120 {
2121 tag := user_message_reference,
2122 len := 2,
2123 opt_value := {
2124 int2_val := oct2int(spars.tp.msg_ref)
2125 }
2126 }
2127 }
2128 };
2129 alt {
2130 [] SMPP.receive(tr_smpp) -> value smpp {
2131 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2132 }
2133 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2134 }
2135
2136 f_expect_clear();
2137}
2138testcase TC_smpp_mo_sms() runs on MTC_CT {
2139 var BSC_ConnHdlr vc_conn;
2140 f_init();
2141 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2142 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2143 vc_conn.done;
2144 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2145}
2146
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002147/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
2148private function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
2149runs on BSC_ConnHdlr {
2150 var SmsParameters spars := valueof(t_SmsPars);
2151 var GSUP_PDU gsup_msg_rx;
2152 var octetstring sm_tpdu;
2153
2154 f_init_handler(pars);
2155
2156 /* We need to inspect GSUP activity */
2157 f_create_gsup_expect(hex2str(g_pars.imsi));
2158
2159 /* Perform location update */
2160 f_perform_lu();
2161
2162 /* Send CM Service Request for SMS */
2163 f_establish_fully(EST_TYPE_MO_SMS);
2164
2165 /* Prepare expected SM-RP-UI (SM TPDU) */
2166 enc_TPDU_RP_DATA_MS_SGSN_fast(
2167 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2168 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2169 spars.tp.udl, spars.tp.ud)),
2170 sm_tpdu);
2171
2172 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2173 imsi := g_pars.imsi,
2174 sm_rp_mr := spars.rp.msg_ref,
2175 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2176 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(?),
2177 /* FIXME: MSISDN coding troubles */
2178 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(?),
2179 /* TODO: can we use decmatch here? */
2180 sm_rp_ui := sm_tpdu
2181 );
2182
2183 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2184 f_mo_sms_submit(spars);
2185 alt {
2186 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
2187 log("RX MO-forwardSM-Req");
2188 log(gsup_msg_rx);
2189 setverdict(pass);
2190 }
2191 [] GSUP.receive {
2192 log("RX unexpected GSUP message");
2193 setverdict(fail);
2194 mtc.stop;
2195 }
2196 }
2197
2198 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2199 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2200 imsi := g_pars.imsi,
2201 sm_rp_mr := spars.rp.msg_ref)));
2202 /* Expect RP-ACK on DTAP */
2203 f_mo_sms_wait_rp_ack(spars);
2204
2205 f_expect_clear();
2206}
2207testcase TC_gsup_mo_sms() runs on MTC_CT {
2208 var BSC_ConnHdlr vc_conn;
2209 f_init();
2210 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2211 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2212 vc_conn.done;
2213 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2214}
2215
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002216/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
2217private function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
2218runs on BSC_ConnHdlr {
2219 var SmsParameters spars := valueof(t_SmsPars);
2220 var GSUP_PDU gsup_msg_rx;
2221
2222 f_init_handler(pars);
2223
2224 /* We need to inspect GSUP activity */
2225 f_create_gsup_expect(hex2str(g_pars.imsi));
2226
2227 /* Perform location update */
2228 f_perform_lu();
2229
2230 /* Send CM Service Request for SMS */
2231 f_establish_fully(EST_TYPE_MO_SMS);
2232
2233 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2234 imsi := g_pars.imsi,
2235 sm_rp_mr := spars.rp.msg_ref,
2236 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2237 );
2238
2239 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2240 f_mo_smma(spars);
2241 alt {
2242 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
2243 log("RX MO-ReadyForSM-Req");
2244 log(gsup_msg_rx);
2245 setverdict(pass);
2246 }
2247 [] GSUP.receive {
2248 log("RX unexpected GSUP message");
2249 setverdict(fail);
2250 mtc.stop;
2251 }
2252 }
2253
2254 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2255 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2256 imsi := g_pars.imsi,
2257 sm_rp_mr := spars.rp.msg_ref)));
2258 /* Expect RP-ACK on DTAP */
2259 f_mo_sms_wait_rp_ack(spars);
2260
2261 f_expect_clear();
2262}
2263testcase TC_gsup_mo_smma() runs on MTC_CT {
2264 var BSC_ConnHdlr vc_conn;
2265 f_init();
2266 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2267 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2268 vc_conn.done;
2269 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2270}
2271
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002272/* Helper for sending MT SMS over GSUP */
2273private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2274runs on BSC_ConnHdlr {
2275 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2276 imsi := g_pars.imsi,
2277 /* NOTE: MSC should assign RP-MR itself */
2278 sm_rp_mr := 'FF'O,
2279 /* FIXME: extract SM-RP-DA from spars.rp.dest */
2280 /* TODO: fix encoding of ts_GSUP_SM_RP_DA_IMSI */
2281 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(g_pars.msisdn)),
2282 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(g_pars.msisdn)),
2283 /* Encoded SMS TPDU (taken from Wireshark)
2284 * FIXME: we should encode spars somehow */
2285 sm_rp_ui := '00068021436500008111328130858200'O,
2286 sm_rp_mms := mms
2287 ));
2288}
2289
2290/* Test successful MT-SMS (RP-ACK) over GSUP */
2291private function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
2292runs on BSC_ConnHdlr {
2293 var SmsParameters spars := valueof(t_SmsPars);
2294
2295 f_init_handler(pars);
2296
2297 /* We need to inspect GSUP activity */
2298 f_create_gsup_expect(hex2str(g_pars.imsi));
2299
2300 /* Perform location update */
2301 f_perform_lu();
2302
2303 /* Register an 'expect' for given IMSI (+TMSI) */
2304 if (isvalue(g_pars.tmsi)) {
2305 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2306 } else {
2307 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2308 }
2309
2310 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2311 imsi := g_pars.imsi,
2312 /* NOTE: MSC should assign RP-MR itself */
2313 sm_rp_mr := ?
2314 );
2315
2316 /* Submit a MT SMS on GSUP */
2317 f_gsup_forwardSM_req(spars);
2318
2319 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
2320 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2321 f_establish_fully(EST_TYPE_PAG_RESP);
2322
2323 /* Wait for MT SMS on DTAP */
2324 f_mt_sms_expect(spars);
2325
2326 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2327 f_mt_sms_send_rp_ack(spars);
2328 alt {
2329 [] GSUP.receive(mt_forwardSM_res) {
2330 log("RX MT-forwardSM-Res (RP-ACK)");
2331 setverdict(pass);
2332 }
2333 [] GSUP.receive {
2334 log("RX unexpected GSUP message");
2335 setverdict(fail);
2336 mtc.stop;
2337 }
2338 }
2339
2340 f_expect_clear();
2341}
2342testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2343 var BSC_ConnHdlrPars pars;
2344 var BSC_ConnHdlr vc_conn;
2345 f_init();
2346 pars := f_init_pars(90);
2347 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2348 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2349 vc_conn.done;
2350 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2351}
2352
2353/* Test rejected MT-SMS (RP-ERROR) over GSUP */
2354private function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
2355runs on BSC_ConnHdlr {
2356 var SmsParameters spars := valueof(t_SmsPars);
2357 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2358
2359 f_init_handler(pars);
2360
2361 /* We need to inspect GSUP activity */
2362 f_create_gsup_expect(hex2str(g_pars.imsi));
2363
2364 /* Perform location update */
2365 f_perform_lu();
2366
2367 /* Register an 'expect' for given IMSI (+TMSI) */
2368 if (isvalue(g_pars.tmsi)) {
2369 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2370 } else {
2371 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2372 }
2373
2374 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2375 imsi := g_pars.imsi,
2376 /* NOTE: MSC should assign RP-MR itself */
2377 sm_rp_mr := ?,
2378 sm_rp_cause := sm_rp_cause
2379 );
2380
2381 /* Submit a MT SMS on GSUP */
2382 f_gsup_forwardSM_req(spars);
2383
2384 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
2385 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2386 f_establish_fully(EST_TYPE_PAG_RESP);
2387
2388 /* Wait for MT SMS on DTAP */
2389 f_mt_sms_expect(spars);
2390
2391 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2392 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2393 alt {
2394 [] GSUP.receive(mt_forwardSM_err) {
2395 log("RX MT-forwardSM-Err (RP-ERROR)");
2396 setverdict(pass);
2397 mtc.stop;
2398 }
2399 [] GSUP.receive {
2400 log("RX unexpected GSUP message");
2401 setverdict(fail);
2402 mtc.stop;
2403 }
2404 }
2405
2406 f_expect_clear();
2407}
2408testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2409 var BSC_ConnHdlrPars pars;
2410 var BSC_ConnHdlr vc_conn;
2411 f_init();
2412 pars := f_init_pars(91);
2413 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2414 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2415 vc_conn.done;
2416 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2417}
2418
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002419/* Test SM-RP-MR assignment for MT-SMS over GSUP */
2420private function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
2421runs on BSC_ConnHdlr {
2422 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2423 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2424
2425 f_init_handler(pars);
2426
2427 /* We need to inspect GSUP activity */
2428 f_create_gsup_expect(hex2str(g_pars.imsi));
2429
2430 /* Perform location update */
2431 f_perform_lu();
2432
2433 /* Register an 'expect' for given IMSI (+TMSI) */
2434 if (isvalue(g_pars.tmsi)) {
2435 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2436 } else {
2437 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2438 }
2439
2440 /* Submit the 1st MT SMS on GSUP */
2441 log("TX MT-forwardSM-Req for the 1st SMS");
2442 f_gsup_forwardSM_req(spars1);
2443
2444 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
2445 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2446 f_establish_fully(EST_TYPE_PAG_RESP);
2447
2448 /* Wait for 1st MT SMS on DTAP */
2449 f_mt_sms_expect(spars1);
2450 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2451 ", SM-RP-MR is ", spars1.rp.msg_ref);
2452
2453 /* Submit the 2nd MT SMS on GSUP */
2454 log("TX MT-forwardSM-Req for the 2nd SMS");
2455 f_gsup_forwardSM_req(spars2);
2456
2457 /* Wait for 2nd MT SMS on DTAP */
2458 f_mt_sms_expect(spars2);
2459 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2460 ", SM-RP-MR is ", spars2.rp.msg_ref);
2461
2462 /* Both transaction IDs shall be different */
2463 if (spars1.tid == spars2.tid) {
2464 log("Both DTAP transaction IDs shall be different");
2465 setverdict(fail);
2466 }
2467
2468 /* Both SM-RP-MR values shall be different */
2469 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2470 log("Both SM-RP-MR values shall be different");
2471 setverdict(fail);
2472 }
2473
2474 /* Both SM-RP-MR values shall be assigned */
2475 if (spars1.rp.msg_ref == 'FF'O) {
2476 log("Unassigned SM-RP-MR value for the 1st SMS");
2477 setverdict(fail);
2478 }
2479 if (spars2.rp.msg_ref == 'FF'O) {
2480 log("Unassigned SM-RP-MR value for the 2nd SMS");
2481 setverdict(fail);
2482 }
2483
2484 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2485 f_mt_sms_send_rp_ack(spars1);
2486 alt {
2487 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2488 imsi := g_pars.imsi,
2489 sm_rp_mr := spars1.rp.msg_ref
2490 )) {
2491 log("RX MT-forwardSM-Res (RP-ACK)");
2492 setverdict(pass);
2493 }
2494 [] GSUP.receive {
2495 log("RX unexpected GSUP message");
2496 setverdict(fail);
2497 mtc.stop;
2498 }
2499 }
2500
2501 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2502 f_mt_sms_send_rp_ack(spars2);
2503 alt {
2504 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2505 imsi := g_pars.imsi,
2506 sm_rp_mr := spars2.rp.msg_ref
2507 )) {
2508 log("RX MT-forwardSM-Res (RP-ACK)");
2509 setverdict(pass);
2510 }
2511 [] GSUP.receive {
2512 log("RX unexpected GSUP message");
2513 setverdict(fail);
2514 mtc.stop;
2515 }
2516 }
2517
2518 f_expect_clear();
2519}
2520testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2521 var BSC_ConnHdlrPars pars;
2522 var BSC_ConnHdlr vc_conn;
2523 f_init();
2524 pars := f_init_pars(92);
2525 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2526 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2527 vc_conn.done;
2528 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2529}
2530
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002531/* Test SM-RP-MR assignment for MT-SMS over GSUP */
2532private function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
2533runs on BSC_ConnHdlr {
2534 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2535 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2536
2537 f_init_handler(pars);
2538
2539 /* We need to inspect GSUP activity */
2540 f_create_gsup_expect(hex2str(g_pars.imsi));
2541
2542 /* Perform location update */
2543 f_perform_lu();
2544
2545 /* Register an 'expect' for given IMSI (+TMSI) */
2546 if (isvalue(g_pars.tmsi)) {
2547 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2548 } else {
2549 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2550 }
2551
2552 /* Send CM Service Request for MO SMMA */
2553 f_establish_fully(EST_TYPE_MO_SMS);
2554
2555 /* Submit MO SMMA on DTAP */
2556 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2557 spars_mo.rp.msg_ref := '00'O;
2558 f_mo_smma(spars_mo);
2559
2560 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2561 alt {
2562 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2563 imsi := g_pars.imsi,
2564 sm_rp_mr := spars_mo.rp.msg_ref,
2565 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2566 )) {
2567 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2568 setverdict(pass);
2569 }
2570 [] GSUP.receive {
2571 log("RX unexpected GSUP message");
2572 setverdict(fail);
2573 mtc.stop;
2574 }
2575 }
2576
2577 /* Submit MT SMS on GSUP */
2578 log("TX MT-forwardSM-Req for the MT SMS");
2579 f_gsup_forwardSM_req(spars_mt);
2580
2581 /* Wait for MT SMS on DTAP */
2582 f_mt_sms_expect(spars_mt);
2583 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2584 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2585
2586 /* Both SM-RP-MR values shall be different */
2587 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2588 log("Both SM-RP-MR values shall be different");
2589 setverdict(fail);
2590 }
2591
2592 /* SM-RP-MR value for MT SMS shall be assigned */
2593 if (spars_mt.rp.msg_ref == 'FF'O) {
2594 log("Unassigned SM-RP-MR value for the MT SMS");
2595 setverdict(fail);
2596 }
2597
2598 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2599 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2600 imsi := g_pars.imsi,
2601 sm_rp_mr := spars_mo.rp.msg_ref)));
2602 /* Expect RP-ACK for MO SMMA on DTAP */
2603 f_mo_sms_wait_rp_ack(spars_mo);
2604
2605 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2606 f_mt_sms_send_rp_ack(spars_mt);
2607 alt {
2608 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2609 imsi := g_pars.imsi,
2610 sm_rp_mr := spars_mt.rp.msg_ref
2611 )) {
2612 log("RX MT-forwardSM-Res (RP-ACK)");
2613 setverdict(pass);
2614 }
2615 [] GSUP.receive {
2616 log("RX unexpected GSUP message");
2617 setverdict(fail);
2618 mtc.stop;
2619 }
2620 }
2621
2622 f_expect_clear();
2623}
2624testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
2625 var BSC_ConnHdlrPars pars;
2626 var BSC_ConnHdlr vc_conn;
2627 f_init();
2628 pars := f_init_pars(93);
2629 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2630 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
2631 vc_conn.done;
2632 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2633}
2634
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002635/* Test multi-part MT-SMS over GSUP */
2636private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
2637runs on BSC_ConnHdlr {
2638 var SmsParameters spars := valueof(t_SmsPars);
2639
2640 f_init_handler(pars);
2641
2642 /* We need to inspect GSUP activity */
2643 f_create_gsup_expect(hex2str(g_pars.imsi));
2644
2645 /* Perform location update */
2646 f_perform_lu();
2647
2648 /* Register an 'expect' for given IMSI (+TMSI) */
2649 if (isvalue(g_pars.tmsi)) {
2650 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2651 } else {
2652 f_bssmap_register_imsi(g_pars.imsi, 'FFFFFFFF'O);
2653 }
2654
2655 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2656 imsi := g_pars.imsi,
2657 /* NOTE: MSC should assign RP-MR itself */
2658 sm_rp_mr := ?
2659 );
2660
2661 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
2662 for (var integer i := 3; i >= 0; i := i-1) {
2663 /* Submit a MT SMS on GSUP (MMS is decremented) */
2664 f_gsup_forwardSM_req(spars, int2oct(i, 1));
2665
2666 /* Expect Paging Request and Establish connection */
2667 if (i == 3) { /* ... only once! */
2668 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2669 f_establish_fully(EST_TYPE_PAG_RESP);
2670 }
2671
2672 /* Wait for MT SMS on DTAP */
2673 f_mt_sms_expect(spars);
2674
2675 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2676 f_mt_sms_send_rp_ack(spars);
2677 alt {
2678 [] GSUP.receive(mt_forwardSM_res) {
2679 log("RX MT-forwardSM-Res (RP-ACK)");
2680 setverdict(pass);
2681 }
2682 [] GSUP.receive {
2683 log("RX unexpected GSUP message");
2684 setverdict(fail);
2685 mtc.stop;
2686 }
2687 }
2688
2689 /* Keep some 'distance' between transmissions */
2690 f_sleep(1.5);
2691 }
2692
2693 f_expect_clear();
2694}
2695testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
2696 var BSC_ConnHdlrPars pars;
2697 var BSC_ConnHdlr vc_conn;
2698 f_init();
2699 pars := f_init_pars(91);
2700 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2701 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
2702 vc_conn.done;
2703 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2704}
2705
Harald Weltef640a012018-04-14 17:49:21 +02002706/* convert GSM L3 TON to SMPP_TON enum */
2707function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
2708 select (ton) {
2709 case ('000'B) { return unknown; }
2710 case ('001'B) { return international; }
2711 case ('010'B) { return national; }
2712 case ('011'B) { return network_specific; }
2713 case ('100'B) { return subscriber_number; }
2714 case ('101'B) { return alphanumeric; }
2715 case ('110'B) { return abbreviated; }
2716 }
2717 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02002718 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002719}
2720/* convert GSM L3 NPI to SMPP_NPI enum */
2721function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2722 select (npi) {
2723 case ('0000'B) { return unknown; }
2724 case ('0001'B) { return isdn; }
2725 case ('0011'B) { return data; }
2726 case ('0100'B) { return telex; }
2727 case ('0110'B) { return land_mobile; }
2728 case ('1000'B) { return national; }
2729 case ('1001'B) { return private_; }
2730 case ('1010'B) { return ermes; }
2731 }
2732 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02002733 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002734}
2735
2736/* build a SMPP_SM from SmsParameters */
2737function f_mt_sm_from_spars(SmsParameters spars)
2738runs on BSC_ConnHdlr return SMPP_SM {
2739 var SMPP_SM sm := {
2740 service_type := "CMT",
2741 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2742 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2743 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2744 dest_addr_ton := international,
2745 dest_addr_npi := isdn,
2746 destination_addr := hex2str(g_pars.msisdn),
2747 esm_class := '00000001'B,
2748 protocol_id := 0,
2749 priority_flag := 0,
2750 schedule_delivery_time := "",
2751 validity_period := "",
2752 registered_delivery := '00000000'B,
2753 replace_if_present := 0,
2754 data_coding := '00000001'B,
2755 sm_default_msg_id := 0,
2756 sm_length := spars.tp.udl,
2757 short_message := spars.tp.ud,
2758 opt_pars := {}
2759 };
2760 return sm;
2761}
2762
2763/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2764private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2765 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2766 if (trans_mode) {
2767 sm.esm_class := '00000010'B;
2768 }
2769
2770 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2771 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2772 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2773 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2774 * before we expect the SMS delivery on the BSC/radio side */
2775 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2776 }
2777
2778 /* MSC->BSC: expect PAGING from MSC */
2779 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2780 /* Establish DTAP / BSSAP / SCCP connection */
2781 f_establish_fully(EST_TYPE_PAG_RESP);
2782 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2783
2784 f_mt_sms(spars);
2785
2786 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2787 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2788 }
2789 f_expect_clear();
2790}
2791
2792/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2793private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2794 f_init_handler(pars);
2795
2796 /* Perform location update so IMSI is known + registered in MSC/VLR */
2797 f_perform_lu();
2798 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2799
2800 /* register an 'expect' for given IMSI (+TMSI) */
2801 var OCT4 tmsi;
2802 if (isvalue(g_pars.tmsi)) {
2803 tmsi := g_pars.tmsi;
2804 } else {
2805 tmsi := 'FFFFFFFF'O;
2806 }
2807 f_bssmap_register_imsi(g_pars.imsi, tmsi);
2808
2809 var SmsParameters spars := valueof(t_SmsPars);
2810 /* TODO: test with more intelligent user data; test different coding schemes */
2811 spars.tp.ud := '00'O;
2812 spars.tp.udl := 1;
2813
2814 /* first test the non-transaction store+forward mode */
2815 f_smpp_mt_sms(spars, false);
2816
2817 /* then test the transaction mode */
2818 f_smpp_mt_sms(spars, true);
2819}
2820testcase TC_smpp_mt_sms() runs on MTC_CT {
2821 var BSC_ConnHdlr vc_conn;
2822 f_init();
2823 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
2824 vc_conn.done;
2825}
2826
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002827/***********************************************************************
2828 * USSD Testing
2829 ***********************************************************************/
2830
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07002831private altstep as_unexp_gsup_or_bssap_msg()
2832runs on BSC_ConnHdlr {
2833 [] GSUP.receive {
2834 setverdict(fail, "Unknown/unexpected GSUP received");
2835 self.stop;
2836 }
2837 [] BSSAP.receive {
2838 setverdict(fail, "Unknown/unexpected BSSAP message received");
2839 self.stop;
2840 }
2841}
2842
2843private function f_expect_gsup_msg(template GSUP_PDU msg)
2844runs on BSC_ConnHdlr return GSUP_PDU {
2845 var GSUP_PDU gsup_msg_complete;
2846
2847 alt {
2848 [] GSUP.receive(msg) -> value gsup_msg_complete {
2849 setverdict(pass);
2850 }
2851 /* We don't expect anything else */
2852 [] as_unexp_gsup_or_bssap_msg();
2853 }
2854
2855 return gsup_msg_complete;
2856}
2857
2858private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg)
2859runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
2860 var PDU_DTAP_MT bssap_msg_complete;
2861
2862 alt {
2863 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
2864 setverdict(pass);
2865 }
2866 /* We don't expect anything else */
2867 [] as_unexp_gsup_or_bssap_msg();
2868 }
2869
2870 return bssap_msg_complete.dtap;
2871}
2872
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002873/* LU followed by MO USSD request */
2874private function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002875runs on BSC_ConnHdlr {
2876 f_init_handler(pars);
2877
2878 /* Perform location update */
2879 f_perform_lu();
2880
2881 /* Send CM Service Request for SS/USSD */
2882 f_establish_fully(EST_TYPE_SS_ACT);
2883
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002884 /* We need to inspect GSUP activity */
2885 f_create_gsup_expect(hex2str(g_pars.imsi));
2886
2887 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2888 invoke_id := 5, /* Phone may not start from 0 or 1 */
2889 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2890 ussd_string := "*#100#"
2891 );
2892
2893 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
2894 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
2895 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2896 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
2897 )
2898
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002899 /* Compose a new SS/REGISTER message with request */
2900 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
2901 tid := 1, /* We just need a single transaction */
2902 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002903 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002904 );
2905
2906 /* Compose SS/RELEASE_COMPLETE template with expected response */
2907 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
2908 tid := 1, /* Response should arrive within the same transaction */
2909 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002910 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002911 );
2912
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002913 /* Compose expected MSC -> HLR message */
2914 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
2915 imsi := g_pars.imsi,
2916 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2917 ss := valueof(facility_req)
2918 );
2919
2920 /* To be used for sending response with correct session ID */
2921 var GSUP_PDU gsup_req_complete;
2922
2923 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002924 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07002925 /* Expect GSUP message containing the SS payload */
2926 gsup_req_complete := f_expect_gsup_msg(gsup_req);
2927
2928 /* Compose the response from HLR using received session ID */
2929 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
2930 imsi := g_pars.imsi,
2931 sid := gsup_req_complete.ies[1].val.session_id,
2932 state := OSMO_GSUP_SESSION_STATE_END,
2933 ss := valueof(facility_rsp)
2934 );
2935
2936 /* Finally, HLR terminates the session */
2937 GSUP.send(gsup_rsp);
2938 /* Expect RELEASE_COMPLETE message with the response */
2939 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002940
2941 f_expect_clear();
2942}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002943testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002944 var BSC_ConnHdlr vc_conn;
2945 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002946 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002947 vc_conn.done;
2948}
2949
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07002950/* LU followed by MT USSD notification */
2951private function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
2952runs on BSC_ConnHdlr {
2953 f_init_handler(pars);
2954
2955 /* Perform location update */
2956 f_perform_lu();
2957
2958 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
2959
2960 /* We need to inspect GSUP activity */
2961 f_create_gsup_expect(hex2str(g_pars.imsi));
2962
2963 /* Facility IE with network-originated USSD notification */
2964 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
2965 op_code := SS_OP_CODE_USS_NOTIFY,
2966 ussd_string := "Mahlzeit!"
2967 );
2968
2969 /* Facility IE with acknowledgment to the USSD notification */
2970 var template OCTN facility_rsp := enc_SS_FacilityInformation(
2971 /* In case of USSD notification, Return Result is empty */
2972 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
2973 );
2974
2975 /* Compose a new MT SS/REGISTER message with USSD notification */
2976 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
2977 tid := 0, /* FIXME: most likely, it should be 0 */
2978 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
2979 facility := valueof(facility_req)
2980 );
2981
2982 /* Compose HLR -> MSC GSUP message */
2983 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
2984 imsi := g_pars.imsi,
2985 sid := '20000101'O,
2986 state := OSMO_GSUP_SESSION_STATE_BEGIN,
2987 ss := valueof(facility_req)
2988 );
2989
2990 /* Send it to MSC and expect Paging Request */
2991 GSUP.send(gsup_req);
2992 alt {
2993 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2994 setverdict(pass);
2995 }
2996 /* We don't expect anything else */
2997 [] as_unexp_gsup_or_bssap_msg();
2998 }
2999
3000 /* Send Paging Response and expect USSD notification */
3001 f_establish_fully(EST_TYPE_PAG_RESP);
3002 /* Expect MT REGISTER message with USSD notification */
3003 f_expect_mt_dtap_msg(ussd_ntf);
3004
3005 /* Compose a new MO SS/FACILITY message with empty response */
3006 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3007 tid := 0, /* FIXME: it shall match the request tid */
3008 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3009 facility := valueof(facility_rsp)
3010 );
3011
3012 /* Compose expected MSC -> HLR GSUP message */
3013 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3014 imsi := g_pars.imsi,
3015 sid := '20000101'O,
3016 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3017 ss := valueof(facility_rsp)
3018 );
3019
3020 /* MS sends response to the notification */
3021 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3022 /* Expect GSUP message containing the SS payload */
3023 f_expect_gsup_msg(gsup_rsp);
3024
3025 /* Compose expected MT SS/RELEASE COMPLETE message */
3026 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3027 tid := 0, /* FIXME: it shall match the request tid */
3028 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3029 facility := omit
3030 );
3031
3032 /* Compose MSC -> HLR GSUP message */
3033 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3034 imsi := g_pars.imsi,
3035 sid := '20000101'O,
3036 state := OSMO_GSUP_SESSION_STATE_END
3037 );
3038
3039 /* Finally, HLR terminates the session */
3040 GSUP.send(gsup_term)
3041 /* Expect MT RELEASE COMPLETE without Facility IE */
3042 f_expect_mt_dtap_msg(ussd_term);
3043
3044 f_expect_clear();
3045}
3046testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3047 var BSC_ConnHdlr vc_conn;
3048 f_init();
3049 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3050 vc_conn.done;
3051}
3052
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003053/* LU followed by MT call and MO USSD request during this call */
3054private function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003055runs on BSC_ConnHdlr {
3056 f_init_handler(pars);
3057
3058 /* Call parameters taken from f_tc_lu_and_mt_call */
3059 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3060 cpars.mgcp_connection_id_bss := '10004'H;
3061 cpars.mgcp_connection_id_mss := '10005'H;
3062 cpars.mgcp_ep := "rtpbridge/1@mgw";
3063 cpars.bss_rtp_port := 1110;
3064
3065 /* Perform location update */
3066 f_perform_lu();
3067
3068 /* Establish a MT call */
3069 f_mt_call_establish(cpars);
3070
3071 /* Hold the call for some time */
3072 f_sleep(1.0);
3073
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003074 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3075 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3076 ussd_string := "*#100#"
3077 );
3078
3079 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3080 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3081 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3082 )
3083
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003084 /* Compose a new SS/REGISTER message with request */
3085 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3086 tid := 1, /* We just need a single transaction */
3087 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003088 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003089 );
3090
3091 /* Compose SS/RELEASE_COMPLETE template with expected response */
3092 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3093 tid := 1, /* Response should arrive within the same transaction */
3094 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003095 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003096 );
3097
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003098 /* Compose expected MSC -> HLR message */
3099 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3100 imsi := g_pars.imsi,
3101 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3102 ss := valueof(facility_req)
3103 );
3104
3105 /* To be used for sending response with correct session ID */
3106 var GSUP_PDU gsup_req_complete;
3107
3108 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003109 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003110 /* Expect GSUP message containing the SS payload */
3111 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3112
3113 /* Compose the response from HLR using received session ID */
3114 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3115 imsi := g_pars.imsi,
3116 sid := gsup_req_complete.ies[1].val.session_id,
3117 state := OSMO_GSUP_SESSION_STATE_END,
3118 ss := valueof(facility_rsp)
3119 );
3120
3121 /* Finally, HLR terminates the session */
3122 GSUP.send(gsup_rsp);
3123 /* Expect RELEASE_COMPLETE message with the response */
3124 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003125
3126 /* Hold the call for some time */
3127 f_sleep(1.0);
3128
3129 /* Release the call (does Clear Complete itself) */
3130 f_call_hangup(cpars, true);
3131}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003132testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003133 var BSC_ConnHdlr vc_conn;
3134 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003135 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003136 vc_conn.done;
3137}
3138
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003139/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
3140private function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3141 f_init_handler(pars);
3142 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
3143 var MNCC_PDU mncc;
3144 var MgcpCommand mgcp_cmd;
3145
3146 f_perform_lu();
3147
3148 f_establish_fully();
3149 f_create_mncc_expect(hex2str(cpars.called_party));
3150 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
3151
3152 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
3153 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
3154 cpars.mncc_callref := mncc.u.signal.callref;
3155 log("mncc_callref=", cpars.mncc_callref);
3156 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
3157 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
3158
3159 MNCC.send(ts_MNCC_ALERT_req(cpars.mncc_callref));
3160 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_ALERTING(cpars.transaction_id)));
3161 MGCP.receive(tr_CRCX);
3162
3163 f_sleep(1.0);
3164 BSSAP.send(ts_BSSMAP_ClearRequest(0));
3165
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003166 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003167
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003168 interleave {
3169 [] MNCC.receive(tr_MNCC_REL_ind(?, ?)) { };
3170 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
3171 BSSAP.send(ts_BSSMAP_ClearComplete);
3172 };
3173 }
3174
3175 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003176
3177 f_sleep(1.0);
3178}
3179testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3180 var BSC_ConnHdlr vc_conn;
3181 f_init();
3182
3183 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3184 vc_conn.done;
3185}
3186
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003187/* LU followed by MT call and MT USSD request during this call */
3188private function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
3189runs on BSC_ConnHdlr {
3190 f_init_handler(pars);
3191
3192 /* Call parameters taken from f_tc_lu_and_mt_call */
3193 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
3194 cpars.mgcp_connection_id_bss := '10004'H;
3195 cpars.mgcp_connection_id_mss := '10005'H;
3196 cpars.mgcp_ep := "rtpbridge/1@mgw";
3197 cpars.bss_rtp_port := 1110;
3198
3199 /* Perform location update */
3200 f_perform_lu();
3201
3202 /* Establish a MT call */
3203 f_mt_call_establish(cpars);
3204
3205 /* Hold the call for some time */
3206 f_sleep(1.0);
3207
3208 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3209 op_code := SS_OP_CODE_USS_REQUEST,
3210 ussd_string := "Please type anything..."
3211 );
3212
3213 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3214 op_code := SS_OP_CODE_USS_REQUEST,
3215 ussd_string := "Nope."
3216 )
3217
3218 /* Compose MT SS/REGISTER message with network-originated request */
3219 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3220 tid := 0, /* FIXME: most likely, it should be 0 */
3221 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3222 facility := valueof(facility_req)
3223 );
3224
3225 /* Compose HLR -> MSC GSUP message */
3226 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3227 imsi := g_pars.imsi,
3228 sid := '20000101'O,
3229 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3230 ss := valueof(facility_req)
3231 );
3232
3233 /* Send it to MSC */
3234 GSUP.send(gsup_req);
3235 /* Expect MT REGISTER message with USSD request */
3236 f_expect_mt_dtap_msg(ussd_req);
3237
3238 /* Compose a new MO SS/FACILITY message with response */
3239 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3240 tid := 0, /* FIXME: it shall match the request tid */
3241 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3242 facility := valueof(facility_rsp)
3243 );
3244
3245 /* Compose expected MSC -> HLR GSUP message */
3246 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3247 imsi := g_pars.imsi,
3248 sid := '20000101'O,
3249 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3250 ss := valueof(facility_rsp)
3251 );
3252
3253 /* MS sends response */
3254 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3255 f_expect_gsup_msg(gsup_rsp);
3256
3257 /* Compose expected MT SS/RELEASE COMPLETE message */
3258 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3259 tid := 0, /* FIXME: it shall match the request tid */
3260 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3261 facility := omit
3262 );
3263
3264 /* Compose MSC -> HLR GSUP message */
3265 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3266 imsi := g_pars.imsi,
3267 sid := '20000101'O,
3268 state := OSMO_GSUP_SESSION_STATE_END
3269 );
3270
3271 /* Finally, HLR terminates the session */
3272 GSUP.send(gsup_term);
3273 /* Expect MT RELEASE COMPLETE without Facility IE */
3274 f_expect_mt_dtap_msg(ussd_term);
3275
3276 /* Hold the call for some time */
3277 f_sleep(1.0);
3278
3279 /* Release the call (does Clear Complete itself) */
3280 f_call_hangup(cpars, true);
3281}
3282testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3283 var BSC_ConnHdlr vc_conn;
3284 f_init();
3285 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3286 vc_conn.done;
3287}
3288
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003289/* LU followed by MO USSD request and MO Release during transaction */
3290private function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
3291runs on BSC_ConnHdlr {
3292 f_init_handler(pars);
3293
3294 /* Perform location update */
3295 f_perform_lu();
3296
3297 /* Send CM Service Request for SS/USSD */
3298 f_establish_fully(EST_TYPE_SS_ACT);
3299
3300 /* We need to inspect GSUP activity */
3301 f_create_gsup_expect(hex2str(g_pars.imsi));
3302
3303 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3304 invoke_id := 1, /* Initial request */
3305 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3306 ussd_string := "*6766*266#"
3307 );
3308
3309 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3310 invoke_id := 2, /* Counter request */
3311 op_code := SS_OP_CODE_USS_REQUEST,
3312 ussd_string := "Password?!?"
3313 )
3314
3315 /* Compose MO SS/REGISTER message with request */
3316 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3317 tid := 1, /* We just need a single transaction */
3318 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3319 facility := valueof(facility_ms_req)
3320 );
3321
3322 /* Compose expected MSC -> HLR message */
3323 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3324 imsi := g_pars.imsi,
3325 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3326 ss := valueof(facility_ms_req)
3327 );
3328
3329 /* To be used for sending response with correct session ID */
3330 var GSUP_PDU gsup_ms_req_complete;
3331
3332 /* Initiate a new transaction */
3333 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3334 /* Expect GSUP request with original Facility IE */
3335 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3336
3337 /* Compose the response from HLR using received session ID */
3338 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3339 imsi := g_pars.imsi,
3340 sid := gsup_ms_req_complete.ies[1].val.session_id,
3341 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3342 ss := valueof(facility_net_req)
3343 );
3344
3345 /* Compose expected MT SS/FACILITY template with counter request */
3346 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3347 tid := 1, /* Response should arrive within the same transaction */
3348 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3349 facility := valueof(facility_net_req)
3350 );
3351
3352 /* Send response over GSUP */
3353 GSUP.send(gsup_net_req);
3354 /* Expect MT SS/FACILITY message with counter request */
3355 f_expect_mt_dtap_msg(ussd_net_req);
3356
3357 /* Compose MO SS/RELEASE COMPLETE */
3358 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3359 tid := 1, /* Response should arrive within the same transaction */
3360 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3361 facility := omit
3362 /* TODO: cause? */
3363 );
3364
3365 /* Compose expected HLR -> MSC abort message */
3366 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3367 imsi := g_pars.imsi,
3368 sid := gsup_ms_req_complete.ies[1].val.session_id,
3369 state := OSMO_GSUP_SESSION_STATE_END
3370 );
3371
3372 /* Abort transaction */
3373 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3374 /* Expect GSUP message indicating abort */
3375 f_expect_gsup_msg(gsup_abort);
3376
3377 f_expect_clear();
3378}
3379testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3380 var BSC_ConnHdlr vc_conn;
3381 f_init();
3382 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3383 vc_conn.done;
3384}
3385
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003386/* LU followed by MO USSD request and MT Release due to timeout */
3387private function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
3388runs on BSC_ConnHdlr {
3389 f_init_handler(pars);
3390
3391 /* Perform location update */
3392 f_perform_lu();
3393
3394 /* Send CM Service Request for SS/USSD */
3395 f_establish_fully(EST_TYPE_SS_ACT);
3396
3397 /* We need to inspect GSUP activity */
3398 f_create_gsup_expect(hex2str(g_pars.imsi));
3399
3400 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3401 invoke_id := 1,
3402 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3403 ussd_string := "#release_me");
3404
3405 /* Compose MO SS/REGISTER message with request */
3406 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3407 tid := 1, /* An arbitrary transaction identifier */
3408 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3409 facility := valueof(facility_ms_req));
3410
3411 /* Compose expected MSC -> HLR message */
3412 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3413 imsi := g_pars.imsi,
3414 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3415 ss := valueof(facility_ms_req));
3416
3417 /* To be used for sending response with correct session ID */
3418 var GSUP_PDU gsup_ms_req_complete;
3419
3420 /* Initiate a new SS transaction */
3421 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3422 /* Expect GSUP request with original Facility IE */
3423 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3424
3425 /* Don't respond, wait for timeout */
3426 f_sleep(3.0);
3427
3428 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3429 tid := 1, /* Should match the request's tid */
3430 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3431 cause := *, /* TODO: expect some specific value */
3432 facility := omit);
3433
3434 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3435 imsi := g_pars.imsi,
3436 sid := gsup_ms_req_complete.ies[1].val.session_id,
3437 state := OSMO_GSUP_SESSION_STATE_END,
3438 cause := ?); /* TODO: expect some specific value */
3439
3440 /* Expect release on both interfaces */
3441 interleave {
3442 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3443 [] GSUP.receive(gsup_rel) { };
3444 }
3445
3446 f_expect_clear();
3447 setverdict(pass);
3448}
3449testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3450 var BSC_ConnHdlr vc_conn;
3451 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003452 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003453 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3454 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003455 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003456}
3457
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003458/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
3459private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3460 pars.net.expect_auth := true;
3461 pars.net.expect_ciph := true;
3462 pars.net.kc_support := '02'O; /* A5/1 only */
3463 f_init_handler(pars);
3464
3465 g_pars.vec := f_gen_auth_vec_2g();
3466
3467 /* Can't use f_perform_lu() directly. Code below is based on it. */
3468
3469 /* tell GSUP dispatcher to send this IMSI to us */
3470 f_create_gsup_expect(hex2str(g_pars.imsi));
3471
3472 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3473 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
3474 f_bssap_compl_l3(l3_lu);
3475
3476 f_mm_auth();
3477
3478 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3479 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3480 alt {
3481 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3482 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
3483 }
3484 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3485 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3486 mtc.stop;
3487 }
3488 [] BSSAP.receive {
3489 setverdict(fail, "Unknown/unexpected BSSAP received");
3490 mtc.stop;
3491 }
3492 }
3493
3494 /* Expect LU reject from MSC. */
3495 alt {
3496 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3497 setverdict(pass);
3498 }
3499 [] BSSAP.receive {
3500 setverdict(fail, "Unknown/unexpected BSSAP received");
3501 mtc.stop;
3502 }
3503 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01003504 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003505}
3506
3507testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
3508 var BSC_ConnHdlr vc_conn;
3509 f_init();
3510 f_vty_config(MSCVTY, "network", "encryption a5 1");
3511
3512 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52);
3513 vc_conn.done;
3514}
3515
Harald Weltef640a012018-04-14 17:49:21 +02003516/* TODO (SMS):
3517 * different user data lengths
3518 * SMPP transaction mode with unsuccessful delivery
3519 * queued MT-SMS with no paging response + later delivery
3520 * different data coding schemes
3521 * multi-part SMS
3522 * user-data headers
3523 * TP-PID for SMS to SIM
3524 * behavior if SMS memory is full + RP-SMMA
3525 * delivery reports
3526 * SMPP osmocom extensions
3527 * more-messages-to-send
3528 * SMS during ongoing call (SACCH/SAPI3)
3529 */
3530
3531/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01003532 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
3533 * malformed messages (missing IE, invalid message type): properly rejected?
3534 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
3535 * 3G/2G auth permutations
3536 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01003537 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01003538 * too long L3 INFO in DTAP
3539 * too long / padded BSSAP
3540 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01003541 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01003542
Harald Welte4263c522018-12-06 11:56:27 +01003543/* Perform a location updatye at the A-Interface and run some checks to confirm
3544 * that everything is back to normal. */
3545private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
3546 var SmsParameters spars := valueof(t_SmsPars);
3547
3548 /* Perform a location update, the SGs association is expected to fall
3549 * back to NULL */
3550 f_perform_lu();
3551 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3552
3553 /* Trigger a paging request and expect the paging on BSSMAP, this is
3554 * to make sure that pagings are sent throught the A-Interface again
3555 * and not throught the SGs interface.*/
3556 f_bssmap_register_imsi(g_pars.imsi, g_pars.tmsi);
3557 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3558
3559 alt {
3560 [] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
3561 setverdict(pass);
3562 }
3563 [] SGsAP.receive {
3564 setverdict(fail, "Received unexpected message on SGs");
3565 }
3566 }
3567
3568 /* Send an SMS to make sure that also payload messages are routed
3569 * throught the A-Interface again */
3570 f_establish_fully(EST_TYPE_MO_SMS);
3571 f_mo_sms(spars);
3572 f_expect_clear();
3573}
3574
3575private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3576 var charstring vlr_name;
3577 f_init_handler(pars);
3578
3579 vlr_name := f_sgsap_reset_mme(mp_mme_name);
3580 log("VLR name: ", vlr_name);
3581 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01003582 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01003583}
3584
3585testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003586 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003587 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003588 f_init(1, true);
3589 pars := f_init_pars(11810, true);
3590 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003591 vc_conn.done;
3592}
3593
3594/* like f_mm_auth() but for SGs */
3595function f_mm_auth_sgs() runs on BSC_ConnHdlr {
3596 if (g_pars.net.expect_auth) {
3597 g_pars.vec := f_gen_auth_vec_3g();
3598 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
3599 g_pars.vec.sres,
3600 g_pars.vec.kc,
3601 g_pars.vec.ik,
3602 g_pars.vec.ck,
3603 g_pars.vec.autn,
3604 g_pars.vec.res));
3605 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
3606 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
3607 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
3608 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
3609 }
3610}
3611
3612/* like f_perform_lu(), but on SGs rather than BSSAP */
3613function f_sgs_perform_lu() runs on BSC_ConnHdlr {
3614 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3615 var PDU_SGsAP lur;
3616 var PDU_SGsAP lua;
3617 var PDU_SGsAP mm_info;
3618 var octetstring mm_info_dtap;
3619
3620 /* tell GSUP dispatcher to send this IMSI to us */
3621 f_create_gsup_expect(hex2str(g_pars.imsi));
3622
3623 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3624 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3625 /* Old LAI, if MS sends it */
3626 /* TMSI status, if MS has no valid TMSI */
3627 /* IMEISV, if it supports "automatic device detection" */
3628 /* TAI, if available in MME */
3629 /* E-CGI, if available in MME */
3630 SGsAP.send(lur);
3631
3632 /* FIXME: is this really done over SGs? The Ue is already authenticated
3633 * via the MME ... */
3634 f_mm_auth_sgs();
3635
3636 /* Expect MSC to perform LU with HLR */
3637 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3638 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
3639 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
3640 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
3641
3642 alt {
3643 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
3644 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
3645 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
3646 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
3647 }
3648 setverdict(pass);
3649 }
3650 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3651 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
3652 }
3653 [] SGsAP.receive {
3654 setverdict(fail, "Received unexpected message on SGs");
3655 }
3656 }
3657
3658 /* Check MM information */
3659 if (mp_mm_info == true) {
3660 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
3661 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
3662 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
3663 setverdict(fail, "Unexpected MM Information");
3664 }
3665 }
3666
3667 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3668}
3669
3670private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3671 f_init_handler(pars);
3672 f_sgs_perform_lu();
3673 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3674
3675 f_sgsap_bssmap_screening();
3676
3677 setverdict(pass);
3678}
3679testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003680 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003681 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003682 f_init(1, true);
3683 pars := f_init_pars(11811, true);
3684 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003685 vc_conn.done;
3686}
3687
3688/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
3689private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3690 f_init_handler(pars);
3691 var PDU_SGsAP lur;
3692
3693 f_create_gsup_expect(hex2str(g_pars.imsi));
3694 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3695 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3696 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3697 SGsAP.send(lur);
3698
3699 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3700 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
3701 alt {
3702 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3703 setverdict(pass);
3704 }
3705 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
3706 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
3707 mtc.stop;
3708 }
3709 [] SGsAP.receive {
3710 setverdict(fail, "Received unexpected message on SGs");
3711 }
3712 }
3713
3714 f_sgsap_bssmap_screening();
3715
3716 setverdict(pass);
3717}
3718testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003719 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003720 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003721 f_init(1, true);
3722 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01003723
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003724 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003725 vc_conn.done;
3726}
3727
3728/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
3729private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3730 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3731 var PDU_SGsAP lur;
3732
3733 f_init_handler(pars);
3734
3735 /* tell GSUP dispatcher to send this IMSI to us */
3736 f_create_gsup_expect(hex2str(g_pars.imsi));
3737
3738 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
3739 ts_SGsAP_LAI('901'H, '70'H, 2342)));
3740 /* Old LAI, if MS sends it */
3741 /* TMSI status, if MS has no valid TMSI */
3742 /* IMEISV, if it supports "automatic device detection" */
3743 /* TAI, if available in MME */
3744 /* E-CGI, if available in MME */
3745 SGsAP.send(lur);
3746
3747 /* FIXME: is this really done over SGs? The Ue is already authenticated
3748 * via the MME ... */
3749 f_mm_auth_sgs();
3750
3751 /* Expect MSC to perform LU with HLR */
3752 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
3753 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
3754 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
3755 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
3756
3757 alt {
3758 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
3759 setverdict(pass);
3760 }
3761 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
3762 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
3763 }
3764 [] SGsAP.receive {
3765 setverdict(fail, "Received unexpected message on SGs");
3766 }
3767 }
3768
3769 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3770
3771 /* Wait until the VLR has abort the TMSI reallocation procedure */
3772 f_sleep(45.0);
3773
3774 /* The outcome does not change the SGs state, see also 5.2.3.4 */
3775 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3776
3777 f_sgsap_bssmap_screening();
3778
3779 setverdict(pass);
3780}
3781testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003782 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003783 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003784 f_init(1, true);
3785 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01003786
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003787 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003788 vc_conn.done;
3789}
3790
3791private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
3792runs on BSC_ConnHdlr {
3793 f_init_handler(pars);
3794 f_sgs_perform_lu();
3795 f_sleep(3.0);
3796
3797 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3798 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
3799 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
3800 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3801
3802 f_sgsap_bssmap_screening();
3803
3804 setverdict(pass);
3805}
3806testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003807 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003808 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003809 f_init(1, true);
3810 pars := f_init_pars(11814, true);
3811 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003812 vc_conn.done;
3813}
3814
3815private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
3816runs on BSC_ConnHdlr {
3817 f_init_handler(pars);
3818 f_sgs_perform_lu();
3819 f_sleep(3.0);
3820
3821 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
3822 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
3823 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
3824 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3825 /* FIXME: How to verify that VLR has removed MM context? */
3826
3827 f_sgsap_bssmap_screening();
3828
3829 setverdict(pass);
3830}
3831testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003832 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003833 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003834 f_init(1, true);
3835 pars := f_init_pars(11815, true);
3836 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003837 vc_conn.done;
3838}
3839
3840/* Trigger a paging request via VTY and send a paging reject in response */
3841private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
3842runs on BSC_ConnHdlr {
3843 f_init_handler(pars);
3844 f_sgs_perform_lu();
3845 f_sleep(1.0);
3846
3847 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3848 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3849 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3850 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3851
3852 /* Initiate paging via VTY */
3853 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3854 alt {
3855 [] SGsAP.receive(exp_resp) {
3856 setverdict(pass);
3857 }
3858 [] SGsAP.receive {
3859 setverdict(fail, "Received unexpected message on SGs");
3860 }
3861 }
3862
3863 /* Now reject the paging */
3864 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
3865
3866 /* Wait for the states inside the MSC to settle and check the state
3867 * of the SGs Association */
3868 f_sleep(1.0);
3869 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
3870
3871 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
3872 * but we also need to cover tha case where the cause code indicates an
3873 * "IMSI detached for EPS services". In those cases the VLR is expected to
3874 * try paging on tha A/Iu interface. This will be another testcase similar to
3875 * this one, but extended with checks for the presence of the A/Iu paging
3876 * messages. */
3877
3878 f_sgsap_bssmap_screening();
3879
3880 setverdict(pass);
3881}
3882testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003883 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003884 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003885 f_init(1, true);
3886 pars := f_init_pars(11816, true);
3887 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003888 vc_conn.done;
3889}
3890
3891/* Trigger a paging request via VTY and send a paging reject that indicates
3892 * that the subscriber intentionally rejected the call. */
3893private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
3894runs on BSC_ConnHdlr {
3895 f_init_handler(pars);
3896 f_sgs_perform_lu();
3897 f_sleep(1.0);
3898
3899 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3900 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3901 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3902 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3903
3904 /* Initiate paging via VTY */
3905 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3906 alt {
3907 [] SGsAP.receive(exp_resp) {
3908 setverdict(pass);
3909 }
3910 [] SGsAP.receive {
3911 setverdict(fail, "Received unexpected message on SGs");
3912 }
3913 }
3914
3915 /* Now reject the paging */
3916 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
3917
3918 /* Wait for the states inside the MSC to settle and check the state
3919 * of the SGs Association */
3920 f_sleep(1.0);
3921 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3922
3923 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
3924 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
3925 * to check back how this works and how it can be tested */
3926
3927 f_sgsap_bssmap_screening();
3928
3929 setverdict(pass);
3930}
3931testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003932 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003933 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003934 f_init(1, true);
3935 pars := f_init_pars(11817, true);
3936 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003937 vc_conn.done;
3938}
3939
3940/* Trigger a paging request via VTY and send an UE unreacable messge in response */
3941private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
3942runs on BSC_ConnHdlr {
3943 f_init_handler(pars);
3944 f_sgs_perform_lu();
3945 f_sleep(1.0);
3946
3947 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3948 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3949 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3950 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3951
3952 /* Initiate paging via VTY */
3953 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3954 alt {
3955 [] SGsAP.receive(exp_resp) {
3956 setverdict(pass);
3957 }
3958 [] SGsAP.receive {
3959 setverdict(fail, "Received unexpected message on SGs");
3960 }
3961 }
3962
3963 /* Now pretend that the UE is unreachable */
3964 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
3965
3966 /* Wait for the states inside the MSC to settle and check the state
3967 * of the SGs Association. */
3968 f_sleep(1.0);
3969 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
3970
3971 f_sgsap_bssmap_screening();
3972
3973 setverdict(pass);
3974}
3975testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003976 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01003977 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01003978 f_init(1, true);
3979 pars := f_init_pars(11818, true);
3980 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01003981 vc_conn.done;
3982}
3983
3984/* Trigger a paging request via VTY but don't respond to it */
3985private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
3986runs on BSC_ConnHdlr {
3987 f_init_handler(pars);
3988 f_sgs_perform_lu();
3989 f_sleep(1.0);
3990
3991 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
3992 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
3993 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
3994 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
3995
3996 /* Initiate paging via VTY */
3997 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
3998 alt {
3999 [] SGsAP.receive(exp_resp) {
4000 setverdict(pass);
4001 }
4002 [] SGsAP.receive {
4003 setverdict(fail, "Received unexpected message on SGs");
4004 }
4005 }
4006
4007 /* Now do nothing, the MSC/VLR should fail silently to page after a
4008 * few seconds, The SGs association must remain unchanged. */
4009 f_sleep(15.0);
4010 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4011
4012 f_sgsap_bssmap_screening();
4013
4014 setverdict(pass);
4015}
4016testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004017 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004018 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004019 f_init(1, true);
4020 pars := f_init_pars(11819, true);
4021 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004022 vc_conn.done;
4023}
4024
4025/* Trigger a paging request via VTY and slip in an LU */
4026private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4027runs on BSC_ConnHdlr {
4028 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4029 f_init_handler(pars);
4030
4031 /* First we prepar the situation, where the SGs association is in state
4032 * NULL and the confirmed by radio contact indicator is set to false
4033 * as well. This can be archived by performing an SGs LU and then
4034 * resetting the VLR */
4035 f_sgs_perform_lu();
4036 f_sgsap_reset_mme(mp_mme_name);
4037 f_sleep(1.0);
4038 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4039
4040 /* Perform a paging, expect the paging messages on the SGs interface */
4041 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4042 alt {
4043 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4044 setverdict(pass);
4045 }
4046 [] SGsAP.receive {
4047 setverdict(fail, "Received unexpected message on SGs");
4048 }
4049 }
4050
4051 /* Perform the LU as normal */
4052 f_sgs_perform_lu();
4053 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4054
4055 /* Expect a new paging request right after the LU */
4056 alt {
4057 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4058 setverdict(pass);
4059 }
4060 [] SGsAP.receive {
4061 setverdict(fail, "Received unexpected message on SGs");
4062 }
4063 }
4064
4065 /* Test is done now, lets round everything up by rejecting the paging
4066 * cleanly. */
4067 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4068 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4069
4070 f_sgsap_bssmap_screening();
4071
4072 setverdict(pass);
4073}
4074testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004075 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004076 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004077 f_init(1, true);
4078 pars := f_init_pars(11820, true);
4079 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004080 vc_conn.done;
4081}
4082
4083/* Send unexpected unit-data through the SGs interface */
4084private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4085 f_init_handler(pars);
4086 f_sleep(1.0);
4087
4088 /* This simulates what happens when a subscriber without SGs
4089 * association gets unitdata via the SGs interface. */
4090
4091 /* Make sure the subscriber exists and the SGs association
4092 * is in NULL state */
4093 f_perform_lu();
4094 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4095
4096 /* Send some random unit data, the MSC/VLR should send a release
4097 * immediately. */
4098 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4099 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
4100
4101 f_sgsap_bssmap_screening();
4102
4103 setverdict(pass);
4104}
4105testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004106 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004107 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004108 f_init(1, true);
4109 pars := f_init_pars(11821, true);
4110 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004111 vc_conn.done;
4112}
4113
4114/* Send unsolicited unit-data through the SGs interface */
4115private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4116 f_init_handler(pars);
4117 f_sleep(1.0);
4118
4119 /* This simulates what happens when the MME attempts to send unitdata
4120 * to a subscriber that is completely unknown to the VLR */
4121
4122 /* Send some random unit data, the MSC/VLR should send a release
4123 * immediately. */
4124 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4125 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
4126
4127 f_sgsap_bssmap_screening();
4128
4129 setverdict(pass);
4130}
4131testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004132 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004133 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004134 f_init(1, true);
4135 pars := f_init_pars(11822, true);
4136 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004137 vc_conn.done;
4138}
4139
4140private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
4141 /* FIXME: Match an actual payload (second questionmark), the type is
4142 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
4143 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
4144 setverdict(fail, "Unexpected SMS related PDU from MSC");
4145 mtc.stop;
4146 }
4147}
4148
4149/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
4150function f_mt_sms_sgs(inout SmsParameters spars)
4151runs on BSC_ConnHdlr {
4152 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4153 var template (value) RPDU_MS_SGSN rp_mo;
4154 var template (value) PDU_ML3_MS_NW l3_mo;
4155
4156 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4157 var template RPDU_SGSN_MS rp_mt;
4158 var template PDU_ML3_NW_MS l3_mt;
4159
4160 var PDU_ML3_NW_MS sgsap_l3_mt;
4161
4162 var default d := activate(as_other_sms_sgs());
4163
4164 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
4165 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
4166 rp_mt := tr_RP_DATA_MT(?, ?, omit, tp_mt);
4167 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
4168
4169 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
4170
4171 /* Extract relevant identifiers */
4172 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
4173 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
4174
4175 /* send CP-ACK for CP-DATA just received */
4176 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
4177
4178 SGsAP.send(l3_mo);
4179
4180 /* send RP-ACK for RP-DATA */
4181 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
4182 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
4183
4184 SGsAP.send(l3_mo);
4185
4186 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
4187 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
4188
4189 SGsAP.receive(l3_mt);
4190
4191 deactivate(d);
4192
4193 setverdict(pass);
4194}
4195
4196/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
4197function f_mo_sms_sgs(inout SmsParameters spars)
4198runs on BSC_ConnHdlr {
4199 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4200 var template (value) RPDU_MS_SGSN rp_mo;
4201 var template (value) PDU_ML3_MS_NW l3_mo;
4202
4203 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4204 var template RPDU_SGSN_MS rp_mt;
4205 var template PDU_ML3_NW_MS l3_mt;
4206
4207 var default d := activate(as_other_sms_sgs());
4208
4209 /* just in case this is routed to SMPP.. */
4210 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
4211
4212 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
4213 spars.tp.udl, spars.tp.ud);
4214 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, spars.rp.orig, spars.rp.dest, tp_mo);
4215 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
4216
4217 SGsAP.send(l3_mo);
4218
4219 /* receive CP-ACK for CP-DATA above */
4220 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
4221
4222 if (ispresent(spars.exp_rp_err)) {
4223 /* expect an RP-ERROR message from MSC with given cause */
4224 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
4225 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4226 SGsAP.receive(l3_mt);
4227 /* send CP-ACK for CP-DATA just received */
4228 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4229 SGsAP.send(l3_mo);
4230 } else {
4231 /* expect RP-ACK for RP-DATA */
4232 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
4233 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4234 SGsAP.receive(l3_mt);
4235 /* send CP-ACO for CP-DATA just received */
4236 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4237 SGsAP.send(l3_mo);
4238 }
4239
4240 deactivate(d);
4241
4242 setverdict(pass);
4243}
4244
4245private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
4246runs on BSC_ConnHdlr {
4247 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
4248}
4249
4250/* Send a MT SMS via SGs interface */
4251private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4252 f_init_handler(pars);
4253 f_sgs_perform_lu();
4254 f_sleep(1.0);
4255 var SmsParameters spars := valueof(t_SmsPars);
4256 spars.tp.ud := 'C8329BFD064D9B53'O;
4257
4258 /* Trigger SMS via VTY */
4259 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4260 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4261
4262 /* Expect a paging request and respond accordingly with a service request */
4263 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
4264 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
4265
4266 /* Connection is now live, receive the MT-SMS */
4267 f_mt_sms_sgs(spars);
4268
4269 /* Expect a concluding release from the MSC */
4270 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4271
4272 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4273 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4274
4275 f_sgsap_bssmap_screening();
4276
4277 setverdict(pass);
4278}
4279testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004280 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004281 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004282 f_init(1, true);
4283 pars := f_init_pars(11823, true);
4284 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004285 vc_conn.done;
4286}
4287
4288/* Send a MO SMS via SGs interface */
4289private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4290 f_init_handler(pars);
4291 f_sgs_perform_lu();
4292 f_sleep(1.0);
4293 var SmsParameters spars := valueof(t_SmsPars);
4294 spars.tp.ud := 'C8329BFD064D9B53'O;
4295
4296 /* Send the MO-SMS */
4297 f_mo_sms_sgs(spars);
4298
4299 /* Expect a concluding release from the MSC/VLR */
4300 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4301
4302 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4303 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4304
4305 setverdict(pass);
4306
4307 f_sgsap_bssmap_screening()
4308}
4309testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004310 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004311 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004312 f_init(1, true);
4313 pars := f_init_pars(11824, true);
4314 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004315 vc_conn.done;
4316}
4317
4318/* Trigger sending of an MT sms via VTY but never respond to anything */
4319private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4320 f_init_handler(pars, 170.0);
4321 f_sgs_perform_lu();
4322 f_sleep(1.0);
4323
4324 var SmsParameters spars := valueof(t_SmsPars);
4325 spars.tp.ud := 'C8329BFD064D9B53'O;
4326 var integer page_count := 0;
4327 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4328 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4329 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4330 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4331
4332 /* Trigger SMS via VTY */
4333 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4334
4335 /* Expect the MSC/VLR to page exactly 10 times before giving up */
4336 alt {
4337 [] SGsAP.receive(exp_pag_req)
4338 {
4339 page_count := page_count + 1;
4340
4341 if (page_count < 10) {
4342 repeat;
4343 }
4344 }
4345 [] SGsAP.receive {
4346 setverdict(fail, "unexpected SGsAP message received");
4347 self.stop;
4348 }
4349 }
4350
4351 /* Wait some time to make sure the MSC is not delivering any further
4352 * paging messages or anything else that could be unexpected. */
4353 timer T := 20.0;
4354 T.start
4355 alt {
4356 [] SGsAP.receive(exp_pag_req)
4357 {
4358 setverdict(fail, "paging seems not to stop!");
4359 mtc.stop;
4360 }
4361 [] SGsAP.receive {
4362 setverdict(fail, "unexpected SGsAP message received");
4363 self.stop;
4364 }
4365 [] T.timeout {
4366 setverdict(pass);
4367 }
4368 }
4369
4370 /* Even on a failed paging the SGs Association should stay intact */
4371 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4372
4373 /* Note: We do not execute f_sgsap_bssmap_screening() here since the
4374 * MSC/VLR would re-try to deliver the test SMS trigered above and
4375 * so the screening would fail. */
4376
4377 /* Expire the subscriber now to avoid that the MSC will try the SMS
4378 * delivery at some later point. */
4379 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
4380
4381 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01004382
4383 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01004384}
4385testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004386 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004387 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004388 f_init(1, true);
4389 pars := f_init_pars(11825, true);
4390 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004391 vc_conn.done;
4392}
4393
4394/* Trigger sending of an MT sms via VTY but reject the paging immediately */
4395private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4396 f_init_handler(pars, 150.0);
4397 f_sgs_perform_lu();
4398 f_sleep(1.0);
4399
4400 var SmsParameters spars := valueof(t_SmsPars);
4401 spars.tp.ud := 'C8329BFD064D9B53'O;
4402 var integer page_count := 0;
4403 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4404 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
4405 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4406 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4407
4408 /* Trigger SMS via VTY */
4409 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4410
4411 /* Expect a paging request and reject it immediately */
4412 SGsAP.receive(exp_pag_req);
4413 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4414
4415 /* The MSC/VLR should no longer try to page once the paging has been
4416 * rejected. Wait some time and check if there are no unexpected
4417 * messages on the SGs interface. */
4418 timer T := 20.0;
4419 T.start
4420 alt {
4421 [] SGsAP.receive(exp_pag_req)
4422 {
4423 setverdict(fail, "paging seems not to stop!");
4424 mtc.stop;
4425 }
4426 [] SGsAP.receive {
4427 setverdict(fail, "unexpected SGsAP message received");
4428 self.stop;
4429 }
4430 [] T.timeout {
4431 setverdict(pass);
4432 }
4433 }
4434
4435 /* A rejected paging with IMSI_unknown (see above) should always send
4436 * the SGs association to NULL. */
4437 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4438
4439 f_sgsap_bssmap_screening();
4440
4441 /* Expire the subscriber now to avoid that the MSC will try the SMS
4442 * delivery at some later point. */
4443 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
4444
4445 setverdict(pass);
4446}
4447testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004448 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004449 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004450 f_init(1, true);
4451 pars := f_init_pars(11826, true);
4452 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004453 vc_conn.done;
4454}
4455
4456/* Perform an MT CSDB call including LU */
4457private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
4458 f_init_handler(pars);
4459
4460 /* Be sure that the BSSMAP reset is done before we begin. */
4461 f_sleep(2.0);
4462
4463 /* Testcase variation: See what happens when we do a regular BSSMAP
4464 * LU first (this should not hurt in any way!) */
4465 if (bssmap_lu) {
4466 f_perform_lu();
4467 }
4468
4469 f_sgs_perform_lu();
4470 f_sleep(1.0);
4471
4472 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4473 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
4474 cpars.bss_rtp_port := 1110;
4475 cpars.mgcp_connection_id_bss := '10004'H;
4476 cpars.mgcp_connection_id_mss := '10005'H;
4477
4478 /* Note: This is an optional parameter. When the call-agent (MSC) does
4479 * supply a full endpoint name this setting will be overwritten. */
4480 cpars.mgcp_ep := "rtpbridge/1@mgw";
4481
4482 /* Initiate a call via MNCC interface */
4483 f_mt_call_initate(cpars);
4484
4485 /* Expect a paging request and respond accordingly with a service request */
4486 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
4487 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
4488
4489 /* Complete the call, hold it for some time and then tear it down */
4490 f_mt_call_complete(cpars);
4491 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01004492 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01004493
4494 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4495 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4496
4497 /* Finally simulate the return of the UE to the 4G network */
4498 SGsAP.send(ts_SGsAP_MO_CSFB_IND(pars.imsi));
4499
4500 /* Test for successful return by triggering a paging, when the paging
4501 * request is received via SGs, we can be sure that the MSC/VLR has
4502 * recognized that the UE is now back on 4G */
4503 f_sleep(1.0);
4504 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4505 alt {
4506 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4507 setverdict(pass);
4508 }
4509 [] SGsAP.receive {
4510 setverdict(fail, "Received unexpected message on SGs");
4511 }
4512 }
4513
4514 f_sgsap_bssmap_screening();
4515
4516 setverdict(pass);
4517}
4518
4519/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
4520private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4521 f_mt_lu_and_csfb_call(id, pars, true);
4522}
4523testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004524 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004525 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004526 f_init(1, true);
4527 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01004528
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004529 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004530 vc_conn.done;
4531}
4532
4533
4534/* Perform a SGSAP LU and then make a CSFB call */
4535private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4536 f_mt_lu_and_csfb_call(id, pars, false);
4537}
4538testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004539 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004540 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004541 f_init(1, true);
4542 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01004543
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004544 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004545 vc_conn.done;
4546}
4547
4548/* SGs TODO:
4549 * LU attempt for IMSI without NAM_PS in HLR
4550 * LU attempt with AUTH FAIL due to invalid RES/SRES
4551 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
4552 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
4553 * implicit IMSI detach from EPS
4554 * implicit IMSI detach from non-EPS
4555 * MM INFO
4556 *
4557 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004558
4559control {
Philipp Maier328d1662018-03-07 10:40:27 +01004560 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01004561 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01004562 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01004563 execute( TC_lu_imsi_reject() );
4564 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01004565 execute( TC_lu_imsi_auth_tmsi() );
4566 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01004567 execute( TC_lu_and_mo_call() );
Harald Welte071ed732018-01-23 19:53:52 +01004568 execute( TC_lu_auth_sai_timeout() );
4569 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01004570 execute( TC_lu_clear_request() );
4571 execute( TC_lu_disconnect() );
4572 execute( TC_lu_by_imei() );
4573 execute( TC_lu_by_tmsi_noauth_unknown() );
4574 execute( TC_imsi_detach_by_imsi() );
4575 execute( TC_imsi_detach_by_tmsi() );
4576 execute( TC_imsi_detach_by_imei() );
4577 execute( TC_emerg_call_imei_reject() );
4578 execute( TC_emerg_call_imsi() );
4579 execute( TC_cm_serv_req_vgcs_reject() );
4580 execute( TC_cm_serv_req_vbs_reject() );
4581 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01004582 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01004583 execute( TC_lu_auth_2G_fail() );
4584 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
4585 execute( TC_cl3_no_payload() );
4586 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01004587 execute( TC_establish_and_nothing() );
4588 execute( TC_mo_setup_and_nothing() );
4589 execute( TC_mo_crcx_ran_timeout() );
4590 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01004591 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01004592 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01004593 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01004594 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01004595 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
4596 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
4597 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01004598 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01004599 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
4600 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01004601 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01004602 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02004603 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01004604
4605 execute( TC_lu_and_mt_call() );
4606
Harald Weltef45efeb2018-04-09 18:19:24 +02004607 execute( TC_lu_and_mo_sms() );
4608 execute( TC_lu_and_mt_sms() );
Philipp Maier3983e702018-11-22 19:01:33 +01004609 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Harald Weltef640a012018-04-14 17:49:21 +02004610 execute( TC_smpp_mo_sms() );
4611 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02004612
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07004613 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07004614 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07004615 execute( TC_gsup_mt_sms_ack() );
4616 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07004617 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07004618 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07004619
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07004620 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07004621 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07004622 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07004623 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07004624 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07004625 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07004626
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004627 execute( TC_cipher_complete_with_invalid_cipher() );
4628
Harald Welte4263c522018-12-06 11:56:27 +01004629 execute( TC_sgsap_reset() );
4630 execute( TC_sgsap_lu() );
4631 execute( TC_sgsap_lu_imsi_reject() );
4632 execute( TC_sgsap_lu_and_nothing() );
4633 execute( TC_sgsap_expl_imsi_det_eps() );
4634 execute( TC_sgsap_expl_imsi_det_noneps() );
4635 execute( TC_sgsap_paging_rej() );
4636 execute( TC_sgsap_paging_subscr_rej() );
4637 execute( TC_sgsap_paging_ue_unr() );
4638 execute( TC_sgsap_paging_and_nothing() );
4639 execute( TC_sgsap_paging_and_lu() );
4640 execute( TC_sgsap_mt_sms() );
4641 execute( TC_sgsap_mo_sms() );
4642 execute( TC_sgsap_mt_sms_and_nothing() );
4643 execute( TC_sgsap_mt_sms_and_reject() );
4644 execute( TC_sgsap_unexp_ud() );
4645 execute( TC_sgsap_unsol_ud() );
4646 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
4647 execute( TC_sgsap_lu_and_mt_call() );
4648
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01004649 /* Run this last: at the time of writing this test crashes the MSC */
4650 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Philipp Maierdb7fb8d2019-02-11 10:50:13 +01004651 execute( TC_gsup_mt_multi_part_sms() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02004652 execute( TC_mo_cc_bssmap_clear() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01004653}
4654
4655
4656}