blob: 6f23e5f40a3a159917c5b78dcdfce48fa14515f5 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
Andreas Eversberg1733de32023-07-27 16:27:05 +020016friend module MSC_Tests_ASCI;
Harald Weltee13cfb22019-04-23 16:52:02 +020017
Harald Weltef6dd64d2017-11-19 12:09:51 +010018import from General_Types all;
19import from Osmocom_Types all;
Pau Espin Pedrole979c402021-04-28 17:29:54 +020020import from GSM_Types all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010021
22import from M3UA_Types all;
23import from M3UA_Emulation all;
24
25import from MTP3asp_Types all;
26import from MTP3asp_PortType all;
27
28import from SCCPasp_Types all;
29import from SCCP_Types all;
30import from SCCP_Emulation all;
31
32import from SCTPasp_Types all;
33import from SCTPasp_PortType all;
34
Harald Weltea49e36e2018-01-21 19:29:33 +010035import from Osmocom_CTRL_Functions all;
36import from Osmocom_CTRL_Types all;
37import from Osmocom_CTRL_Adapter all;
38
Harald Welte3ca1c902018-01-24 18:51:27 +010039import from TELNETasp_PortType all;
40import from Osmocom_VTY_Functions all;
41
Harald Weltea49e36e2018-01-21 19:29:33 +010042import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010043import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010044
Harald Welte4aa970c2018-01-26 10:38:09 +010045import from MGCP_Emulation all;
46import from MGCP_Types all;
47import from MGCP_Templates all;
48import from SDP_Types all;
49
Harald Weltea49e36e2018-01-21 19:29:33 +010050import from GSUP_Emulation all;
51import from GSUP_Types all;
52import from IPA_Emulation all;
53
Harald Weltef6dd64d2017-11-19 12:09:51 +010054import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020055import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010056import from BSSAP_CodecPort all;
57import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020058import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010059import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020060import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010061
Harald Welte4263c522018-12-06 11:56:27 +010062import from SGsAP_Templates all;
63import from SGsAP_Types all;
64import from SGsAP_Emulation all;
65
Harald Weltea49e36e2018-01-21 19:29:33 +010066import from MobileL3_Types all;
67import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070068import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010069import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010070import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010071
Harald Weltef640a012018-04-14 17:49:21 +020072import from SMPP_Types all;
73import from SMPP_Templates all;
74import from SMPP_Emulation all;
75
Stefan Sperlingc307e682018-06-14 15:15:46 +020076import from SCCP_Templates all;
77
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070078import from SS_Types all;
79import from SS_Templates all;
80import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010081import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070082
Philipp Maier948747b2019-04-02 15:22:33 +020083import from TCCConversion_Functions all;
84
Harald Welte9b751a62019-04-14 17:39:29 +020085const integer NUM_BSC := 3;
Harald Weltef6dd64d2017-11-19 12:09:51 +010086
Harald Welte4263c522018-12-06 11:56:27 +010087/* Needed for SGsAP SMS */
88import from MobileL3_SMS_Types all;
89
Harald Weltea4ca4462018-02-09 00:17:14 +010090type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010091 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010092
Harald Welte6811d102019-04-14 22:23:14 +020093 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010094
Harald Weltea49e36e2018-01-21 19:29:33 +010095 /* no 'adapter_CT' for MNCC or GSUP */
96 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010097 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010098 var GSUP_Emulation_CT vc_GSUP;
99 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +0200100 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +0100101 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100102
103 /* only to get events from IPA underneath GSUP */
104 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100105 /* VTY to MSC */
106 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100107
108 /* A port to directly send BSSAP messages. This port is used for
109 * tests that require low level access to sen arbitrary BSSAP
110 * messages. Run f_init_bssap_direct() to connect and initialize */
111 port BSSAP_CODEC_PT BSSAP_DIRECT;
112
113 /* When BSSAP messages are directly sent, then the connection
114 * handler is not active, which means that also no guard timer is
115 * set up. The following timer will serve as a replacement */
116 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100117
118 /* Configure T(tias) over VTY, seconds */
119 var integer g_msc_sccp_timer_ias := 7 * 60;
120 /* Configure T(tiar) over VTY, seconds */
121 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100122}
123
124modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100125 /* remote parameters of IUT */
126 charstring mp_msc_ip := "127.0.0.1";
127 integer mp_msc_ctrl_port := 4255;
128 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100129
Harald Weltea49e36e2018-01-21 19:29:33 +0100130 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100131 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100132 charstring mp_hlr_ip := "127.0.0.1";
133 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100134 charstring mp_mgw_ip := "127.0.0.1";
135 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100136
Harald Weltea49e36e2018-01-21 19:29:33 +0100137 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100138
Harald Weltef640a012018-04-14 17:49:21 +0200139 integer mp_msc_smpp_port := 2775;
140 charstring mp_smpp_system_id := "msc_tester";
141 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100142 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
143 charstring mp_vlr_name := "vlr.example.net";
Eric Wild49888a62022-03-30 03:16:11 +0200144 integer mp_bssap_reset_retries := 1;
Harald Weltef640a012018-04-14 17:49:21 +0200145
Harald Welte6811d102019-04-14 22:23:14 +0200146 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200147 {
148 sccp_service_type := "mtp3_itu",
149 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
150 own_pc := 185,
151 own_ssn := 254,
152 peer_pc := 187,
153 peer_ssn := 254,
154 sio := '83'O,
155 rctx := 0
156 },
157 {
158 sccp_service_type := "mtp3_itu",
159 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
160 own_pc := 186,
161 own_ssn := 254,
162 peer_pc := 187,
163 peer_ssn := 254,
164 sio := '83'O,
165 rctx := 1
166 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100167 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100168}
169
Philipp Maier328d1662018-03-07 10:40:27 +0100170/* altstep for the global guard timer (only used when BSSAP_DIRECT
171 * is used for communication */
172private altstep as_Tguard_direct() runs on MTC_CT {
173 [] Tguard_direct.timeout {
174 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200175 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100176 }
177}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100178
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100179private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
180 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
181 if (respond) {
182 var BIT1 tid_remote := '1'B;
183 if (cpars.mo_call) {
184 tid_remote := '0'B;
185 }
186 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
187 }
188 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100189}
190
Harald Weltef640a012018-04-14 17:49:21 +0200191function f_init_smpp(charstring id) runs on MTC_CT {
192 id := id & "-SMPP";
193 var EsmePars pars := {
194 mode := MODE_TRANSCEIVER,
195 bind := {
196 system_id := mp_smpp_system_id,
197 password := mp_smpp_password,
198 system_type := "MSC_Tests",
199 interface_version := hex2int('34'H),
200 addr_ton := unknown,
201 addr_npi := unknown,
202 address_range := ""
203 },
204 esme_role := true
205 }
206
207 vc_SMPP := SMPP_Emulation_CT.create(id);
208 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
Harald Welte4698a4c2020-08-18 22:57:52 +0200209 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", 0));
Harald Weltef640a012018-04-14 17:49:21 +0200210}
211
212
Harald Weltea49e36e2018-01-21 19:29:33 +0100213function f_init_mncc(charstring id) runs on MTC_CT {
214 id := id & "-MNCC";
215 var MnccOps ops := {
216 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
217 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
218 }
219
220 vc_MNCC := MNCC_Emulation_CT.create(id);
221 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
222 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100223}
224
Harald Welte4aa970c2018-01-26 10:38:09 +0100225function f_init_mgcp(charstring id) runs on MTC_CT {
226 id := id & "-MGCP";
227 var MGCPOps ops := {
228 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
229 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
230 }
231 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100232 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100233 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100234 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200235 mgw_udp_port := mp_mgw_port,
236 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100237 }
238
239 vc_MGCP := MGCP_Emulation_CT.create(id);
240 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
241 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
242}
243
Philipp Maierc09a1312019-04-09 16:05:26 +0200244function ForwardUnitdataCallback(PDU_SGsAP msg)
245runs on SGsAP_Emulation_CT return template PDU_SGsAP {
246 SGsAP_CLIENT.send(msg);
247 return omit;
248}
249
Harald Welte4263c522018-12-06 11:56:27 +0100250function f_init_sgsap(charstring id) runs on MTC_CT {
251 id := id & "-SGsAP";
252 var SGsAPOps ops := {
253 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200254 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100255 }
256 var SGsAP_conn_parameters pars := {
257 remote_ip := mp_msc_ip,
258 remote_sctp_port := 29118,
259 local_ip := "",
260 local_sctp_port := -1
261 }
262
263 vc_SGsAP := SGsAP_Emulation_CT.create(id);
264 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
265 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
266}
267
268
Harald Weltea49e36e2018-01-21 19:29:33 +0100269function f_init_gsup(charstring id) runs on MTC_CT {
270 id := id & "-GSUP";
271 var GsupOps ops := {
272 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
273 }
274
275 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
276 vc_GSUP := GSUP_Emulation_CT.create(id);
277
278 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
279 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
280 /* we use this hack to get events like ASP_IPA_EVENT_UP */
281 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
282
283 vc_GSUP.start(GSUP_Emulation.main(ops, id));
284 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
285
286 /* wait for incoming connection to GSUP port before proceeding */
287 timer T := 10.0;
288 T.start;
289 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700290 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100291 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100292 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200293 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100294 }
295 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100296}
297
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200298function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100299
300 if (g_initialized == true) {
301 return;
302 }
303 g_initialized := true;
304
Philipp Maier75932982018-03-27 14:52:35 +0200305 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200306 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200307 }
308
Pau Espin Pedrol9a5b8ff2021-01-04 19:01:31 +0100309 f_ipa_ctrl_start_client(mp_msc_ip, mp_msc_ctrl_port);
Harald Welte3ca1c902018-01-24 18:51:27 +0100310
311 map(self:MSCVTY, system:MSCVTY);
312 f_vty_set_prompts(MSCVTY);
313 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100314
315 /* set some defaults */
316 f_vty_config(MSCVTY, "network", "authentication optional");
317 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200318 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100319 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100320 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
321 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +0200322 if (osmux) {
323 f_vty_config(MSCVTY, "msc", "osmux on");
324 } else {
325 f_vty_config(MSCVTY, "msc", "osmux off");
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200326 }
Daniel Willmann08862152022-02-22 13:21:49 +0100327
Neels Hofmeyrc47ce852023-03-06 17:16:50 +0100328 /* Configure the MGCP timeout so that a failure to set up all RTP streams triggers within the time that we keep
329 * an otherwise established call open. */
330 f_vty_config(MSCVTY, "msc", "timer mgw X2 3");
331
Daniel Willmann08862152022-02-22 13:21:49 +0100332 for (var integer i := 0; i < num_bsc; i := i + 1) {
333 if (isbound(mp_bssap_cfg[i])) {
334 var RanOps ranops := BSC_RanOps;
335 ranops.use_osmux := osmux;
Eric Wild49888a62022-03-30 03:16:11 +0200336 ranops.bssap_reset_retries := mp_bssap_reset_retries;
Daniel Willmann08862152022-02-22 13:21:49 +0100337 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
338 f_ran_adapter_start(g_bssap[i]);
339 } else {
340 testcase.stop("missing BSSAP configuration");
341 }
342 }
343
344 f_init_mncc("MSC_Test");
345 f_init_mgcp("MSC_Test");
346
347 if (gsup == true) {
348 f_init_gsup("MSC_Test");
349 }
350 f_init_smpp("MSC_Test");
351
352 if (sgsap == true) {
353 f_init_sgsap("MSC_Test");
354 }
355
Harald Weltef6dd64d2017-11-19 12:09:51 +0100356}
357
Philipp Maier328d1662018-03-07 10:40:27 +0100358/* Initialize for a direct connection to BSSAP. This function is an alternative
359 * to f_init() when the high level functions of the BSC_ConnectionHandler are
360 * not needed. */
361function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200362 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200363 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100364
365 /* Start guard timer and activate it as default */
366 Tguard_direct.start
367 activate(as_Tguard_direct());
368}
369
Harald Weltea49e36e2018-01-21 19:29:33 +0100370type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100371
Harald Weltea49e36e2018-01-21 19:29:33 +0100372/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200373function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200374 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O,
375 boolean verify_cell_id := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200376runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100377 var BSC_ConnHdlrNetworkPars net_pars := {
378 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
Neels Hofmeyre860fc42022-10-05 01:15:54 +0200379 net_config := { "authentication optional", "encryption a5 0" },
380 expect_attach_success := true,
Harald Weltede371492018-01-27 23:44:41 +0100381 expect_tmsi := true,
Neels Hofmeyre860fc42022-10-05 01:15:54 +0200382 expect_auth_attempt := false,
383 hlr_has_auth_info := true,
Harald Weltede371492018-01-27 23:44:41 +0100384 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200385 expect_ciph := false,
386 expect_imei := false,
387 expect_imei_early := false,
388 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
389 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100390 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100391 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200392 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
393 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100394 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100395 imei := f_gen_imei(imsi_suffix),
396 imsi := f_gen_imsi(imsi_suffix),
397 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100398 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100399 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100400 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100401 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100402 vec := omit,
Neels Hofmeyrb00c5b02021-06-23 20:05:25 +0200403 vec_keep := false,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100404 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100405 send_early_cm := true,
406 ipa_ctrl_ip := mp_msc_ip,
407 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100408 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100409 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200410 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200411 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100412 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200413 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200414 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200415 ran_is_geran := ran_is_geran,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200416 use_osmux := use_osmux,
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200417 use_ipv6 := false,
Oliver Smith44424db2023-08-22 13:54:09 +0200418 use_csd := false,
Pau Espin Pedrole979c402021-04-28 17:29:54 +0200419 verify_cell_id := verify_cell_id,
420 common_id_last_eutran_plmn := omit
Harald Weltea49e36e2018-01-21 19:29:33 +0100421 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200422 if (not ran_is_geran) {
423 pars.use_umts_aka := true;
424 pars.net.expect_auth := true;
425 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100426 return pars;
427}
428
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200429function f_start_handler_create(BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100430 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200431 var charstring id := testcasename() & int2str(pars.ran_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100432
433 vc_conn := BSC_ConnHdlr.create(id);
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200434
Harald Weltea49e36e2018-01-21 19:29:33 +0100435 /* BSSMAP part / A interface */
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200436 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx].vc_RAN:CLIENT);
437 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100438 /* MNCC part */
439 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
440 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100441 /* MGCP part */
442 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
443 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100444 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200445 if (pars.gsup_enable == true) {
446 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
447 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
448 }
Harald Weltef640a012018-04-14 17:49:21 +0200449 /* SMPP part */
450 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
451 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100452 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100453 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100454 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
455 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
456 }
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200457 return vc_conn;
458}
Harald Weltea49e36e2018-01-21 19:29:33 +0100459
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200460function f_start_handler_run(BSC_ConnHdlr vc_conn, void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT {
461 var charstring id := testcasename() & int2str(pars.ran_idx);
Harald Weltea10db902018-01-27 12:44:49 +0100462 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
463 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100464 vc_conn.start(derefers(fn)(id, pars));
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200465}
466
467function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
468 var BSC_ConnHdlr vc_conn;
469 vc_conn := f_start_handler_create(pars);
470 f_start_handler_run(vc_conn, fn, pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100471 return vc_conn;
472}
473
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200474function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false,
475 boolean verify_cell_id := true)
Harald Welte9b751a62019-04-14 17:39:29 +0200476runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200477 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux, verify_cell_id := verify_cell_id));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100478}
479
Harald Weltea49e36e2018-01-21 19:29:33 +0100480private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100481 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100482 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100483}
Harald Weltea49e36e2018-01-21 19:29:33 +0100484testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
485 var BSC_ConnHdlr vc_conn;
486 f_init();
487
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100488 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100489 vc_conn.done;
490}
491
492private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100493 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100494 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100495 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100496}
Harald Weltea49e36e2018-01-21 19:29:33 +0100497testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
498 var BSC_ConnHdlr vc_conn;
499 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100500 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100501
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100502 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100503 vc_conn.done;
504}
505
506/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200507friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100508 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100509 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
510
511 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200512 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100513 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100514 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
515 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
516 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100517 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
518 f_expect_clear();
519 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100520 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
521 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200522 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100523 }
524 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100525}
526testcase TC_lu_imsi_reject() runs on MTC_CT {
527 var BSC_ConnHdlr vc_conn;
528 f_init();
529
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200530 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100531 vc_conn.done;
532}
533
Harald Weltee13cfb22019-04-23 16:52:02 +0200534
535
Harald Weltea49e36e2018-01-21 19:29:33 +0100536/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200537friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100538 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100539 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
540
541 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200542 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100543 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100544 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
545 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
546 alt {
547 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100548 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
549 f_expect_clear();
550 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100551 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
552 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200553 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100554 }
555 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100556}
557testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
558 var BSC_ConnHdlr vc_conn;
559 f_init();
560
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200561 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100562 vc_conn.done;
563}
564
Harald Weltee13cfb22019-04-23 16:52:02 +0200565
Harald Welte7b1b2812018-01-22 21:23:06 +0100566private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100567 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100568 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100569 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100570}
571testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
572 var BSC_ConnHdlr vc_conn;
573 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100574 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100575
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100576 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100577 vc_conn.done;
578}
579
Harald Weltee13cfb22019-04-23 16:52:02 +0200580
581friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200582 pars.net.expect_auth := true;
583 pars.use_umts_aka := true;
584 f_init_handler(pars);
585 f_perform_lu();
586}
587testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
588 var BSC_ConnHdlr vc_conn;
589 f_init();
590 f_vty_config(MSCVTY, "network", "authentication required");
591
592 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
593 vc_conn.done;
594}
Harald Weltea49e36e2018-01-21 19:29:33 +0100595
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100596/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
597 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
598 */
599friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
600
601 f_init_handler(pars);
602
603 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
604 var PDU_DTAP_MT dtap_mt;
605
606 /* tell GSUP dispatcher to send this IMSI to us */
607 f_create_gsup_expect(hex2str(g_pars.imsi));
608
609 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
610 if (g_pars.ran_is_geran) {
611 f_bssap_compl_l3(l3_lu);
612 if (g_pars.send_early_cm) {
613 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
614 }
615 } else {
616 f_ranap_initial_ue(l3_lu);
617 }
618
619 f_mm_imei_early();
620 f_mm_common();
621 f_msc_lu_hlr();
622 f_mm_imei();
623
624 alt {
625 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
626 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
627 setverdict(fail, "Expected LU ACK, but received LU REJ");
628 mtc.stop;
629 }
630 }
631
632 /* currently (due to bug OS#4337), an extra LU reject is received before
633 terminating the connection. Enabling following line makes the test
634 pass: */
635 //f_expect_lu_reject('16'O); /* Cause: congestion */
636
637 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
638 extra time to avoid race conditons... */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200639 f_expect_clear(7.0, verify_vlr_cell_id := false);
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100640
641 setverdict(pass);
642}
643testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
644 var BSC_ConnHdlr vc_conn;
645 f_init();
646
647 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
648 vc_conn.done;
649}
650
Harald Weltee13cfb22019-04-23 16:52:02 +0200651
Harald Weltea49e36e2018-01-21 19:29:33 +0100652/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200653friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100654runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100655 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100656
657 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100658 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100659 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100660
661 f_create_gsup_expect(hex2str(g_pars.imsi));
662
663 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200664 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200665 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100666
667 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100668 T.start;
669 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100670 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
671 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200672 [] BSSAP.receive {
673 setverdict(fail, "Received unexpected BSSAP");
674 mtc.stop;
675 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100676 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
677 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200678 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100679 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200680 [] T.timeout {
Neels Hofmeyrf1c3c212020-08-19 13:15:32 +0000681 setverdict(fail, "Timeout waiting for CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200682 mtc.stop;
683 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100684 }
685
Harald Welte1ddc7162018-01-27 14:25:46 +0100686 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100687}
Harald Weltea49e36e2018-01-21 19:29:33 +0100688testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
689 var BSC_ConnHdlr vc_conn;
690 f_init();
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200691 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100692 vc_conn.done;
693}
694
Harald Weltee13cfb22019-04-23 16:52:02 +0200695
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000696/* Send CM SERVICE REQ for TMSI that has never performed LU before */
697friend function f_tc_cmserv_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
698runs on BSC_ConnHdlr {
699 f_init_handler(pars);
700
701 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('57111111'O));
702 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
703 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
704
705 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
706 f_cl3_or_initial_ue(l3_info);
707 f_mm_auth();
708
709 timer T := 10.0;
710 T.start;
711 alt {
712 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
713 [] BSSAP.receive {
714 setverdict(fail, "Received unexpected BSSAP");
715 mtc.stop;
716 }
717 [] T.timeout {
718 setverdict(fail, "Timeout waiting for CM SERV REJ");
719 mtc.stop;
720 }
721 }
722
723 f_expect_clear();
724}
725testcase TC_cmserv_tmsi_unknown() runs on MTC_CT {
726 var BSC_ConnHdlr vc_conn;
727 f_init();
728 vc_conn := f_start_handler(refers(f_tc_cmserv_tmsi_unknown), 57, verify_cell_id := false);
729 vc_conn.done;
730}
731
Neels Hofmeyr14d0b132020-08-19 13:49:05 +0000732/* Send Paging Response for IMSI that has never performed LU before */
733friend function f_tc_paging_response_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
734runs on BSC_ConnHdlr {
735 f_init_handler(pars);
736
737 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
738 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
739 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
740
741 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
742 f_cl3_or_initial_ue(l3_info);
743
744 /* The Paging Response gets rejected by a direct Clear Command */
745 f_expect_clear();
746}
747testcase TC_paging_response_imsi_unknown() runs on MTC_CT {
748 var BSC_ConnHdlr vc_conn;
749 f_init();
750 vc_conn := f_start_handler(refers(f_tc_paging_response_imsi_unknown), 58, verify_cell_id := false);
751 vc_conn.done;
752}
753
754/* Send Paging Response for TMSI that has never performed LU before */
755friend function f_tc_paging_response_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
756runs on BSC_ConnHdlr {
757 f_init_handler(pars);
758
759 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('59111111'O));
760 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
761 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
762
763 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
764 f_cl3_or_initial_ue(l3_info);
765
766 /* The Paging Response gets rejected by a direct Clear Command */
767 f_expect_clear();
768}
769testcase TC_paging_response_tmsi_unknown() runs on MTC_CT {
770 var BSC_ConnHdlr vc_conn;
771 f_init();
772 vc_conn := f_start_handler(refers(f_tc_paging_response_tmsi_unknown), 59, verify_cell_id := false);
773 vc_conn.done;
774}
775
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000776
Harald Weltee13cfb22019-04-23 16:52:02 +0200777friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100778 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200779 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100780 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100781 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100782}
783testcase TC_lu_and_mo_call() runs on MTC_CT {
784 var BSC_ConnHdlr vc_conn;
785 f_init();
786
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100787 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100788 vc_conn.done;
789}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200790friend function f_tc_lu_and_mo_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
791 f_init_handler(pars);
792 var CallParameters cpars := valueof(t_CallParams);
793 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
794 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
795 cpars.bss_rtp_ip := "::3";
796 f_perform_lu();
797 f_mo_call(cpars);
798}
799testcase TC_lu_and_mo_call_ipv6() runs on MTC_CT {
800 var BSC_ConnHdlr vc_conn;
801 f_init();
802
803 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call_ipv6), 7);
804 vc_conn.done;
805}
Harald Welte071ed732018-01-23 19:53:52 +0100806
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100807/* Verify T(iar) triggers and releases the channel */
808friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
809 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
810 f_init_handler(pars);
811 var CallParameters cpars := valueof(t_CallParams);
812 f_perform_lu();
813 f_mo_call_establish(cpars);
814
815 /* Expect the channel cleared upon T(iar) triggered: */
816 T_wait_iar.start;
817 alt {
818 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
819 T_wait_iar.stop
820 setverdict(pass);
821 }
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100822 [] T_wait_iar.timeout {
823 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
824 mtc.stop;
825 }
826 }
Harald Welte4a3fa712020-08-19 08:57:33 +0200827 /* DLCX for both directions; if we don't do this, we might receive either of the two during
828 * shutdown causing race conditions */
829 MGCP.receive(tr_DLCX(?));
830 MGCP.receive(tr_DLCX(?));
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100831
832 setverdict(pass);
833}
834testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
835 var BSC_ConnHdlr vc_conn;
836
837 /* Set T(iar) in MSC low enough that it will trigger before other side
838 has time to keep alive with a T(ias). Keep recommended ratio of
839 T(iar) >= T(ias)*2 */
840 g_msc_sccp_timer_ias := 2;
841 g_msc_sccp_timer_iar := 5;
842
843 f_init();
844
845 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
846 vc_conn.done;
847}
848
Harald Weltee13cfb22019-04-23 16:52:02 +0200849
Harald Welte071ed732018-01-23 19:53:52 +0100850/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200851friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100852 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100853
854 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
855 var PDU_DTAP_MT dtap_mt;
856
857 /* tell GSUP dispatcher to send this IMSI to us */
858 f_create_gsup_expect(hex2str(g_pars.imsi));
859
860 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200861 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100862
863 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200864 if (pars.ran_is_geran) {
865 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
866 }
Harald Welte071ed732018-01-23 19:53:52 +0100867
868 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
869 /* The HLR would normally return an auth vector here, but we fail to do so. */
870
871 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100872 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100873}
874testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
875 var BSC_ConnHdlr vc_conn;
876 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100877 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100878
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200879 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8, verify_cell_id := false);
Harald Welte071ed732018-01-23 19:53:52 +0100880 vc_conn.done;
881}
882
Harald Weltee13cfb22019-04-23 16:52:02 +0200883
Harald Welte071ed732018-01-23 19:53:52 +0100884/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200885friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100886 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100887
888 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
889 var PDU_DTAP_MT dtap_mt;
890
891 /* tell GSUP dispatcher to send this IMSI to us */
892 f_create_gsup_expect(hex2str(g_pars.imsi));
893
894 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200895 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100896
897 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200898 if (pars.ran_is_geran) {
899 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
900 }
Harald Welte071ed732018-01-23 19:53:52 +0100901
902 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
903 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
904
905 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100906 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100907}
908testcase TC_lu_auth_sai_err() runs on MTC_CT {
909 var BSC_ConnHdlr vc_conn;
910 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100911 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100912
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200913 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9, verify_cell_id := false);
Harald Welte2bb825f2018-01-22 11:31:18 +0100914 vc_conn.done;
915}
Harald Weltea49e36e2018-01-21 19:29:33 +0100916
Harald Weltee13cfb22019-04-23 16:52:02 +0200917
Harald Weltebc881782018-01-23 20:09:15 +0100918/* Test LU but BSC will send a clear request in the middle */
919private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100920 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100921
922 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
923 var PDU_DTAP_MT dtap_mt;
924
925 /* tell GSUP dispatcher to send this IMSI to us */
926 f_create_gsup_expect(hex2str(g_pars.imsi));
927
928 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200929 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +0200930 f_expect_common_id();
Harald Weltebc881782018-01-23 20:09:15 +0100931
932 /* Send Early Classmark, just for the fun of it */
933 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
934
935 f_sleep(1.0);
936 /* send clear request in the middle of the LU */
937 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200938 alt {
939 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
940 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
941 }
Harald Weltebc881782018-01-23 20:09:15 +0100942 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100943 alt {
944 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200945 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
946 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200947 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200948 repeat;
949 }
Harald Welte6811d102019-04-14 22:23:14 +0200950 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100951 }
Harald Weltebc881782018-01-23 20:09:15 +0100952 setverdict(pass);
953}
954testcase TC_lu_clear_request() runs on MTC_CT {
955 var BSC_ConnHdlr vc_conn;
956 f_init();
957
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100958 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100959 vc_conn.done;
960}
961
Vadim Yanitskiy109e7552021-02-05 05:36:02 +0100962/* Test reaction on Clear Request during a MO Call */
963friend function f_TC_mo_mt_call_clear_request(charstring id, BSC_ConnHdlrPars pars)
964runs on BSC_ConnHdlr {
965 var CallParameters cpars := valueof(t_CallParams);
966 var MNCC_PDU mncc_pdu;
967 timer T := 2.0;
968
969 f_init_handler(pars);
970
971 f_perform_lu();
972
973 /* HACK: reducing code duplication ('66'H - MO, '68'H - MT) */
974 if (pars.imsi == '262420002532766'H)
975 { f_mo_call_establish(cpars); }
976 else
977 { f_mt_call_establish(cpars); }
978
979 /* Hold the line for a while... */
980 f_sleep(2.0);
981
982 /* BSC sends BSSMAP Clear Request (e.g. due to RR failure) */
983 BSSAP.send(ts_BSSMAP_ClearRequest(1));
984
985 /* Expect (optional) CC RELEASE and Clear Command */
986 var default ccrel := activate(as_optional_cc_rel(cpars));
987 f_expect_clear();
988 deactivate(ccrel);
989
990 /* Expect RELease indication on the MNCC socket */
991 T.start;
992 alt {
993 [] MNCC.receive(tr_MNCC_REL_ind(cpars.mncc_callref)) -> value mncc_pdu {
994 log("Rx MNCC REL.ind, cause := ", mncc_pdu.u.signal.cause);
995 setverdict(pass);
996 }
997 [] MNCC.receive(MNCC_PDU:?) -> value mncc_pdu {
998 setverdict(fail, "Rx unexpected MNCC PDU: ", mncc_pdu);
999 }
1000 [] T.timeout {
1001 setverdict(fail, "Timeout waiting for MNCC REL.ind");
1002 }
1003 }
1004}
1005testcase TC_mo_call_clear_request() runs on MTC_CT {
1006 var BSC_ConnHdlr vc_conn;
1007
1008 f_init();
1009
1010 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532766); // '66'H - MO
1011 vc_conn.done;
1012}
1013testcase TC_mt_call_clear_request() runs on MTC_CT {
1014 var BSC_ConnHdlr vc_conn;
1015
1016 f_init();
1017
1018 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532768); // '68'H - MT
1019 vc_conn.done;
1020}
1021
Harald Welte66af9e62018-01-24 17:28:21 +01001022/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +02001023friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001024 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +01001025
1026 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1027 var PDU_DTAP_MT dtap_mt;
1028
1029 /* tell GSUP dispatcher to send this IMSI to us */
1030 f_create_gsup_expect(hex2str(g_pars.imsi));
1031
1032 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001033 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +01001034
1035 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001036 if (pars.ran_is_geran) {
1037 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1038 }
Harald Welte66af9e62018-01-24 17:28:21 +01001039
1040 f_sleep(1.0);
1041 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +02001042 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +01001043 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +01001044 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +01001045}
1046testcase TC_lu_disconnect() runs on MTC_CT {
1047 var BSC_ConnHdlr vc_conn;
1048 f_init();
1049
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001050 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +01001051 vc_conn.done;
1052}
1053
Harald Welteba7b6d92018-01-23 21:32:34 +01001054/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +02001055friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001056 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001057
Harald Welte256571e2018-01-24 18:47:19 +01001058 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +01001059 var PDU_DTAP_MT dtap_mt;
1060
1061 /* tell GSUP dispatcher to send this IMSI to us */
1062 f_create_gsup_expect(hex2str(g_pars.imsi));
1063
1064 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001065 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001066
1067 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001068 if (pars.ran_is_geran) {
1069 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1070 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001071 /* wait for LU reject, ignore any ID REQ */
1072 alt {
1073 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
1074 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
1075 }
1076 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001077 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001078}
1079testcase TC_lu_by_imei() runs on MTC_CT {
1080 var BSC_ConnHdlr vc_conn;
1081 f_init();
1082
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001083 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12, verify_cell_id := false);
Harald Welteba7b6d92018-01-23 21:32:34 +01001084 vc_conn.done;
1085}
1086
Harald Weltee13cfb22019-04-23 16:52:02 +02001087
Harald Welteba7b6d92018-01-23 21:32:34 +01001088/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
1089private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001090 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
1091 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +01001092 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001093
1094 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
1095 var PDU_DTAP_MT dtap_mt;
1096
1097 /* tell GSUP dispatcher to send this IMSI to us */
1098 f_create_gsup_expect(hex2str(g_pars.imsi));
1099
1100 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001101 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001102
1103 /* Send Early Classmark, just for the fun of it */
1104 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1105
1106 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +02001107 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001108 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +01001109 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
Harald Welte79f1e452020-08-18 22:55:02 +02001110 f_expect_common_id();
Harald Welteba7b6d92018-01-23 21:32:34 +01001111
1112 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1113 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1114 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1115 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1116 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1117
1118 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +01001119 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1120 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1121 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001122 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1123 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001124 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +01001125 }
1126 }
1127
Philipp Maier9b690e42018-12-21 11:50:03 +01001128 /* Wait for MM-Information (if enabled) */
1129 f_expect_mm_info();
1130
Harald Welteba7b6d92018-01-23 21:32:34 +01001131 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001132 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001133}
1134testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
1135 var BSC_ConnHdlr vc_conn;
1136 f_init();
1137
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001138 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +01001139 vc_conn.done;
1140}
1141
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001142/* Test LU by unknown TMSI, while the IMSI is already attached: osmo-msc should switch to the attached vlr_subscr. */
1143private function f_tc_attached_imsi_lu_unknown_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1144 f_init_handler(pars);
1145
1146 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('56111111'O);
1147 var PDU_DTAP_MT dtap_mt;
1148
1149 /* tell GSUP dispatcher to send this IMSI to us */
1150 f_create_gsup_expect(hex2str(g_pars.imsi));
1151
1152 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1153 f_cl3_or_initial_ue(l3_lu);
1154
1155 /* Send Early Classmark, just for the fun of it */
1156 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1157
1158 /* Wait for + respond to ID REQ (IMSI) */
1159 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1160 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1161 f_expect_common_id();
1162
1163 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1164 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1165 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1166 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1167 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1168
1169 alt {
1170 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1171 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1172 }
1173 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1174 setverdict(fail, "Expected LU ACK, but received REJ");
1175 mtc.stop;
1176 }
1177 }
1178
1179 /* Wait for MM-Information (if enabled) */
1180 f_expect_mm_info();
1181
1182 /* wait for normal teardown */
Eric Wild85cc1612022-03-30 01:44:29 +02001183 f_expect_clear(verify_vlr_cell_id := false);
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001184
1185 /* Now the same IMSI is still attached in the VLR, and a LU with an unknown TMSI reveals the same IMSI only
1186 * later during ID Response. osmo-msc first creates a new vlr_subscr for the unknown TMSI, and as soon as the
1187 * IMSI becomes known, must notice that this IMSI is still regarded as attached, and must not create evil twins.
1188 */
1189
1190 /* (since the TMSI Reallocation happened, we could do this with exactly the same TMSI as above, but for test
1191 * readability just use a different one.) */
1192 l3_lu := f_build_lu_tmsi('56222222'O);
1193 f_cl3_or_initial_ue(l3_lu);
1194
1195 /* Wait for + respond to ID REQ (IMSI) */
1196 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1197 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1198 f_expect_common_id();
1199
1200 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1201 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1202 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1203 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1204 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1205
1206 alt {
1207 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1208 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1209 }
1210 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1211 setverdict(fail, "Expected LU ACK, but received REJ");
1212 mtc.stop;
1213 }
1214 }
1215
1216 /* Wait for MM-Information (if enabled) */
1217 f_expect_mm_info();
1218
1219 /* wait for normal teardown */
Eric Wild85cc1612022-03-30 01:44:29 +02001220 f_expect_clear(verify_vlr_cell_id := false);
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001221}
1222testcase TC_attached_imsi_lu_unknown_tmsi() runs on MTC_CT {
1223 var BSC_ConnHdlr vc_conn;
1224 f_init();
1225
1226 vc_conn := f_start_handler(refers(f_tc_attached_imsi_lu_unknown_tmsi), 56);
1227 vc_conn.done;
1228}
1229
Harald Welte4d15fa72020-08-19 08:58:28 +02001230friend function f_imsi_detach_by_imsi() runs on BSC_ConnHdlr {
Harald Welte45164da2018-01-24 12:51:27 +01001231 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1232
1233 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001234 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001235
1236 /* Send Early Classmark, just for the fun of it? */
Harald Welte4d15fa72020-08-19 08:58:28 +02001237 if (g_pars.ran_is_geran) {
Harald Weltee13cfb22019-04-23 16:52:02 +02001238 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1239 }
Harald Welte45164da2018-01-24 12:51:27 +01001240
1241 /* wait for normal teardown */
Harald Welte4d15fa72020-08-19 08:58:28 +02001242 f_expect_clear(verify_vlr_cell_id := false);
1243}
1244
1245
1246/* Test IMSI DETACH (MI=IMSI) */
1247friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1248 f_init_handler(pars);
1249
1250 f_imsi_detach_by_imsi();
Harald Welte45164da2018-01-24 12:51:27 +01001251}
1252testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
1253 var BSC_ConnHdlr vc_conn;
1254 f_init();
1255
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001256 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001257 vc_conn.done;
1258}
1259
Harald Weltee13cfb22019-04-23 16:52:02 +02001260
Harald Welte45164da2018-01-24 12:51:27 +01001261/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001262friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001263 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001264
1265 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
1266
1267 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001268 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001269
1270 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001271 if (pars.ran_is_geran) {
1272 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1273 }
Harald Welte45164da2018-01-24 12:51:27 +01001274
1275 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001276 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001277}
1278testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1279 var BSC_ConnHdlr vc_conn;
1280 f_init();
1281
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001282 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001283 vc_conn.done;
1284}
1285
Harald Weltee13cfb22019-04-23 16:52:02 +02001286
Harald Welte45164da2018-01-24 12:51:27 +01001287/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001288friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001289 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001290
Harald Welte256571e2018-01-24 18:47:19 +01001291 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001292
1293 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001294 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001295
1296 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001297 if (pars.ran_is_geran) {
1298 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1299 }
Harald Welte45164da2018-01-24 12:51:27 +01001300
1301 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001302 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001303}
1304testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1305 var BSC_ConnHdlr vc_conn;
1306 f_init();
1307
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001308 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001309 vc_conn.done;
1310}
1311
1312
1313/* helper function for an emergency call. caller passes in mobile identity to use */
1314private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001315 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1316 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001317
Harald Welte0bef21e2018-02-10 09:48:23 +01001318 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001319}
1320
1321/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001322friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001323 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001324
Harald Welte256571e2018-01-24 18:47:19 +01001325 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001326 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001327 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001328 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001329 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001330}
1331testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1332 var BSC_ConnHdlr vc_conn;
1333 f_init();
1334
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001335 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001336 vc_conn.done;
1337}
1338
Harald Weltee13cfb22019-04-23 16:52:02 +02001339
Harald Welted5b91402018-01-24 18:48:16 +01001340/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001341friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001342 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001343 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001344 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001345 /* Then issue emergency call identified by IMSI */
1346 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1347}
1348testcase TC_emerg_call_imsi() runs on MTC_CT {
1349 var BSC_ConnHdlr vc_conn;
1350 f_init();
1351
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001352 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001353 vc_conn.done;
1354}
1355
Harald Weltee13cfb22019-04-23 16:52:02 +02001356
Harald Welte45164da2018-01-24 12:51:27 +01001357/* CM Service Request for VGCS -> reject */
1358private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001359 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001360
1361 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001362 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001363
1364 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001365 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001366 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001367 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001368 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001369}
1370testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1371 var BSC_ConnHdlr vc_conn;
1372 f_init();
1373
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001374 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001375 vc_conn.done;
1376}
1377
1378/* CM Service Request for VBS -> reject */
1379private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001380 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001381
1382 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001383 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001384
1385 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001386 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001387 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001388 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001389 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001390}
1391testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1392 var BSC_ConnHdlr vc_conn;
1393 f_init();
1394
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001395 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001396 vc_conn.done;
1397}
1398
1399/* CM Service Request for LCS -> reject */
1400private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001401 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001402
1403 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001404 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001405
1406 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001407 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001408 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001409 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001410 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001411}
1412testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1413 var BSC_ConnHdlr vc_conn;
1414 f_init();
1415
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001416 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001417 vc_conn.done;
1418}
1419
Harald Welte0195ab12018-01-24 21:50:20 +01001420/* CM Re-Establishment Request */
1421private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001422 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001423
1424 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001425 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001426
1427 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1428 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001429 f_cl3_or_initial_ue(l3_info);
Neels Hofmeyr49bbb512021-07-29 22:51:08 +02001430 /* Older osmo-msc returns: GSM48_REJECT_SRV_OPT_NOT_SUPPORTED = 32,
1431 * newer osmo-msc with CM Re-Establish support returns: GSM48_REJECT_CALL_CAN_NOT_BE_IDENTIFIED = 38 */
1432 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ( (int2oct(32,1), int2oct(38,1)) )));
Harald Welte1ddc7162018-01-27 14:25:46 +01001433 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001434}
1435testcase TC_cm_reest_req_reject() runs on MTC_CT {
1436 var BSC_ConnHdlr vc_conn;
1437 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001438
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001439 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001440 vc_conn.done;
1441}
1442
Harald Weltec638f4d2018-01-24 22:00:36 +01001443/* Test LU (with authentication enabled), with wrong response from MS */
1444private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001445 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001446
1447 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1448
1449 /* tell GSUP dispatcher to send this IMSI to us */
1450 f_create_gsup_expect(hex2str(g_pars.imsi));
1451
1452 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001453 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001454
1455 /* Send Early Classmark, just for the fun of it */
1456 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1457
1458 var AuthVector vec := f_gen_auth_vec_2g();
1459 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1460 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1461 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1462
1463 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1464 /* Send back wrong auth response */
1465 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1466
1467 /* Expect GSUP AUTH FAIL REP to HLR */
1468 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1469
1470 /* Expect LU REJECT with Cause == Illegal MS */
1471 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001472 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001473}
1474testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1475 var BSC_ConnHdlr vc_conn;
1476 f_init();
1477 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001478
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001479 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23, verify_cell_id := false);
Harald Weltec638f4d2018-01-24 22:00:36 +01001480 vc_conn.done;
1481}
1482
Harald Weltede371492018-01-27 23:44:41 +01001483/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001484private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001485 pars.net.expect_auth := true;
1486 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001487 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001488 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001489}
1490testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1491 var BSC_ConnHdlr vc_conn;
1492 f_init();
1493 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001494 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1495
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001496 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001497 vc_conn.done;
1498}
1499
Harald Welte1af6ea82018-01-25 18:33:15 +01001500/* Test Complete L3 without payload */
1501private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001502 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001503
1504 /* Send Complete L3 Info with empty L3 frame */
1505 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1506 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1507
Harald Weltef466eb42018-01-27 14:26:54 +01001508 timer T := 5.0;
1509 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001510 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001511 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001512 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001513 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001514 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001515 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001516 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001517 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001518 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001519 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001520 }
1521 setverdict(pass);
1522}
1523testcase TC_cl3_no_payload() runs on MTC_CT {
1524 var BSC_ConnHdlr vc_conn;
1525 f_init();
1526
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001527 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001528 vc_conn.done;
1529}
1530
1531/* Test Complete L3 with random payload */
1532private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001533 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001534
Daniel Willmannaa14a382018-07-26 08:29:45 +02001535 /* length is limited by PDU_BSSAP length field which includes some
1536 * other fields beside l3info payload. So payl can only be 240 bytes
1537 * Since rnd() returns values < 1 multiply with 241
1538 */
1539 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001540 var octetstring payl := f_rnd_octstring(len);
1541
1542 /* Send Complete L3 Info with empty L3 frame */
1543 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1544 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1545
Harald Weltef466eb42018-01-27 14:26:54 +01001546 timer T := 5.0;
1547 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001548 alt {
1549 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001550 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001551 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001552 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001553 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001554 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001555 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001556 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001557 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001558 }
1559 setverdict(pass);
1560}
1561testcase TC_cl3_rnd_payload() runs on MTC_CT {
1562 var BSC_ConnHdlr vc_conn;
1563 f_init();
1564
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001565 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001566 vc_conn.done;
1567}
1568
Harald Welte116e4332018-01-26 22:17:48 +01001569/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001570friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001571 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001572
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001573 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001574
Harald Welteb9e86fa2018-04-09 18:18:31 +02001575 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001576 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001577}
1578testcase TC_establish_and_nothing() runs on MTC_CT {
1579 var BSC_ConnHdlr vc_conn;
1580 f_init();
1581
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001582 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001583 vc_conn.done;
1584}
1585
Harald Weltee13cfb22019-04-23 16:52:02 +02001586
Harald Welte12510c52018-01-26 22:26:24 +01001587/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001588friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001589 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001590
Harald Welte12510c52018-01-26 22:26:24 +01001591 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001592 cpars.mgw_conn_2.resp := 0;
1593 cpars.stop_after_cc_setup := true;
1594
1595 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001596
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001597 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001598
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001599 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001600
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001601 var default ccrel := activate(as_optional_cc_rel(cpars));
1602
Philipp Maier109e6aa2018-10-17 10:53:32 +02001603 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001604
1605 deactivate(ccrel);
1606
1607 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001608}
1609testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1610 var BSC_ConnHdlr vc_conn;
1611 f_init();
1612
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001613 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001614 vc_conn.done;
1615}
1616
Harald Weltee13cfb22019-04-23 16:52:02 +02001617
Harald Welte3ab88002018-01-26 22:37:25 +01001618/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001619friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001620 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001621 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1622 var MNCC_PDU mncc;
1623 var MgcpCommand mgcp_cmd;
1624
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001625 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001626 /* Do not respond to the second CRCX */
1627 cpars.mgw_conn_2.resp := 0;
1628 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001629
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001630 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001631
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001632 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001633
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001634 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001635}
1636testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1637 var BSC_ConnHdlr vc_conn;
1638 f_init();
1639
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001640 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001641 vc_conn.done;
1642}
1643
Harald Weltee13cfb22019-04-23 16:52:02 +02001644
Harald Welte0cc82d92018-01-26 22:52:34 +01001645/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001646friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001647 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001648
Harald Welte0cc82d92018-01-26 22:52:34 +01001649 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001650
1651 /* Respond with error for the first CRCX */
1652 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001653
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001654 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001655 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001656
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001657 var default ccrel := activate(as_optional_cc_rel(cpars));
1658 f_expect_clear(60.0);
1659 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001660}
1661testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1662 var BSC_ConnHdlr vc_conn;
1663 f_init();
1664
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001665 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001666 vc_conn.done;
1667}
1668
Harald Welte3ab88002018-01-26 22:37:25 +01001669
Harald Welte812f7a42018-01-27 00:49:18 +01001670/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1671private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1672 var MNCC_PDU mncc;
1673 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001674
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001675 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001676 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001677
1678 /* Allocate call reference and send SETUP via MNCC to MSC */
1679 cpars.mncc_callref := f_rnd_int(2147483648);
1680 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1681 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1682
1683 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001684 f_expect_paging();
1685
Harald Welte812f7a42018-01-27 00:49:18 +01001686 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001687 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001688
1689 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1690
1691 /* MSC->MS: SETUP */
1692 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1693}
1694
1695/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001696friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001697 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001698 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1699 var MNCC_PDU mncc;
1700 var MgcpCommand mgcp_cmd;
1701
1702 f_mt_call_start(cpars);
1703
1704 /* MS->MSC: CALL CONFIRMED */
1705 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1706
1707 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1708
1709 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1710 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001711
1712 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1713 * set an endpoint name that fits the pattern. If not, just use the
1714 * endpoint name from the request */
1715 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1716 cpars.mgcp_ep := "rtpbridge/1@mgw";
1717 } else {
1718 cpars.mgcp_ep := mgcp_cmd.line.ep;
1719 }
1720
Harald Welte812f7a42018-01-27 00:49:18 +01001721 /* Respond to CRCX with error */
1722 var MgcpResponse mgcp_rsp := {
1723 line := {
1724 code := "542",
1725 trans_id := mgcp_cmd.line.trans_id,
1726 string := "FORCED_FAIL"
1727 },
Harald Welte812f7a42018-01-27 00:49:18 +01001728 sdp := omit
1729 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001730 var MgcpParameter mgcp_rsp_param := {
1731 code := "Z",
1732 val := cpars.mgcp_ep
1733 };
1734 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001735 MGCP.send(mgcp_rsp);
1736
1737 timer T := 30.0;
1738 T.start;
1739 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001740 [] T.timeout {
1741 setverdict(fail, "Timeout waiting for channel release");
1742 mtc.stop;
1743 }
Harald Welte812f7a42018-01-27 00:49:18 +01001744 [] MNCC.receive { repeat; }
1745 [] GSUP.receive { repeat; }
1746 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1747 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1748 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1749 repeat;
1750 }
1751 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001752 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001753 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001754 }
1755}
1756testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1757 var BSC_ConnHdlr vc_conn;
1758 f_init();
1759
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001760 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001761 vc_conn.done;
1762}
1763
1764
Harald Weltee13cfb22019-04-23 16:52:02 +02001765
Harald Welte812f7a42018-01-27 00:49:18 +01001766/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001767friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte812f7a42018-01-27 00:49:18 +01001768 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Harald Welte812f7a42018-01-27 00:49:18 +01001769 var MgcpCommand mgcp_cmd;
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001770 var PDU_BSSAP bssap;
1771 timer T310;
Harald Welte812f7a42018-01-27 00:49:18 +01001772
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001773 f_init_handler(pars);
1774
Neels Hofmeyr05606152023-03-06 22:42:27 +01001775 /* Make sure X2 does not fire in this test. This test does not send a CN RTP port to osmo-msc, which will
1776 * trigger X2 timeout. We want to test T310, so make X2 significantly longer than T310=30s. */
1777 f_vty_config(MSCVTY, "msc", "timer mgw X2 40");
1778
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001779 /* Initiate a MT call, establish connection */
Harald Welte812f7a42018-01-27 00:49:18 +01001780 f_mt_call_start(cpars);
1781
1782 /* MS->MSC: CALL CONFIRMED */
1783 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1784 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1785
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001786 /* NOTE: MSC is expected to start T310 here */
Harald Welte812f7a42018-01-27 00:49:18 +01001787
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001788 interleave {
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001789 /* MSC->MGW: CRCX (first) */
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001790 [] MGCP.receive(tr_CRCX) -> value mgcp_cmd {
1791 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
1792 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001793
1794 /* BSC->BSC: BSSMAP ASSIGNMENT REQ */
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001795 [] BSSAP.receive(tr_BSSMAP_AssignmentReq(omit, ?)) -> value bssap {
1796 BSSAP.send(ts_BSSMAP_AssignmentComplete(omit,
1797 aoip := f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port),
1798 speechCodec := ts_BSSMAP_IE_SpeechCodec({ ts_CodecFR })));
1799 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001800
1801 /* MSC->MGW: MDCX */
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001802 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
1803 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_1.mgcp_connection_id,
1804 sdp := omit));
1805 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001806
1807 /* MSC->MGW: CRCX (second) */
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001808 [] MGCP.receive(tr_CRCX) -> value mgcp_cmd {
1809 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001810 }
Neels Hofmeyrc29e6dc2022-08-09 02:38:10 +02001811
1812 [] MNCC.receive(tr_MNCC_RTP_CREATE(cpars.mncc_callref));
Neels Hofmeyrd8a4aee2022-07-25 22:07:24 +02001813 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001814
1815 /* Reschedule the guard timeout */
1816 g_Tguard.start(30.0 + 10.0);
1817
1818 /* NOTE: the BSC is expected to respond with CC ALERTING at this state, so
1819 * the MSC would stop T310. However, the idea is to verify T310 expiration
1820 * here, so grab some popcorn and wait for MNCC DISC.ind. */
1821 T310.start(30.0 + 2.0);
Neels Hofmeyre81ef422022-08-07 14:33:06 +02001822 var MNCC_PDU mncc_rx;
Harald Welte812f7a42018-01-27 00:49:18 +01001823 alt {
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001824 [] T310.timeout {
1825 setverdict(fail, "Timeout waiting for MNCC DISC.ind due to T310");
Daniel Willmannafce8662018-07-06 23:11:32 +02001826 mtc.stop;
1827 }
Harald Welte812f7a42018-01-27 00:49:18 +01001828 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1829 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
Neels Hofmeyr13eeb552022-08-07 14:33:37 +02001830 log("Rx MNCC DISC.ind, T310.read yields ", T310.read);
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001831 setverdict(pass);
Harald Welte812f7a42018-01-27 00:49:18 +01001832 }
Neels Hofmeyre81ef422022-08-07 14:33:06 +02001833 [] MNCC.receive(MNCC_PDU:?) -> value mncc_rx {
1834 log("Rx ", mncc_rx);
1835 setverdict(fail, "Expected MNCC DISC.ind, got some other MNCC message instead");
1836 mtc.stop;
1837 }
Harald Welte812f7a42018-01-27 00:49:18 +01001838 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001839
Harald Welte812f7a42018-01-27 00:49:18 +01001840 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1841 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001842 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, '1'B)));
Harald Welte812f7a42018-01-27 00:49:18 +01001843
1844 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001845 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1846 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001847 // FIXME: f_create_mgcp_delete_ep(cpars.mgcp_ep);
Harald Welte812f7a42018-01-27 00:49:18 +01001848 repeat;
1849 }
Harald Welte5946b332018-03-18 23:32:21 +01001850 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001851 }
1852}
1853testcase TC_mt_t310() runs on MTC_CT {
1854 var BSC_ConnHdlr vc_conn;
1855 f_init();
1856
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001857 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001858 vc_conn.done;
1859}
1860
Harald Weltee13cfb22019-04-23 16:52:02 +02001861
Harald Welte167458a2018-01-27 15:58:16 +01001862/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001863friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001864 f_init_handler(pars);
1865 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001866
1867 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001868 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001869
1870 /* First MO call should succeed */
1871 f_mo_call(cpars);
1872
1873 /* Cancel the subscriber in the VLR */
1874 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1875 alt {
1876 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1877 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1878 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001879 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001880 }
1881 }
1882
1883 /* Follow-up transactions should fail */
1884 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1885 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001886 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001887 alt {
1888 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1889 [] BSSAP.receive {
1890 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001891 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001892 }
1893 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001894
1895 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001896 setverdict(pass);
1897}
1898testcase TC_gsup_cancel() runs on MTC_CT {
1899 var BSC_ConnHdlr vc_conn;
1900 f_init();
1901
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001902 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33, verify_cell_id := false);
Harald Welte167458a2018-01-27 15:58:16 +01001903 vc_conn.done;
1904}
1905
Harald Weltee13cfb22019-04-23 16:52:02 +02001906
Harald Welte9de84792018-01-28 01:06:35 +01001907/* A5/1 only permitted on network side, and MS capable to do it */
1908private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1909 pars.net.expect_auth := true;
1910 pars.net.expect_ciph := true;
1911 pars.net.kc_support := '02'O; /* A5/1 only */
1912 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001913 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001914}
1915testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1916 var BSC_ConnHdlr vc_conn;
1917 f_init();
1918 f_vty_config(MSCVTY, "network", "authentication required");
1919 f_vty_config(MSCVTY, "network", "encryption a5 1");
1920
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001921 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001922 vc_conn.done;
1923}
1924
1925/* A5/3 only permitted on network side, and MS capable to do it */
1926private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1927 pars.net.expect_auth := true;
1928 pars.net.expect_ciph := true;
1929 pars.net.kc_support := '08'O; /* A5/3 only */
1930 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001931 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001932}
1933testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1934 var BSC_ConnHdlr vc_conn;
1935 f_init();
1936 f_vty_config(MSCVTY, "network", "authentication required");
1937 f_vty_config(MSCVTY, "network", "encryption a5 3");
1938
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001939 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001940 vc_conn.done;
1941}
1942
1943/* A5/3 only permitted on network side, and MS with only A5/1 support */
1944private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1945 pars.net.expect_auth := true;
1946 pars.net.expect_ciph := true;
1947 pars.net.kc_support := '08'O; /* A5/3 only */
1948 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1949 f_init_handler(pars, 15.0);
1950
1951 /* cannot use f_perform_lu() as we expect a reject */
1952 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1953 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001954 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001955 if (pars.send_early_cm) {
1956 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1957 } else {
1958 pars.cm1.esind := '0'B;
1959 }
Harald Welte9de84792018-01-28 01:06:35 +01001960 f_mm_auth();
1961 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001962 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1963 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1964 repeat;
1965 }
Harald Welte5946b332018-03-18 23:32:21 +01001966 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1967 f_expect_clear();
1968 }
Harald Welte9de84792018-01-28 01:06:35 +01001969 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1970 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001971 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001972 }
1973 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001974 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001975 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001976 }
1977 }
1978 setverdict(pass);
1979}
1980testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1981 var BSC_ConnHdlr vc_conn;
1982 f_init();
1983 f_vty_config(MSCVTY, "network", "authentication required");
1984 f_vty_config(MSCVTY, "network", "encryption a5 3");
1985
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001986 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001987 vc_conn.done;
1988}
1989testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1990 var BSC_ConnHdlrPars pars;
1991 var BSC_ConnHdlr vc_conn;
1992 f_init();
1993 f_vty_config(MSCVTY, "network", "authentication required");
1994 f_vty_config(MSCVTY, "network", "encryption a5 3");
1995
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001996 pars := f_init_pars(361, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001997 pars.send_early_cm := false;
1998 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001999 vc_conn.done;
2000}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01002001testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
2002 var BSC_ConnHdlr vc_conn;
2003 f_init();
2004 f_vty_config(MSCVTY, "network", "authentication required");
2005 f_vty_config(MSCVTY, "network", "encryption a5 3");
2006
2007 /* Make sure the MSC category is on DEBUG level to trigger the log
2008 * message that is reported in OS#2947 to trigger the segfault */
2009 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
2010
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02002011 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362, verify_cell_id := false);
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01002012 vc_conn.done;
2013}
Harald Welte9de84792018-01-28 01:06:35 +01002014
2015/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
2016private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2017 pars.net.expect_auth := true;
2018 pars.net.expect_ciph := true;
2019 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
2020 pars.cm1.a5_1 := '1'B;
2021 pars.cm2.a5_1 := '1'B;
2022 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2023 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
2024 f_init_handler(pars, 15.0);
2025
2026 /* cannot use f_perform_lu() as we expect a reject */
2027 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
2028 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02002029 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01002030 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
2031 f_mm_auth();
2032 alt {
Harald Welte5946b332018-03-18 23:32:21 +01002033 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
2034 f_expect_clear();
2035 }
Harald Welte9de84792018-01-28 01:06:35 +01002036 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
2037 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02002038 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01002039 }
2040 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01002041 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02002042 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01002043 }
2044 }
2045 setverdict(pass);
2046}
2047testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
2048 var BSC_ConnHdlr vc_conn;
2049 f_init();
2050 f_vty_config(MSCVTY, "network", "authentication required");
2051 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
2052
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02002053 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37, verify_cell_id := false);
Harald Welte9de84792018-01-28 01:06:35 +01002054 vc_conn.done;
2055}
2056
Eric Wild26f4a622021-05-17 15:27:05 +02002057/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with only A5/1 support */
2058private function f_tc_lu_imsi_auth_tmsi_encr_0134_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2059 pars.net.expect_auth := true;
2060 pars.net.expect_ciph := true;
2061 pars.net.kc_support := '03'O; /* A5/0 + A5/1 */
2062 pars.cm1.a5_1 := '0'B;
2063 pars.cm2.a5_1 := '0'B;
2064 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2065 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2066 pars.cm2.classmarkInformationType2_oct5.cm3 := '0'B;
2067 pars.cm3 := omit;
2068 pars.use_umts_aka := true;
2069
2070 f_init_handler(pars, 15.0);
2071 f_perform_lu();
2072}
2073testcase TC_lu_imsi_auth_tmsi_encr_0134_1() runs on MTC_CT {
2074 var BSC_ConnHdlr vc_conn;
2075 f_init();
2076 f_vty_config(MSCVTY, "network", "authentication required");
2077 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2078
2079 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_1), 39);
2080 vc_conn.done;
2081}
2082
2083/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with A5/3 + A5/4 support */
2084private function f_tc_lu_imsi_auth_tmsi_encr_0134_34(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2085 pars.net.expect_auth := true;
2086 pars.net.expect_ciph := true;
2087 pars.net.kc_support := '19'O; /* A5/3 + A5/4 */
2088 pars.cm1.a5_1 := '1'B;
2089 pars.cm2.a5_1 := '1'B;
2090 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
2091 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2092 pars.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
2093 pars.cm3 := valueof(ts_CM3_default);
2094 pars.use_umts_aka := true;
2095
2096 f_init_handler(pars, 15.0);
2097 f_perform_lu();
2098}
2099testcase TC_lu_imsi_auth_tmsi_encr_0134_34() runs on MTC_CT {
2100 var BSC_ConnHdlr vc_conn;
2101 f_init();
2102 f_vty_config(MSCVTY, "network", "authentication required");
2103 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2104
2105 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_34), 40);
2106 vc_conn.done;
2107}
2108
2109/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with A5/3 support but no CM3 */
2110private function f_tc_lu_imsi_auth_tmsi_encr_0134_34_no_cm3(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2111 pars.net.expect_auth := true;
2112 pars.net.expect_ciph := true;
2113 pars.net.kc_support := '19'O; /* A5/3 + A5/4 */
2114 pars.cm1.a5_1 := '1'B;
2115 pars.cm2.a5_1 := '1'B;
2116 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
2117 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2118 pars.cm2.classmarkInformationType2_oct5.cm3 := '0'B;
2119 pars.cm3 := omit;
2120 pars.use_umts_aka := true;
2121
2122 f_init_handler(pars, 15.0);
2123 f_perform_lu();
2124}
2125testcase TC_lu_imsi_auth_tmsi_encr_0134_34_no_cm3() runs on MTC_CT {
2126 var BSC_ConnHdlr vc_conn;
2127 f_init();
2128 f_vty_config(MSCVTY, "network", "authentication required");
2129 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2130
2131 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_34_no_cm3), 41);
2132 vc_conn.done;
2133}
2134
Harald Welte9de84792018-01-28 01:06:35 +01002135/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
2136private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2137 pars.net.expect_auth := true;
2138 pars.net.expect_ciph := true;
2139 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
2140 pars.cm1.a5_1 := '1'B;
2141 pars.cm2.a5_1 := '1'B;
2142 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2143 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
2144 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002145 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01002146}
2147testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
2148 var BSC_ConnHdlr vc_conn;
2149 f_init();
2150 f_vty_config(MSCVTY, "network", "authentication required");
2151 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
2152
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002153 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01002154 vc_conn.done;
2155}
2156
Harald Welte33ec09b2018-02-10 15:34:46 +01002157/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01002158friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01002159 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002160 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002161 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01002162
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002163 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01002164 f_mt_call(cpars);
2165}
2166testcase TC_lu_and_mt_call() runs on MTC_CT {
2167 var BSC_ConnHdlr vc_conn;
2168 f_init();
2169
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002170 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01002171 vc_conn.done;
2172}
2173
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002174testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
2175 var BSC_ConnHdlr vc_conn;
2176 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002177
2178 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
2179 vc_conn.done;
2180}
2181
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002182/* LU followed by MT call (including paging) */
2183friend function f_tc_lu_and_mt_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2184 f_init_handler(pars);
2185 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2186 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
2187 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
2188 cpars.bss_rtp_ip := "::3";
Pau Espin Pedrol563b3d02020-09-09 20:19:52 +02002189 cpars.mncc_rtp_ip := "::9";
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002190 f_perform_lu();
2191 f_mt_call(cpars);
2192}
2193testcase TC_lu_and_mt_call_ipv6() runs on MTC_CT {
2194 var BSC_ConnHdlr vc_conn;
2195 f_init();
2196
2197 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_ipv6), 39);
2198 vc_conn.done;
2199}
2200
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002201/* MT call while already Paging */
2202friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2203 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
2204 var SmsParameters spars := valueof(t_SmsPars);
2205 var OCT4 tmsi;
2206
2207 f_init_handler(pars);
2208
2209 /* Perform location update */
2210 f_perform_lu();
2211
2212 /* register an 'expect' for given IMSI (+TMSI) */
2213 if (isvalue(g_pars.tmsi)) {
2214 tmsi := g_pars.tmsi;
2215 } else {
2216 tmsi := 'FFFFFFFF'O;
2217 }
2218 f_ran_register_imsi(g_pars.imsi, tmsi);
2219
2220 log("start Paging by an SMS");
2221 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2222
2223 /* MSC->BSC: expect PAGING from MSC */
2224 f_expect_paging();
2225
2226 log("MNCC signals MT call, before Paging Response");
Oliver Smith97dc91f2023-05-31 13:53:21 +02002227 f_mt_call_initiate(cpars);
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002228 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
2229
2230 f_sleep(0.5);
2231 log("phone answers Paging, expecting both SMS and MT call to be established");
2232 f_establish_fully(EST_TYPE_PAG_RESP);
2233 spars.tp.ud := 'C8329BFD064D9B53'O;
2234 interleave {
2235 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
2236 log("Got SMS-DELIVER");
2237 };
2238 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
2239 log("Got CC Setup");
2240 };
2241 }
2242 setverdict(pass);
2243 log("success, tear down");
2244 var default ccrel := activate(as_optional_cc_rel(cpars));
2245 if (g_pars.ran_is_geran) {
2246 BSSAP.send(ts_BSSMAP_ClearRequest(0));
2247 } else {
2248 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
2249 }
2250 f_expect_clear();
2251 deactivate(ccrel);
2252 f_vty_sms_clear(hex2str(g_pars.imsi));
2253}
2254testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
2255 var BSC_ConnHdlrPars pars;
2256 var BSC_ConnHdlr vc_conn;
2257 f_init();
2258 pars := f_init_pars(391);
2259 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
2260 vc_conn.done;
2261}
2262
Daniel Willmann8b084372018-02-04 13:35:26 +01002263/* Test MO Call SETUP with DTMF */
2264private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2265 f_init_handler(pars);
2266 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01002267
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002268 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01002269 f_mo_seq_dtmf_dup(cpars);
2270}
2271testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
2272 var BSC_ConnHdlr vc_conn;
2273 f_init();
2274
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002275 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01002276 vc_conn.done;
2277}
Harald Welte9de84792018-01-28 01:06:35 +01002278
Philipp Maier328d1662018-03-07 10:40:27 +01002279testcase TC_cr_before_reset() runs on MTC_CT {
2280 timer T := 4.0;
2281 var boolean reset_ack_seen := false;
2282 f_init_bssap_direct();
2283
Harald Welte3ca0ce12019-04-23 17:18:48 +02002284 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02002285
Daniel Willmanne8018962018-08-21 14:18:00 +02002286 f_sleep(3.0);
2287
Philipp Maier328d1662018-03-07 10:40:27 +01002288 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02002289 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01002290
2291 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02002292 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01002293 T.start
2294 alt {
2295 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
2296 reset_ack_seen := true;
2297 repeat;
2298 }
2299
2300 /* Acknowledge MSC sided reset requests */
2301 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02002302 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01002303 repeat;
2304 }
2305
2306 /* Ignore all other messages (e.g CR from the connection request) */
2307 [] BSSAP_DIRECT.receive { repeat }
2308
2309 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
2310 * deadlock situation. The MSC is then unable to respond to any
2311 * further BSSMAP RESET or any other sort of traffic. */
2312 [reset_ack_seen == true] T.timeout { setverdict(pass) }
2313 [reset_ack_seen == false] T.timeout {
2314 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02002315 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01002316 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01002317 }
Philipp Maier328d1662018-03-07 10:40:27 +01002318}
Harald Welte9de84792018-01-28 01:06:35 +01002319
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002320/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02002321friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002322 f_init_handler(pars);
2323 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2324 var MNCC_PDU mncc;
2325 var MgcpCommand mgcp_cmd;
2326
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002327 /* Do not respond to the second CRCX */
2328 cpars.mgw_conn_2.resp := 0;
2329
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002330 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002331 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002332
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002333 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002334
2335 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002336
2337 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002338}
2339testcase TC_mo_release_timeout() runs on MTC_CT {
2340 var BSC_ConnHdlr vc_conn;
2341 f_init();
2342
2343 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
2344 vc_conn.done;
2345}
2346
Harald Welte12510c52018-01-26 22:26:24 +01002347
Philipp Maier2a98a732018-03-19 16:06:12 +01002348/* LU followed by MT call (including paging) */
2349private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2350 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002351 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01002352
2353 /* Intentionally disable the CRCX response */
2354 cpars.mgw_drop_dlcx := true;
2355
2356 /* Perform location update and call */
2357 f_perform_lu();
2358 f_mt_call(cpars);
2359}
2360testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
2361 var BSC_ConnHdlr vc_conn;
2362 f_init();
2363
2364 /* Perform an almost normal looking locationupdate + mt-call, but do
2365 * not respond to the DLCX at the end of the call */
2366 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
2367 vc_conn.done;
2368
2369 /* Wait a guard period until the MGCP layer in the MSC times out,
2370 * if the MSC is vulnerable to the use-after-free situation that is
2371 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
2372 * segfault now */
2373 f_sleep(6.0);
2374
2375 /* Run the init procedures once more. If the MSC has crashed, this
2376 * this will fail */
2377 f_init();
2378}
Harald Welte45164da2018-01-24 12:51:27 +01002379
Philipp Maier75932982018-03-27 14:52:35 +02002380/* Two BSSMAP resets from two different BSCs */
2381testcase TC_reset_two() runs on MTC_CT {
2382 var BSC_ConnHdlr vc_conn;
2383 f_init(2);
2384 f_sleep(2.0);
2385 setverdict(pass);
2386}
2387
Harald Weltee13cfb22019-04-23 16:52:02 +02002388/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
2389testcase TC_reset_two_1iu() runs on MTC_CT {
2390 var BSC_ConnHdlr vc_conn;
2391 f_init(3);
2392 f_sleep(2.0);
2393 setverdict(pass);
2394}
2395
Harald Weltef640a012018-04-14 17:49:21 +02002396/***********************************************************************
2397 * SMS Testing
2398 ***********************************************************************/
2399
Harald Weltef45efeb2018-04-09 18:19:24 +02002400/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002401friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002402 var SmsParameters spars := valueof(t_SmsPars);
2403
2404 f_init_handler(pars);
2405
2406 /* Perform location update and call */
2407 f_perform_lu();
2408
2409 f_establish_fully(EST_TYPE_MO_SMS);
2410
2411 //spars.exp_rp_err := 96; /* invalid mandatory information */
2412 f_mo_sms(spars);
2413
2414 f_expect_clear();
2415}
2416testcase TC_lu_and_mo_sms() runs on MTC_CT {
2417 var BSC_ConnHdlr vc_conn;
2418 f_init();
2419 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2420 vc_conn.done;
2421}
2422
Harald Weltee13cfb22019-04-23 16:52:02 +02002423
Harald Weltef45efeb2018-04-09 18:19:24 +02002424private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002425runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002426 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2427}
2428
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002429/* Remove still pending SMS */
2430private function f_vty_sms_clear(charstring imsi)
2431runs on BSC_ConnHdlr {
2432 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2433 f_vty_transceive(MSCVTY, "sms-queue clear");
2434}
2435
Harald Weltef45efeb2018-04-09 18:19:24 +02002436/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002437friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002438 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002439
2440 f_init_handler(pars);
2441
2442 /* Perform location update and call */
2443 f_perform_lu();
2444
2445 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002446 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002447
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002448 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002449
2450 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002451 f_expect_paging();
2452
Harald Weltef45efeb2018-04-09 18:19:24 +02002453 /* Establish DTAP / BSSAP / SCCP connection */
2454 f_establish_fully(EST_TYPE_PAG_RESP);
2455
2456 spars.tp.ud := 'C8329BFD064D9B53'O;
2457 f_mt_sms(spars);
2458
2459 f_expect_clear();
2460}
2461testcase TC_lu_and_mt_sms() runs on MTC_CT {
2462 var BSC_ConnHdlrPars pars;
2463 var BSC_ConnHdlr vc_conn;
2464 f_init();
2465 pars := f_init_pars(43);
2466 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002467 vc_conn.done;
2468}
2469
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002470/* SMS added while already Paging */
2471friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2472 var SmsParameters spars := valueof(t_SmsPars);
2473 var OCT4 tmsi;
2474
2475 f_init_handler(pars);
2476
2477 f_perform_lu();
2478
2479 /* register an 'expect' for given IMSI (+TMSI) */
2480 if (isvalue(g_pars.tmsi)) {
2481 tmsi := g_pars.tmsi;
2482 } else {
2483 tmsi := 'FFFFFFFF'O;
2484 }
2485 f_ran_register_imsi(g_pars.imsi, tmsi);
2486
2487 log("first SMS");
2488 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2489
2490 /* MSC->BSC: expect PAGING from MSC */
2491 f_expect_paging();
2492
2493 log("second SMS");
2494 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2495 * with the pending paging. Another SMS: */
2496 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2497
2498 /* Establish DTAP / BSSAP / SCCP connection */
2499 f_establish_fully(EST_TYPE_PAG_RESP);
2500
2501 spars.tp.ud := 'C8329BFD064D9B53'O;
2502 f_mt_sms(spars);
2503
2504 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2505 f_mt_sms(spars);
2506
2507 f_expect_clear();
2508}
2509testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2510 var BSC_ConnHdlrPars pars;
2511 var BSC_ConnHdlr vc_conn;
2512 f_init();
2513 pars := f_init_pars(44);
2514 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2515 vc_conn.done;
2516}
Harald Weltee13cfb22019-04-23 16:52:02 +02002517
Philipp Maier3983e702018-11-22 19:01:33 +01002518/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002519friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002520 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002521
Philipp Maier3983e702018-11-22 19:01:33 +01002522 f_init_handler(pars, 150.0);
2523
2524 /* Perform location update */
2525 f_perform_lu();
2526
2527 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002528 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002529
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002530 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2531
Neels Hofmeyr16237742019-03-06 15:34:01 +01002532 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002533 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002534
2535 /* Wait some time to make sure the MSC is not delivering any further
2536 * paging messages or anything else that could be unexpected. */
2537 timer T := 20.0;
2538 T.start
2539 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002540 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2541 setverdict(fail, "paging seems not to stop!");
2542 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002543 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002544 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2545 setverdict(fail, "paging seems not to stop!");
2546 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002547 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002548 [] BSSAP.receive {
2549 setverdict(fail, "unexpected BSSAP message received");
2550 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002551 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002552 [] T.timeout {
2553 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002554 }
2555 }
2556
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002557 f_vty_sms_clear(hex2str(g_pars.imsi));
2558
Philipp Maier3983e702018-11-22 19:01:33 +01002559 setverdict(pass);
2560}
2561testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2562 var BSC_ConnHdlrPars pars;
2563 var BSC_ConnHdlr vc_conn;
2564 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002565 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002566 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002567 vc_conn.done;
2568}
2569
Alexander Couzensfc02f242019-09-12 03:43:18 +02002570/* LU followed by MT SMS with repeated paging */
2571friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2572 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002573
2574 f_init_handler(pars);
2575
2576 /* Perform location update and call */
2577 f_perform_lu();
2578
2579 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002580 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002581
2582 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2583
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002584 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002585 /* MSC->BSC: expect PAGING from MSC */
2586 f_expect_paging();
2587
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002588 if (g_pars.ran_is_geran) {
2589 log("GERAN: expect no further Paging");
2590 } else {
2591 log("UTRAN: expect more Paging");
2592 }
2593
2594 timer T := 5.0;
2595 T.start;
2596 alt {
2597 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2598 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2599 mtc.stop;
2600 }
2601 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2602 log("UTRAN: second Paging received, as expected");
2603 setverdict(pass);
2604 }
2605 [] T.timeout {
2606 if (g_pars.ran_is_geran) {
2607 log("GERAN: No further Paging received, as expected");
2608 setverdict(pass);
2609 } else {
2610 setverdict(fail, "UTRAN: Expected a second Paging");
2611 mtc.stop;
2612 }
2613 }
2614 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002615
2616 /* Establish DTAP / BSSAP / SCCP connection */
2617 f_establish_fully(EST_TYPE_PAG_RESP);
2618
2619 spars.tp.ud := 'C8329BFD064D9B53'O;
2620 f_mt_sms(spars);
2621
2622 f_expect_clear();
2623}
2624testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2625 var BSC_ConnHdlrPars pars;
2626 var BSC_ConnHdlr vc_conn;
2627 f_init();
2628 pars := f_init_pars(1844);
2629 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2630 vc_conn.done;
2631}
Harald Weltee13cfb22019-04-23 16:52:02 +02002632
Harald Weltef640a012018-04-14 17:49:21 +02002633/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002634friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002635 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002636
Harald Weltef640a012018-04-14 17:49:21 +02002637 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002638
Harald Weltef640a012018-04-14 17:49:21 +02002639 /* Perform location update so IMSI is known + registered in MSC/VLR */
2640 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002641
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002642 /* MS/UE submits a MO SMS */
2643 f_establish_fully(EST_TYPE_MO_SMS);
2644 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002645
2646 var SMPP_PDU smpp;
2647 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2648 tr_smpp.body.deliver_sm := {
2649 service_type := "CMT",
2650 source_addr_ton := network_specific,
2651 source_addr_npi := isdn,
2652 source_addr := hex2str(pars.msisdn),
2653 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2654 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2655 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2656 esm_class := '00000001'B,
2657 protocol_id := 0,
2658 priority_flag := 0,
2659 schedule_delivery_time := "",
2660 replace_if_present := 0,
2661 data_coding := '00000001'B,
2662 sm_default_msg_id := 0,
2663 sm_length := ?,
2664 short_message := spars.tp.ud,
2665 opt_pars := {
2666 {
2667 tag := user_message_reference,
2668 len := 2,
2669 opt_value := {
2670 int2_val := oct2int(spars.tp.msg_ref)
2671 }
2672 }
2673 }
2674 };
2675 alt {
2676 [] SMPP.receive(tr_smpp) -> value smpp {
2677 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2678 }
2679 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2680 }
2681
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002682 /* MSC terminates the SMS transaction with RP-ACK */
2683 f_mo_sms_wait_rp_ack(spars);
2684
Harald Weltef640a012018-04-14 17:49:21 +02002685 f_expect_clear();
2686}
2687testcase TC_smpp_mo_sms() runs on MTC_CT {
2688 var BSC_ConnHdlr vc_conn;
2689 f_init();
2690 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2691 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2692 vc_conn.done;
2693 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2694}
2695
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002696/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2697friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2698runs on BSC_ConnHdlr {
2699 var SmsParameters spars := valueof(t_SmsPars);
2700 var SMPP_PDU smpp_pdu;
2701 timer T := 3.0;
2702
2703 f_init_handler(pars);
2704
2705 /* Perform location update */
2706 f_perform_lu();
2707
2708 /* MS/UE submits a MO SMS */
2709 f_establish_fully(EST_TYPE_MO_SMS);
2710 f_mo_sms_submit(spars);
2711
2712 /* ESME responds with an error (Invalid Destination Address) */
2713 T.start;
2714 alt {
2715 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2716 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2717 }
2718 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2719 [] T.timeout {
2720 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2721 mtc.stop;
2722 }
2723 }
2724
2725 /* Expect RP-ERROR on BSSAP interface */
2726 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2727 f_mo_sms_wait_rp_ack(spars);
2728
2729 f_expect_clear();
2730}
2731testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2732 var BSC_ConnHdlr vc_conn;
2733 f_init();
2734 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2735 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2736 vc_conn.done;
2737 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2738}
2739
Harald Weltee13cfb22019-04-23 16:52:02 +02002740
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002741/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002742friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002743runs on BSC_ConnHdlr {
2744 var SmsParameters spars := valueof(t_SmsPars);
2745 var GSUP_PDU gsup_msg_rx;
2746 var octetstring sm_tpdu;
2747
2748 f_init_handler(pars);
2749
2750 /* We need to inspect GSUP activity */
2751 f_create_gsup_expect(hex2str(g_pars.imsi));
2752
2753 /* Perform location update */
2754 f_perform_lu();
2755
2756 /* Send CM Service Request for SMS */
2757 f_establish_fully(EST_TYPE_MO_SMS);
2758
2759 /* Prepare expected SM-RP-UI (SM TPDU) */
2760 enc_TPDU_RP_DATA_MS_SGSN_fast(
2761 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2762 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2763 spars.tp.udl, spars.tp.ud)),
2764 sm_tpdu);
2765
2766 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2767 imsi := g_pars.imsi,
2768 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002769 /* SM-RP-DA: SMSC address */
2770 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2771 number := spars.rp.smsc_addr.rP_NumberDigits,
2772 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2773 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2774 ext := spars.rp.smsc_addr.rP_Ext)),
2775 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2776 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2777 number := g_pars.msisdn,
2778 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2779 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002780 /* TODO: can we use decmatch here? */
2781 sm_rp_ui := sm_tpdu
2782 );
2783
2784 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2785 f_mo_sms_submit(spars);
2786 alt {
2787 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002788 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002789 setverdict(pass);
2790 }
2791 [] GSUP.receive {
2792 log("RX unexpected GSUP message");
2793 setverdict(fail);
2794 mtc.stop;
2795 }
2796 }
2797
2798 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2799 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2800 imsi := g_pars.imsi,
2801 sm_rp_mr := spars.rp.msg_ref)));
2802 /* Expect RP-ACK on DTAP */
2803 f_mo_sms_wait_rp_ack(spars);
2804
2805 f_expect_clear();
2806}
2807testcase TC_gsup_mo_sms() runs on MTC_CT {
2808 var BSC_ConnHdlr vc_conn;
2809 f_init();
2810 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2811 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2812 vc_conn.done;
2813 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2814}
2815
Harald Weltee13cfb22019-04-23 16:52:02 +02002816
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002817/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002818friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002819runs on BSC_ConnHdlr {
2820 var SmsParameters spars := valueof(t_SmsPars);
2821 var GSUP_PDU gsup_msg_rx;
2822
2823 f_init_handler(pars);
2824
2825 /* We need to inspect GSUP activity */
2826 f_create_gsup_expect(hex2str(g_pars.imsi));
2827
2828 /* Perform location update */
2829 f_perform_lu();
2830
2831 /* Send CM Service Request for SMS */
2832 f_establish_fully(EST_TYPE_MO_SMS);
2833
2834 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2835 imsi := g_pars.imsi,
2836 sm_rp_mr := spars.rp.msg_ref,
2837 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2838 );
2839
2840 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2841 f_mo_smma(spars);
2842 alt {
2843 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002844 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002845 setverdict(pass);
2846 }
2847 [] GSUP.receive {
2848 log("RX unexpected GSUP message");
2849 setverdict(fail);
2850 mtc.stop;
2851 }
2852 }
2853
2854 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2855 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2856 imsi := g_pars.imsi,
2857 sm_rp_mr := spars.rp.msg_ref)));
2858 /* Expect RP-ACK on DTAP */
2859 f_mo_sms_wait_rp_ack(spars);
2860
2861 f_expect_clear();
2862}
2863testcase TC_gsup_mo_smma() runs on MTC_CT {
2864 var BSC_ConnHdlr vc_conn;
2865 f_init();
2866 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2867 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2868 vc_conn.done;
2869 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2870}
2871
Harald Weltee13cfb22019-04-23 16:52:02 +02002872
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002873/* Helper for sending MT SMS over GSUP */
2874private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2875runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002876 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002877 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2878 number := spars.rp.smsc_addr.rP_NumberDigits,
2879 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2880 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2881 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002882
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002883 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2884 imsi := g_pars.imsi,
2885 /* NOTE: MSC should assign RP-MR itself */
2886 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002887 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002888 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002889 /* Encoded SMS TPDU (taken from Wireshark)
2890 * FIXME: we should encode spars somehow */
2891 sm_rp_ui := '00068021436500008111328130858200'O,
2892 sm_rp_mms := mms
2893 ));
2894}
2895
2896/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002897friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002898runs on BSC_ConnHdlr {
2899 var SmsParameters spars := valueof(t_SmsPars);
2900
2901 f_init_handler(pars);
2902
2903 /* We need to inspect GSUP activity */
2904 f_create_gsup_expect(hex2str(g_pars.imsi));
2905
2906 /* Perform location update */
2907 f_perform_lu();
2908
2909 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002910 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002911
2912 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2913 imsi := g_pars.imsi,
2914 /* NOTE: MSC should assign RP-MR itself */
2915 sm_rp_mr := ?
2916 );
2917
2918 /* Submit a MT SMS on GSUP */
2919 f_gsup_forwardSM_req(spars);
2920
2921 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002922 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002923 f_establish_fully(EST_TYPE_PAG_RESP);
2924
2925 /* Wait for MT SMS on DTAP */
2926 f_mt_sms_expect(spars);
2927
2928 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2929 f_mt_sms_send_rp_ack(spars);
2930 alt {
2931 [] GSUP.receive(mt_forwardSM_res) {
2932 log("RX MT-forwardSM-Res (RP-ACK)");
2933 setverdict(pass);
2934 }
2935 [] GSUP.receive {
2936 log("RX unexpected GSUP message");
2937 setverdict(fail);
2938 mtc.stop;
2939 }
2940 }
2941
2942 f_expect_clear();
2943}
2944testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2945 var BSC_ConnHdlrPars pars;
2946 var BSC_ConnHdlr vc_conn;
2947 f_init();
2948 pars := f_init_pars(90);
2949 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2950 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2951 vc_conn.done;
2952 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2953}
2954
Harald Weltee13cfb22019-04-23 16:52:02 +02002955
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002956/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002957friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002958runs on BSC_ConnHdlr {
2959 var SmsParameters spars := valueof(t_SmsPars);
2960 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2961
2962 f_init_handler(pars);
2963
2964 /* We need to inspect GSUP activity */
2965 f_create_gsup_expect(hex2str(g_pars.imsi));
2966
2967 /* Perform location update */
2968 f_perform_lu();
2969
2970 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002971 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002972
2973 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2974 imsi := g_pars.imsi,
2975 /* NOTE: MSC should assign RP-MR itself */
2976 sm_rp_mr := ?,
2977 sm_rp_cause := sm_rp_cause
2978 );
2979
2980 /* Submit a MT SMS on GSUP */
2981 f_gsup_forwardSM_req(spars);
2982
2983 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002984 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002985 f_establish_fully(EST_TYPE_PAG_RESP);
2986
2987 /* Wait for MT SMS on DTAP */
2988 f_mt_sms_expect(spars);
2989
2990 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2991 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2992 alt {
2993 [] GSUP.receive(mt_forwardSM_err) {
2994 log("RX MT-forwardSM-Err (RP-ERROR)");
2995 setverdict(pass);
2996 mtc.stop;
2997 }
2998 [] GSUP.receive {
2999 log("RX unexpected GSUP message");
3000 setverdict(fail);
3001 mtc.stop;
3002 }
3003 }
3004
3005 f_expect_clear();
3006}
3007testcase TC_gsup_mt_sms_err() runs on MTC_CT {
3008 var BSC_ConnHdlrPars pars;
3009 var BSC_ConnHdlr vc_conn;
3010 f_init();
3011 pars := f_init_pars(91);
3012 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3013 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
3014 vc_conn.done;
3015 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3016}
3017
Harald Weltee13cfb22019-04-23 16:52:02 +02003018
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003019/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02003020friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003021runs on BSC_ConnHdlr {
3022 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
3023 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
3024
3025 f_init_handler(pars);
3026
3027 /* We need to inspect GSUP activity */
3028 f_create_gsup_expect(hex2str(g_pars.imsi));
3029
3030 /* Perform location update */
3031 f_perform_lu();
3032
3033 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003034 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003035
3036 /* Submit the 1st MT SMS on GSUP */
3037 log("TX MT-forwardSM-Req for the 1st SMS");
3038 f_gsup_forwardSM_req(spars1);
3039
3040 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02003041 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003042 f_establish_fully(EST_TYPE_PAG_RESP);
3043
3044 /* Wait for 1st MT SMS on DTAP */
3045 f_mt_sms_expect(spars1);
3046 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
3047 ", SM-RP-MR is ", spars1.rp.msg_ref);
3048
3049 /* Submit the 2nd MT SMS on GSUP */
3050 log("TX MT-forwardSM-Req for the 2nd SMS");
3051 f_gsup_forwardSM_req(spars2);
3052
3053 /* Wait for 2nd MT SMS on DTAP */
3054 f_mt_sms_expect(spars2);
3055 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
3056 ", SM-RP-MR is ", spars2.rp.msg_ref);
3057
3058 /* Both transaction IDs shall be different */
3059 if (spars1.tid == spars2.tid) {
3060 log("Both DTAP transaction IDs shall be different");
3061 setverdict(fail);
3062 }
3063
3064 /* Both SM-RP-MR values shall be different */
3065 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
3066 log("Both SM-RP-MR values shall be different");
3067 setverdict(fail);
3068 }
3069
3070 /* Both SM-RP-MR values shall be assigned */
3071 if (spars1.rp.msg_ref == 'FF'O) {
3072 log("Unassigned SM-RP-MR value for the 1st SMS");
3073 setverdict(fail);
3074 }
3075 if (spars2.rp.msg_ref == 'FF'O) {
3076 log("Unassigned SM-RP-MR value for the 2nd SMS");
3077 setverdict(fail);
3078 }
3079
3080 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
3081 f_mt_sms_send_rp_ack(spars1);
3082 alt {
3083 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3084 imsi := g_pars.imsi,
3085 sm_rp_mr := spars1.rp.msg_ref
3086 )) {
3087 log("RX MT-forwardSM-Res (RP-ACK)");
3088 setverdict(pass);
3089 }
3090 [] GSUP.receive {
3091 log("RX unexpected GSUP message");
3092 setverdict(fail);
3093 mtc.stop;
3094 }
3095 }
3096
3097 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
3098 f_mt_sms_send_rp_ack(spars2);
3099 alt {
3100 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3101 imsi := g_pars.imsi,
3102 sm_rp_mr := spars2.rp.msg_ref
3103 )) {
3104 log("RX MT-forwardSM-Res (RP-ACK)");
3105 setverdict(pass);
3106 }
3107 [] GSUP.receive {
3108 log("RX unexpected GSUP message");
3109 setverdict(fail);
3110 mtc.stop;
3111 }
3112 }
3113
3114 f_expect_clear();
3115}
3116testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
3117 var BSC_ConnHdlrPars pars;
3118 var BSC_ConnHdlr vc_conn;
3119 f_init();
3120 pars := f_init_pars(92);
3121 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3122 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
3123 vc_conn.done;
3124 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3125}
3126
Harald Weltee13cfb22019-04-23 16:52:02 +02003127
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003128/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02003129friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003130runs on BSC_ConnHdlr {
3131 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
3132 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
3133
3134 f_init_handler(pars);
3135
3136 /* We need to inspect GSUP activity */
3137 f_create_gsup_expect(hex2str(g_pars.imsi));
3138
3139 /* Perform location update */
3140 f_perform_lu();
3141
3142 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003143 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003144
3145 /* Send CM Service Request for MO SMMA */
3146 f_establish_fully(EST_TYPE_MO_SMS);
3147
3148 /* Submit MO SMMA on DTAP */
3149 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
3150 spars_mo.rp.msg_ref := '00'O;
3151 f_mo_smma(spars_mo);
3152
3153 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
3154 alt {
3155 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
3156 imsi := g_pars.imsi,
3157 sm_rp_mr := spars_mo.rp.msg_ref,
3158 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
3159 )) {
3160 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
3161 setverdict(pass);
3162 }
3163 [] GSUP.receive {
3164 log("RX unexpected GSUP message");
3165 setverdict(fail);
3166 mtc.stop;
3167 }
3168 }
3169
3170 /* Submit MT SMS on GSUP */
3171 log("TX MT-forwardSM-Req for the MT SMS");
3172 f_gsup_forwardSM_req(spars_mt);
3173
3174 /* Wait for MT SMS on DTAP */
3175 f_mt_sms_expect(spars_mt);
3176 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
3177 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
3178
3179 /* Both SM-RP-MR values shall be different */
3180 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
3181 log("Both SM-RP-MR values shall be different");
3182 setverdict(fail);
3183 }
3184
3185 /* SM-RP-MR value for MT SMS shall be assigned */
3186 if (spars_mt.rp.msg_ref == 'FF'O) {
3187 log("Unassigned SM-RP-MR value for the MT SMS");
3188 setverdict(fail);
3189 }
3190
3191 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
3192 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
3193 imsi := g_pars.imsi,
3194 sm_rp_mr := spars_mo.rp.msg_ref)));
3195 /* Expect RP-ACK for MO SMMA on DTAP */
3196 f_mo_sms_wait_rp_ack(spars_mo);
3197
3198 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
3199 f_mt_sms_send_rp_ack(spars_mt);
3200 alt {
3201 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3202 imsi := g_pars.imsi,
3203 sm_rp_mr := spars_mt.rp.msg_ref
3204 )) {
3205 log("RX MT-forwardSM-Res (RP-ACK)");
3206 setverdict(pass);
3207 }
3208 [] GSUP.receive {
3209 log("RX unexpected GSUP message");
3210 setverdict(fail);
3211 mtc.stop;
3212 }
3213 }
3214
3215 f_expect_clear();
3216}
3217testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
3218 var BSC_ConnHdlrPars pars;
3219 var BSC_ConnHdlr vc_conn;
3220 f_init();
3221 pars := f_init_pars(93);
3222 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3223 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
3224 vc_conn.done;
3225 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3226}
3227
Harald Weltee13cfb22019-04-23 16:52:02 +02003228
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003229/* Test multi-part MT-SMS over GSUP */
3230private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
3231runs on BSC_ConnHdlr {
3232 var SmsParameters spars := valueof(t_SmsPars);
3233
3234 f_init_handler(pars);
3235
3236 /* We need to inspect GSUP activity */
3237 f_create_gsup_expect(hex2str(g_pars.imsi));
3238
3239 /* Perform location update */
3240 f_perform_lu();
3241
3242 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003243 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003244
3245 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
3246 imsi := g_pars.imsi,
3247 /* NOTE: MSC should assign RP-MR itself */
3248 sm_rp_mr := ?
3249 );
3250
3251 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
3252 for (var integer i := 3; i >= 0; i := i-1) {
3253 /* Submit a MT SMS on GSUP (MMS is decremented) */
3254 f_gsup_forwardSM_req(spars, int2oct(i, 1));
3255
3256 /* Expect Paging Request and Establish connection */
3257 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02003258 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003259 f_establish_fully(EST_TYPE_PAG_RESP);
3260 }
3261
3262 /* Wait for MT SMS on DTAP */
3263 f_mt_sms_expect(spars);
3264
3265 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
3266 f_mt_sms_send_rp_ack(spars);
3267 alt {
3268 [] GSUP.receive(mt_forwardSM_res) {
3269 log("RX MT-forwardSM-Res (RP-ACK)");
3270 setverdict(pass);
3271 }
3272 [] GSUP.receive {
3273 log("RX unexpected GSUP message");
3274 setverdict(fail);
3275 mtc.stop;
3276 }
3277 }
3278
3279 /* Keep some 'distance' between transmissions */
3280 f_sleep(1.5);
3281 }
3282
3283 f_expect_clear();
3284}
3285testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
3286 var BSC_ConnHdlrPars pars;
3287 var BSC_ConnHdlr vc_conn;
3288 f_init();
3289 pars := f_init_pars(91);
3290 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3291 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
3292 vc_conn.done;
3293 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3294}
3295
Harald Weltef640a012018-04-14 17:49:21 +02003296/* convert GSM L3 TON to SMPP_TON enum */
3297function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
3298 select (ton) {
3299 case ('000'B) { return unknown; }
3300 case ('001'B) { return international; }
3301 case ('010'B) { return national; }
3302 case ('011'B) { return network_specific; }
3303 case ('100'B) { return subscriber_number; }
3304 case ('101'B) { return alphanumeric; }
3305 case ('110'B) { return abbreviated; }
3306 }
3307 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02003308 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003309}
3310/* convert GSM L3 NPI to SMPP_NPI enum */
3311function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
3312 select (npi) {
3313 case ('0000'B) { return unknown; }
3314 case ('0001'B) { return isdn; }
3315 case ('0011'B) { return data; }
3316 case ('0100'B) { return telex; }
3317 case ('0110'B) { return land_mobile; }
3318 case ('1000'B) { return national; }
3319 case ('1001'B) { return private_; }
3320 case ('1010'B) { return ermes; }
3321 }
3322 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02003323 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003324}
3325
3326/* build a SMPP_SM from SmsParameters */
3327function f_mt_sm_from_spars(SmsParameters spars)
3328runs on BSC_ConnHdlr return SMPP_SM {
3329 var SMPP_SM sm := {
3330 service_type := "CMT",
3331 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
3332 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
3333 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
3334 dest_addr_ton := international,
3335 dest_addr_npi := isdn,
3336 destination_addr := hex2str(g_pars.msisdn),
3337 esm_class := '00000001'B,
3338 protocol_id := 0,
3339 priority_flag := 0,
3340 schedule_delivery_time := "",
3341 validity_period := "",
3342 registered_delivery := '00000000'B,
3343 replace_if_present := 0,
3344 data_coding := '00000001'B,
3345 sm_default_msg_id := 0,
3346 sm_length := spars.tp.udl,
3347 short_message := spars.tp.ud,
3348 opt_pars := {}
3349 };
3350 return sm;
3351}
3352
3353/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
3354private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
3355 var SMPP_SM sm := f_mt_sm_from_spars(spars);
3356 if (trans_mode) {
3357 sm.esm_class := '00000010'B;
3358 }
3359
3360 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
3361 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
3362 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3363 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
3364 * before we expect the SMS delivery on the BSC/radio side */
3365 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3366 }
3367
3368 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02003369 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02003370 /* Establish DTAP / BSSAP / SCCP connection */
3371 f_establish_fully(EST_TYPE_PAG_RESP);
3372 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3373
3374 f_mt_sms(spars);
3375
3376 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3377 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3378 }
3379 f_expect_clear();
3380}
3381
3382/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
3383private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3384 f_init_handler(pars);
3385
3386 /* Perform location update so IMSI is known + registered in MSC/VLR */
3387 f_perform_lu();
3388 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3389
3390 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003391 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02003392
3393 var SmsParameters spars := valueof(t_SmsPars);
3394 /* TODO: test with more intelligent user data; test different coding schemes */
3395 spars.tp.ud := '00'O;
3396 spars.tp.udl := 1;
3397
3398 /* first test the non-transaction store+forward mode */
3399 f_smpp_mt_sms(spars, false);
3400
3401 /* then test the transaction mode */
3402 f_smpp_mt_sms(spars, true);
3403}
3404testcase TC_smpp_mt_sms() runs on MTC_CT {
3405 var BSC_ConnHdlr vc_conn;
3406 f_init();
3407 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
3408 vc_conn.done;
3409}
3410
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003411/***********************************************************************
3412 * USSD Testing
3413 ***********************************************************************/
3414
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003415private altstep as_unexp_gsup_or_bssap_msg()
3416runs on BSC_ConnHdlr {
3417 [] GSUP.receive {
3418 setverdict(fail, "Unknown/unexpected GSUP received");
3419 self.stop;
3420 }
3421 [] BSSAP.receive {
3422 setverdict(fail, "Unknown/unexpected BSSAP message received");
3423 self.stop;
3424 }
3425}
3426
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003427private function f_expect_gsup_msg(template GSUP_PDU msg,
3428 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003429runs on BSC_ConnHdlr return GSUP_PDU {
3430 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003431 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003432
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003433 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003434 alt {
3435 [] GSUP.receive(msg) -> value gsup_msg_complete {
3436 setverdict(pass);
3437 }
3438 /* We don't expect anything else */
3439 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003440 [] T.timeout {
3441 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3442 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003443 }
3444
3445 return gsup_msg_complete;
3446}
3447
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003448private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3449 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003450runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3451 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003452 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003453
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003454 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003455 alt {
3456 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3457 setverdict(pass);
3458 }
3459 /* We don't expect anything else */
3460 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003461 [] T.timeout {
3462 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3463 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003464 }
3465
3466 return bssap_msg_complete.dtap;
3467}
3468
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003469/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003470friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003471runs on BSC_ConnHdlr {
3472 f_init_handler(pars);
3473
3474 /* Perform location update */
3475 f_perform_lu();
3476
3477 /* Send CM Service Request for SS/USSD */
3478 f_establish_fully(EST_TYPE_SS_ACT);
3479
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003480 /* We need to inspect GSUP activity */
3481 f_create_gsup_expect(hex2str(g_pars.imsi));
3482
3483 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3484 invoke_id := 5, /* Phone may not start from 0 or 1 */
3485 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3486 ussd_string := "*#100#"
3487 );
3488
3489 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3490 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3491 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3492 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3493 )
3494
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003495 /* Compose a new SS/REGISTER message with request */
3496 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3497 tid := 1, /* We just need a single transaction */
3498 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003499 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003500 );
3501
3502 /* Compose SS/RELEASE_COMPLETE template with expected response */
3503 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3504 tid := 1, /* Response should arrive within the same transaction */
3505 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003506 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003507 );
3508
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003509 /* Compose expected MSC -> HLR message */
3510 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3511 imsi := g_pars.imsi,
3512 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3513 ss := valueof(facility_req)
3514 );
3515
3516 /* To be used for sending response with correct session ID */
3517 var GSUP_PDU gsup_req_complete;
3518
3519 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003520 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003521 /* Expect GSUP message containing the SS payload */
3522 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3523
3524 /* Compose the response from HLR using received session ID */
3525 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3526 imsi := g_pars.imsi,
3527 sid := gsup_req_complete.ies[1].val.session_id,
3528 state := OSMO_GSUP_SESSION_STATE_END,
3529 ss := valueof(facility_rsp)
3530 );
3531
3532 /* Finally, HLR terminates the session */
3533 GSUP.send(gsup_rsp);
3534 /* Expect RELEASE_COMPLETE message with the response */
3535 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003536
3537 f_expect_clear();
3538}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003539testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003540 var BSC_ConnHdlr vc_conn;
3541 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003542 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003543 vc_conn.done;
3544}
3545
Harald Weltee13cfb22019-04-23 16:52:02 +02003546
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003547/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003548friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003549runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003550 timer T := 5.0;
3551
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003552 f_init_handler(pars);
3553
3554 /* Perform location update */
3555 f_perform_lu();
3556
Harald Welte6811d102019-04-14 22:23:14 +02003557 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003558
3559 /* We need to inspect GSUP activity */
3560 f_create_gsup_expect(hex2str(g_pars.imsi));
3561
3562 /* Facility IE with network-originated USSD notification */
3563 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3564 op_code := SS_OP_CODE_USS_NOTIFY,
3565 ussd_string := "Mahlzeit!"
3566 );
3567
3568 /* Facility IE with acknowledgment to the USSD notification */
3569 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3570 /* In case of USSD notification, Return Result is empty */
3571 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3572 );
3573
3574 /* Compose a new MT SS/REGISTER message with USSD notification */
3575 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3576 tid := 0, /* FIXME: most likely, it should be 0 */
3577 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3578 facility := valueof(facility_req)
3579 );
3580
3581 /* Compose HLR -> MSC GSUP message */
3582 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3583 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003584 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003585 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3586 ss := valueof(facility_req)
3587 );
3588
3589 /* Send it to MSC and expect Paging Request */
3590 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003591 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003592 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003593 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3594 setverdict(pass);
3595 }
Harald Welte62113fc2019-05-09 13:04:02 +02003596 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003597 setverdict(pass);
3598 }
3599 /* We don't expect anything else */
3600 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003601 [] T.timeout {
3602 setverdict(fail, "Timeout waiting for Paging Request");
3603 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003604 }
3605
3606 /* Send Paging Response and expect USSD notification */
3607 f_establish_fully(EST_TYPE_PAG_RESP);
3608 /* Expect MT REGISTER message with USSD notification */
3609 f_expect_mt_dtap_msg(ussd_ntf);
3610
3611 /* Compose a new MO SS/FACILITY message with empty response */
3612 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3613 tid := 0, /* FIXME: it shall match the request tid */
3614 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3615 facility := valueof(facility_rsp)
3616 );
3617
3618 /* Compose expected MSC -> HLR GSUP message */
3619 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3620 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003621 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003622 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3623 ss := valueof(facility_rsp)
3624 );
3625
3626 /* MS sends response to the notification */
3627 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3628 /* Expect GSUP message containing the SS payload */
3629 f_expect_gsup_msg(gsup_rsp);
3630
3631 /* Compose expected MT SS/RELEASE COMPLETE message */
3632 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3633 tid := 0, /* FIXME: it shall match the request tid */
3634 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3635 facility := omit
3636 );
3637
3638 /* Compose MSC -> HLR GSUP message */
3639 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3640 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003641 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003642 state := OSMO_GSUP_SESSION_STATE_END
3643 );
3644
3645 /* Finally, HLR terminates the session */
3646 GSUP.send(gsup_term)
3647 /* Expect MT RELEASE COMPLETE without Facility IE */
3648 f_expect_mt_dtap_msg(ussd_term);
3649
3650 f_expect_clear();
3651}
3652testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3653 var BSC_ConnHdlr vc_conn;
3654 f_init();
3655 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3656 vc_conn.done;
3657}
3658
Harald Weltee13cfb22019-04-23 16:52:02 +02003659
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003660/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003661friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003662runs on BSC_ConnHdlr {
3663 f_init_handler(pars);
3664
3665 /* Call parameters taken from f_tc_lu_and_mt_call */
3666 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003667
3668 /* Perform location update */
3669 f_perform_lu();
3670
3671 /* Establish a MT call */
3672 f_mt_call_establish(cpars);
3673
3674 /* Hold the call for some time */
3675 f_sleep(1.0);
3676
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003677 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3678 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3679 ussd_string := "*#100#"
3680 );
3681
3682 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3683 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3684 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3685 )
3686
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003687 /* Compose a new SS/REGISTER message with request */
3688 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3689 tid := 1, /* We just need a single transaction */
3690 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003691 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003692 );
3693
3694 /* Compose SS/RELEASE_COMPLETE template with expected response */
3695 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3696 tid := 1, /* Response should arrive within the same transaction */
3697 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003698 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003699 );
3700
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003701 /* Compose expected MSC -> HLR message */
3702 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3703 imsi := g_pars.imsi,
3704 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3705 ss := valueof(facility_req)
3706 );
3707
3708 /* To be used for sending response with correct session ID */
3709 var GSUP_PDU gsup_req_complete;
3710
3711 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003712 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003713 /* Expect GSUP message containing the SS payload */
3714 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3715
3716 /* Compose the response from HLR using received session ID */
3717 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3718 imsi := g_pars.imsi,
3719 sid := gsup_req_complete.ies[1].val.session_id,
3720 state := OSMO_GSUP_SESSION_STATE_END,
3721 ss := valueof(facility_rsp)
3722 );
3723
3724 /* Finally, HLR terminates the session */
3725 GSUP.send(gsup_rsp);
3726 /* Expect RELEASE_COMPLETE message with the response */
3727 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003728
3729 /* Hold the call for some time */
3730 f_sleep(1.0);
3731
3732 /* Release the call (does Clear Complete itself) */
3733 f_call_hangup(cpars, true);
3734}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003735testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003736 var BSC_ConnHdlr vc_conn;
3737 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003738 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003739 vc_conn.done;
3740}
3741
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003742/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003743friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003744 f_init_handler(pars);
3745 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003746 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003747
3748 f_perform_lu();
3749
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003750 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003751 f_mo_call_establish(cpars);
3752 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003753 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003754
3755 f_sleep(1.0);
3756}
3757testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3758 var BSC_ConnHdlr vc_conn;
3759 f_init();
3760
3761 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3762 vc_conn.done;
3763}
3764
Harald Weltee13cfb22019-04-23 16:52:02 +02003765
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003766/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003767friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003768runs on BSC_ConnHdlr {
3769 f_init_handler(pars);
3770
3771 /* Call parameters taken from f_tc_lu_and_mt_call */
3772 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003773
3774 /* Perform location update */
3775 f_perform_lu();
3776
3777 /* Establish a MT call */
3778 f_mt_call_establish(cpars);
3779
3780 /* Hold the call for some time */
3781 f_sleep(1.0);
3782
3783 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3784 op_code := SS_OP_CODE_USS_REQUEST,
3785 ussd_string := "Please type anything..."
3786 );
3787
3788 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3789 op_code := SS_OP_CODE_USS_REQUEST,
3790 ussd_string := "Nope."
3791 )
3792
3793 /* Compose MT SS/REGISTER message with network-originated request */
3794 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3795 tid := 0, /* FIXME: most likely, it should be 0 */
3796 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3797 facility := valueof(facility_req)
3798 );
3799
3800 /* Compose HLR -> MSC GSUP message */
3801 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3802 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003803 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003804 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3805 ss := valueof(facility_req)
3806 );
3807
3808 /* Send it to MSC */
3809 GSUP.send(gsup_req);
3810 /* Expect MT REGISTER message with USSD request */
3811 f_expect_mt_dtap_msg(ussd_req);
3812
3813 /* Compose a new MO SS/FACILITY message with response */
3814 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3815 tid := 0, /* FIXME: it shall match the request tid */
3816 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3817 facility := valueof(facility_rsp)
3818 );
3819
3820 /* Compose expected MSC -> HLR GSUP message */
3821 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3822 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003823 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003824 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3825 ss := valueof(facility_rsp)
3826 );
3827
3828 /* MS sends response */
3829 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3830 f_expect_gsup_msg(gsup_rsp);
3831
3832 /* Compose expected MT SS/RELEASE COMPLETE message */
3833 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3834 tid := 0, /* FIXME: it shall match the request tid */
3835 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3836 facility := omit
3837 );
3838
3839 /* Compose MSC -> HLR GSUP message */
3840 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3841 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003842 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003843 state := OSMO_GSUP_SESSION_STATE_END
3844 );
3845
3846 /* Finally, HLR terminates the session */
3847 GSUP.send(gsup_term);
3848 /* Expect MT RELEASE COMPLETE without Facility IE */
3849 f_expect_mt_dtap_msg(ussd_term);
3850
3851 /* Hold the call for some time */
3852 f_sleep(1.0);
3853
3854 /* Release the call (does Clear Complete itself) */
3855 f_call_hangup(cpars, true);
3856}
3857testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3858 var BSC_ConnHdlr vc_conn;
3859 f_init();
3860 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3861 vc_conn.done;
3862}
3863
Harald Weltee13cfb22019-04-23 16:52:02 +02003864
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003865/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003866friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003867runs on BSC_ConnHdlr {
3868 f_init_handler(pars);
3869
3870 /* Perform location update */
3871 f_perform_lu();
3872
3873 /* Send CM Service Request for SS/USSD */
3874 f_establish_fully(EST_TYPE_SS_ACT);
3875
3876 /* We need to inspect GSUP activity */
3877 f_create_gsup_expect(hex2str(g_pars.imsi));
3878
3879 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3880 invoke_id := 1, /* Initial request */
3881 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3882 ussd_string := "*6766*266#"
3883 );
3884
3885 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3886 invoke_id := 2, /* Counter request */
3887 op_code := SS_OP_CODE_USS_REQUEST,
3888 ussd_string := "Password?!?"
3889 )
3890
3891 /* Compose MO SS/REGISTER message with request */
3892 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3893 tid := 1, /* We just need a single transaction */
3894 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3895 facility := valueof(facility_ms_req)
3896 );
3897
3898 /* Compose expected MSC -> HLR message */
3899 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3900 imsi := g_pars.imsi,
3901 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3902 ss := valueof(facility_ms_req)
3903 );
3904
3905 /* To be used for sending response with correct session ID */
3906 var GSUP_PDU gsup_ms_req_complete;
3907
3908 /* Initiate a new transaction */
3909 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3910 /* Expect GSUP request with original Facility IE */
3911 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3912
3913 /* Compose the response from HLR using received session ID */
3914 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3915 imsi := g_pars.imsi,
3916 sid := gsup_ms_req_complete.ies[1].val.session_id,
3917 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3918 ss := valueof(facility_net_req)
3919 );
3920
3921 /* Compose expected MT SS/FACILITY template with counter request */
3922 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3923 tid := 1, /* Response should arrive within the same transaction */
3924 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3925 facility := valueof(facility_net_req)
3926 );
3927
3928 /* Send response over GSUP */
3929 GSUP.send(gsup_net_req);
3930 /* Expect MT SS/FACILITY message with counter request */
3931 f_expect_mt_dtap_msg(ussd_net_req);
3932
3933 /* Compose MO SS/RELEASE COMPLETE */
3934 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3935 tid := 1, /* Response should arrive within the same transaction */
3936 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3937 facility := omit
3938 /* TODO: cause? */
3939 );
3940
3941 /* Compose expected HLR -> MSC abort message */
3942 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3943 imsi := g_pars.imsi,
3944 sid := gsup_ms_req_complete.ies[1].val.session_id,
3945 state := OSMO_GSUP_SESSION_STATE_END
3946 );
3947
3948 /* Abort transaction */
3949 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3950 /* Expect GSUP message indicating abort */
3951 f_expect_gsup_msg(gsup_abort);
3952
3953 f_expect_clear();
3954}
3955testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3956 var BSC_ConnHdlr vc_conn;
3957 f_init();
3958 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3959 vc_conn.done;
3960}
3961
Harald Weltee13cfb22019-04-23 16:52:02 +02003962
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003963/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003964friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003965runs on BSC_ConnHdlr {
3966 f_init_handler(pars);
3967
3968 /* Perform location update */
3969 f_perform_lu();
3970
3971 /* Send CM Service Request for SS/USSD */
3972 f_establish_fully(EST_TYPE_SS_ACT);
3973
3974 /* We need to inspect GSUP activity */
3975 f_create_gsup_expect(hex2str(g_pars.imsi));
3976
3977 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3978 invoke_id := 1,
3979 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3980 ussd_string := "#release_me");
3981
3982 /* Compose MO SS/REGISTER message with request */
3983 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3984 tid := 1, /* An arbitrary transaction identifier */
3985 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3986 facility := valueof(facility_ms_req));
3987
3988 /* Compose expected MSC -> HLR message */
3989 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3990 imsi := g_pars.imsi,
3991 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3992 ss := valueof(facility_ms_req));
3993
3994 /* To be used for sending response with correct session ID */
3995 var GSUP_PDU gsup_ms_req_complete;
3996
3997 /* Initiate a new SS transaction */
3998 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3999 /* Expect GSUP request with original Facility IE */
4000 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
4001
4002 /* Don't respond, wait for timeout */
4003 f_sleep(3.0);
4004
4005 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4006 tid := 1, /* Should match the request's tid */
4007 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
4008 cause := *, /* TODO: expect some specific value */
4009 facility := omit);
4010
4011 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
4012 imsi := g_pars.imsi,
4013 sid := gsup_ms_req_complete.ies[1].val.session_id,
4014 state := OSMO_GSUP_SESSION_STATE_END,
4015 cause := ?); /* TODO: expect some specific value */
4016
4017 /* Expect release on both interfaces */
4018 interleave {
4019 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
4020 [] GSUP.receive(gsup_rel) { };
4021 }
4022
4023 f_expect_clear();
4024 setverdict(pass);
4025}
4026testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
4027 var BSC_ConnHdlr vc_conn;
4028 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07004029 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07004030 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
4031 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07004032 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07004033}
4034
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004035/* MT (network-originated) USSD for unknown subscriber */
4036friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
4037runs on BSC_ConnHdlr {
4038 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
4039 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004040
4041 f_init_handler(pars);
4042 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
4043 f_create_gsup_expect(hex2str(imsi));
4044
4045 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4046 imsi := imsi,
4047 sid := sid,
4048 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4049 ss := f_rnd_octstring(23)
4050 );
4051
4052 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
4053 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4054 imsi := imsi,
4055 sid := sid,
4056 state := OSMO_GSUP_SESSION_STATE_END,
4057 cause := 2 /* FIXME: introduce an enumerated type! */
4058 );
4059
4060 /* Initiate a MT USSD notification */
4061 GSUP.send(gsup_req);
4062
4063 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07004064 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004065}
4066testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
4067 var BSC_ConnHdlr vc_conn;
4068 f_init();
4069 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
4070 vc_conn.done;
4071}
4072
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07004073/* MO (mobile-originated) SS/USSD for unknown transaction */
4074friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
4075runs on BSC_ConnHdlr {
4076 f_init_handler(pars);
4077
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004078 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07004079 f_create_gsup_expect(hex2str(g_pars.imsi));
4080
4081 /* Perform location update */
4082 f_perform_lu();
4083
4084 /* Send CM Service Request for SS/USSD */
4085 f_establish_fully(EST_TYPE_SS_ACT);
4086
4087 /* GSM 04.80 FACILITY message for a non-existing transaction */
4088 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
4089 tid := 1, /* An arbitrary transaction identifier */
4090 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4091 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
4092 );
4093
4094 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
4095 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
4096 tid := 1, /* An arbitrary transaction identifier */
4097 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4098 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
4099 );
4100
4101 /* Expected response from the network */
4102 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4103 tid := 1, /* Same as in the FACILITY message */
4104 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
4105 facility := omit
4106 );
4107
4108 /* Send GSM 04.80 FACILITY for non-existing transaction */
4109 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
4110
4111 /* Expect GSM 04.80 RELEASE COMPLETE message */
4112 f_expect_mt_dtap_msg(mt_ss_rel);
4113 f_expect_clear();
4114
4115 /* Send another CM Service Request for SS/USSD */
4116 f_establish_fully(EST_TYPE_SS_ACT);
4117
4118 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
4119 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
4120
4121 /* Expect GSM 04.80 RELEASE COMPLETE message */
4122 f_expect_mt_dtap_msg(mt_ss_rel);
4123 f_expect_clear();
4124}
4125testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
4126 var BSC_ConnHdlr vc_conn;
4127 f_init();
4128 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
4129 vc_conn.done;
4130}
4131
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004132/* MT (network-originated) USSD for unknown session */
4133friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
4134runs on BSC_ConnHdlr {
4135 var OCT4 sid := '20000333'O;
4136
4137 f_init_handler(pars);
4138
4139 /* Perform location update */
4140 f_perform_lu();
4141
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004142 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004143 f_create_gsup_expect(hex2str(g_pars.imsi));
4144
4145 /* Request referencing a non-existing SS session */
4146 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4147 imsi := g_pars.imsi,
4148 sid := sid,
4149 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
4150 ss := f_rnd_octstring(23)
4151 );
4152
4153 /* Error with some cause value */
4154 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4155 imsi := g_pars.imsi,
4156 sid := sid,
4157 state := OSMO_GSUP_SESSION_STATE_END,
4158 cause := ? /* FIXME: introduce an enumerated type! */
4159 );
4160
4161 /* Initiate a MT USSD notification */
4162 GSUP.send(gsup_req);
4163
4164 /* Expect GSUP PROC_SS_ERROR message */
4165 f_expect_gsup_msg(gsup_rsp);
4166}
4167testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
4168 var BSC_ConnHdlr vc_conn;
4169 f_init();
4170 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
4171 vc_conn.done;
4172}
4173
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004174/* MT (network-originated) USSD and no response to Paging Request */
4175friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
4176runs on BSC_ConnHdlr {
4177 timer TP := 2.0; /* Paging timer */
4178
4179 f_init_handler(pars);
4180
4181 /* Perform location update */
4182 f_perform_lu();
4183
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004184 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004185 f_create_gsup_expect(hex2str(g_pars.imsi));
4186
4187 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4188 imsi := g_pars.imsi,
4189 sid := '20000444'O,
4190 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4191 ss := f_rnd_octstring(23)
4192 );
4193
4194 /* Error with some cause value */
4195 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4196 imsi := g_pars.imsi,
4197 sid := '20000444'O,
4198 state := OSMO_GSUP_SESSION_STATE_END,
4199 cause := ? /* FIXME: introduce an enumerated type! */
4200 );
4201
4202 /* Initiate a MT USSD notification */
4203 GSUP.send(gsup_req);
4204
4205 /* Send it to MSC and expect Paging Request */
4206 TP.start;
4207 alt {
4208 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4209 setverdict(pass);
4210 }
4211 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4212 setverdict(pass);
4213 }
4214 /* We don't expect anything else */
4215 [] as_unexp_gsup_or_bssap_msg();
4216 [] TP.timeout {
4217 setverdict(fail, "Timeout waiting for Paging Request");
4218 }
4219 }
4220
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07004221 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
4222 * OsmoMSC waits for Paging Response 10 seconds by default. */
4223 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004224}
4225testcase TC_proc_ss_paging_fail() runs on MTC_CT {
4226 var BSC_ConnHdlr vc_conn;
4227 f_init();
4228 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
4229 vc_conn.done;
4230}
4231
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004232/* MT (network-originated) USSD followed by immediate abort */
4233friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
4234runs on BSC_ConnHdlr {
4235 var octetstring facility := f_rnd_octstring(23);
4236 var OCT4 sid := '20000555'O;
4237 timer TP := 2.0;
4238
4239 f_init_handler(pars);
4240
4241 /* Perform location update */
4242 f_perform_lu();
4243
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004244 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004245 f_create_gsup_expect(hex2str(g_pars.imsi));
4246
4247 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
4248 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4249 imsi := g_pars.imsi, sid := sid,
4250 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4251 ss := facility
4252 );
4253
4254 /* On the MS side, we expect GSM 04.80 REGISTER message */
4255 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
4256 tid := 0, /* Most likely, it should be 0 */
4257 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4258 facility := facility
4259 );
4260
4261 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
4262 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
4263 imsi := g_pars.imsi, sid := sid,
4264 state := OSMO_GSUP_SESSION_STATE_END,
4265 cause := 0 /* FIXME: introduce an enumerated type! */
4266 );
4267
4268 /* On the MS side, we expect GSM 04.80 REGISTER message */
4269 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4270 tid := 0, /* Most likely, it should be 0 */
4271 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4272 cause := *, /* FIXME: expect some specific cause value */
4273 facility := omit
4274 );
4275
4276 /* Initiate a MT USSD with random payload */
4277 GSUP.send(gsup_req);
4278
4279 /* Expect Paging Request */
4280 TP.start;
4281 alt {
4282 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4283 setverdict(pass);
4284 }
4285 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4286 setverdict(pass);
4287 }
4288 /* We don't expect anything else */
4289 [] as_unexp_gsup_or_bssap_msg();
4290 [] TP.timeout {
4291 setverdict(fail, "Timeout waiting for Paging Request");
4292 }
4293 }
4294
4295 /* Send Paging Response and establish connection */
4296 f_establish_fully(EST_TYPE_PAG_RESP);
4297 /* Expect MT REGISTER message with random facility */
4298 f_expect_mt_dtap_msg(dtap_reg);
4299
4300 /* HLR/EUSE decides to abort the session even
4301 * before getting any response from the MS */
4302 /* Initiate a MT USSD with random payload */
4303 GSUP.send(gsup_abort);
4304
4305 /* Expect RELEASE COMPLETE on ths MS side */
4306 f_expect_mt_dtap_msg(dtap_rel);
4307
4308 f_expect_clear();
4309}
4310testcase TC_proc_ss_abort() runs on MTC_CT {
4311 var BSC_ConnHdlr vc_conn;
4312 f_init();
4313 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
4314 vc_conn.done;
4315}
4316
Harald Weltee13cfb22019-04-23 16:52:02 +02004317
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01004318/* Verify multiple concurrent MO SS/USSD transactions
4319 * (one subscriber - one transaction) */
4320testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
4321 var BSC_ConnHdlr vc_conn[16];
4322 var integer i;
4323
4324 f_init();
4325
4326 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4327 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
4328 }
4329
4330 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4331 vc_conn[i].done;
4332 }
4333}
4334
4335/* Verify multiple concurrent MT SS/USSD transactions
4336 * (one subscriber - one transaction) */
4337testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
4338 var BSC_ConnHdlr vc_conn[16];
4339 var integer i;
4340 var OCT4 sid;
4341
4342 f_init();
4343
4344 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4345 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
4346 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
4347 f_init_pars(226 + i, gsup_sid := sid));
4348 }
4349
4350 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4351 vc_conn[i].done;
4352 }
4353}
4354
4355
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004356/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
4357private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4358 pars.net.expect_auth := true;
4359 pars.net.expect_ciph := true;
4360 pars.net.kc_support := '02'O; /* A5/1 only */
4361 f_init_handler(pars);
4362
4363 g_pars.vec := f_gen_auth_vec_2g();
4364
4365 /* Can't use f_perform_lu() directly. Code below is based on it. */
4366
4367 /* tell GSUP dispatcher to send this IMSI to us */
4368 f_create_gsup_expect(hex2str(g_pars.imsi));
4369
4370 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4371 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02004372 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004373
4374 f_mm_auth();
4375
4376 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4377 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4378 alt {
4379 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4380 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
4381 }
4382 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4383 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4384 mtc.stop;
4385 }
4386 [] BSSAP.receive {
4387 setverdict(fail, "Unknown/unexpected BSSAP received");
4388 mtc.stop;
4389 }
4390 }
Harald Welte79f1e452020-08-18 22:55:02 +02004391 f_expect_common_id();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004392
4393 /* Expect LU reject from MSC. */
4394 alt {
4395 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4396 setverdict(pass);
4397 }
4398 [] BSSAP.receive {
4399 setverdict(fail, "Unknown/unexpected BSSAP received");
4400 mtc.stop;
4401 }
4402 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01004403 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004404}
4405
4406testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
4407 var BSC_ConnHdlr vc_conn;
4408 f_init();
4409 f_vty_config(MSCVTY, "network", "encryption a5 1");
4410
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02004411 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52, verify_cell_id := false);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004412 vc_conn.done;
4413}
4414
Harald Welteb2284bd2019-05-10 11:30:43 +02004415/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
4416friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4417 f_init_handler(pars);
4418
4419 /* tell GSUP dispatcher to send this IMSI to us */
4420 f_create_gsup_expect(hex2str(g_pars.imsi));
4421
4422 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4423 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4424
4425 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4426 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4427 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +02004428 f_expect_common_id();
Harald Welteb2284bd2019-05-10 11:30:43 +02004429
4430 /* Expect LU reject from MSC. */
4431 alt {
4432 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4433 setverdict(pass);
4434 }
4435 [] BSSAP.receive {
4436 setverdict(fail, "Unknown/unexpected BSSAP received");
4437 mtc.stop;
4438 }
4439 }
Eric Wild85cc1612022-03-30 01:44:29 +02004440 f_expect_clear(verify_vlr_cell_id:=false);
Harald Welteb2284bd2019-05-10 11:30:43 +02004441}
4442testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4443 var BSC_ConnHdlr vc_conn;
4444 f_init();
4445 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4446 vc_conn.done;
4447}
4448
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004449private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4450 pars.net.expect_auth := true;
4451 pars.net.expect_ciph := true;
4452 pars.net.kc_support := kc_support;
4453 f_init_handler(pars);
4454
4455 g_pars.vec := f_gen_auth_vec_2g();
4456
4457 /* Can't use f_perform_lu() directly. Code below is based on it. */
4458
4459 /* tell GSUP dispatcher to send this IMSI to us */
4460 f_create_gsup_expect(hex2str(g_pars.imsi));
4461
4462 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4463 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4464 f_cl3_or_initial_ue(l3_lu);
4465
4466 f_mm_auth();
4467
4468 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4469 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4470 alt {
4471 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4472 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4473 }
4474 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4475 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4476 repeat;
4477 }
4478 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4479 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4480 mtc.stop;
4481 }
4482 [] BSSAP.receive {
4483 setverdict(fail, "Unknown/unexpected BSSAP received");
4484 mtc.stop;
4485 }
4486 }
Harald Welte79f1e452020-08-18 22:55:02 +02004487 f_expect_common_id();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004488
4489 /* TODO: Verify MSC is using the best cipher available! How? */
4490
4491 f_msc_lu_hlr();
Neels Hofmeyre860fc42022-10-05 01:15:54 +02004492 as_accept_reject_lu();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004493 f_expect_clear();
4494 setverdict(pass);
4495}
4496
4497/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4498private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4499 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4500}
4501
4502/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4503private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4504 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4505}
4506
4507/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4508private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4509 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4510}
4511
4512testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4513 var BSC_ConnHdlr vc_conn;
4514 f_init();
4515 f_vty_config(MSCVTY, "network", "encryption a5 1");
4516
4517 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4518 vc_conn.done;
4519}
4520
4521testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4522 var BSC_ConnHdlr vc_conn;
4523 f_init();
4524 f_vty_config(MSCVTY, "network", "encryption a5 3");
4525
4526 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4527 vc_conn.done;
4528}
4529
4530testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4531 var BSC_ConnHdlr vc_conn;
4532 f_init();
4533 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4534
4535 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4536 vc_conn.done;
4537}
Harald Welteb2284bd2019-05-10 11:30:43 +02004538
Harald Weltef640a012018-04-14 17:49:21 +02004539/* TODO (SMS):
4540 * different user data lengths
4541 * SMPP transaction mode with unsuccessful delivery
4542 * queued MT-SMS with no paging response + later delivery
4543 * different data coding schemes
4544 * multi-part SMS
4545 * user-data headers
4546 * TP-PID for SMS to SIM
4547 * behavior if SMS memory is full + RP-SMMA
4548 * delivery reports
4549 * SMPP osmocom extensions
4550 * more-messages-to-send
4551 * SMS during ongoing call (SACCH/SAPI3)
4552 */
4553
4554/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004555 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4556 * malformed messages (missing IE, invalid message type): properly rejected?
4557 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4558 * 3G/2G auth permutations
4559 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004560 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004561 * too long L3 INFO in DTAP
4562 * too long / padded BSSAP
4563 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004564 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004565
Harald Weltee13cfb22019-04-23 16:52:02 +02004566/***********************************************************************
4567 * SGsAP Testing
4568 ***********************************************************************/
4569
Philipp Maier948747b2019-04-02 15:22:33 +02004570/* Check if a subscriber exists in the VLR */
4571private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4572
4573 var CtrlValue active_subsribers;
4574 var integer rc;
4575 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4576
4577 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4578 if (rc < 0) {
4579 return false;
4580 }
4581
4582 return true;
4583}
4584
Pau Espin Pedrolcefe9da2021-07-02 18:38:27 +02004585/* Perform a Location Update at the A-Interface and run some checks to confirm
Harald Welte4263c522018-12-06 11:56:27 +01004586 * that everything is back to normal. */
4587private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4588 var SmsParameters spars := valueof(t_SmsPars);
4589
Pau Espin Pedrol7593a8a2021-07-02 18:55:16 +02004590 /* From now on, since we initiated LU from A-Interface, we expect no
4591 * LastEutranPLMNId on Common Id, since the SGs interface should be gone
4592 */
4593 g_pars.common_id_last_eutran_plmn := omit;
4594
Harald Welte4263c522018-12-06 11:56:27 +01004595 /* Perform a location update, the SGs association is expected to fall
4596 * back to NULL */
4597 f_perform_lu();
4598 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4599
4600 /* Trigger a paging request and expect the paging on BSSMAP, this is
4601 * to make sure that pagings are sent throught the A-Interface again
4602 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004603 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004604 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4605
4606 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004607 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4608 setverdict(pass);
4609 }
Harald Welte62113fc2019-05-09 13:04:02 +02004610 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004611 setverdict(pass);
4612 }
4613 [] SGsAP.receive {
4614 setverdict(fail, "Received unexpected message on SGs");
4615 }
4616 }
4617
4618 /* Send an SMS to make sure that also payload messages are routed
4619 * throught the A-Interface again */
4620 f_establish_fully(EST_TYPE_MO_SMS);
4621 f_mo_sms(spars);
4622 f_expect_clear();
4623}
4624
4625private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4626 var charstring vlr_name;
4627 f_init_handler(pars);
4628
4629 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4630 log("VLR name: ", vlr_name);
4631 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004632 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004633}
4634
4635testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004636 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004637 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004638 f_init(1, true);
4639 pars := f_init_pars(11810, true);
4640 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004641 vc_conn.done;
4642}
4643
4644/* like f_mm_auth() but for SGs */
4645function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4646 if (g_pars.net.expect_auth) {
4647 g_pars.vec := f_gen_auth_vec_3g();
4648 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4649 g_pars.vec.sres,
4650 g_pars.vec.kc,
4651 g_pars.vec.ik,
4652 g_pars.vec.ck,
4653 g_pars.vec.autn,
4654 g_pars.vec.res));
4655 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4656 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4657 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4658 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4659 }
4660}
4661
4662/* like f_perform_lu(), but on SGs rather than BSSAP */
4663function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4664 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4665 var PDU_SGsAP lur;
4666 var PDU_SGsAP lua;
4667 var PDU_SGsAP mm_info;
4668 var octetstring mm_info_dtap;
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004669 var GsmMcc mcc;
4670 var GsmMnc mnc;
4671 var template (omit) TrackingAreaIdentityValue tai := omit;
Harald Welte4263c522018-12-06 11:56:27 +01004672
4673 /* tell GSUP dispatcher to send this IMSI to us */
4674 f_create_gsup_expect(hex2str(g_pars.imsi));
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004675 if (g_pars.common_id_last_eutran_plmn != omit) {
4676 f_dec_mcc_mnc(g_pars.common_id_last_eutran_plmn, mcc, mnc);
4677 tai := ts_SGsAP_TAI(mcc, mnc, 555);
4678 }
Harald Welte4263c522018-12-06 11:56:27 +01004679 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
Pau Espin Pedrol3768a6f2021-04-28 14:24:23 +02004680 ts_SGsAP_LAI('901'H, '70'H, 2342),
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004681 tai));
Harald Welte4263c522018-12-06 11:56:27 +01004682 /* Old LAI, if MS sends it */
4683 /* TMSI status, if MS has no valid TMSI */
4684 /* IMEISV, if it supports "automatic device detection" */
4685 /* TAI, if available in MME */
4686 /* E-CGI, if available in MME */
4687 SGsAP.send(lur);
4688
4689 /* FIXME: is this really done over SGs? The Ue is already authenticated
4690 * via the MME ... */
4691 f_mm_auth_sgs();
4692
4693 /* Expect MSC to perform LU with HLR */
4694 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4695 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4696 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4697 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4698
4699 alt {
4700 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4701 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4702 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4703 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4704 }
4705 setverdict(pass);
4706 }
4707 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4708 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4709 }
4710 [] SGsAP.receive {
4711 setverdict(fail, "Received unexpected message on SGs");
4712 }
4713 }
4714
4715 /* Check MM information */
4716 if (mp_mm_info == true) {
4717 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4718 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4719 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4720 setverdict(fail, "Unexpected MM Information");
4721 }
4722 }
4723
4724 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4725}
4726
4727private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4728 f_init_handler(pars);
4729 f_sgs_perform_lu();
4730 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4731
4732 f_sgsap_bssmap_screening();
4733
4734 setverdict(pass);
4735}
4736testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004737 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004738 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004739 f_init(1, true);
4740 pars := f_init_pars(11811, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004741 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004742 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004743 vc_conn.done;
4744}
4745
4746/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4747private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4748 f_init_handler(pars);
4749 var PDU_SGsAP lur;
4750
4751 f_create_gsup_expect(hex2str(g_pars.imsi));
4752 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4753 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4754 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4755 SGsAP.send(lur);
4756
4757 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4758 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4759 alt {
4760 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4761 setverdict(pass);
4762 }
4763 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4764 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4765 mtc.stop;
4766 }
4767 [] SGsAP.receive {
4768 setverdict(fail, "Received unexpected message on SGs");
4769 }
4770 }
4771
4772 f_sgsap_bssmap_screening();
4773
4774 setverdict(pass);
4775}
4776testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004777 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004778 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004779 f_init(1, true);
4780 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004781
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004782 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004783 vc_conn.done;
4784}
4785
4786/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4787private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4788 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4789 var PDU_SGsAP lur;
4790
4791 f_init_handler(pars);
4792
4793 /* tell GSUP dispatcher to send this IMSI to us */
4794 f_create_gsup_expect(hex2str(g_pars.imsi));
4795
4796 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4797 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4798 /* Old LAI, if MS sends it */
4799 /* TMSI status, if MS has no valid TMSI */
4800 /* IMEISV, if it supports "automatic device detection" */
4801 /* TAI, if available in MME */
4802 /* E-CGI, if available in MME */
4803 SGsAP.send(lur);
4804
4805 /* FIXME: is this really done over SGs? The Ue is already authenticated
4806 * via the MME ... */
4807 f_mm_auth_sgs();
4808
4809 /* Expect MSC to perform LU with HLR */
4810 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4811 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4812 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4813 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4814
4815 alt {
4816 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4817 setverdict(pass);
4818 }
4819 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4820 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4821 }
4822 [] SGsAP.receive {
4823 setverdict(fail, "Received unexpected message on SGs");
4824 }
4825 }
4826
4827 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4828
4829 /* Wait until the VLR has abort the TMSI reallocation procedure */
4830 f_sleep(45.0);
4831
4832 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4833 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4834
4835 f_sgsap_bssmap_screening();
4836
4837 setverdict(pass);
4838}
4839testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004840 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004841 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004842 f_init(1, true);
4843 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004844
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004845 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004846 vc_conn.done;
4847}
4848
4849private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4850runs on BSC_ConnHdlr {
4851 f_init_handler(pars);
4852 f_sgs_perform_lu();
4853 f_sleep(3.0);
4854
4855 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4856 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4857 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4858 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4859
4860 f_sgsap_bssmap_screening();
4861
4862 setverdict(pass);
4863}
4864testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004865 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004866 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004867 f_init(1, true);
4868 pars := f_init_pars(11814, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004869 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004870 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004871 vc_conn.done;
4872}
4873
Philipp Maierfc19f172019-03-21 11:17:54 +01004874private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4875runs on BSC_ConnHdlr {
4876 f_init_handler(pars);
4877 f_sgs_perform_lu();
4878 f_sleep(3.0);
4879
4880 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4881 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4882 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4883 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4884
4885 f_sgsap_bssmap_screening();
4886
4887 setverdict(pass);
4888}
4889testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4890 var BSC_ConnHdlrPars pars;
4891 var BSC_ConnHdlr vc_conn;
4892 f_init(1, true);
4893 pars := f_init_pars(11814, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004894 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maierfc19f172019-03-21 11:17:54 +01004895 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4896 vc_conn.done;
4897}
4898
Harald Welte4263c522018-12-06 11:56:27 +01004899private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4900runs on BSC_ConnHdlr {
4901 f_init_handler(pars);
4902 f_sgs_perform_lu();
4903 f_sleep(3.0);
4904
4905 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4906 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4907 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004908
4909 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4910 setverdict(fail, "subscriber not removed from VLR");
4911 }
Harald Welte4263c522018-12-06 11:56:27 +01004912
4913 f_sgsap_bssmap_screening();
4914
4915 setverdict(pass);
4916}
4917testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004918 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004919 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004920 f_init(1, true);
4921 pars := f_init_pars(11815, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004922 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004923 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004924 vc_conn.done;
4925}
4926
Philipp Maier5d812702019-03-21 10:51:26 +01004927private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4928runs on BSC_ConnHdlr {
4929 f_init_handler(pars);
4930 f_sgs_perform_lu();
4931 f_sleep(3.0);
4932
4933 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4934 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4935 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4936
4937 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4938 setverdict(fail, "subscriber not removed from VLR");
4939 }
4940
4941 f_sgsap_bssmap_screening();
4942
4943 setverdict(pass);
4944}
4945testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4946 var BSC_ConnHdlrPars pars;
4947 var BSC_ConnHdlr vc_conn;
4948 f_init(1, true);
4949 pars := f_init_pars(11815, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004950 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier5d812702019-03-21 10:51:26 +01004951 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4952 vc_conn.done;
4953}
4954
Harald Welte4263c522018-12-06 11:56:27 +01004955/* Trigger a paging request via VTY and send a paging reject in response */
4956private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4957runs on BSC_ConnHdlr {
4958 f_init_handler(pars);
4959 f_sgs_perform_lu();
4960 f_sleep(1.0);
4961
4962 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4963 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4964 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4965 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4966
4967 /* Initiate paging via VTY */
4968 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4969 alt {
4970 [] SGsAP.receive(exp_resp) {
4971 setverdict(pass);
4972 }
4973 [] SGsAP.receive {
4974 setverdict(fail, "Received unexpected message on SGs");
4975 }
4976 }
4977
4978 /* Now reject the paging */
4979 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4980
4981 /* Wait for the states inside the MSC to settle and check the state
4982 * of the SGs Association */
4983 f_sleep(1.0);
4984 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4985
4986 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4987 * but we also need to cover tha case where the cause code indicates an
4988 * "IMSI detached for EPS services". In those cases the VLR is expected to
4989 * try paging on tha A/Iu interface. This will be another testcase similar to
4990 * this one, but extended with checks for the presence of the A/Iu paging
4991 * messages. */
4992
4993 f_sgsap_bssmap_screening();
4994
4995 setverdict(pass);
4996}
4997testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004998 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004999 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005000 f_init(1, true);
5001 pars := f_init_pars(11816, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005002 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005003 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005004 vc_conn.done;
5005}
5006
5007/* Trigger a paging request via VTY and send a paging reject that indicates
5008 * that the subscriber intentionally rejected the call. */
5009private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
5010runs on BSC_ConnHdlr {
5011 f_init_handler(pars);
5012 f_sgs_perform_lu();
5013 f_sleep(1.0);
5014
5015 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5016 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
5017 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5018 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5019
5020 /* Initiate paging via VTY */
5021 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5022 alt {
5023 [] SGsAP.receive(exp_resp) {
5024 setverdict(pass);
5025 }
5026 [] SGsAP.receive {
5027 setverdict(fail, "Received unexpected message on SGs");
5028 }
5029 }
5030
5031 /* Now reject the paging */
5032 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
5033
5034 /* Wait for the states inside the MSC to settle and check the state
5035 * of the SGs Association */
5036 f_sleep(1.0);
5037 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5038
5039 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
5040 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
5041 * to check back how this works and how it can be tested */
5042
5043 f_sgsap_bssmap_screening();
5044
5045 setverdict(pass);
5046}
5047testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005048 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005049 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005050 f_init(1, true);
5051 pars := f_init_pars(11817, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005052 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005053 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005054 vc_conn.done;
5055}
5056
5057/* Trigger a paging request via VTY and send an UE unreacable messge in response */
5058private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
5059runs on BSC_ConnHdlr {
5060 f_init_handler(pars);
5061 f_sgs_perform_lu();
5062 f_sleep(1.0);
5063
5064 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5065 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
5066 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5067 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5068
5069 /* Initiate paging via VTY */
5070 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5071 alt {
5072 [] SGsAP.receive(exp_resp) {
5073 setverdict(pass);
5074 }
5075 [] SGsAP.receive {
5076 setverdict(fail, "Received unexpected message on SGs");
5077 }
5078 }
5079
5080 /* Now pretend that the UE is unreachable */
5081 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
5082
5083 /* Wait for the states inside the MSC to settle and check the state
5084 * of the SGs Association. */
5085 f_sleep(1.0);
5086 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5087
5088 f_sgsap_bssmap_screening();
5089
5090 setverdict(pass);
5091}
5092testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005093 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005094 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005095 f_init(1, true);
5096 pars := f_init_pars(11818, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005097 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005098 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005099 vc_conn.done;
5100}
5101
5102/* Trigger a paging request via VTY but don't respond to it */
5103private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
5104runs on BSC_ConnHdlr {
5105 f_init_handler(pars);
5106 f_sgs_perform_lu();
5107 f_sleep(1.0);
5108
5109 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5110 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02005111 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01005112 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5113 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5114
5115 /* Initiate paging via VTY */
5116 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5117 alt {
5118 [] SGsAP.receive(exp_resp) {
5119 setverdict(pass);
5120 }
5121 [] SGsAP.receive {
5122 setverdict(fail, "Received unexpected message on SGs");
5123 }
5124 }
5125
Philipp Maier34218102019-09-24 09:15:49 +02005126 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
5127 * after some time */
5128 timer T := 10.0;
5129 T.start
5130 alt {
5131 [] SGsAP.receive(exp_serv_abrt)
5132 {
5133 setverdict(pass);
5134 }
5135 [] SGsAP.receive {
5136 setverdict(fail, "unexpected SGsAP message received");
5137 self.stop;
5138 }
5139 [] T.timeout {
5140 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
5141 self.stop;
5142 }
5143 }
5144
5145 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01005146 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5147
5148 f_sgsap_bssmap_screening();
5149
5150 setverdict(pass);
5151}
5152testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005153 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005154 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005155 f_init(1, true);
5156 pars := f_init_pars(11819, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005157 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005158 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005159 vc_conn.done;
5160}
5161
5162/* Trigger a paging request via VTY and slip in an LU */
5163private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
5164runs on BSC_ConnHdlr {
5165 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5166 f_init_handler(pars);
5167
5168 /* First we prepar the situation, where the SGs association is in state
5169 * NULL and the confirmed by radio contact indicator is set to false
5170 * as well. This can be archived by performing an SGs LU and then
5171 * resetting the VLR */
5172 f_sgs_perform_lu();
5173 f_sgsap_reset_mme(mp_mme_name);
5174 f_sleep(1.0);
5175 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5176
5177 /* Perform a paging, expect the paging messages on the SGs interface */
5178 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5179 alt {
5180 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5181 setverdict(pass);
5182 }
5183 [] SGsAP.receive {
5184 setverdict(fail, "Received unexpected message on SGs");
5185 }
5186 }
5187
5188 /* Perform the LU as normal */
5189 f_sgs_perform_lu();
5190 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5191
5192 /* Expect a new paging request right after the LU */
5193 alt {
5194 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5195 setverdict(pass);
5196 }
5197 [] SGsAP.receive {
5198 setverdict(fail, "Received unexpected message on SGs");
5199 }
5200 }
5201
5202 /* Test is done now, lets round everything up by rejecting the paging
5203 * cleanly. */
5204 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
5205 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5206
5207 f_sgsap_bssmap_screening();
5208
5209 setverdict(pass);
5210}
5211testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005212 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005213 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005214 f_init(1, true);
5215 pars := f_init_pars(11820, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005216 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005217 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005218 vc_conn.done;
5219}
5220
5221/* Send unexpected unit-data through the SGs interface */
5222private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5223 f_init_handler(pars);
5224 f_sleep(1.0);
5225
5226 /* This simulates what happens when a subscriber without SGs
5227 * association gets unitdata via the SGs interface. */
5228
5229 /* Make sure the subscriber exists and the SGs association
5230 * is in NULL state */
5231 f_perform_lu();
5232 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5233
5234 /* Send some random unit data, the MSC/VLR should send a release
5235 * immediately. */
5236 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5237 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
5238
5239 f_sgsap_bssmap_screening();
5240
5241 setverdict(pass);
5242}
5243testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005244 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005245 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005246 f_init(1, true);
5247 pars := f_init_pars(11821, true);
5248 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005249 vc_conn.done;
5250}
5251
5252/* Send unsolicited unit-data through the SGs interface */
5253private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5254 f_init_handler(pars);
5255 f_sleep(1.0);
5256
5257 /* This simulates what happens when the MME attempts to send unitdata
5258 * to a subscriber that is completely unknown to the VLR */
5259
5260 /* Send some random unit data, the MSC/VLR should send a release
5261 * immediately. */
5262 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5263 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
5264
5265 f_sgsap_bssmap_screening();
5266
Harald Welte4d15fa72020-08-19 08:58:28 +02005267 /* clean-up VLR state about this subscriber */
5268 f_imsi_detach_by_imsi();
5269
Harald Welte4263c522018-12-06 11:56:27 +01005270 setverdict(pass);
5271}
5272testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005273 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005274 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005275 f_init(1, true);
5276 pars := f_init_pars(11822, true);
5277 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005278 vc_conn.done;
5279}
5280
5281private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
5282 /* FIXME: Match an actual payload (second questionmark), the type is
5283 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
5284 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
5285 setverdict(fail, "Unexpected SMS related PDU from MSC");
5286 mtc.stop;
5287 }
5288}
5289
5290/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
5291function f_mt_sms_sgs(inout SmsParameters spars)
5292runs on BSC_ConnHdlr {
5293 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5294 var template (value) RPDU_MS_SGSN rp_mo;
5295 var template (value) PDU_ML3_MS_NW l3_mo;
5296
5297 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5298 var template RPDU_SGSN_MS rp_mt;
5299 var template PDU_ML3_NW_MS l3_mt;
5300
5301 var PDU_ML3_NW_MS sgsap_l3_mt;
5302
5303 var default d := activate(as_other_sms_sgs());
5304
5305 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
5306 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09005307 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01005308 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
5309
5310 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
5311
5312 /* Extract relevant identifiers */
5313 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
5314 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
5315
5316 /* send CP-ACK for CP-DATA just received */
5317 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
5318
5319 SGsAP.send(l3_mo);
5320
5321 /* send RP-ACK for RP-DATA */
5322 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
5323 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
5324
5325 SGsAP.send(l3_mo);
5326
5327 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
5328 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
5329
5330 SGsAP.receive(l3_mt);
5331
5332 deactivate(d);
5333
5334 setverdict(pass);
5335}
5336
5337/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
5338function f_mo_sms_sgs(inout SmsParameters spars)
5339runs on BSC_ConnHdlr {
5340 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5341 var template (value) RPDU_MS_SGSN rp_mo;
5342 var template (value) PDU_ML3_MS_NW l3_mo;
5343
5344 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5345 var template RPDU_SGSN_MS rp_mt;
5346 var template PDU_ML3_NW_MS l3_mt;
5347
5348 var default d := activate(as_other_sms_sgs());
5349
5350 /* just in case this is routed to SMPP.. */
5351 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
5352
5353 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
5354 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09005355 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01005356 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
5357
5358 SGsAP.send(l3_mo);
5359
5360 /* receive CP-ACK for CP-DATA above */
5361 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
5362
5363 if (ispresent(spars.exp_rp_err)) {
5364 /* expect an RP-ERROR message from MSC with given cause */
5365 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
5366 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5367 SGsAP.receive(l3_mt);
5368 /* send CP-ACK for CP-DATA just received */
5369 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5370 SGsAP.send(l3_mo);
5371 } else {
5372 /* expect RP-ACK for RP-DATA */
5373 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
5374 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5375 SGsAP.receive(l3_mt);
5376 /* send CP-ACO for CP-DATA just received */
5377 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5378 SGsAP.send(l3_mo);
5379 }
5380
5381 deactivate(d);
5382
5383 setverdict(pass);
5384}
5385
5386private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
5387runs on BSC_ConnHdlr {
5388 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
5389}
5390
5391/* Send a MT SMS via SGs interface */
5392private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5393 f_init_handler(pars);
5394 f_sgs_perform_lu();
5395 f_sleep(1.0);
5396 var SmsParameters spars := valueof(t_SmsPars);
5397 spars.tp.ud := 'C8329BFD064D9B53'O;
5398
5399 /* Trigger SMS via VTY */
5400 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5401 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5402
5403 /* Expect a paging request and respond accordingly with a service request */
5404 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
5405 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
5406
5407 /* Connection is now live, receive the MT-SMS */
5408 f_mt_sms_sgs(spars);
5409
5410 /* Expect a concluding release from the MSC */
5411 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5412
5413 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5414 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5415
5416 f_sgsap_bssmap_screening();
5417
5418 setverdict(pass);
5419}
5420testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005421 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005422 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005423 f_init(1, true);
5424 pars := f_init_pars(11823, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005425 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005426 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005427 vc_conn.done;
5428}
5429
5430/* Send a MO SMS via SGs interface */
5431private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5432 f_init_handler(pars);
5433 f_sgs_perform_lu();
5434 f_sleep(1.0);
5435 var SmsParameters spars := valueof(t_SmsPars);
5436 spars.tp.ud := 'C8329BFD064D9B53'O;
5437
5438 /* Send the MO-SMS */
5439 f_mo_sms_sgs(spars);
5440
5441 /* Expect a concluding release from the MSC/VLR */
5442 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5443
5444 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5445 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5446
5447 setverdict(pass);
5448
5449 f_sgsap_bssmap_screening()
5450}
5451testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005452 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005453 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005454 f_init(1, true);
5455 pars := f_init_pars(11824, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005456 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005457 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005458 vc_conn.done;
5459}
5460
5461/* Trigger sending of an MT sms via VTY but never respond to anything */
5462private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5463 f_init_handler(pars, 170.0);
5464 f_sgs_perform_lu();
5465 f_sleep(1.0);
5466
5467 var SmsParameters spars := valueof(t_SmsPars);
5468 spars.tp.ud := 'C8329BFD064D9B53'O;
5469 var integer page_count := 0;
5470 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5471 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5472 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5473 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5474
5475 /* Trigger SMS via VTY */
5476 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5477
Neels Hofmeyr16237742019-03-06 15:34:01 +01005478 /* Expect the MSC/VLR to page exactly once */
5479 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005480
5481 /* Wait some time to make sure the MSC is not delivering any further
5482 * paging messages or anything else that could be unexpected. */
5483 timer T := 20.0;
5484 T.start
5485 alt {
5486 [] SGsAP.receive(exp_pag_req)
5487 {
5488 setverdict(fail, "paging seems not to stop!");
5489 mtc.stop;
5490 }
5491 [] SGsAP.receive {
5492 setverdict(fail, "unexpected SGsAP message received");
5493 self.stop;
5494 }
5495 [] T.timeout {
5496 setverdict(pass);
5497 }
5498 }
5499
5500 /* Even on a failed paging the SGs Association should stay intact */
5501 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5502
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005503 /* Make sure that the SMS we just inserted is cleared and the
5504 * subscriber is expired. This is necessary because otherwise the MSC
5505 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005506
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005507 f_vty_sms_clear(hex2str(g_pars.imsi));
5508
Harald Welte4263c522018-12-06 11:56:27 +01005509 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5510
5511 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005512
5513 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005514}
5515testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005516 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005517 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005518 f_init(1, true);
5519 pars := f_init_pars(11825, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005520 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005521 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005522 vc_conn.done;
5523}
5524
5525/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5526private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5527 f_init_handler(pars, 150.0);
5528 f_sgs_perform_lu();
5529 f_sleep(1.0);
5530
5531 var SmsParameters spars := valueof(t_SmsPars);
5532 spars.tp.ud := 'C8329BFD064D9B53'O;
5533 var integer page_count := 0;
5534 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5535 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5536 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5537 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5538
5539 /* Trigger SMS via VTY */
5540 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5541
5542 /* Expect a paging request and reject it immediately */
5543 SGsAP.receive(exp_pag_req);
5544 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5545
5546 /* The MSC/VLR should no longer try to page once the paging has been
5547 * rejected. Wait some time and check if there are no unexpected
5548 * messages on the SGs interface. */
5549 timer T := 20.0;
5550 T.start
5551 alt {
5552 [] SGsAP.receive(exp_pag_req)
5553 {
5554 setverdict(fail, "paging seems not to stop!");
5555 mtc.stop;
5556 }
5557 [] SGsAP.receive {
5558 setverdict(fail, "unexpected SGsAP message received");
5559 self.stop;
5560 }
5561 [] T.timeout {
5562 setverdict(pass);
5563 }
5564 }
5565
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005566 f_vty_sms_clear(hex2str(g_pars.imsi));
5567
Harald Welte4263c522018-12-06 11:56:27 +01005568 /* A rejected paging with IMSI_unknown (see above) should always send
5569 * the SGs association to NULL. */
5570 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5571
5572 f_sgsap_bssmap_screening();
5573
Harald Welte4263c522018-12-06 11:56:27 +01005574 setverdict(pass);
5575}
5576testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005577 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005578 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005579 f_init(1, true);
5580 pars := f_init_pars(11826, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005581 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005582 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005583 vc_conn.done;
5584}
5585
Pau Espin Pedrol3acd19e2021-04-28 12:59:52 +02005586/* Perform an MT CSFB call including LU */
Harald Welte4263c522018-12-06 11:56:27 +01005587private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5588 f_init_handler(pars);
5589
5590 /* Be sure that the BSSMAP reset is done before we begin. */
5591 f_sleep(2.0);
5592
5593 /* Testcase variation: See what happens when we do a regular BSSMAP
5594 * LU first (this should not hurt in any way!) */
5595 if (bssmap_lu) {
5596 f_perform_lu();
5597 }
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005598 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Harald Welte4263c522018-12-06 11:56:27 +01005599
5600 f_sgs_perform_lu();
5601 f_sleep(1.0);
5602
5603 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5604 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005605
5606 /* Initiate a call via MNCC interface */
Oliver Smith97dc91f2023-05-31 13:53:21 +02005607 f_mt_call_initiate(cpars);
Harald Welte4263c522018-12-06 11:56:27 +01005608
5609 /* Expect a paging request and respond accordingly with a service request */
5610 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5611 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5612
5613 /* Complete the call, hold it for some time and then tear it down */
5614 f_mt_call_complete(cpars);
5615 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005616 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005617
5618 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5619 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5620
Harald Welte4263c522018-12-06 11:56:27 +01005621 /* Test for successful return by triggering a paging, when the paging
5622 * request is received via SGs, we can be sure that the MSC/VLR has
5623 * recognized that the UE is now back on 4G */
5624 f_sleep(1.0);
5625 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5626 alt {
5627 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5628 setverdict(pass);
5629 }
5630 [] SGsAP.receive {
5631 setverdict(fail, "Received unexpected message on SGs");
5632 }
5633 }
5634
5635 f_sgsap_bssmap_screening();
5636
5637 setverdict(pass);
5638}
5639
5640/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5641private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5642 f_mt_lu_and_csfb_call(id, pars, true);
5643}
5644testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005645 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005646 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005647 f_init(1, true);
5648 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005649
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005650 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005651 vc_conn.done;
5652}
5653
Harald Welte4263c522018-12-06 11:56:27 +01005654/* Perform a SGSAP LU and then make a CSFB call */
5655private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5656 f_mt_lu_and_csfb_call(id, pars, false);
5657}
5658testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005659 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005660 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005661 f_init(1, true);
5662 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005663
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005664 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005665 vc_conn.done;
5666}
5667
Philipp Maier628c0052019-04-09 17:36:57 +02005668/* Simulate an HLR/VLR failure */
5669private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5670 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5671 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5672
5673 var PDU_SGsAP lur;
5674
5675 f_init_handler(pars);
5676
5677 /* Attempt location update (which is expected to fail) */
5678 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5679 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5680 SGsAP.send(lur);
5681
5682 /* Respond to SGsAP-RESET-INDICATION from VLR */
5683 alt {
5684 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5685 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5686 setverdict(pass);
5687 }
5688 [] SGsAP.receive {
5689 setverdict(fail, "Received unexpected message on SGs");
5690 }
5691 }
5692
5693 f_sleep(1.0);
5694 setverdict(pass);
5695}
5696testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5697 var BSC_ConnHdlrPars pars;
5698 var BSC_ConnHdlr vc_conn;
5699 f_init(1, true, false);
5700 pars := f_init_pars(11811, true, false);
5701 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5702 vc_conn.done;
5703}
5704
Harald Welte4263c522018-12-06 11:56:27 +01005705/* SGs TODO:
5706 * LU attempt for IMSI without NAM_PS in HLR
5707 * LU attempt with AUTH FAIL due to invalid RES/SRES
5708 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5709 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5710 * implicit IMSI detach from EPS
5711 * implicit IMSI detach from non-EPS
5712 * MM INFO
5713 *
5714 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005715
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005716private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5717 f_init_handler(pars);
5718 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005719
5720 f_perform_lu();
5721 f_mo_call_establish(cpars);
5722
5723 f_sleep(1.0);
5724
5725 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5726 var BssmapCause cause := enum2int(cause_val);
5727
5728 var template BSSMAP_FIELD_CellIdentificationList cil;
5729 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5730
5731 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5732 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5733
5734 f_call_hangup(cpars, true);
5735}
5736testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5737 var BSC_ConnHdlr vc_conn;
5738 f_init();
5739
5740 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5741 vc_conn.done;
5742}
5743
5744private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5745 var MgcpCommand mgcp_cmd;
5746 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr8913b9e2021-07-27 22:33:45 +02005747 var charstring conn_id;
5748 f_mgcp_find_param_entry(mgcp_cmd.params, "I", conn_id);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005749 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005750 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005751 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005752 { int2str(cpars.rtp_payload_type) },
5753 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5754 cpars.rtp_sdp_format)),
5755 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr8913b9e2021-07-27 22:33:45 +02005756 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, str2hex(conn_id), sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005757 repeat;
5758 }
5759}
5760
Neels Hofmeyr8853afb2021-07-27 22:34:15 +02005761private altstep as_mgcp_ack_all_dlcx(CallParameters cpars) runs on BSC_ConnHdlr {
5762 var MgcpCommand mgcp_cmd;
5763 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
5764 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
5765 repeat;
5766 }
5767}
5768
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005769private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005770 var CallParameters cpars;
5771
5772 cpars := valueof(t_CallParams('12345'H, 0));
5773 if (pars.use_ipv6) {
5774 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5775 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5776 cpars.bss_rtp_ip := "::3";
5777 }
Oliver Smith44424db2023-08-22 13:54:09 +02005778 if (pars.use_csd) {
5779 f_set_cpars_csd(cpars, "BS25T", '1'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_4800);
5780 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005781
5782 f_init_handler(pars);
5783
5784 f_vty_transceive(MSCVTY, "configure terminal");
5785 f_vty_transceive(MSCVTY, "msc");
5786 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005787 f_vty_transceive(MSCVTY, "neighbor a cgi 023 42 5 6 ran-pc 0.24.2");
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005788 f_vty_transceive(MSCVTY, "exit");
5789 f_vty_transceive(MSCVTY, "exit");
5790
5791 f_perform_lu();
5792 f_mo_call_establish(cpars);
5793
5794 f_sleep(1.0);
5795
5796 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5797
5798 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5799 var BssmapCause cause := enum2int(cause_val);
5800
5801 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005802 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('023'H, '42'H, 5, 6) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005803
5804 /* old BSS sends Handover Required */
5805 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5806
5807 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5808
5809 /* MSC forwards the RR Handover Command to old BSS */
5810 var PDU_BSSAP ho_command;
5811 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5812
5813 log("GOT HandoverCommand", ho_command);
5814
5815 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5816
5817 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5818 f_expect_clear();
5819
5820 log("FIRST inter-BSC Handover done");
5821
5822
5823 /* ------------------------ */
5824
5825 /* Ok, that went well, now the other BSC is handovering back here --
5826 * from now on this here is the new BSS. */
Andreas Eversberge5a6ef12023-07-28 10:45:20 +02005827 f_create_bssmap_exp_n_connect(193);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005828
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005829 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
5830 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
5831 var template BSSMAP_IE_KC128 kC128;
5832 var OCT1 a5_perm_alg;
5833 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
Vadim Yanitskiyc5fcb892022-08-04 04:06:07 +07005834 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation,
5835 chosenEncryptionAlgorithm,
5836 kC128, codecList := ?);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005837 var PDU_BSSAP ho_request;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005838 alt {
5839 [] BSSAP.receive(expect_ho_request);
5840 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
5841 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
5842 " got ", ho_request);
5843 setverdict(fail, "Wrong handoverRequest received");
5844 mtc.stop;
5845 }
5846 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005847
5848 /* new BSS composes a RR Handover Command */
5849 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5850 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005851 var BSSMAP_IE_AoIP_TransportLayerAddress tla tla :=
5852 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005853 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5854 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5855
5856 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5857
5858 f_sleep(0.5);
5859
5860 /* Notify that the MS is now over here */
5861
5862 BSSAP.send(ts_BSSMAP_HandoverDetect);
5863 f_sleep(0.1);
5864 BSSAP.send(ts_BSSMAP_HandoverComplete);
5865
5866 f_sleep(3.0);
5867
5868 deactivate(ack_mdcx);
5869
5870 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5871
5872 /* blatant cheating */
5873 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5874 last_n_sd[0] := 3;
5875 f_bssmap_continue_after_n_sd(last_n_sd);
5876
5877 f_call_hangup(cpars, true);
5878 f_sleep(1.0);
5879 deactivate(ccrel);
5880
5881 setverdict(pass);
5882}
5883private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005884 var charstring bss_rtp_ip;
5885 if (pars.use_ipv6) {
5886 bss_rtp_ip := "::8";
5887 } else {
5888 bss_rtp_ip := "1.2.3.4";
5889 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005890 f_init_handler(pars);
Andreas Eversberge5a6ef12023-07-28 10:45:20 +02005891 f_create_bssmap_exp_n_connect(194);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005892
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005893 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
5894 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
5895 var template BSSMAP_IE_KC128 kC128;
5896 var OCT1 a5_perm_alg;
5897 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
Vadim Yanitskiyc5fcb892022-08-04 04:06:07 +07005898 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation,
5899 chosenEncryptionAlgorithm,
5900 kC128, codecList := ?);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005901 var PDU_BSSAP ho_request;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005902 alt {
5903 [] BSSAP.receive(expect_ho_request);
5904 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
5905 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
5906 " got ", ho_request);
5907 setverdict(fail, "Wrong handoverRequest received");
5908 mtc.stop;
5909 }
5910 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005911 /* new BSS composes a RR Handover Command */
5912 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5913 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005914 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
5915 valueof(f_ts_BSSMAP_IE_AoIP_TLA(bss_rtp_ip, 2342));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005916 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5917 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5918
5919 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5920
5921 f_sleep(0.5);
5922
5923 /* Notify that the MS is now over here */
5924
5925 BSSAP.send(ts_BSSMAP_HandoverDetect);
5926 f_sleep(0.1);
5927 BSSAP.send(ts_BSSMAP_HandoverComplete);
5928
5929 f_sleep(3.0);
5930
5931 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5932 * ... handover back to the first BSC :P */
5933
5934 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5935 var BssmapCause cause := enum2int(cause_val);
5936
5937 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005938 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005939
5940 /* old BSS sends Handover Required */
5941 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5942
5943 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5944
5945 /* MSC forwards the RR Handover Command to old BSS */
5946 var PDU_BSSAP ho_command;
5947 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5948
5949 log("GOT HandoverCommand", ho_command);
5950
5951 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5952
5953 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5954 f_expect_clear();
5955 setverdict(pass);
5956}
Oliver Smith44424db2023-08-22 13:54:09 +02005957function f_tc_ho_inter_bsc_main(boolean use_ipv6 := false, integer a5_n := 0, boolean use_csd := false) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005958 var BSC_ConnHdlr vc_conn0;
5959 var BSC_ConnHdlr vc_conn1;
5960 f_init(2);
5961
5962 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005963 pars0.use_ipv6 := use_ipv6;
Oliver Smith44424db2023-08-22 13:54:09 +02005964 pars0.use_csd := use_csd;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005965 pars0.net.expect_ciph := a5_n > 0;
5966 pars0.net.expect_auth := pars0.net.expect_ciph;
5967 pars0.net.kc_support := bit2oct('00000001'B << a5_n);
5968 pars0.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
5969 pars0.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
5970 pars0.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
5971 pars0.cm3 := valueof(ts_CM3_default);
5972 pars0.use_umts_aka := true;
5973 pars0.vec := f_gen_auth_vec_3g();
5974 pars0.vec_keep := true;
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005975 pars0.ran_idx := 0;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005976
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005977 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005978 pars1.use_ipv6 := use_ipv6;
Oliver Smith44424db2023-08-22 13:54:09 +02005979 pars1.use_csd := use_csd;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005980 pars1.net.expect_ciph := pars0.net.expect_ciph;
5981 pars1.net.expect_auth := pars0.net.expect_ciph;
5982 pars1.net.kc_support := bit2oct('00000001'B << a5_n);
5983 pars1.cm2 := pars0.cm2;
5984 pars1.cm3 := pars0.cm3;
5985 pars1.use_umts_aka := true;
5986 /* Both components need the same auth vector info because we expect f_tc_ho_inter_bsc0's ciphering key to be
5987 * identical to the one that shows up in f_tc_ho_inter_bsc1. Can only do that by feeding in a vector to both
5988 * components and then not overwriting it in BSC_ConnectionHandler. */
5989 pars1.vec := pars0.vec;
5990 pars1.vec_keep := true;
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005991 pars1.ran_idx := 1;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005992
5993 if (a5_n > 0) {
5994 f_vty_config(MSCVTY, "network", "authentication required");
5995 }
5996 f_vty_config(MSCVTY, "network", "encryption a5 " & int2str(a5_n));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005997
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005998 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0);
5999 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006000 vc_conn0.done;
6001 vc_conn1.done;
6002}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006003testcase TC_ho_inter_bsc() runs on MTC_CT {
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02006004 f_tc_ho_inter_bsc_main(false, a5_n := 0);
6005}
6006testcase TC_ho_inter_bsc_a5_1() runs on MTC_CT {
6007 f_tc_ho_inter_bsc_main(false, a5_n := 1);
6008}
6009testcase TC_ho_inter_bsc_a5_3() runs on MTC_CT {
6010 f_tc_ho_inter_bsc_main(false, a5_n := 3);
6011}
6012testcase TC_ho_inter_bsc_a5_4() runs on MTC_CT {
6013 f_tc_ho_inter_bsc_main(false, a5_n := 4);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006014}
6015testcase TC_ho_inter_bsc_ipv6() runs on MTC_CT {
6016 f_tc_ho_inter_bsc_main(true);
6017}
Oliver Smith44424db2023-08-22 13:54:09 +02006018testcase TC_ho_inter_bsc_csd() runs on MTC_CT {
6019 f_tc_ho_inter_bsc_main(use_csd := true);
6020}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006021
6022function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
6023 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
6024 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
6025 log("MS_NW patched enc_l3: ", enc_l3);
6026}
6027
6028private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006029 var CallParameters cpars;
Neels Hofmeyr906af102021-07-01 12:08:35 +02006030 var PDU_BSSAP ho_request;
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006031
6032 cpars := valueof(t_CallParams('12345'H, 0));
6033 if (pars.use_ipv6) {
Oliver Smithbe922912023-08-23 15:27:37 +02006034 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
6035 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
6036 cpars.bss_rtp_ip := "::3";
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006037 }
Oliver Smithcaa36c92023-08-23 15:30:33 +02006038 if (pars.use_csd) {
6039 f_set_cpars_csd(cpars, "BS25T", '1'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_4800);
6040 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006041 var hexstring ho_number := f_gen_msisdn(99999);
6042
6043 f_init_handler(pars);
6044
6045 f_create_mncc_expect(hex2str(ho_number));
6046
6047 f_vty_transceive(MSCVTY, "configure terminal");
6048 f_vty_transceive(MSCVTY, "msc");
6049 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
6050 f_vty_transceive(MSCVTY, "exit");
6051 f_vty_transceive(MSCVTY, "exit");
6052
6053 f_perform_lu();
6054 f_mo_call_establish(cpars);
6055
6056 f_sleep(1.0);
6057
6058 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
6059
6060 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
6061 var BssmapCause cause := enum2int(cause_val);
6062
6063 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr36ebc332021-06-23 03:20:32 +02006064 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('017'H, '017'H, 1, 1) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006065
6066 /* old BSS sends Handover Required */
6067 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
6068
6069 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
6070 * This MSC tries to reach the other MSC via GSUP. */
6071
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006072 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
6073 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
6074 var template BSSMAP_IE_KC128 kC128;
6075 var OCT1 a5_perm_alg;
6076 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
Vadim Yanitskiyc5fcb892022-08-04 04:06:07 +07006077 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation,
6078 chosenEncryptionAlgorithm,
6079 kC128, codecList := ?);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006080
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006081 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
6082 var GSUP_PDU prep_ho_req;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006083 alt {
6084 [] GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
6085 pars.imsi, destination_name := remote_msc_name,
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006086 an_apdu := t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, pdu := ?))) -> value prep_ho_req;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006087 [] GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST)) {
6088 setverdict(fail, "Wrong OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST message received");
6089 mtc.stop;
6090 }
6091 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006092
6093 var GSUP_IeValue source_name_ie;
6094 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
6095 var octetstring local_msc_name := source_name_ie.source_name;
6096
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006097 /* Decode PDU to 1) match with expect_ho_request and 2) to forward the actual chosen encryption algorithm. */
Neels Hofmeyr906af102021-07-01 12:08:35 +02006098 var GSUP_IeValue an_apdu_ie;
6099 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_AN_APDU_IE, an_apdu_ie);
6100 ho_request := dec_PDU_BSSAP(an_apdu_ie.an_apdu.pdu);
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006101 if (not match(ho_request, expect_ho_request)) {
6102 setverdict(fail, "Wrong PDU in OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST message received");
6103 mtc.stop;
6104 }
Neels Hofmeyr906af102021-07-01 12:08:35 +02006105
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006106 /* Remote MSC has figured out its BSC and signals success */
6107 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
6108 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
6109 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
Neels Hofmeyr906af102021-07-01 12:08:35 +02006110 aoIPTransportLayer := omit,
6111 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}),
6112 chosenEncryptionAlgorithm := ho_request.pdu.bssmap.handoverRequest.chosenEncryptionAlgorithm));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006113 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
6114 pars.imsi,
6115 ho_number,
6116 remote_msc_name, local_msc_name,
6117 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
6118
6119 /* MSC forwards the RR Handover Command to old BSS */
6120 BSSAP.receive(tr_BSSMAP_HandoverCommand);
6121
6122 /* The MS shows up at remote new BSS */
6123
6124 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
6125 pars.imsi, remote_msc_name, local_msc_name,
6126 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6127 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
6128 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
6129 f_sleep(0.1);
6130
6131 /* Save the MS sequence counters for use on the other connection */
6132 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
6133
6134 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
6135 pars.imsi, remote_msc_name, local_msc_name,
6136 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6137 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
6138
6139 /* The local BSS conn clears, all communication goes via remote MSC now */
6140 f_expect_clear();
6141
6142 /**********************************/
6143 /* Play through some signalling across the inter-MSC link.
6144 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
6145
6146 if (false) {
6147 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
6148 invoke_id := 5, /* Phone may not start from 0 or 1 */
6149 op_code := SS_OP_CODE_PROCESS_USS_REQ,
6150 ussd_string := "*#100#"
6151 );
6152
6153 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
6154 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
6155 op_code := SS_OP_CODE_PROCESS_USS_REQ,
6156 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
6157 )
6158
6159 /* Compose a new SS/REGISTER message with request */
6160 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
6161 tid := 1, /* We just need a single transaction */
6162 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
6163 facility := valueof(facility_req)
6164 );
6165 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
6166
6167 /* Compose SS/RELEASE_COMPLETE template with expected response */
6168 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
6169 tid := 1, /* Response should arrive within the same transaction */
6170 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
6171 facility := valueof(facility_rsp)
6172 );
6173
6174 /* Compose expected MSC -> HLR message */
6175 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
6176 imsi := g_pars.imsi,
6177 state := OSMO_GSUP_SESSION_STATE_BEGIN,
6178 ss := valueof(facility_req)
6179 );
6180
6181 /* To be used for sending response with correct session ID */
6182 var GSUP_PDU gsup_req_complete;
6183
6184 /* Request own number */
6185 /* From remote MSC instead of BSSAP directly */
6186 /* Patch the correct N_SD value into the message. */
6187 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
6188 var RAN_Emulation.ConnectionData cd;
6189 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
6190 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
6191 pars.imsi, remote_msc_name, local_msc_name,
6192 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6193 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
6194 ))
6195 ));
6196
6197 /* Expect GSUP message containing the SS payload */
6198 gsup_req_complete := f_expect_gsup_msg(gsup_req);
6199
6200 /* Compose the response from HLR using received session ID */
6201 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
6202 imsi := g_pars.imsi,
6203 sid := gsup_req_complete.ies[1].val.session_id,
6204 state := OSMO_GSUP_SESSION_STATE_END,
6205 ss := valueof(facility_rsp)
6206 );
6207
6208 /* Finally, HLR terminates the session */
6209 GSUP.send(gsup_rsp);
6210
6211 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
6212 var GSUP_PDU gsup_ussd_rsp;
6213 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
6214 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
6215
6216 var GSUP_IeValue an_apdu;
6217 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
6218 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
6219 mtc.stop;
6220 }
6221 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
6222 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
6223 log("Expecting", ussd_rsp);
6224 log("Got", dtap_mt);
6225 if (not match(dtap_mt, ussd_rsp)) {
6226 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
6227 mtc.stop;
6228 }
6229 }
6230 /**********************************/
6231
6232
6233 /* inter-MSC handover back to the first MSC */
Andreas Eversberge5a6ef12023-07-28 10:45:20 +02006234 f_create_bssmap_exp_n_connect(193);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006235 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
6236
6237 /* old BSS sends Handover Required, via inter-MSC E link: like
6238 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
6239 * but via GSUP */
6240 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
6241 pars.imsi, remote_msc_name, local_msc_name,
6242 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6243 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
6244 ))
6245 ));
6246
6247 /* MSC asks local BSS to prepare Handover to it */
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006248 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
Vadim Yanitskiyc5fcb892022-08-04 04:06:07 +07006249 expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation,
6250 chosenEncryptionAlgorithm,
6251 kC128, codecList := ?);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006252 alt {
Neels Hofmeyr906af102021-07-01 12:08:35 +02006253 [] BSSAP.receive(expect_ho_request) -> value ho_request;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006254 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
6255 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
6256 " got ", ho_request);
6257 setverdict(fail, "Wrong handoverRequest received");
6258 mtc.stop;
6259 }
6260 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006261
6262 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
6263 f_bssmap_continue_after_n_sd(last_n_sd);
6264
6265 /* new BSS composes a RR Handover Command */
6266 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
6267 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006268 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
6269 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006270 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
Neels Hofmeyr906af102021-07-01 12:08:35 +02006271 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}),
6272 chosenEncryptionAlgorithm := ho_request.pdu.bssmap.handoverRequest.chosenEncryptionAlgorithm));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006273
6274 /* HandoverCommand goes out via remote MSC-I */
6275 var GSUP_PDU prep_subsq_ho_res;
6276 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
6277 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
6278
6279 /* MS shows up at the local BSS */
6280 BSSAP.send(ts_BSSMAP_HandoverDetect);
6281 f_sleep(0.1);
6282 BSSAP.send(ts_BSSMAP_HandoverComplete);
6283
6284 /* Handover Succeeded message */
6285 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
6286 pars.imsi, destination_name := remote_msc_name));
6287
6288 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
6289 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
6290 pars.imsi, destination_name := remote_msc_name));
6291
6292 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
6293
6294 f_sleep(1.0);
6295 deactivate(ack_mdcx);
6296
6297 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
6298 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
6299 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
6300 MNCC.clear;
6301
6302 var default ccrel := activate(as_optional_cc_rel(cpars, true));
6303 f_call_hangup(cpars, true);
6304 f_sleep(1.0);
6305 deactivate(ccrel);
6306
6307 setverdict(pass);
6308}
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006309function f_tc_ho_inter_msc_out_a5(integer a5_n) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006310 var BSC_ConnHdlr vc_conn;
6311 f_init(1);
6312
6313 var BSC_ConnHdlrPars pars := f_init_pars(54);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006314 pars.net.expect_ciph := a5_n > 0;
6315 pars.net.expect_auth := pars.net.expect_ciph;
6316 pars.net.kc_support := bit2oct('00000001'B << a5_n);
6317 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
6318 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
6319 pars.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
6320 pars.cm3 := valueof(ts_CM3_default);
6321 pars.use_umts_aka := true;
6322
6323 if (a5_n > 0) {
6324 f_vty_config(MSCVTY, "network", "authentication required");
6325 }
6326 f_vty_config(MSCVTY, "network", "encryption a5 " & int2str(a5_n));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006327
Neels Hofmeyr60122f82021-07-28 17:59:38 +02006328 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006329 vc_conn.done;
6330}
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006331testcase TC_ho_inter_msc_out() runs on MTC_CT {
6332 f_tc_ho_inter_msc_out_a5(0);
6333}
6334testcase TC_ho_inter_msc_out_a5_1() runs on MTC_CT {
6335 f_tc_ho_inter_msc_out_a5(1);
6336}
6337testcase TC_ho_inter_msc_out_a5_3() runs on MTC_CT {
6338 f_tc_ho_inter_msc_out_a5(3);
6339}
6340testcase TC_ho_inter_msc_out_a5_4() runs on MTC_CT {
6341 f_tc_ho_inter_msc_out_a5(4);
6342}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006343testcase TC_ho_inter_msc_out_ipv6() runs on MTC_CT {
6344 var BSC_ConnHdlr vc_conn;
6345 f_init(1);
6346
6347 var BSC_ConnHdlrPars pars := f_init_pars(54);
6348 pars.use_ipv6 := true;
6349
Neels Hofmeyr60122f82021-07-28 17:59:38 +02006350 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006351 vc_conn.done;
6352}
Oliver Smithcaa36c92023-08-23 15:30:33 +02006353testcase TC_ho_inter_msc_out_csd() runs on MTC_CT {
6354 var BSC_ConnHdlr vc_conn;
6355 f_init(1);
6356
6357 var BSC_ConnHdlrPars pars := f_init_pars(54);
6358 pars.use_csd := true;
6359
6360 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars);
6361 vc_conn.done;
6362}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006363
Oliver Smith1d118ff2019-07-03 10:57:35 +02006364private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6365 pars.net.expect_auth := true;
6366 pars.net.expect_imei := true;
6367 f_init_handler(pars);
6368 f_perform_lu();
6369}
6370testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
6371 var BSC_ConnHdlr vc_conn;
6372 f_init();
6373 f_vty_config(MSCVTY, "network", "authentication required");
6374 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6375
6376 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
6377 vc_conn.done;
6378}
6379
6380private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6381 pars.net.expect_auth := true;
6382 pars.use_umts_aka := true;
6383 pars.net.expect_imei := true;
6384 f_init_handler(pars);
6385 f_perform_lu();
6386}
6387testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
6388 var BSC_ConnHdlr vc_conn;
6389 f_init();
6390 f_vty_config(MSCVTY, "network", "authentication required");
6391 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6392
6393 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
6394 vc_conn.done;
6395}
6396
6397private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6398 pars.net.expect_imei := true;
6399 f_init_handler(pars);
6400 f_perform_lu();
6401}
6402testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
6403 var BSC_ConnHdlr vc_conn;
6404 f_init();
6405 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6406
6407 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
6408 vc_conn.done;
6409}
6410
6411private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6412 pars.net.expect_tmsi := false;
6413 pars.net.expect_imei := true;
6414 f_init_handler(pars);
6415 f_perform_lu();
6416}
6417testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
6418 var BSC_ConnHdlr vc_conn;
6419 f_init();
6420 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6421 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6422
6423 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
6424 vc_conn.done;
6425}
6426
6427private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6428 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006429
6430 pars.net.expect_auth := true;
6431 pars.net.expect_imei := true;
6432 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6433 f_init_handler(pars);
6434
6435 /* Cannot use f_perform_lu() as we expect a reject */
6436 l3_lu := f_build_lu_imsi(g_pars.imsi)
6437 f_create_gsup_expect(hex2str(g_pars.imsi));
6438 f_bssap_compl_l3(l3_lu);
6439 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6440
6441 f_mm_common();
6442 f_msc_lu_hlr();
6443 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006444 f_expect_lu_reject();
Eric Wild85cc1612022-03-30 01:44:29 +02006445 f_expect_clear(verify_vlr_cell_id:=false);
Oliver Smith1d118ff2019-07-03 10:57:35 +02006446}
6447testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
6448 var BSC_ConnHdlr vc_conn;
6449 f_init();
6450 f_vty_config(MSCVTY, "network", "authentication required");
6451 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6452
6453 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
6454 vc_conn.done;
6455}
6456
6457private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6458 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006459
6460 pars.net.expect_auth := true;
6461 pars.net.expect_imei := true;
6462 pars.net.check_imei_error := true;
6463 f_init_handler(pars);
6464
6465 /* Cannot use f_perform_lu() as we expect a reject */
6466 l3_lu := f_build_lu_imsi(g_pars.imsi)
6467 f_create_gsup_expect(hex2str(g_pars.imsi));
6468 f_bssap_compl_l3(l3_lu);
6469 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6470
6471 f_mm_common();
6472 f_msc_lu_hlr();
6473 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006474 f_expect_lu_reject();
Eric Wild85cc1612022-03-30 01:44:29 +02006475 f_expect_clear(verify_vlr_cell_id:=false);
Oliver Smith1d118ff2019-07-03 10:57:35 +02006476}
6477testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
6478 var BSC_ConnHdlr vc_conn;
6479 f_init();
6480 f_vty_config(MSCVTY, "network", "authentication required");
6481 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6482
6483 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
6484 vc_conn.done;
6485}
6486
6487private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6488 pars.net.expect_auth := true;
6489 pars.net.expect_imei_early := true;
6490 f_init_handler(pars);
6491 f_perform_lu();
6492}
6493testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
6494 var BSC_ConnHdlr vc_conn;
6495 f_init();
6496 f_vty_config(MSCVTY, "network", "authentication required");
6497 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6498
6499 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
6500 vc_conn.done;
6501}
6502
6503private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6504 pars.net.expect_auth := true;
6505 pars.use_umts_aka := true;
6506 pars.net.expect_imei_early := true;
6507 f_init_handler(pars);
6508 f_perform_lu();
6509}
6510testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
6511 var BSC_ConnHdlr vc_conn;
6512 f_init();
6513 f_vty_config(MSCVTY, "network", "authentication required");
6514 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6515
6516 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
6517 vc_conn.done;
6518}
6519
6520private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6521 pars.net.expect_imei_early := true;
6522 f_init_handler(pars);
6523 f_perform_lu();
6524}
6525testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
6526 var BSC_ConnHdlr vc_conn;
6527 f_init();
6528 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6529
6530 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
6531 vc_conn.done;
6532}
6533
6534private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6535 pars.net.expect_tmsi := false;
6536 pars.net.expect_imei_early := true;
6537 f_init_handler(pars);
6538 f_perform_lu();
6539}
6540testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
6541 var BSC_ConnHdlr vc_conn;
6542 f_init();
6543 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6544 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6545
6546 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
6547 vc_conn.done;
6548}
6549
6550private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6551 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006552
6553 pars.net.expect_auth := true;
6554 pars.net.expect_imei_early := true;
6555 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6556 f_init_handler(pars);
6557
6558 /* Cannot use f_perform_lu() as we expect a reject */
6559 l3_lu := f_build_lu_imsi(g_pars.imsi)
6560 f_create_gsup_expect(hex2str(g_pars.imsi));
6561 f_bssap_compl_l3(l3_lu);
6562 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6563
6564 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006565 f_expect_lu_reject();
Eric Wild85cc1612022-03-30 01:44:29 +02006566 f_expect_clear(verify_vlr_cell_id:=false);
Oliver Smith1d118ff2019-07-03 10:57:35 +02006567}
6568testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
6569 var BSC_ConnHdlr vc_conn;
6570 f_init();
6571 f_vty_config(MSCVTY, "network", "authentication required");
6572 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6573
6574 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
6575 vc_conn.done;
6576}
6577
6578private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6579 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006580
6581 pars.net.expect_auth := true;
6582 pars.net.expect_imei_early := true;
6583 pars.net.check_imei_error := true;
6584 f_init_handler(pars);
6585
6586 /* Cannot use f_perform_lu() as we expect a reject */
6587 l3_lu := f_build_lu_imsi(g_pars.imsi)
6588 f_create_gsup_expect(hex2str(g_pars.imsi));
6589 f_bssap_compl_l3(l3_lu);
6590 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6591
6592 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006593 f_expect_lu_reject();
Eric Wild85cc1612022-03-30 01:44:29 +02006594 f_expect_clear(verify_vlr_cell_id:=false);
Oliver Smith1d118ff2019-07-03 10:57:35 +02006595}
6596testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
6597 var BSC_ConnHdlr vc_conn;
6598 f_init();
6599 f_vty_config(MSCVTY, "network", "authentication required");
6600 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6601
6602 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
6603 vc_conn.done;
6604}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006605
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006606friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6607 f_init_handler(pars);
6608 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6609
6610 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
6611 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
6612 * will cause a use-after-free after that event dispatch. */
6613 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
6614 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
6615 cpars.rtp_sdp_format := "FOO/8000";
6616 cpars.expect_release := true;
6617
6618 f_perform_lu();
6619 f_mo_call_establish(cpars);
6620}
6621testcase TC_invalid_mgcp_crash() runs on MTC_CT {
6622 var BSC_ConnHdlr vc_conn;
6623 f_init();
6624
6625 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
6626 vc_conn.done;
6627}
6628
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006629friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
6630runs on BSC_ConnHdlr {
6631 pars.tmsi := 'FFFFFFFF'O;
6632 f_init_handler(pars);
6633
6634 f_create_gsup_expect(hex2str(g_pars.imsi));
6635
6636 /* Initiate Location Updating using an unknown TMSI */
6637 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
6638
6639 /* Expect an Identity Request, send response with no identity */
6640 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
6641 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
6642 lengthIndicator := 1,
6643 mobileIdentityV := {
6644 typeOfIdentity := '000'B,
6645 oddEvenInd_identity := {
6646 no_identity := {
6647 oddevenIndicator := '0'B,
6648 fillerDigits := '00000'H
6649 }
6650 }
6651 }
6652 })));
6653
6654 f_expect_lu_reject();
6655 f_expect_clear();
6656}
6657testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
6658 var BSC_ConnHdlr vc_conn;
6659
6660 f_init();
6661
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006662 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7, verify_cell_id := false);
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006663 vc_conn.done;
6664}
6665
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006666/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6667 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6668 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6669friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6670runs on BSC_ConnHdlr {
6671 var charstring imsi := hex2str(pars.imsi);
6672
6673 f_init_handler(pars);
6674
6675 /* Perform location update */
6676 f_perform_lu();
6677
6678 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6679 f_create_gsup_expect(hex2str(g_pars.imsi));
6680
6681 /* Initiate paging procedure from the VTY */
6682 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6683 f_expect_paging();
6684
6685 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6686 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6687
6688 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6689 f_establish_fully(EST_TYPE_PAG_RESP);
6690
6691 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6692 * In this case we do not send anything and just wait for a Clear Command. */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006693 f_expect_clear(verify_vlr_cell_id := false);
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006694}
6695testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6696 var BSC_ConnHdlr vc_conn;
6697
6698 f_init();
6699
6700 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6701 vc_conn.done;
6702}
6703
Neels Hofmeyr3ad76a42022-08-09 02:57:49 +02006704private altstep as_mncc_rx_rtp_create(CallParameters cpars) runs on BSC_ConnHdlr {
6705 [] MNCC.receive(tr_MNCC_RTP_CREATE(cpars.mncc_callref));
6706}
6707
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006708const charstring REEST_LOST_CONNECTION := "REEST_LOST_CONNECTION";
6709const charstring REEST_CLEARED := "REEST_CLEARED";
6710
6711friend function f_tc_call_re_establishment_1(charstring id, BSC_ConnHdlrPars pars)
6712 runs on BSC_ConnHdlr {
6713 f_init_handler(pars, t_guard := 30.0);
6714
6715 f_perform_lu();
6716
6717 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6718 f_mo_call_establish(cpars);
6719 f_sleep(3.0);
6720 COORD.send(REEST_LOST_CONNECTION);
6721 COORD.send(cpars);
6722 f_expect_clear(verify_vlr_cell_id := false);
6723 COORD.send(REEST_CLEARED);
6724}
6725
6726friend function f_tc_call_re_establishment_2(charstring id, BSC_ConnHdlrPars pars)
6727 runs on BSC_ConnHdlr {
6728 f_init_handler(pars, t_guard := 30.0);
6729 var CallParameters cpars;
6730
6731 COORD.receive(REEST_LOST_CONNECTION);
6732 COORD.receive(tr_CallParams) -> value cpars;
6733
6734 f_gsup_change_connhdlr(hex2str(g_pars.imsi));
6735 f_create_smpp_expect(hex2str(pars.msisdn));
6736
6737 /* The MS has lost the first channel and decides to show up on a new conn (on a nearby neighbor cell) to ask for
6738 * CM Re-Establishment. Send a Complete Layer 3 to osmo-msc with a CM Re-Establishment Request. */
6739 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
6740 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REESTABL_REQ(mi));
6741 f_cl3_or_initial_ue(l3_info);
6742
6743 /* At this point the other test component should receive the Clear Command for the first A connection. */
6744
6745 /* This new connection continues with Authentication... */
6746 f_mm_common();
6747
6748 /* ...and with Assignment of a voice channel. */
6749 var template BSSMAP_IE_AoIP_TransportLayerAddress tla_ass :=
Neels Hofmeyr02d513e2022-07-25 22:07:24 +02006750 (f_tr_BSSMAP_IE_AoIP_TLA(cpars.mgw_conn_1.mgw_rtp_ip, ?),
6751 f_tr_BSSMAP_IE_AoIP_TLA(cpars.mgw_conn_2.mgw_rtp_ip, ?));
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006752 BSSAP.receive(tr_BSSMAP_AssignmentReq(omit, tla_ass));
6753 /* By this Assignment Request, the CM Re-Establishment Request is implicitly accepted. */
6754
6755 /* Send Assignment Complete from BSC */
6756 var template BSSMAP_IE_AoIP_TransportLayerAddress tla;
6757 tla := f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port);
6758 var BSSMAP_IE_SpeechCodec codec;
6759 codec := valueof(ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}));
6760
6761 /* Make really sure the other component is done with its MGCP */
6762 COORD.receive(REEST_CLEARED);
6763
6764 /* Transfer state for this call over to this test component so we can resolve MNCC and MGCP in this function. */
6765 f_mncc_change_connhdlr(cpars.mncc_callref);
6766 f_mgcp_change_connhdlr(cpars.mgcp_ep);
6767
6768 /* osmo-msc may redirect the MGW endpoint to the newly allocated channel.
6769 * Apparently osmo-msc currently also sends an MDCX to the CN side, just repeating the same configuration that
6770 * is already in use. This test accepts any number of or even lack of MDCX. */
6771 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
Neels Hofmeyr3ad76a42022-08-09 02:57:49 +02006772 var default optional_rtp_create := activate(as_mncc_rx_rtp_create(cpars));
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006773
6774 BSSAP.send(ts_BSSMAP_AssignmentComplete(omit, tla, codec));
Neels Hofmeyr3ad76a42022-08-09 02:57:49 +02006775
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006776 /* The call has been fully re-established.
6777 * Let a bit of time pass before hanging up, for everything to settle. */
6778 f_sleep(3.0);
6779
Neels Hofmeyr3ad76a42022-08-09 02:57:49 +02006780 deactivate(optional_rtp_create);
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006781 deactivate(ack_mdcx);
6782
6783 /* Hang up the call and clear the new, second A connection */
6784 var default ack_dlcx := activate(as_mgcp_ack_all_dlcx(cpars));
6785
6786 /* CC release. This is the proper MS initiated release sequence as shown by
6787 * https://git.osmocom.org/osmo-msc/tree/doc/sequence_charts/voice_call_full.msc?id=e53ecde83e4fb2470209e818e9ad76a2d6a19190
6788 * f_call_hangup() seems a bit mixed up, so here a "proper" sequence. Fix of f_call_hangup() pending. */
6789 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_DISC(cpars.transaction_id, '0'B, '0000000'B)));
6790 MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref));
6791 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
6792 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
6793 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, '0'B)));
6794 MNCC.receive(tr_MNCC_REL_cnf(cpars.mncc_callref, cause := *));
6795
6796 /* BSSAP clear */
6797 interleave {
6798 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
6799 BSSAP.send(ts_BSSMAP_ClearComplete);
6800 }
6801 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
6802 }
6803
6804 f_sleep(1.0);
6805 deactivate(ack_dlcx);
6806}
6807
6808testcase TC_call_re_establishment() runs on MTC_CT {
6809 var BSC_ConnHdlr vc_conn1;
6810 var BSC_ConnHdlr vc_conn2;
6811 f_init();
6812
6813 var BSC_ConnHdlrPars pars1 := f_init_pars(91);
6814 var BSC_ConnHdlrPars pars2 := pars1;
6815
6816 vc_conn1 := f_start_handler_create(pars1);
6817 vc_conn2 := f_start_handler_create(pars2);
6818 connect(vc_conn1:COORD, vc_conn2:COORD);
6819 f_start_handler_run(vc_conn1, refers(f_tc_call_re_establishment_1), pars1);
6820 f_start_handler_run(vc_conn2, refers(f_tc_call_re_establishment_2), pars2);
6821 vc_conn1.done;
6822 vc_conn2.done;
6823}
6824
Neels Hofmeyra9b2dcf2021-07-28 00:57:58 +02006825testcase TC_call_re_establishment_auth() runs on MTC_CT {
6826 var BSC_ConnHdlr vc_conn1;
6827 var BSC_ConnHdlr vc_conn2;
6828 f_init();
6829
6830 f_vty_config(MSCVTY, "network", "authentication required");
6831
6832 var BSC_ConnHdlrPars pars1 := f_init_pars(92);
6833 pars1.net.expect_auth := true;
6834 var BSC_ConnHdlrPars pars2 := pars1;
6835
6836 vc_conn1 := f_start_handler_create(pars1);
6837 vc_conn2 := f_start_handler_create(pars2);
6838 connect(vc_conn1:COORD, vc_conn2:COORD);
6839 f_start_handler_run(vc_conn1, refers(f_tc_call_re_establishment_1), pars1);
6840 f_start_handler_run(vc_conn2, refers(f_tc_call_re_establishment_2), pars2);
6841 vc_conn1.done;
6842 vc_conn2.done;
6843}
6844
Neels Hofmeyr48e4d7d2021-07-28 00:57:58 +02006845testcase TC_call_re_establishment_ciph() runs on MTC_CT {
6846 var BSC_ConnHdlr vc_conn1;
6847 var BSC_ConnHdlr vc_conn2;
6848 f_init();
6849
6850 f_vty_config(MSCVTY, "network", "authentication required");
6851 f_vty_config(MSCVTY, "network", "encryption a5 3");
6852
6853 var BSC_ConnHdlrPars pars1 := f_init_pars(92);
6854 pars1.net.expect_auth := true;
6855 pars1.net.expect_ciph := true;
6856 pars1.net.kc_support := '08'O; /* A5/3 only */
6857 var BSC_ConnHdlrPars pars2 := pars1;
6858
6859 vc_conn1 := f_start_handler_create(pars1);
6860 vc_conn2 := f_start_handler_create(pars2);
6861 connect(vc_conn1:COORD, vc_conn2:COORD);
6862 f_start_handler_run(vc_conn1, refers(f_tc_call_re_establishment_1), pars1);
6863 f_start_handler_run(vc_conn2, refers(f_tc_call_re_establishment_2), pars2);
6864 vc_conn1.done;
6865 vc_conn2.done;
6866}
6867
Neels Hofmeyr07ea7f22022-05-05 01:39:26 +02006868/* Establish a conn with a valid Mobile Identity. Then send a CM Service Request containing a mismatching Mobile
6869 * Identity on the same conn. Caused a crash, see OS#5532. */
6870friend function f_tc_cm_serv_wrong_mi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6871 f_init_handler(pars);
6872
6873 /* Set up a fully identified conn */
6874 f_perform_lu();
6875 f_establish_fully();
6876
6877 /* CM Serv Req with mismatching Mobile Identity */
6878 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(f_gen_imsi(99999))); /* ensure it is different from below*/
6879 BSSAP.send(ts_PDU_DTAP_MO(ts_CM_SERV_REQ(CM_TYPE_MO_SMS, mi)));
6880 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ));
6881
6882 /* Cancel the first CM Service from f_establish_fully() */
6883 BSSAP.send(ts_BSSMAP_ClearRequest(0));
6884
6885 f_expect_clear();
6886}
6887testcase TC_cm_serv_wrong_mi() runs on MTC_CT {
6888 var BSC_ConnHdlr vc_conn;
6889 f_init();
6890 vc_conn := f_start_handler(refers(f_tc_cm_serv_wrong_mi), 94);
6891 vc_conn.done;
6892}
6893
Neels Hofmeyre860fc42022-10-05 01:15:54 +02006894/* a5 0 a5 0 a5 0 3 a5 0 3 a5 3 a5 3
6895 * HLR has auth info no yes no yes no yes
6896 *
6897 * test case index [0] [1] [2] [3] [4] [5]
6898 * authentication optional No auth No auth attempt auth, auth reject auth
6899 * (%) fall back to +ciph +ciph
6900 * no-auth
6901 *
6902 * [6] [7] [8] [9] [10] [11]
6903 * authentication mandatory reject auth reject auth reject auth
6904 * only +ciph +ciph
6905 *
6906 * (%): Arguably, when HLR has auth info, the MSC should use it. Current behavior of osmo-msc is to not attempt auth at
6907 * all. Related: OS#4830.
6908 */
6909type record of BSC_ConnHdlrNetworkPars rof_netpars;
6910
6911const rof_netpars auth_options_testcases := {
6912 {
6913 /* [0] auth optional, encr a5 0: no-auth" */
6914 kc_support := '01'O,
6915 net_config := { "authentication optional",
6916 "encryption a5 0" },
6917 expect_attach_success := true,
6918 expect_tmsi := true,
6919 expect_auth_attempt := false,
6920 hlr_has_auth_info := false,
6921 expect_auth := false,
6922 expect_ciph := false,
6923 expect_imei := false,
6924 expect_imei_early := false,
6925 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
6926 check_imei_error := false
6927 },
6928 {
6929 /* [1] auth optional, encr a5 0, HLR HAS auth info: no-auth */
6930 kc_support := '01'O,
6931 net_config := { "authentication optional",
6932 "encryption a5 0" },
6933 expect_attach_success := true,
6934 expect_tmsi := true,
6935 expect_auth_attempt := false,
6936 hlr_has_auth_info := true,
6937 expect_auth := false,
6938 expect_ciph := false,
6939 expect_imei := false,
6940 expect_imei_early := false,
6941 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
6942 check_imei_error := false
6943 },
6944 {
6945 /* [2] auth optional, encr a5 0 3, HLR has NO Auth Info: Fall back to no-auth" */
6946 kc_support := '09'O,
6947 net_config := { "authentication optional",
6948 "encryption a5 0 3" },
6949 expect_attach_success := true,
6950 expect_tmsi := true,
6951 expect_auth_attempt := true,
6952 hlr_has_auth_info := false,
6953 expect_auth := false,
6954 expect_ciph := false,
6955 expect_imei := false,
6956 expect_imei_early := false,
6957 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
6958 check_imei_error := false
6959 },
6960 {
6961 /* [3] auth optional, encr a5 0 3, HLR HAS Auth Info: Use A5/3 */
6962 kc_support := '09'O,
6963 net_config := { "authentication optional",
6964 "encryption a5 0 3" },
6965 expect_attach_success := true,
6966 expect_tmsi := true,
6967 expect_auth_attempt := true,
6968 hlr_has_auth_info := true,
6969 expect_auth := true,
6970 expect_ciph := true,
6971 expect_imei := false,
6972 expect_imei_early := false,
6973 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
6974 check_imei_error := false
6975 },
6976 {
6977 /* [4] auth optional, encr a5 3, HLR has NO Auth Info: reject.
6978 * Auth is required implicitly because ciph is required. */
6979 kc_support := '08'O,
6980 net_config := { "authentication optional",
6981 "encryption a5 3" },
6982 expect_attach_success := false,
6983 expect_tmsi := true,
6984 expect_auth_attempt := true,
6985 hlr_has_auth_info := false,
6986 expect_auth := false,
6987 expect_ciph := false,
6988 expect_imei := false,
6989 expect_imei_early := false,
6990 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
6991 check_imei_error := false
6992 },
6993 {
6994 /* [5] auth optional, encr a5 3, HLR HAS Auth Info: auth + ciph.
6995 * Auth is required implicitly because ciph is required. */
6996 kc_support := '08'O,
6997 net_config := { "authentication optional",
6998 "encryption a5 3" },
6999 expect_attach_success := true,
7000 expect_tmsi := true,
7001 expect_auth_attempt := true,
7002 hlr_has_auth_info := true,
7003 expect_auth := true,
7004 expect_ciph := true,
7005 expect_imei := false,
7006 expect_imei_early := false,
7007 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
7008 check_imei_error := false
7009 },
7010
7011 /* Same as above, but with 'authentication required' */
7012
7013 {
7014 /* [6] auth required, encr a5 0, HLR has NO auth info: reject */
7015 kc_support := '01'O,
7016 net_config := { "authentication required",
7017 "encryption a5 0" },
7018 expect_attach_success := false,
7019 expect_tmsi := true,
7020 expect_auth_attempt := true,
7021 hlr_has_auth_info := false,
7022 expect_auth := false,
7023 expect_ciph := false,
7024 expect_imei := false,
7025 expect_imei_early := false,
7026 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
7027 check_imei_error := false
7028 },
7029 {
7030 /* [7] auth required, encr a5 0, HLR HAS auth info: do auth, no ciph" */
7031 kc_support := '01'O,
7032 net_config := { "authentication required",
7033 "encryption a5 0" },
7034 expect_attach_success := true,
7035 expect_tmsi := true,
7036 expect_auth_attempt := true,
7037 hlr_has_auth_info := true,
7038 expect_auth := true,
7039 expect_ciph := false,
7040 expect_imei := false,
7041 expect_imei_early := false,
7042 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
7043 check_imei_error := false
7044 },
7045 {
7046 /* [8] auth required, encr a5 0 3, HLR has NO Auth Info: reject */
7047 kc_support := '09'O,
7048 net_config := { "authentication required",
7049 "encryption a5 0 3" },
7050 expect_attach_success := false,
7051 expect_tmsi := true,
7052 expect_auth_attempt := true,
7053 hlr_has_auth_info := false,
7054 expect_auth := false,
7055 expect_ciph := false,
7056 expect_imei := false,
7057 expect_imei_early := false,
7058 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
7059 check_imei_error := false
7060 },
7061 {
7062 /* [9] auth required, encr a5 0 3, HLR HAS Auth Info: Use A5/3 */
7063 kc_support := '09'O,
7064 net_config := { "authentication required",
7065 "encryption a5 0 3" },
7066 expect_attach_success := true,
7067 expect_tmsi := true,
7068 expect_auth_attempt := true,
7069 hlr_has_auth_info := true,
7070 expect_auth := true,
7071 expect_ciph := true,
7072 expect_imei := false,
7073 expect_imei_early := false,
7074 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
7075 check_imei_error := false
7076 },
7077 {
7078 /* [10] auth required, encr a5 3, HLR has NO Auth Info: reject. */
7079 kc_support := '08'O,
7080 net_config := { "authentication required",
7081 "encryption a5 3" },
7082 expect_attach_success := false,
7083 expect_tmsi := true,
7084 expect_auth_attempt := true,
7085 hlr_has_auth_info := false,
7086 expect_auth := false,
7087 expect_ciph := false,
7088 expect_imei := false,
7089 expect_imei_early := false,
7090 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
7091 check_imei_error := false
7092 },
7093 {
7094 /* [11] auth required, encr a5 3, HLR HAS Auth Info: auth + ciph. */
7095 kc_support := '08'O,
7096 net_config := { "authentication required",
7097 "encryption a5 3" },
7098 expect_attach_success := true,
7099 expect_tmsi := true,
7100 expect_auth_attempt := true,
7101 hlr_has_auth_info := true,
7102 expect_auth := true,
7103 expect_ciph := true,
7104 expect_imei := false,
7105 expect_imei_early := false,
7106 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
7107 check_imei_error := false
7108 }
7109};
7110
7111private function f_tc_auth_options(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
7112 f_init_handler(pars);
7113
7114 /* Location Updating */
7115 log(MSCVTY, "f_perform_lu() starting");
7116 f_perform_lu();
7117 log(MSCVTY, "f_perform_lu() done");
7118
7119 f_sleep(1.0);
7120
7121 if (not pars.net.expect_attach_success) {
7122 /* Expected above LU to fail. In order to test CM Service Request below, a LU has to succeed first. So
7123 * run another LU that will be successful. Careful not to load auth tokens into the VLR that may taint
7124 * the test for CM Service Request below. */
7125
7126 log(MSCVTY, "Running a successful LU so that CM Service Request can be tested");
7127 var BSC_ConnHdlrNetworkPars saved_net := g_pars.net;
7128 g_pars.net.kc_support := '01'O;
7129 g_pars.net.expect_attach_success := true;
7130 g_pars.net.expect_auth_attempt := false;
7131 g_pars.net.expect_auth := false;
7132 g_pars.net.expect_ciph := false;
7133 f_vty_config3(MSCVTY, {"network"}, {"authentication optional", "encryption a5 0"});
7134 f_perform_lu();
7135
7136 /* Reconfigure like it was before */
7137 g_pars.net := saved_net;
7138 f_vty_config3(MSCVTY, {"network"}, g_pars.net.net_config);
7139 log(MSCVTY, "Running a successful LU done");
7140 }
7141
7142 /* CM Service Request */
7143 log(MSCVTY, "f_establish_fully() starting");
7144 f_establish_fully();
7145 log(MSCVTY, "f_establish_fully() done");
7146 BSSAP.send(ts_BSSMAP_ClearRequest(0));
7147 f_expect_clear();
7148}
7149
7150function f_TC_auth_options(integer tc_i) runs on MTC_CT {
7151 f_init();
7152
7153 var BSC_ConnHdlrNetworkPars tc := auth_options_testcases[tc_i];
7154
7155 f_vty_config3(MSCVTY, {"network"}, tc.net_config);
7156
7157 var BSC_ConnHdlrPars pars := f_init_pars(42300 + tc_i);
7158 pars.net := tc;
7159
7160 var BSC_ConnHdlr vc_conn;
7161 vc_conn := f_start_handler_with_pars(refers(f_tc_auth_options), pars);
7162 vc_conn.done;
7163}
7164
7165testcase TC_auth_options_0() runs on MTC_CT {
7166 f_TC_auth_options(0);
7167}
7168
7169testcase TC_auth_options_1() runs on MTC_CT {
7170 f_TC_auth_options(1);
7171}
7172
7173testcase TC_auth_options_2() runs on MTC_CT {
7174 f_TC_auth_options(2);
7175}
7176
7177testcase TC_auth_options_3() runs on MTC_CT {
7178 f_TC_auth_options(3);
7179}
7180
7181testcase TC_auth_options_4() runs on MTC_CT {
7182 f_TC_auth_options(4);
7183}
7184
7185testcase TC_auth_options_5() runs on MTC_CT {
7186 f_TC_auth_options(5);
7187}
7188
7189testcase TC_auth_options_6() runs on MTC_CT {
7190 f_TC_auth_options(6);
7191}
7192
7193testcase TC_auth_options_7() runs on MTC_CT {
7194 f_TC_auth_options(7);
7195}
7196
7197testcase TC_auth_options_8() runs on MTC_CT {
7198 f_TC_auth_options(8);
7199}
7200
7201testcase TC_auth_options_9() runs on MTC_CT {
7202 f_TC_auth_options(9);
7203}
7204
7205testcase TC_auth_options_10() runs on MTC_CT {
7206 f_TC_auth_options(10);
7207}
7208
7209testcase TC_auth_options_11() runs on MTC_CT {
7210 f_TC_auth_options(11);
7211}
7212
Oliver Smithc4a0c3c2023-08-23 15:40:12 +02007213private function f_set_cpars_csd(inout CallParameters cpars, charstring bs_name, BIT1 async,
7214 GSM48_bcap_transp transp, GSM48_bcap_user_rate user_rate) {
Oliver Smith9c417f22023-07-07 13:25:11 +02007215 log("-----------------------------------------------");
Oliver Smithc4a0c3c2023-08-23 15:40:12 +02007216 log("CSD Bearer Service: " & bs_name);
Oliver Smith9c417f22023-07-07 13:25:11 +02007217 log("-----------------------------------------------");
Oliver Smith9c417f22023-07-07 13:25:11 +02007218
Oliver Smith92b280c2023-04-20 13:13:23 +02007219 cpars.csd := true;
Oliver Smithc4a0c3c2023-08-23 15:40:12 +02007220
Oliver Smith9c417f22023-07-07 13:25:11 +02007221 cpars.bearer_cap := valueof(ts_Bcap_csd);
7222 cpars.bearer_cap.octet6.synchronous_asynchronous := async;
7223 cpars.bearer_cap.octet6.connectionElement := int2bit(enum2int(transp), 2);
7224 cpars.bearer_cap.octet6.userRate := int2bit(enum2int(user_rate), 4);
7225
Oliver Smithc4a0c3c2023-08-23 15:40:12 +02007226 cpars.mncc_bearer_cap := valueof(ts_MNCC_bcap_data);
7227 cpars.mncc_bearer_cap.data.async := bit2int(async);
7228 cpars.mncc_bearer_cap.data.transp := transp;
7229 cpars.mncc_bearer_cap.data.user_rate := user_rate;
7230}
7231
7232friend function f_mo_csd(charstring bs_name, BIT1 async, GSM48_bcap_transp transp, GSM48_bcap_user_rate user_rate)
7233 runs on BSC_ConnHdlr {
7234 var CallParameters cpars := valueof(t_CallParams);
7235
7236 g_Tguard.start(20.0);
7237 f_set_cpars_csd(cpars, bs_name, async, transp, user_rate);
Oliver Smith92b280c2023-04-20 13:13:23 +02007238 f_perform_lu();
Oliver Smith98e24bc2023-07-07 12:36:59 +02007239 f_mo_call(cpars, 0.5);
Oliver Smith92b280c2023-04-20 13:13:23 +02007240}
Oliver Smith9c417f22023-07-07 13:25:11 +02007241
7242friend function f_tc_lu_and_mo_csd(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
7243 f_init_handler(pars);
7244
7245 f_mo_csd("BS21T", '1'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_300);
7246 f_mo_csd("BS22T", '1'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_1200);
7247 f_mo_csd("BS24T", '1'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_2400);
7248 f_mo_csd("BS25T", '1'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_4800);
7249 f_mo_csd("BS26T", '1'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_9600);
7250
7251 f_mo_csd("BS21NT", '1'B, GSM48_BCAP_TR_RLP, GSM48_BCAP_UR_300);
7252 f_mo_csd("BS22NT", '1'B, GSM48_BCAP_TR_RLP, GSM48_BCAP_UR_1200);
7253 f_mo_csd("BS24NT", '1'B, GSM48_BCAP_TR_RLP, GSM48_BCAP_UR_2400);
7254 f_mo_csd("BS25NT", '1'B, GSM48_BCAP_TR_RLP, GSM48_BCAP_UR_4800);
7255 f_mo_csd("BS26NT", '1'B, GSM48_BCAP_TR_RLP, GSM48_BCAP_UR_9600);
7256
7257 f_mo_csd("BS31T", '0'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_1200);
7258 f_mo_csd("BS32T", '0'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_2400);
7259 f_mo_csd("BS33T", '0'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_4800);
7260 f_mo_csd("BS34T", '0'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_9600);
7261}
Oliver Smith92b280c2023-04-20 13:13:23 +02007262testcase TC_lu_and_mo_csd() runs on MTC_CT {
7263 var BSC_ConnHdlr vc_conn;
7264 f_init();
7265
7266 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_csd), 7);
7267 vc_conn.done;
7268}
7269
Oliver Smith8cf75ab2023-06-21 16:19:51 +02007270friend function f_mt_csd(charstring bs_name, BIT1 async, GSM48_bcap_transp transp, GSM48_bcap_user_rate user_rate)
7271 runs on BSC_ConnHdlr {
Oliver Smithc1dd36a2023-05-31 13:52:24 +02007272 var CallParameters cpars := valueof(t_CallParams);
Oliver Smith8cf75ab2023-06-21 16:19:51 +02007273
Oliver Smithc4a0c3c2023-08-23 15:40:12 +02007274 g_Tguard.start(20.0);
7275 f_set_cpars_csd(cpars, bs_name, async, transp, user_rate);
Oliver Smithc1dd36a2023-05-31 13:52:24 +02007276 f_perform_lu();
Oliver Smith98e24bc2023-07-07 12:36:59 +02007277 f_mt_call(cpars, 0.5);
Oliver Smithc1dd36a2023-05-31 13:52:24 +02007278}
Oliver Smith8cf75ab2023-06-21 16:19:51 +02007279friend function f_tc_lu_and_mt_csd(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
7280 f_init_handler(pars);
7281
7282 f_mt_csd("BS21T", '1'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_300);
7283 f_mt_csd("BS22T", '1'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_1200);
7284 f_mt_csd("BS24T", '1'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_2400);
7285 f_mt_csd("BS25T", '1'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_4800);
7286 f_mt_csd("BS26T", '1'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_9600);
7287
7288 f_mt_csd("BS21NT", '1'B, GSM48_BCAP_TR_RLP, GSM48_BCAP_UR_300);
7289 f_mt_csd("BS22NT", '1'B, GSM48_BCAP_TR_RLP, GSM48_BCAP_UR_1200);
7290 f_mt_csd("BS24NT", '1'B, GSM48_BCAP_TR_RLP, GSM48_BCAP_UR_2400);
7291 f_mt_csd("BS25NT", '1'B, GSM48_BCAP_TR_RLP, GSM48_BCAP_UR_4800);
7292 f_mt_csd("BS26NT", '1'B, GSM48_BCAP_TR_RLP, GSM48_BCAP_UR_9600);
7293
7294 f_mt_csd("BS31T", '0'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_1200);
7295 f_mt_csd("BS32T", '0'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_2400);
7296 f_mt_csd("BS33T", '0'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_4800);
7297 f_mt_csd("BS34T", '0'B, GSM48_BCAP_TR_TRANSP, GSM48_BCAP_UR_9600);
7298}
Oliver Smithc1dd36a2023-05-31 13:52:24 +02007299testcase TC_lu_and_mt_csd() runs on MTC_CT {
7300 var BSC_ConnHdlr vc_conn;
7301 f_init();
7302
7303 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_csd), 7);
7304 vc_conn.done;
7305}
7306
Harald Weltef6dd64d2017-11-19 12:09:51 +01007307control {
Philipp Maier328d1662018-03-07 10:40:27 +01007308 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01007309 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01007310 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01007311 execute( TC_lu_imsi_reject() );
7312 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01007313 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02007314 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01007315 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01007316 execute( TC_cmserv_imsi_unknown() );
Neels Hofmeyr13737fb2020-08-19 13:16:14 +00007317 execute( TC_cmserv_tmsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01007318 execute( TC_lu_and_mo_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02007319 execute( TC_lu_and_mo_call_ipv6() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01007320 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01007321 execute( TC_lu_auth_sai_timeout() );
7322 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01007323 execute( TC_lu_clear_request() );
Vadim Yanitskiy109e7552021-02-05 05:36:02 +01007324 execute( TC_mo_call_clear_request() );
7325 execute( TC_mt_call_clear_request() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01007326 execute( TC_lu_disconnect() );
7327 execute( TC_lu_by_imei() );
7328 execute( TC_lu_by_tmsi_noauth_unknown() );
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00007329 execute( TC_attached_imsi_lu_unknown_tmsi() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01007330 execute( TC_imsi_detach_by_imsi() );
7331 execute( TC_imsi_detach_by_tmsi() );
7332 execute( TC_imsi_detach_by_imei() );
7333 execute( TC_emerg_call_imei_reject() );
7334 execute( TC_emerg_call_imsi() );
7335 execute( TC_cm_serv_req_vgcs_reject() );
7336 execute( TC_cm_serv_req_vbs_reject() );
7337 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01007338 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01007339 execute( TC_lu_auth_2G_fail() );
7340 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
7341 execute( TC_cl3_no_payload() );
7342 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01007343 execute( TC_establish_and_nothing() );
7344 execute( TC_mo_setup_and_nothing() );
7345 execute( TC_mo_crcx_ran_timeout() );
7346 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01007347 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01007348 execute( TC_mo_setup_and_dtmf_dup() );
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01007349 execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01007350 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01007351 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
7352 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
7353 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01007354 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01007355 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
7356 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Eric Wild26f4a622021-05-17 15:27:05 +02007357 execute( TC_lu_imsi_auth_tmsi_encr_0134_1() );
7358 execute( TC_lu_imsi_auth_tmsi_encr_0134_34() );
7359 execute( TC_lu_imsi_auth_tmsi_encr_0134_34_no_cm3() );
7360
Philipp Maier94f3f1b2018-03-15 18:54:13 +01007361 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01007362 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02007363 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01007364
7365 execute( TC_lu_and_mt_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02007366 execute( TC_lu_and_mt_call_ipv6() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01007367 execute( TC_lu_and_mt_call_already_paging() );
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +02007368 execute( TC_lu_and_mt_call_osmux() );
Harald Welte33ec09b2018-02-10 15:34:46 +01007369
Harald Weltef45efeb2018-04-09 18:19:24 +02007370 execute( TC_lu_and_mo_sms() );
7371 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01007372 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01007373 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02007374 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02007375 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07007376 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02007377 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02007378
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07007379 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07007380 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07007381 execute( TC_gsup_mt_sms_ack() );
7382 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07007383 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07007384 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07007385 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07007386
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07007387 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07007388 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07007389 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07007390 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07007391 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07007392 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07007393
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07007394 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07007395 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07007396 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07007397 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07007398 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07007399
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01007400 execute( TC_multi_lu_and_mo_ussd() );
7401 execute( TC_multi_lu_and_mt_ussd() );
7402
Stefan Sperling89eb1f32018-12-17 15:06:20 +01007403 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01007404 execute( TC_cipher_complete_1_without_cipher() );
7405 execute( TC_cipher_complete_3_without_cipher() );
7406 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02007407 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01007408
Harald Welte4263c522018-12-06 11:56:27 +01007409 execute( TC_sgsap_reset() );
7410 execute( TC_sgsap_lu() );
7411 execute( TC_sgsap_lu_imsi_reject() );
7412 execute( TC_sgsap_lu_and_nothing() );
7413 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01007414 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01007415 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01007416 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01007417 execute( TC_sgsap_paging_rej() );
7418 execute( TC_sgsap_paging_subscr_rej() );
7419 execute( TC_sgsap_paging_ue_unr() );
7420 execute( TC_sgsap_paging_and_nothing() );
7421 execute( TC_sgsap_paging_and_lu() );
7422 execute( TC_sgsap_mt_sms() );
7423 execute( TC_sgsap_mo_sms() );
7424 execute( TC_sgsap_mt_sms_and_nothing() );
7425 execute( TC_sgsap_mt_sms_and_reject() );
7426 execute( TC_sgsap_unexp_ud() );
7427 execute( TC_sgsap_unsol_ud() );
7428 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
7429 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02007430 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01007431
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02007432 execute( TC_ho_inter_bsc_unknown_cell() );
7433 execute( TC_ho_inter_bsc() );
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02007434 execute( TC_ho_inter_bsc_a5_1() );
7435 execute( TC_ho_inter_bsc_a5_3() );
7436 execute( TC_ho_inter_bsc_a5_4() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02007437 execute( TC_ho_inter_bsc_ipv6() );
Oliver Smith44424db2023-08-22 13:54:09 +02007438 execute( TC_ho_inter_bsc_csd() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02007439
7440 execute( TC_ho_inter_msc_out() );
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02007441 execute( TC_ho_inter_msc_out_a5_1() );
7442 execute( TC_ho_inter_msc_out_a5_3() );
7443 execute( TC_ho_inter_msc_out_a5_4() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02007444 execute( TC_ho_inter_msc_out_ipv6() );
Oliver Smithcaa36c92023-08-23 15:30:33 +02007445 execute( TC_ho_inter_msc_out_csd() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02007446
Oliver Smith1d118ff2019-07-03 10:57:35 +02007447 execute( TC_lu_imsi_auth_tmsi_check_imei() );
7448 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
7449 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
7450 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
7451 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
7452 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
7453 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
7454 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
7455 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
7456 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
7457 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
7458 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01007459 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Pau Espin Pedrol609f1d62020-09-15 16:01:55 +02007460
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02007461 execute( TC_mo_cc_bssmap_clear() );
Neels Hofmeyr8df69622019-11-02 19:16:03 +01007462 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01007463 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07007464 execute( TC_lu_and_expire_while_paging() );
Pau Espin Pedrol174fac22021-02-26 13:20:10 +01007465 execute( TC_paging_response_imsi_unknown() );
7466 execute( TC_paging_response_tmsi_unknown() );
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02007467
7468 execute( TC_call_re_establishment() );
Neels Hofmeyra9b2dcf2021-07-28 00:57:58 +02007469 execute( TC_call_re_establishment_auth() );
Neels Hofmeyr48e4d7d2021-07-28 00:57:58 +02007470 execute( TC_call_re_establishment_ciph() );
Neels Hofmeyr07ea7f22022-05-05 01:39:26 +02007471
7472 execute( TC_cm_serv_wrong_mi() );
Neels Hofmeyre860fc42022-10-05 01:15:54 +02007473
7474 execute( TC_auth_options_0() );
7475 execute( TC_auth_options_1() );
7476 execute( TC_auth_options_2() );
7477 execute( TC_auth_options_3() );
7478 execute( TC_auth_options_4() );
7479 execute( TC_auth_options_5() );
7480 execute( TC_auth_options_6() );
7481 execute( TC_auth_options_7() );
7482 execute( TC_auth_options_8() );
7483 execute( TC_auth_options_9() );
7484 execute( TC_auth_options_10() );
7485 execute( TC_auth_options_11() );
Oliver Smith92b280c2023-04-20 13:13:23 +02007486
7487 execute( TC_lu_and_mo_csd() );
Oliver Smithc1dd36a2023-05-31 13:52:24 +02007488 execute( TC_lu_and_mt_csd() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01007489}
7490
7491
7492}