blob: 6bad9c35346fd695a9f10d5f12829586fb463350 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
19
20import from M3UA_Types all;
21import from M3UA_Emulation all;
22
23import from MTP3asp_Types all;
24import from MTP3asp_PortType all;
25
26import from SCCPasp_Types all;
27import from SCCP_Types all;
28import from SCCP_Emulation all;
29
30import from SCTPasp_Types all;
31import from SCTPasp_PortType all;
32
Harald Weltea49e36e2018-01-21 19:29:33 +010033import from Osmocom_CTRL_Functions all;
34import from Osmocom_CTRL_Types all;
35import from Osmocom_CTRL_Adapter all;
36
Harald Welte3ca1c902018-01-24 18:51:27 +010037import from TELNETasp_PortType all;
38import from Osmocom_VTY_Functions all;
39
Harald Weltea49e36e2018-01-21 19:29:33 +010040import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010041import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010042
Harald Welte4aa970c2018-01-26 10:38:09 +010043import from MGCP_Emulation all;
44import from MGCP_Types all;
45import from MGCP_Templates all;
46import from SDP_Types all;
47
Harald Weltea49e36e2018-01-21 19:29:33 +010048import from GSUP_Emulation all;
49import from GSUP_Types all;
50import from IPA_Emulation all;
51
Harald Weltef6dd64d2017-11-19 12:09:51 +010052import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020053import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010054import from BSSAP_CodecPort all;
55import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020056import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010057import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020058import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010059
Harald Welte4263c522018-12-06 11:56:27 +010060import from SGsAP_Templates all;
61import from SGsAP_Types all;
62import from SGsAP_Emulation all;
63
Harald Weltea49e36e2018-01-21 19:29:33 +010064import from MobileL3_Types all;
65import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070066import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010067import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010068import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010069
Harald Weltef640a012018-04-14 17:49:21 +020070import from SMPP_Types all;
71import from SMPP_Templates all;
72import from SMPP_Emulation all;
73
Stefan Sperlingc307e682018-06-14 15:15:46 +020074import from SCCP_Templates all;
75
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070076import from SS_Types all;
77import from SS_Templates all;
78import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010079import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070080
Philipp Maier948747b2019-04-02 15:22:33 +020081import from TCCConversion_Functions all;
82
Harald Welte9b751a62019-04-14 17:39:29 +020083const integer NUM_BSC := 3;
Harald Weltef6dd64d2017-11-19 12:09:51 +010084
Harald Welte4263c522018-12-06 11:56:27 +010085/* Needed for SGsAP SMS */
86import from MobileL3_SMS_Types all;
87
Harald Weltea4ca4462018-02-09 00:17:14 +010088type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010089 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010090
Harald Welte6811d102019-04-14 22:23:14 +020091 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010092
Harald Weltea49e36e2018-01-21 19:29:33 +010093 /* no 'adapter_CT' for MNCC or GSUP */
94 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010095 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010096 var GSUP_Emulation_CT vc_GSUP;
97 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020098 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +010099 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100100
101 /* only to get events from IPA underneath GSUP */
102 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100103 /* VTY to MSC */
104 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100105
106 /* A port to directly send BSSAP messages. This port is used for
107 * tests that require low level access to sen arbitrary BSSAP
108 * messages. Run f_init_bssap_direct() to connect and initialize */
109 port BSSAP_CODEC_PT BSSAP_DIRECT;
110
111 /* When BSSAP messages are directly sent, then the connection
112 * handler is not active, which means that also no guard timer is
113 * set up. The following timer will serve as a replacement */
114 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100115
116 /* Configure T(tias) over VTY, seconds */
117 var integer g_msc_sccp_timer_ias := 7 * 60;
118 /* Configure T(tiar) over VTY, seconds */
119 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100120}
121
122modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100123 /* remote parameters of IUT */
124 charstring mp_msc_ip := "127.0.0.1";
125 integer mp_msc_ctrl_port := 4255;
126 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100127
Harald Weltea49e36e2018-01-21 19:29:33 +0100128 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100129 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100130 charstring mp_hlr_ip := "127.0.0.1";
131 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100132 charstring mp_mgw_ip := "127.0.0.1";
133 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100134
Harald Weltea49e36e2018-01-21 19:29:33 +0100135 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100136
Harald Weltef640a012018-04-14 17:49:21 +0200137 integer mp_msc_smpp_port := 2775;
138 charstring mp_smpp_system_id := "msc_tester";
139 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100140 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
141 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200142
Harald Welte6811d102019-04-14 22:23:14 +0200143 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200144 {
145 sccp_service_type := "mtp3_itu",
146 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
147 own_pc := 185,
148 own_ssn := 254,
149 peer_pc := 187,
150 peer_ssn := 254,
151 sio := '83'O,
152 rctx := 0
153 },
154 {
155 sccp_service_type := "mtp3_itu",
156 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
157 own_pc := 186,
158 own_ssn := 254,
159 peer_pc := 187,
160 peer_ssn := 254,
161 sio := '83'O,
162 rctx := 1
163 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100164 };
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200165
166 boolean mp_enable_cell_id_test := true;
Pau Espin Pedrol609f1d62020-09-15 16:01:55 +0200167
168 boolean mp_enable_crashing_tests := true;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100169}
170
Philipp Maier328d1662018-03-07 10:40:27 +0100171/* altstep for the global guard timer (only used when BSSAP_DIRECT
172 * is used for communication */
173private altstep as_Tguard_direct() runs on MTC_CT {
174 [] Tguard_direct.timeout {
175 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200176 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100177 }
178}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100179
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100180private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
181 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
182 if (respond) {
183 var BIT1 tid_remote := '1'B;
184 if (cpars.mo_call) {
185 tid_remote := '0'B;
186 }
187 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
188 }
189 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100190}
191
Harald Weltef640a012018-04-14 17:49:21 +0200192function f_init_smpp(charstring id) runs on MTC_CT {
193 id := id & "-SMPP";
194 var EsmePars pars := {
195 mode := MODE_TRANSCEIVER,
196 bind := {
197 system_id := mp_smpp_system_id,
198 password := mp_smpp_password,
199 system_type := "MSC_Tests",
200 interface_version := hex2int('34'H),
201 addr_ton := unknown,
202 addr_npi := unknown,
203 address_range := ""
204 },
205 esme_role := true
206 }
207
208 vc_SMPP := SMPP_Emulation_CT.create(id);
209 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
Harald Welte4698a4c2020-08-18 22:57:52 +0200210 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", 0));
Harald Weltef640a012018-04-14 17:49:21 +0200211}
212
213
Harald Weltea49e36e2018-01-21 19:29:33 +0100214function f_init_mncc(charstring id) runs on MTC_CT {
215 id := id & "-MNCC";
216 var MnccOps ops := {
217 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
218 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
219 }
220
221 vc_MNCC := MNCC_Emulation_CT.create(id);
222 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
223 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100224}
225
Harald Welte4aa970c2018-01-26 10:38:09 +0100226function f_init_mgcp(charstring id) runs on MTC_CT {
227 id := id & "-MGCP";
228 var MGCPOps ops := {
229 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
230 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
231 }
232 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100233 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100234 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100235 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200236 mgw_udp_port := mp_mgw_port,
237 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100238 }
239
240 vc_MGCP := MGCP_Emulation_CT.create(id);
241 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
242 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
243}
244
Philipp Maierc09a1312019-04-09 16:05:26 +0200245function ForwardUnitdataCallback(PDU_SGsAP msg)
246runs on SGsAP_Emulation_CT return template PDU_SGsAP {
247 SGsAP_CLIENT.send(msg);
248 return omit;
249}
250
Harald Welte4263c522018-12-06 11:56:27 +0100251function f_init_sgsap(charstring id) runs on MTC_CT {
252 id := id & "-SGsAP";
253 var SGsAPOps ops := {
254 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200255 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100256 }
257 var SGsAP_conn_parameters pars := {
258 remote_ip := mp_msc_ip,
259 remote_sctp_port := 29118,
260 local_ip := "",
261 local_sctp_port := -1
262 }
263
264 vc_SGsAP := SGsAP_Emulation_CT.create(id);
265 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
266 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
267}
268
269
Harald Weltea49e36e2018-01-21 19:29:33 +0100270function f_init_gsup(charstring id) runs on MTC_CT {
271 id := id & "-GSUP";
272 var GsupOps ops := {
273 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
274 }
275
276 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
277 vc_GSUP := GSUP_Emulation_CT.create(id);
278
279 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
280 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
281 /* we use this hack to get events like ASP_IPA_EVENT_UP */
282 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
283
284 vc_GSUP.start(GSUP_Emulation.main(ops, id));
285 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
286
287 /* wait for incoming connection to GSUP port before proceeding */
288 timer T := 10.0;
289 T.start;
290 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700291 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100292 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100293 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200294 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100295 }
296 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100297}
298
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200299function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100300
301 if (g_initialized == true) {
302 return;
303 }
304 g_initialized := true;
305
Philipp Maier75932982018-03-27 14:52:35 +0200306 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200307 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200308 }
309
310 for (var integer i := 0; i < num_bsc; i := i + 1) {
311 if (isbound(mp_bssap_cfg[i])) {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200312 var RanOps ranops := BSC_RanOps;
313 ranops.use_osmux := osmux;
314 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
Harald Welte3ca0ce12019-04-23 17:18:48 +0200315 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200316 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200317 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200318 }
319 }
320
Pau Espin Pedrol9a5b8ff2021-01-04 19:01:31 +0100321 f_ipa_ctrl_start_client(mp_msc_ip, mp_msc_ctrl_port);
Harald Weltea49e36e2018-01-21 19:29:33 +0100322 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100323 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200324
325 if (gsup == true) {
326 f_init_gsup("MSC_Test");
327 }
Harald Weltef640a012018-04-14 17:49:21 +0200328 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100329
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100330 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100331 f_init_sgsap("MSC_Test");
332 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100333
334 map(self:MSCVTY, system:MSCVTY);
335 f_vty_set_prompts(MSCVTY);
336 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100337
338 /* set some defaults */
339 f_vty_config(MSCVTY, "network", "authentication optional");
340 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200341 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100342 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100343 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
344 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +0200345 if (osmux) {
346 f_vty_config(MSCVTY, "msc", "osmux on");
347 } else {
348 f_vty_config(MSCVTY, "msc", "osmux off");
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200349 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100350}
351
Philipp Maier328d1662018-03-07 10:40:27 +0100352/* Initialize for a direct connection to BSSAP. This function is an alternative
353 * to f_init() when the high level functions of the BSC_ConnectionHandler are
354 * not needed. */
355function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200356 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200357 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100358
359 /* Start guard timer and activate it as default */
360 Tguard_direct.start
361 activate(as_Tguard_direct());
362}
363
Harald Weltea49e36e2018-01-21 19:29:33 +0100364type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100365
Harald Weltea49e36e2018-01-21 19:29:33 +0100366/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200367function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200368 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O,
369 boolean verify_cell_id := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200370runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100371 var BSC_ConnHdlrNetworkPars net_pars := {
372 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
373 expect_tmsi := true,
374 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200375 expect_ciph := false,
376 expect_imei := false,
377 expect_imei_early := false,
378 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
379 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100380 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100381 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200382 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
383 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100384 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100385 imei := f_gen_imei(imsi_suffix),
386 imsi := f_gen_imsi(imsi_suffix),
387 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100388 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100389 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100390 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100391 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100392 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100393 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100394 send_early_cm := true,
395 ipa_ctrl_ip := mp_msc_ip,
396 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100397 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100398 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200399 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200400 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100401 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200402 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200403 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200404 ran_is_geran := ran_is_geran,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200405 use_osmux := use_osmux,
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200406 use_ipv6 := false,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200407 verify_cell_id := mp_enable_cell_id_test and verify_cell_id
Harald Weltea49e36e2018-01-21 19:29:33 +0100408 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200409 if (not ran_is_geran) {
410 pars.use_umts_aka := true;
411 pars.net.expect_auth := true;
412 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100413 return pars;
414}
415
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200416function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars, integer bssap_idx := 0) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100417 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200418 var charstring id := testcasename() & int2str(bssap_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100419
420 vc_conn := BSC_ConnHdlr.create(id);
421 /* BSSMAP part / A interface */
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200422 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:CLIENT);
423 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100424 /* MNCC part */
425 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
426 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100427 /* MGCP part */
428 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
429 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100430 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200431 if (pars.gsup_enable == true) {
432 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
433 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
434 }
Harald Weltef640a012018-04-14 17:49:21 +0200435 /* SMPP part */
436 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
437 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100438 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100439 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100440 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
441 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
442 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100443
Harald Weltea10db902018-01-27 12:44:49 +0100444 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
445 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100446 vc_conn.start(derefers(fn)(id, pars));
447 return vc_conn;
448}
449
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200450function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false,
451 boolean verify_cell_id := true)
Harald Welte9b751a62019-04-14 17:39:29 +0200452runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200453 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux, verify_cell_id := verify_cell_id));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100454}
455
Harald Weltea49e36e2018-01-21 19:29:33 +0100456private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100457 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100458 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100459}
Harald Weltea49e36e2018-01-21 19:29:33 +0100460testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
461 var BSC_ConnHdlr vc_conn;
462 f_init();
463
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100464 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100465 vc_conn.done;
466}
467
468private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100469 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100470 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100471 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100472}
Harald Weltea49e36e2018-01-21 19:29:33 +0100473testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
474 var BSC_ConnHdlr vc_conn;
475 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100476 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100477
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100478 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100479 vc_conn.done;
480}
481
482/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200483friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100484 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100485 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
486
487 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200488 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100489 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100490 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
491 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
492 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100493 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
494 f_expect_clear();
495 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100496 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
497 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200498 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100499 }
500 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100501}
502testcase TC_lu_imsi_reject() runs on MTC_CT {
503 var BSC_ConnHdlr vc_conn;
504 f_init();
505
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200506 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100507 vc_conn.done;
508}
509
Harald Weltee13cfb22019-04-23 16:52:02 +0200510
511
Harald Weltea49e36e2018-01-21 19:29:33 +0100512/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200513friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100514 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100515 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
516
517 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200518 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100519 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100520 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
521 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
522 alt {
523 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100524 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
525 f_expect_clear();
526 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100527 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
528 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200529 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100530 }
531 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100532}
533testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
534 var BSC_ConnHdlr vc_conn;
535 f_init();
536
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200537 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100538 vc_conn.done;
539}
540
Harald Weltee13cfb22019-04-23 16:52:02 +0200541
Harald Welte7b1b2812018-01-22 21:23:06 +0100542private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100543 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100544 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100545 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100546}
547testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
548 var BSC_ConnHdlr vc_conn;
549 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100550 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100551
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100552 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100553 vc_conn.done;
554}
555
Harald Weltee13cfb22019-04-23 16:52:02 +0200556
557friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200558 pars.net.expect_auth := true;
559 pars.use_umts_aka := true;
560 f_init_handler(pars);
561 f_perform_lu();
562}
563testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
564 var BSC_ConnHdlr vc_conn;
565 f_init();
566 f_vty_config(MSCVTY, "network", "authentication required");
567
568 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
569 vc_conn.done;
570}
Harald Weltea49e36e2018-01-21 19:29:33 +0100571
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100572/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
573 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
574 */
575friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
576
577 f_init_handler(pars);
578
579 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
580 var PDU_DTAP_MT dtap_mt;
581
582 /* tell GSUP dispatcher to send this IMSI to us */
583 f_create_gsup_expect(hex2str(g_pars.imsi));
584
585 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
586 if (g_pars.ran_is_geran) {
587 f_bssap_compl_l3(l3_lu);
588 if (g_pars.send_early_cm) {
589 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
590 }
591 } else {
592 f_ranap_initial_ue(l3_lu);
593 }
594
595 f_mm_imei_early();
596 f_mm_common();
597 f_msc_lu_hlr();
598 f_mm_imei();
599
600 alt {
601 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
602 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
603 setverdict(fail, "Expected LU ACK, but received LU REJ");
604 mtc.stop;
605 }
606 }
607
608 /* currently (due to bug OS#4337), an extra LU reject is received before
609 terminating the connection. Enabling following line makes the test
610 pass: */
611 //f_expect_lu_reject('16'O); /* Cause: congestion */
612
613 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
614 extra time to avoid race conditons... */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200615 f_expect_clear(7.0, verify_vlr_cell_id := false);
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100616
617 setverdict(pass);
618}
619testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
620 var BSC_ConnHdlr vc_conn;
621 f_init();
622
623 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
624 vc_conn.done;
625}
626
Harald Weltee13cfb22019-04-23 16:52:02 +0200627
Harald Weltea49e36e2018-01-21 19:29:33 +0100628/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200629friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100630runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100631 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100632
633 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100634 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100635 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100636
637 f_create_gsup_expect(hex2str(g_pars.imsi));
638
639 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200640 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200641 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100642
643 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100644 T.start;
645 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100646 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
647 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200648 [] BSSAP.receive {
649 setverdict(fail, "Received unexpected BSSAP");
650 mtc.stop;
651 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100652 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
653 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200654 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100655 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200656 [] T.timeout {
Neels Hofmeyrf1c3c212020-08-19 13:15:32 +0000657 setverdict(fail, "Timeout waiting for CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200658 mtc.stop;
659 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100660 }
661
Harald Welte1ddc7162018-01-27 14:25:46 +0100662 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100663}
Harald Weltea49e36e2018-01-21 19:29:33 +0100664testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
665 var BSC_ConnHdlr vc_conn;
666 f_init();
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200667 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100668 vc_conn.done;
669}
670
Harald Weltee13cfb22019-04-23 16:52:02 +0200671
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000672/* Send CM SERVICE REQ for TMSI that has never performed LU before */
673friend function f_tc_cmserv_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
674runs on BSC_ConnHdlr {
675 f_init_handler(pars);
676
677 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('57111111'O));
678 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
679 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
680
681 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
682 f_cl3_or_initial_ue(l3_info);
683 f_mm_auth();
684
685 timer T := 10.0;
686 T.start;
687 alt {
688 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
689 [] BSSAP.receive {
690 setverdict(fail, "Received unexpected BSSAP");
691 mtc.stop;
692 }
693 [] T.timeout {
694 setverdict(fail, "Timeout waiting for CM SERV REJ");
695 mtc.stop;
696 }
697 }
698
699 f_expect_clear();
700}
701testcase TC_cmserv_tmsi_unknown() runs on MTC_CT {
702 var BSC_ConnHdlr vc_conn;
703 f_init();
704 vc_conn := f_start_handler(refers(f_tc_cmserv_tmsi_unknown), 57, verify_cell_id := false);
705 vc_conn.done;
706}
707
Neels Hofmeyr14d0b132020-08-19 13:49:05 +0000708/* Send Paging Response for IMSI that has never performed LU before */
709friend function f_tc_paging_response_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
710runs on BSC_ConnHdlr {
711 f_init_handler(pars);
712
713 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
714 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
715 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
716
717 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
718 f_cl3_or_initial_ue(l3_info);
719
720 /* The Paging Response gets rejected by a direct Clear Command */
721 f_expect_clear();
722}
723testcase TC_paging_response_imsi_unknown() runs on MTC_CT {
724 var BSC_ConnHdlr vc_conn;
725 f_init();
726 vc_conn := f_start_handler(refers(f_tc_paging_response_imsi_unknown), 58, verify_cell_id := false);
727 vc_conn.done;
728}
729
730/* Send Paging Response for TMSI that has never performed LU before */
731friend function f_tc_paging_response_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
732runs on BSC_ConnHdlr {
733 f_init_handler(pars);
734
735 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('59111111'O));
736 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
737 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
738
739 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
740 f_cl3_or_initial_ue(l3_info);
741
742 /* The Paging Response gets rejected by a direct Clear Command */
743 f_expect_clear();
744}
745testcase TC_paging_response_tmsi_unknown() runs on MTC_CT {
746 var BSC_ConnHdlr vc_conn;
747 f_init();
748 vc_conn := f_start_handler(refers(f_tc_paging_response_tmsi_unknown), 59, verify_cell_id := false);
749 vc_conn.done;
750}
751
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000752
Harald Weltee13cfb22019-04-23 16:52:02 +0200753friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100754 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200755 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100756 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100757 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100758}
759testcase TC_lu_and_mo_call() runs on MTC_CT {
760 var BSC_ConnHdlr vc_conn;
761 f_init();
762
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100763 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100764 vc_conn.done;
765}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200766friend function f_tc_lu_and_mo_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
767 f_init_handler(pars);
768 var CallParameters cpars := valueof(t_CallParams);
769 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
770 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
771 cpars.bss_rtp_ip := "::3";
772 f_perform_lu();
773 f_mo_call(cpars);
774}
775testcase TC_lu_and_mo_call_ipv6() runs on MTC_CT {
776 var BSC_ConnHdlr vc_conn;
777 f_init();
778
779 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call_ipv6), 7);
780 vc_conn.done;
781}
Harald Welte071ed732018-01-23 19:53:52 +0100782
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100783/* Verify T(iar) triggers and releases the channel */
784friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
785 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
786 f_init_handler(pars);
787 var CallParameters cpars := valueof(t_CallParams);
788 f_perform_lu();
789 f_mo_call_establish(cpars);
790
791 /* Expect the channel cleared upon T(iar) triggered: */
792 T_wait_iar.start;
793 alt {
794 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
795 T_wait_iar.stop
796 setverdict(pass);
797 }
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100798 [] T_wait_iar.timeout {
799 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
800 mtc.stop;
801 }
802 }
Harald Welte4a3fa712020-08-19 08:57:33 +0200803 /* DLCX for both directions; if we don't do this, we might receive either of the two during
804 * shutdown causing race conditions */
805 MGCP.receive(tr_DLCX(?));
806 MGCP.receive(tr_DLCX(?));
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100807
808 setverdict(pass);
809}
810testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
811 var BSC_ConnHdlr vc_conn;
812
813 /* Set T(iar) in MSC low enough that it will trigger before other side
814 has time to keep alive with a T(ias). Keep recommended ratio of
815 T(iar) >= T(ias)*2 */
816 g_msc_sccp_timer_ias := 2;
817 g_msc_sccp_timer_iar := 5;
818
819 f_init();
820
821 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
822 vc_conn.done;
823}
824
Harald Weltee13cfb22019-04-23 16:52:02 +0200825
Harald Welte071ed732018-01-23 19:53:52 +0100826/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200827friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100828 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100829
830 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
831 var PDU_DTAP_MT dtap_mt;
832
833 /* tell GSUP dispatcher to send this IMSI to us */
834 f_create_gsup_expect(hex2str(g_pars.imsi));
835
836 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200837 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100838
839 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200840 if (pars.ran_is_geran) {
841 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
842 }
Harald Welte071ed732018-01-23 19:53:52 +0100843
844 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
845 /* The HLR would normally return an auth vector here, but we fail to do so. */
846
847 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100848 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100849}
850testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
851 var BSC_ConnHdlr vc_conn;
852 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100853 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100854
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200855 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8, verify_cell_id := false);
Harald Welte071ed732018-01-23 19:53:52 +0100856 vc_conn.done;
857}
858
Harald Weltee13cfb22019-04-23 16:52:02 +0200859
Harald Welte071ed732018-01-23 19:53:52 +0100860/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200861friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100862 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100863
864 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
865 var PDU_DTAP_MT dtap_mt;
866
867 /* tell GSUP dispatcher to send this IMSI to us */
868 f_create_gsup_expect(hex2str(g_pars.imsi));
869
870 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200871 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100872
873 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200874 if (pars.ran_is_geran) {
875 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
876 }
Harald Welte071ed732018-01-23 19:53:52 +0100877
878 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
879 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
880
881 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100882 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100883}
884testcase TC_lu_auth_sai_err() runs on MTC_CT {
885 var BSC_ConnHdlr vc_conn;
886 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100887 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100888
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200889 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9, verify_cell_id := false);
Harald Welte2bb825f2018-01-22 11:31:18 +0100890 vc_conn.done;
891}
Harald Weltea49e36e2018-01-21 19:29:33 +0100892
Harald Weltee13cfb22019-04-23 16:52:02 +0200893
Harald Weltebc881782018-01-23 20:09:15 +0100894/* Test LU but BSC will send a clear request in the middle */
895private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100896 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100897
898 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
899 var PDU_DTAP_MT dtap_mt;
900
901 /* tell GSUP dispatcher to send this IMSI to us */
902 f_create_gsup_expect(hex2str(g_pars.imsi));
903
904 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200905 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +0200906 f_expect_common_id();
Harald Weltebc881782018-01-23 20:09:15 +0100907
908 /* Send Early Classmark, just for the fun of it */
909 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
910
911 f_sleep(1.0);
912 /* send clear request in the middle of the LU */
913 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200914 alt {
915 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
916 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
917 }
Harald Weltebc881782018-01-23 20:09:15 +0100918 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100919 alt {
920 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200921 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
922 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200923 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200924 repeat;
925 }
Harald Welte6811d102019-04-14 22:23:14 +0200926 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100927 }
Harald Weltebc881782018-01-23 20:09:15 +0100928 setverdict(pass);
929}
930testcase TC_lu_clear_request() runs on MTC_CT {
931 var BSC_ConnHdlr vc_conn;
932 f_init();
933
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100934 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100935 vc_conn.done;
936}
937
Vadim Yanitskiy109e7552021-02-05 05:36:02 +0100938/* Test reaction on Clear Request during a MO Call */
939friend function f_TC_mo_mt_call_clear_request(charstring id, BSC_ConnHdlrPars pars)
940runs on BSC_ConnHdlr {
941 var CallParameters cpars := valueof(t_CallParams);
942 var MNCC_PDU mncc_pdu;
943 timer T := 2.0;
944
945 f_init_handler(pars);
946
947 f_perform_lu();
948
949 /* HACK: reducing code duplication ('66'H - MO, '68'H - MT) */
950 if (pars.imsi == '262420002532766'H)
951 { f_mo_call_establish(cpars); }
952 else
953 { f_mt_call_establish(cpars); }
954
955 /* Hold the line for a while... */
956 f_sleep(2.0);
957
958 /* BSC sends BSSMAP Clear Request (e.g. due to RR failure) */
959 BSSAP.send(ts_BSSMAP_ClearRequest(1));
960
961 /* Expect (optional) CC RELEASE and Clear Command */
962 var default ccrel := activate(as_optional_cc_rel(cpars));
963 f_expect_clear();
964 deactivate(ccrel);
965
966 /* Expect RELease indication on the MNCC socket */
967 T.start;
968 alt {
969 [] MNCC.receive(tr_MNCC_REL_ind(cpars.mncc_callref)) -> value mncc_pdu {
970 log("Rx MNCC REL.ind, cause := ", mncc_pdu.u.signal.cause);
971 setverdict(pass);
972 }
973 [] MNCC.receive(MNCC_PDU:?) -> value mncc_pdu {
974 setverdict(fail, "Rx unexpected MNCC PDU: ", mncc_pdu);
975 }
976 [] T.timeout {
977 setverdict(fail, "Timeout waiting for MNCC REL.ind");
978 }
979 }
980}
981testcase TC_mo_call_clear_request() runs on MTC_CT {
982 var BSC_ConnHdlr vc_conn;
983
984 f_init();
985
986 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532766); // '66'H - MO
987 vc_conn.done;
988}
989testcase TC_mt_call_clear_request() runs on MTC_CT {
990 var BSC_ConnHdlr vc_conn;
991
992 f_init();
993
994 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532768); // '68'H - MT
995 vc_conn.done;
996}
997
Harald Welte66af9e62018-01-24 17:28:21 +0100998/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200999friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001000 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +01001001
1002 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1003 var PDU_DTAP_MT dtap_mt;
1004
1005 /* tell GSUP dispatcher to send this IMSI to us */
1006 f_create_gsup_expect(hex2str(g_pars.imsi));
1007
1008 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001009 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +01001010
1011 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001012 if (pars.ran_is_geran) {
1013 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1014 }
Harald Welte66af9e62018-01-24 17:28:21 +01001015
1016 f_sleep(1.0);
1017 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +02001018 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +01001019 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +01001020 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +01001021}
1022testcase TC_lu_disconnect() runs on MTC_CT {
1023 var BSC_ConnHdlr vc_conn;
1024 f_init();
1025
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001026 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +01001027 vc_conn.done;
1028}
1029
Harald Welteba7b6d92018-01-23 21:32:34 +01001030/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +02001031friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001032 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001033
Harald Welte256571e2018-01-24 18:47:19 +01001034 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +01001035 var PDU_DTAP_MT dtap_mt;
1036
1037 /* tell GSUP dispatcher to send this IMSI to us */
1038 f_create_gsup_expect(hex2str(g_pars.imsi));
1039
1040 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001041 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001042
1043 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001044 if (pars.ran_is_geran) {
1045 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1046 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001047 /* wait for LU reject, ignore any ID REQ */
1048 alt {
1049 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
1050 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
1051 }
1052 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001053 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001054}
1055testcase TC_lu_by_imei() runs on MTC_CT {
1056 var BSC_ConnHdlr vc_conn;
1057 f_init();
1058
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001059 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12, verify_cell_id := false);
Harald Welteba7b6d92018-01-23 21:32:34 +01001060 vc_conn.done;
1061}
1062
Harald Weltee13cfb22019-04-23 16:52:02 +02001063
Harald Welteba7b6d92018-01-23 21:32:34 +01001064/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
1065private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001066 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
1067 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +01001068 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001069
1070 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
1071 var PDU_DTAP_MT dtap_mt;
1072
1073 /* tell GSUP dispatcher to send this IMSI to us */
1074 f_create_gsup_expect(hex2str(g_pars.imsi));
1075
1076 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001077 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001078
1079 /* Send Early Classmark, just for the fun of it */
1080 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1081
1082 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +02001083 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001084 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +01001085 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
Harald Welte79f1e452020-08-18 22:55:02 +02001086 f_expect_common_id();
Harald Welteba7b6d92018-01-23 21:32:34 +01001087
1088 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1089 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1090 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1091 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1092 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1093
1094 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +01001095 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1096 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1097 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001098 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1099 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001100 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +01001101 }
1102 }
1103
Philipp Maier9b690e42018-12-21 11:50:03 +01001104 /* Wait for MM-Information (if enabled) */
1105 f_expect_mm_info();
1106
Harald Welteba7b6d92018-01-23 21:32:34 +01001107 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001108 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001109}
1110testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
1111 var BSC_ConnHdlr vc_conn;
1112 f_init();
1113
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001114 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +01001115 vc_conn.done;
1116}
1117
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001118/* Test LU by unknown TMSI, while the IMSI is already attached: osmo-msc should switch to the attached vlr_subscr. */
1119private function f_tc_attached_imsi_lu_unknown_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1120 f_init_handler(pars);
1121
1122 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('56111111'O);
1123 var PDU_DTAP_MT dtap_mt;
1124
1125 /* tell GSUP dispatcher to send this IMSI to us */
1126 f_create_gsup_expect(hex2str(g_pars.imsi));
1127
1128 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1129 f_cl3_or_initial_ue(l3_lu);
1130
1131 /* Send Early Classmark, just for the fun of it */
1132 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1133
1134 /* Wait for + respond to ID REQ (IMSI) */
1135 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1136 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1137 f_expect_common_id();
1138
1139 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1140 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1141 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1142 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1143 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1144
1145 alt {
1146 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1147 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1148 }
1149 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1150 setverdict(fail, "Expected LU ACK, but received REJ");
1151 mtc.stop;
1152 }
1153 }
1154
1155 /* Wait for MM-Information (if enabled) */
1156 f_expect_mm_info();
1157
1158 /* wait for normal teardown */
1159 f_expect_clear();
1160
1161 /* Now the same IMSI is still attached in the VLR, and a LU with an unknown TMSI reveals the same IMSI only
1162 * later during ID Response. osmo-msc first creates a new vlr_subscr for the unknown TMSI, and as soon as the
1163 * IMSI becomes known, must notice that this IMSI is still regarded as attached, and must not create evil twins.
1164 */
1165
1166 /* (since the TMSI Reallocation happened, we could do this with exactly the same TMSI as above, but for test
1167 * readability just use a different one.) */
1168 l3_lu := f_build_lu_tmsi('56222222'O);
1169 f_cl3_or_initial_ue(l3_lu);
1170
1171 /* Wait for + respond to ID REQ (IMSI) */
1172 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1173 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1174 f_expect_common_id();
1175
1176 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1177 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1178 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1179 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1180 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1181
1182 alt {
1183 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1184 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1185 }
1186 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1187 setverdict(fail, "Expected LU ACK, but received REJ");
1188 mtc.stop;
1189 }
1190 }
1191
1192 /* Wait for MM-Information (if enabled) */
1193 f_expect_mm_info();
1194
1195 /* wait for normal teardown */
1196 f_expect_clear();
1197}
1198testcase TC_attached_imsi_lu_unknown_tmsi() runs on MTC_CT {
1199 var BSC_ConnHdlr vc_conn;
1200 f_init();
1201
1202 vc_conn := f_start_handler(refers(f_tc_attached_imsi_lu_unknown_tmsi), 56);
1203 vc_conn.done;
1204}
1205
Harald Welte4d15fa72020-08-19 08:58:28 +02001206friend function f_imsi_detach_by_imsi() runs on BSC_ConnHdlr {
Harald Welte45164da2018-01-24 12:51:27 +01001207 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1208
1209 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001210 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001211
1212 /* Send Early Classmark, just for the fun of it? */
Harald Welte4d15fa72020-08-19 08:58:28 +02001213 if (g_pars.ran_is_geran) {
Harald Weltee13cfb22019-04-23 16:52:02 +02001214 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1215 }
Harald Welte45164da2018-01-24 12:51:27 +01001216
1217 /* wait for normal teardown */
Harald Welte4d15fa72020-08-19 08:58:28 +02001218 f_expect_clear(verify_vlr_cell_id := false);
1219}
1220
1221
1222/* Test IMSI DETACH (MI=IMSI) */
1223friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1224 f_init_handler(pars);
1225
1226 f_imsi_detach_by_imsi();
Harald Welte45164da2018-01-24 12:51:27 +01001227}
1228testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
1229 var BSC_ConnHdlr vc_conn;
1230 f_init();
1231
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001232 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001233 vc_conn.done;
1234}
1235
Harald Weltee13cfb22019-04-23 16:52:02 +02001236
Harald Welte45164da2018-01-24 12:51:27 +01001237/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001238friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001239 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001240
1241 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
1242
1243 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001244 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001245
1246 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001247 if (pars.ran_is_geran) {
1248 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1249 }
Harald Welte45164da2018-01-24 12:51:27 +01001250
1251 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001252 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001253}
1254testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1255 var BSC_ConnHdlr vc_conn;
1256 f_init();
1257
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001258 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001259 vc_conn.done;
1260}
1261
Harald Weltee13cfb22019-04-23 16:52:02 +02001262
Harald Welte45164da2018-01-24 12:51:27 +01001263/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001264friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001265 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001266
Harald Welte256571e2018-01-24 18:47:19 +01001267 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001268
1269 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001270 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001271
1272 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001273 if (pars.ran_is_geran) {
1274 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1275 }
Harald Welte45164da2018-01-24 12:51:27 +01001276
1277 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001278 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001279}
1280testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1281 var BSC_ConnHdlr vc_conn;
1282 f_init();
1283
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001284 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001285 vc_conn.done;
1286}
1287
1288
1289/* helper function for an emergency call. caller passes in mobile identity to use */
1290private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001291 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1292 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001293
Harald Welte0bef21e2018-02-10 09:48:23 +01001294 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001295}
1296
1297/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001298friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001299 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001300
Harald Welte256571e2018-01-24 18:47:19 +01001301 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001302 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001303 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001304 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001305 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001306}
1307testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1308 var BSC_ConnHdlr vc_conn;
1309 f_init();
1310
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001311 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001312 vc_conn.done;
1313}
1314
Harald Weltee13cfb22019-04-23 16:52:02 +02001315
Harald Welted5b91402018-01-24 18:48:16 +01001316/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001317friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001318 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001319 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001320 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001321 /* Then issue emergency call identified by IMSI */
1322 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1323}
1324testcase TC_emerg_call_imsi() runs on MTC_CT {
1325 var BSC_ConnHdlr vc_conn;
1326 f_init();
1327
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001328 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001329 vc_conn.done;
1330}
1331
Harald Weltee13cfb22019-04-23 16:52:02 +02001332
Harald Welte45164da2018-01-24 12:51:27 +01001333/* CM Service Request for VGCS -> reject */
1334private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001335 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001336
1337 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001338 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001339
1340 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001341 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001342 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001343 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001344 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001345}
1346testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1347 var BSC_ConnHdlr vc_conn;
1348 f_init();
1349
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001350 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001351 vc_conn.done;
1352}
1353
1354/* CM Service Request for VBS -> reject */
1355private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001356 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001357
1358 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001359 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001360
1361 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001362 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001363 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001364 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001365 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001366}
1367testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1368 var BSC_ConnHdlr vc_conn;
1369 f_init();
1370
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001371 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001372 vc_conn.done;
1373}
1374
1375/* CM Service Request for LCS -> reject */
1376private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001377 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001378
1379 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001380 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001381
1382 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001383 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001384 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001385 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001386 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001387}
1388testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1389 var BSC_ConnHdlr vc_conn;
1390 f_init();
1391
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001392 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001393 vc_conn.done;
1394}
1395
Harald Welte0195ab12018-01-24 21:50:20 +01001396/* CM Re-Establishment Request */
1397private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001398 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001399
1400 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001401 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001402
1403 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1404 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001405 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001406 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001407 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001408}
1409testcase TC_cm_reest_req_reject() runs on MTC_CT {
1410 var BSC_ConnHdlr vc_conn;
1411 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001412
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001413 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001414 vc_conn.done;
1415}
1416
Harald Weltec638f4d2018-01-24 22:00:36 +01001417/* Test LU (with authentication enabled), with wrong response from MS */
1418private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001419 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001420
1421 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1422
1423 /* tell GSUP dispatcher to send this IMSI to us */
1424 f_create_gsup_expect(hex2str(g_pars.imsi));
1425
1426 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001427 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001428
1429 /* Send Early Classmark, just for the fun of it */
1430 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1431
1432 var AuthVector vec := f_gen_auth_vec_2g();
1433 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1434 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1435 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1436
1437 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1438 /* Send back wrong auth response */
1439 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1440
1441 /* Expect GSUP AUTH FAIL REP to HLR */
1442 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1443
1444 /* Expect LU REJECT with Cause == Illegal MS */
1445 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001446 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001447}
1448testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1449 var BSC_ConnHdlr vc_conn;
1450 f_init();
1451 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001452
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001453 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23, verify_cell_id := false);
Harald Weltec638f4d2018-01-24 22:00:36 +01001454 vc_conn.done;
1455}
1456
Harald Weltede371492018-01-27 23:44:41 +01001457/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001458private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001459 pars.net.expect_auth := true;
1460 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001461 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001462 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001463}
1464testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1465 var BSC_ConnHdlr vc_conn;
1466 f_init();
1467 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001468 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1469
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001470 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001471 vc_conn.done;
1472}
1473
Harald Welte1af6ea82018-01-25 18:33:15 +01001474/* Test Complete L3 without payload */
1475private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001476 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001477
1478 /* Send Complete L3 Info with empty L3 frame */
1479 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1480 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1481
Harald Weltef466eb42018-01-27 14:26:54 +01001482 timer T := 5.0;
1483 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001484 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001485 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001486 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001487 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001488 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001489 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001490 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001491 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001492 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001493 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001494 }
1495 setverdict(pass);
1496}
1497testcase TC_cl3_no_payload() runs on MTC_CT {
1498 var BSC_ConnHdlr vc_conn;
1499 f_init();
1500
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001501 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001502 vc_conn.done;
1503}
1504
1505/* Test Complete L3 with random payload */
1506private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001507 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001508
Daniel Willmannaa14a382018-07-26 08:29:45 +02001509 /* length is limited by PDU_BSSAP length field which includes some
1510 * other fields beside l3info payload. So payl can only be 240 bytes
1511 * Since rnd() returns values < 1 multiply with 241
1512 */
1513 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001514 var octetstring payl := f_rnd_octstring(len);
1515
1516 /* Send Complete L3 Info with empty L3 frame */
1517 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1518 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1519
Harald Weltef466eb42018-01-27 14:26:54 +01001520 timer T := 5.0;
1521 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001522 alt {
1523 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001524 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001525 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001526 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001527 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001528 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001529 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001530 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001531 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001532 }
1533 setverdict(pass);
1534}
1535testcase TC_cl3_rnd_payload() runs on MTC_CT {
1536 var BSC_ConnHdlr vc_conn;
1537 f_init();
1538
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001539 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001540 vc_conn.done;
1541}
1542
Harald Welte116e4332018-01-26 22:17:48 +01001543/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001544friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001545 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001546
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001547 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001548
Harald Welteb9e86fa2018-04-09 18:18:31 +02001549 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001550 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001551}
1552testcase TC_establish_and_nothing() runs on MTC_CT {
1553 var BSC_ConnHdlr vc_conn;
1554 f_init();
1555
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001556 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001557 vc_conn.done;
1558}
1559
Harald Weltee13cfb22019-04-23 16:52:02 +02001560
Harald Welte12510c52018-01-26 22:26:24 +01001561/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001562friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001563 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001564
Harald Welte12510c52018-01-26 22:26:24 +01001565 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001566 cpars.mgw_conn_2.resp := 0;
1567 cpars.stop_after_cc_setup := true;
1568
1569 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001570
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001571 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001572
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001573 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001574
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001575 var default ccrel := activate(as_optional_cc_rel(cpars));
1576
Philipp Maier109e6aa2018-10-17 10:53:32 +02001577 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001578
1579 deactivate(ccrel);
1580
1581 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001582}
1583testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1584 var BSC_ConnHdlr vc_conn;
1585 f_init();
1586
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001587 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001588 vc_conn.done;
1589}
1590
Harald Weltee13cfb22019-04-23 16:52:02 +02001591
Harald Welte3ab88002018-01-26 22:37:25 +01001592/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001593friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001594 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001595 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1596 var MNCC_PDU mncc;
1597 var MgcpCommand mgcp_cmd;
1598
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001599 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001600 /* Do not respond to the second CRCX */
1601 cpars.mgw_conn_2.resp := 0;
1602 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001603
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001604 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001605
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001606 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001607
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001608 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001609}
1610testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1611 var BSC_ConnHdlr vc_conn;
1612 f_init();
1613
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001614 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001615 vc_conn.done;
1616}
1617
Harald Weltee13cfb22019-04-23 16:52:02 +02001618
Harald Welte0cc82d92018-01-26 22:52:34 +01001619/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001620friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001621 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001622
Harald Welte0cc82d92018-01-26 22:52:34 +01001623 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001624
1625 /* Respond with error for the first CRCX */
1626 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001627
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001628 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001629 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001630
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001631 var default ccrel := activate(as_optional_cc_rel(cpars));
1632 f_expect_clear(60.0);
1633 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001634}
1635testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1636 var BSC_ConnHdlr vc_conn;
1637 f_init();
1638
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001639 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001640 vc_conn.done;
1641}
1642
Harald Welte3ab88002018-01-26 22:37:25 +01001643
Harald Welte812f7a42018-01-27 00:49:18 +01001644/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1645private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1646 var MNCC_PDU mncc;
1647 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001648
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001649 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001650 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001651
1652 /* Allocate call reference and send SETUP via MNCC to MSC */
1653 cpars.mncc_callref := f_rnd_int(2147483648);
1654 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1655 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1656
1657 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001658 f_expect_paging();
1659
Harald Welte812f7a42018-01-27 00:49:18 +01001660 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001661 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001662
1663 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1664
1665 /* MSC->MS: SETUP */
1666 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1667}
1668
1669/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001670friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001671 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001672 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1673 var MNCC_PDU mncc;
1674 var MgcpCommand mgcp_cmd;
1675
1676 f_mt_call_start(cpars);
1677
1678 /* MS->MSC: CALL CONFIRMED */
1679 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1680
1681 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1682
1683 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1684 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001685
1686 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1687 * set an endpoint name that fits the pattern. If not, just use the
1688 * endpoint name from the request */
1689 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1690 cpars.mgcp_ep := "rtpbridge/1@mgw";
1691 } else {
1692 cpars.mgcp_ep := mgcp_cmd.line.ep;
1693 }
1694
Harald Welte812f7a42018-01-27 00:49:18 +01001695 /* Respond to CRCX with error */
1696 var MgcpResponse mgcp_rsp := {
1697 line := {
1698 code := "542",
1699 trans_id := mgcp_cmd.line.trans_id,
1700 string := "FORCED_FAIL"
1701 },
Harald Welte812f7a42018-01-27 00:49:18 +01001702 sdp := omit
1703 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001704 var MgcpParameter mgcp_rsp_param := {
1705 code := "Z",
1706 val := cpars.mgcp_ep
1707 };
1708 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001709 MGCP.send(mgcp_rsp);
1710
1711 timer T := 30.0;
1712 T.start;
1713 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001714 [] T.timeout {
1715 setverdict(fail, "Timeout waiting for channel release");
1716 mtc.stop;
1717 }
Harald Welte812f7a42018-01-27 00:49:18 +01001718 [] MNCC.receive { repeat; }
1719 [] GSUP.receive { repeat; }
1720 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1721 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1722 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1723 repeat;
1724 }
1725 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001726 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001727 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001728 }
1729}
1730testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1731 var BSC_ConnHdlr vc_conn;
1732 f_init();
1733
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001734 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001735 vc_conn.done;
1736}
1737
1738
Harald Weltee13cfb22019-04-23 16:52:02 +02001739
Harald Welte812f7a42018-01-27 00:49:18 +01001740/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001741friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte812f7a42018-01-27 00:49:18 +01001742 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Harald Welte812f7a42018-01-27 00:49:18 +01001743 var MgcpCommand mgcp_cmd;
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001744 var PDU_BSSAP bssap;
1745 timer T310;
Harald Welte812f7a42018-01-27 00:49:18 +01001746
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001747 f_init_handler(pars);
1748
1749 /* Initiate a MT call, establish connection */
Harald Welte812f7a42018-01-27 00:49:18 +01001750 f_mt_call_start(cpars);
1751
1752 /* MS->MSC: CALL CONFIRMED */
1753 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1754 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1755
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001756 /* NOTE: MSC is expected to start T310 here */
Harald Welte812f7a42018-01-27 00:49:18 +01001757
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001758 /* MSC->MGW: CRCX (first) */
1759 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1760 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
1761
1762 /* BSC->BSC: BSSMAP ASSIGNMENT REQ */
1763 BSSAP.receive(tr_BSSMAP_AssignmentReq(omit, ?)) -> value bssap;
1764 BSSAP.send(ts_BSSMAP_AssignmentComplete(omit,
1765 aoip := f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port),
1766 speechCodec := ts_BSSMAP_IE_SpeechCodec({ ts_CodecFR })));
1767
1768 /* MSC->MGW: MDCX */
1769 MGCP.receive(tr_MDCX) -> value mgcp_cmd;
1770 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_1.mgcp_connection_id,
1771 sdp := omit));
1772
1773 /* MSC->MGW: CRCX (second) */
1774 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1775 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
1776 MNCC.receive(tr_MNCC_RTP_CREATE(cpars.mncc_callref));
1777
1778 /* Reschedule the guard timeout */
1779 g_Tguard.start(30.0 + 10.0);
1780
1781 /* NOTE: the BSC is expected to respond with CC ALERTING at this state, so
1782 * the MSC would stop T310. However, the idea is to verify T310 expiration
1783 * here, so grab some popcorn and wait for MNCC DISC.ind. */
1784 T310.start(30.0 + 2.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001785 alt {
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001786 [] T310.timeout {
1787 setverdict(fail, "Timeout waiting for MNCC DISC.ind due to T310");
Daniel Willmannafce8662018-07-06 23:11:32 +02001788 mtc.stop;
1789 }
Harald Welte812f7a42018-01-27 00:49:18 +01001790 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1791 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001792 log("Rx MNCC DISC.ind, T310.read yelds ", T310.read);
1793 setverdict(pass);
Harald Welte812f7a42018-01-27 00:49:18 +01001794 }
1795 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001796
Harald Welte812f7a42018-01-27 00:49:18 +01001797 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1798 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001799 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, '1'B)));
Harald Welte812f7a42018-01-27 00:49:18 +01001800
1801 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001802 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1803 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001804 // FIXME: f_create_mgcp_delete_ep(cpars.mgcp_ep);
Harald Welte812f7a42018-01-27 00:49:18 +01001805 repeat;
1806 }
Harald Welte5946b332018-03-18 23:32:21 +01001807 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001808 }
1809}
1810testcase TC_mt_t310() runs on MTC_CT {
1811 var BSC_ConnHdlr vc_conn;
1812 f_init();
1813
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001814 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001815 vc_conn.done;
1816}
1817
Harald Weltee13cfb22019-04-23 16:52:02 +02001818
Harald Welte167458a2018-01-27 15:58:16 +01001819/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001820friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001821 f_init_handler(pars);
1822 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001823
1824 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001825 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001826
1827 /* First MO call should succeed */
1828 f_mo_call(cpars);
1829
1830 /* Cancel the subscriber in the VLR */
1831 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1832 alt {
1833 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1834 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1835 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001836 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001837 }
1838 }
1839
1840 /* Follow-up transactions should fail */
1841 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1842 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001843 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001844 alt {
1845 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1846 [] BSSAP.receive {
1847 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001848 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001849 }
1850 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001851
1852 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001853 setverdict(pass);
1854}
1855testcase TC_gsup_cancel() runs on MTC_CT {
1856 var BSC_ConnHdlr vc_conn;
1857 f_init();
1858
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001859 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33, verify_cell_id := false);
Harald Welte167458a2018-01-27 15:58:16 +01001860 vc_conn.done;
1861}
1862
Harald Weltee13cfb22019-04-23 16:52:02 +02001863
Harald Welte9de84792018-01-28 01:06:35 +01001864/* A5/1 only permitted on network side, and MS capable to do it */
1865private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1866 pars.net.expect_auth := true;
1867 pars.net.expect_ciph := true;
1868 pars.net.kc_support := '02'O; /* A5/1 only */
1869 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001870 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001871}
1872testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1873 var BSC_ConnHdlr vc_conn;
1874 f_init();
1875 f_vty_config(MSCVTY, "network", "authentication required");
1876 f_vty_config(MSCVTY, "network", "encryption a5 1");
1877
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001878 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001879 vc_conn.done;
1880}
1881
1882/* A5/3 only permitted on network side, and MS capable to do it */
1883private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1884 pars.net.expect_auth := true;
1885 pars.net.expect_ciph := true;
1886 pars.net.kc_support := '08'O; /* A5/3 only */
1887 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001888 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001889}
1890testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1891 var BSC_ConnHdlr vc_conn;
1892 f_init();
1893 f_vty_config(MSCVTY, "network", "authentication required");
1894 f_vty_config(MSCVTY, "network", "encryption a5 3");
1895
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001896 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001897 vc_conn.done;
1898}
1899
1900/* A5/3 only permitted on network side, and MS with only A5/1 support */
1901private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1902 pars.net.expect_auth := true;
1903 pars.net.expect_ciph := true;
1904 pars.net.kc_support := '08'O; /* A5/3 only */
1905 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1906 f_init_handler(pars, 15.0);
1907
1908 /* cannot use f_perform_lu() as we expect a reject */
1909 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1910 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001911 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001912 if (pars.send_early_cm) {
1913 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1914 } else {
1915 pars.cm1.esind := '0'B;
1916 }
Harald Welte9de84792018-01-28 01:06:35 +01001917 f_mm_auth();
1918 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001919 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1920 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1921 repeat;
1922 }
Harald Welte5946b332018-03-18 23:32:21 +01001923 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1924 f_expect_clear();
1925 }
Harald Welte9de84792018-01-28 01:06:35 +01001926 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1927 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001928 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001929 }
1930 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001931 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001932 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001933 }
1934 }
1935 setverdict(pass);
1936}
1937testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1938 var BSC_ConnHdlr vc_conn;
1939 f_init();
1940 f_vty_config(MSCVTY, "network", "authentication required");
1941 f_vty_config(MSCVTY, "network", "encryption a5 3");
1942
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001943 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001944 vc_conn.done;
1945}
1946testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1947 var BSC_ConnHdlrPars pars;
1948 var BSC_ConnHdlr vc_conn;
1949 f_init();
1950 f_vty_config(MSCVTY, "network", "authentication required");
1951 f_vty_config(MSCVTY, "network", "encryption a5 3");
1952
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001953 pars := f_init_pars(361, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001954 pars.send_early_cm := false;
1955 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001956 vc_conn.done;
1957}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001958testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1959 var BSC_ConnHdlr vc_conn;
1960 f_init();
1961 f_vty_config(MSCVTY, "network", "authentication required");
1962 f_vty_config(MSCVTY, "network", "encryption a5 3");
1963
1964 /* Make sure the MSC category is on DEBUG level to trigger the log
1965 * message that is reported in OS#2947 to trigger the segfault */
1966 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1967
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001968 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362, verify_cell_id := false);
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001969 vc_conn.done;
1970}
Harald Welte9de84792018-01-28 01:06:35 +01001971
1972/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1973private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1974 pars.net.expect_auth := true;
1975 pars.net.expect_ciph := true;
1976 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1977 pars.cm1.a5_1 := '1'B;
1978 pars.cm2.a5_1 := '1'B;
1979 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1980 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1981 f_init_handler(pars, 15.0);
1982
1983 /* cannot use f_perform_lu() as we expect a reject */
1984 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1985 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001986 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001987 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1988 f_mm_auth();
1989 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001990 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1991 f_expect_clear();
1992 }
Harald Welte9de84792018-01-28 01:06:35 +01001993 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1994 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001995 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001996 }
1997 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001998 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001999 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01002000 }
2001 }
2002 setverdict(pass);
2003}
2004testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
2005 var BSC_ConnHdlr vc_conn;
2006 f_init();
2007 f_vty_config(MSCVTY, "network", "authentication required");
2008 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
2009
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02002010 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37, verify_cell_id := false);
Harald Welte9de84792018-01-28 01:06:35 +01002011 vc_conn.done;
2012}
2013
2014/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
2015private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2016 pars.net.expect_auth := true;
2017 pars.net.expect_ciph := true;
2018 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
2019 pars.cm1.a5_1 := '1'B;
2020 pars.cm2.a5_1 := '1'B;
2021 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2022 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
2023 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002024 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01002025}
2026testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
2027 var BSC_ConnHdlr vc_conn;
2028 f_init();
2029 f_vty_config(MSCVTY, "network", "authentication required");
2030 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
2031
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002032 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01002033 vc_conn.done;
2034}
2035
Harald Welte33ec09b2018-02-10 15:34:46 +01002036/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01002037friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01002038 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002039 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002040 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01002041
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002042 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01002043 f_mt_call(cpars);
2044}
2045testcase TC_lu_and_mt_call() runs on MTC_CT {
2046 var BSC_ConnHdlr vc_conn;
2047 f_init();
2048
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002049 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01002050 vc_conn.done;
2051}
2052
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002053testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
2054 var BSC_ConnHdlr vc_conn;
2055 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002056
2057 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
2058 vc_conn.done;
2059}
2060
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002061/* LU followed by MT call (including paging) */
2062friend function f_tc_lu_and_mt_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2063 f_init_handler(pars);
2064 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2065 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
2066 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
2067 cpars.bss_rtp_ip := "::3";
Pau Espin Pedrol563b3d02020-09-09 20:19:52 +02002068 cpars.mncc_rtp_ip := "::9";
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002069 f_perform_lu();
2070 f_mt_call(cpars);
2071}
2072testcase TC_lu_and_mt_call_ipv6() runs on MTC_CT {
2073 var BSC_ConnHdlr vc_conn;
2074 f_init();
2075
2076 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_ipv6), 39);
2077 vc_conn.done;
2078}
2079
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002080/* MT call while already Paging */
2081friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2082 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
2083 var SmsParameters spars := valueof(t_SmsPars);
2084 var OCT4 tmsi;
2085
2086 f_init_handler(pars);
2087
2088 /* Perform location update */
2089 f_perform_lu();
2090
2091 /* register an 'expect' for given IMSI (+TMSI) */
2092 if (isvalue(g_pars.tmsi)) {
2093 tmsi := g_pars.tmsi;
2094 } else {
2095 tmsi := 'FFFFFFFF'O;
2096 }
2097 f_ran_register_imsi(g_pars.imsi, tmsi);
2098
2099 log("start Paging by an SMS");
2100 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2101
2102 /* MSC->BSC: expect PAGING from MSC */
2103 f_expect_paging();
2104
2105 log("MNCC signals MT call, before Paging Response");
2106 f_mt_call_initate(cpars);
2107 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
2108
2109 f_sleep(0.5);
2110 log("phone answers Paging, expecting both SMS and MT call to be established");
2111 f_establish_fully(EST_TYPE_PAG_RESP);
2112 spars.tp.ud := 'C8329BFD064D9B53'O;
2113 interleave {
2114 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
2115 log("Got SMS-DELIVER");
2116 };
2117 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
2118 log("Got CC Setup");
2119 };
2120 }
2121 setverdict(pass);
2122 log("success, tear down");
2123 var default ccrel := activate(as_optional_cc_rel(cpars));
2124 if (g_pars.ran_is_geran) {
2125 BSSAP.send(ts_BSSMAP_ClearRequest(0));
2126 } else {
2127 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
2128 }
2129 f_expect_clear();
2130 deactivate(ccrel);
2131 f_vty_sms_clear(hex2str(g_pars.imsi));
2132}
2133testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
2134 var BSC_ConnHdlrPars pars;
2135 var BSC_ConnHdlr vc_conn;
2136 f_init();
2137 pars := f_init_pars(391);
2138 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
2139 vc_conn.done;
2140}
2141
Daniel Willmann8b084372018-02-04 13:35:26 +01002142/* Test MO Call SETUP with DTMF */
2143private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2144 f_init_handler(pars);
2145 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01002146
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002147 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01002148 f_mo_seq_dtmf_dup(cpars);
2149}
2150testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
2151 var BSC_ConnHdlr vc_conn;
2152 f_init();
2153
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002154 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01002155 vc_conn.done;
2156}
Harald Welte9de84792018-01-28 01:06:35 +01002157
Philipp Maier328d1662018-03-07 10:40:27 +01002158testcase TC_cr_before_reset() runs on MTC_CT {
2159 timer T := 4.0;
2160 var boolean reset_ack_seen := false;
2161 f_init_bssap_direct();
2162
Harald Welte3ca0ce12019-04-23 17:18:48 +02002163 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02002164
Daniel Willmanne8018962018-08-21 14:18:00 +02002165 f_sleep(3.0);
2166
Philipp Maier328d1662018-03-07 10:40:27 +01002167 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02002168 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01002169
2170 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02002171 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01002172 T.start
2173 alt {
2174 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
2175 reset_ack_seen := true;
2176 repeat;
2177 }
2178
2179 /* Acknowledge MSC sided reset requests */
2180 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02002181 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01002182 repeat;
2183 }
2184
2185 /* Ignore all other messages (e.g CR from the connection request) */
2186 [] BSSAP_DIRECT.receive { repeat }
2187
2188 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
2189 * deadlock situation. The MSC is then unable to respond to any
2190 * further BSSMAP RESET or any other sort of traffic. */
2191 [reset_ack_seen == true] T.timeout { setverdict(pass) }
2192 [reset_ack_seen == false] T.timeout {
2193 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02002194 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01002195 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01002196 }
Philipp Maier328d1662018-03-07 10:40:27 +01002197}
Harald Welte9de84792018-01-28 01:06:35 +01002198
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002199/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02002200friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002201 f_init_handler(pars);
2202 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2203 var MNCC_PDU mncc;
2204 var MgcpCommand mgcp_cmd;
2205
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002206 /* Do not respond to the second CRCX */
2207 cpars.mgw_conn_2.resp := 0;
2208
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002209 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002210 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002211
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002212 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002213
2214 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002215
2216 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002217}
2218testcase TC_mo_release_timeout() runs on MTC_CT {
2219 var BSC_ConnHdlr vc_conn;
2220 f_init();
2221
2222 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
2223 vc_conn.done;
2224}
2225
Harald Welte12510c52018-01-26 22:26:24 +01002226
Philipp Maier2a98a732018-03-19 16:06:12 +01002227/* LU followed by MT call (including paging) */
2228private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2229 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002230 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01002231
2232 /* Intentionally disable the CRCX response */
2233 cpars.mgw_drop_dlcx := true;
2234
2235 /* Perform location update and call */
2236 f_perform_lu();
2237 f_mt_call(cpars);
2238}
2239testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
2240 var BSC_ConnHdlr vc_conn;
2241 f_init();
2242
2243 /* Perform an almost normal looking locationupdate + mt-call, but do
2244 * not respond to the DLCX at the end of the call */
2245 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
2246 vc_conn.done;
2247
2248 /* Wait a guard period until the MGCP layer in the MSC times out,
2249 * if the MSC is vulnerable to the use-after-free situation that is
2250 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
2251 * segfault now */
2252 f_sleep(6.0);
2253
2254 /* Run the init procedures once more. If the MSC has crashed, this
2255 * this will fail */
2256 f_init();
2257}
Harald Welte45164da2018-01-24 12:51:27 +01002258
Philipp Maier75932982018-03-27 14:52:35 +02002259/* Two BSSMAP resets from two different BSCs */
2260testcase TC_reset_two() runs on MTC_CT {
2261 var BSC_ConnHdlr vc_conn;
2262 f_init(2);
2263 f_sleep(2.0);
2264 setverdict(pass);
2265}
2266
Harald Weltee13cfb22019-04-23 16:52:02 +02002267/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
2268testcase TC_reset_two_1iu() runs on MTC_CT {
2269 var BSC_ConnHdlr vc_conn;
2270 f_init(3);
2271 f_sleep(2.0);
2272 setverdict(pass);
2273}
2274
Harald Weltef640a012018-04-14 17:49:21 +02002275/***********************************************************************
2276 * SMS Testing
2277 ***********************************************************************/
2278
Harald Weltef45efeb2018-04-09 18:19:24 +02002279/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002280friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002281 var SmsParameters spars := valueof(t_SmsPars);
2282
2283 f_init_handler(pars);
2284
2285 /* Perform location update and call */
2286 f_perform_lu();
2287
2288 f_establish_fully(EST_TYPE_MO_SMS);
2289
2290 //spars.exp_rp_err := 96; /* invalid mandatory information */
2291 f_mo_sms(spars);
2292
2293 f_expect_clear();
2294}
2295testcase TC_lu_and_mo_sms() runs on MTC_CT {
2296 var BSC_ConnHdlr vc_conn;
2297 f_init();
2298 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2299 vc_conn.done;
2300}
2301
Harald Weltee13cfb22019-04-23 16:52:02 +02002302
Harald Weltef45efeb2018-04-09 18:19:24 +02002303private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002304runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002305 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2306}
2307
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002308/* Remove still pending SMS */
2309private function f_vty_sms_clear(charstring imsi)
2310runs on BSC_ConnHdlr {
2311 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2312 f_vty_transceive(MSCVTY, "sms-queue clear");
2313}
2314
Harald Weltef45efeb2018-04-09 18:19:24 +02002315/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002316friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002317 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002318
2319 f_init_handler(pars);
2320
2321 /* Perform location update and call */
2322 f_perform_lu();
2323
2324 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002325 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002326
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002327 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002328
2329 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002330 f_expect_paging();
2331
Harald Weltef45efeb2018-04-09 18:19:24 +02002332 /* Establish DTAP / BSSAP / SCCP connection */
2333 f_establish_fully(EST_TYPE_PAG_RESP);
2334
2335 spars.tp.ud := 'C8329BFD064D9B53'O;
2336 f_mt_sms(spars);
2337
2338 f_expect_clear();
2339}
2340testcase TC_lu_and_mt_sms() runs on MTC_CT {
2341 var BSC_ConnHdlrPars pars;
2342 var BSC_ConnHdlr vc_conn;
2343 f_init();
2344 pars := f_init_pars(43);
2345 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002346 vc_conn.done;
2347}
2348
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002349/* SMS added while already Paging */
2350friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2351 var SmsParameters spars := valueof(t_SmsPars);
2352 var OCT4 tmsi;
2353
2354 f_init_handler(pars);
2355
2356 f_perform_lu();
2357
2358 /* register an 'expect' for given IMSI (+TMSI) */
2359 if (isvalue(g_pars.tmsi)) {
2360 tmsi := g_pars.tmsi;
2361 } else {
2362 tmsi := 'FFFFFFFF'O;
2363 }
2364 f_ran_register_imsi(g_pars.imsi, tmsi);
2365
2366 log("first SMS");
2367 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2368
2369 /* MSC->BSC: expect PAGING from MSC */
2370 f_expect_paging();
2371
2372 log("second SMS");
2373 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2374 * with the pending paging. Another SMS: */
2375 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2376
2377 /* Establish DTAP / BSSAP / SCCP connection */
2378 f_establish_fully(EST_TYPE_PAG_RESP);
2379
2380 spars.tp.ud := 'C8329BFD064D9B53'O;
2381 f_mt_sms(spars);
2382
2383 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2384 f_mt_sms(spars);
2385
2386 f_expect_clear();
2387}
2388testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2389 var BSC_ConnHdlrPars pars;
2390 var BSC_ConnHdlr vc_conn;
2391 f_init();
2392 pars := f_init_pars(44);
2393 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2394 vc_conn.done;
2395}
Harald Weltee13cfb22019-04-23 16:52:02 +02002396
Philipp Maier3983e702018-11-22 19:01:33 +01002397/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002398friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002399 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002400
Philipp Maier3983e702018-11-22 19:01:33 +01002401 f_init_handler(pars, 150.0);
2402
2403 /* Perform location update */
2404 f_perform_lu();
2405
2406 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002407 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002408
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002409 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2410
Neels Hofmeyr16237742019-03-06 15:34:01 +01002411 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002412 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002413
2414 /* Wait some time to make sure the MSC is not delivering any further
2415 * paging messages or anything else that could be unexpected. */
2416 timer T := 20.0;
2417 T.start
2418 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002419 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2420 setverdict(fail, "paging seems not to stop!");
2421 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002422 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002423 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2424 setverdict(fail, "paging seems not to stop!");
2425 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002426 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002427 [] BSSAP.receive {
2428 setverdict(fail, "unexpected BSSAP message received");
2429 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002430 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002431 [] T.timeout {
2432 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002433 }
2434 }
2435
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002436 f_vty_sms_clear(hex2str(g_pars.imsi));
2437
Philipp Maier3983e702018-11-22 19:01:33 +01002438 setverdict(pass);
2439}
2440testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2441 var BSC_ConnHdlrPars pars;
2442 var BSC_ConnHdlr vc_conn;
2443 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002444 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002445 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002446 vc_conn.done;
2447}
2448
Alexander Couzensfc02f242019-09-12 03:43:18 +02002449/* LU followed by MT SMS with repeated paging */
2450friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2451 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002452
2453 f_init_handler(pars);
2454
2455 /* Perform location update and call */
2456 f_perform_lu();
2457
2458 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002459 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002460
2461 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2462
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002463 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002464 /* MSC->BSC: expect PAGING from MSC */
2465 f_expect_paging();
2466
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002467 if (g_pars.ran_is_geran) {
2468 log("GERAN: expect no further Paging");
2469 } else {
2470 log("UTRAN: expect more Paging");
2471 }
2472
2473 timer T := 5.0;
2474 T.start;
2475 alt {
2476 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2477 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2478 mtc.stop;
2479 }
2480 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2481 log("UTRAN: second Paging received, as expected");
2482 setverdict(pass);
2483 }
2484 [] T.timeout {
2485 if (g_pars.ran_is_geran) {
2486 log("GERAN: No further Paging received, as expected");
2487 setverdict(pass);
2488 } else {
2489 setverdict(fail, "UTRAN: Expected a second Paging");
2490 mtc.stop;
2491 }
2492 }
2493 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002494
2495 /* Establish DTAP / BSSAP / SCCP connection */
2496 f_establish_fully(EST_TYPE_PAG_RESP);
2497
2498 spars.tp.ud := 'C8329BFD064D9B53'O;
2499 f_mt_sms(spars);
2500
2501 f_expect_clear();
2502}
2503testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2504 var BSC_ConnHdlrPars pars;
2505 var BSC_ConnHdlr vc_conn;
2506 f_init();
2507 pars := f_init_pars(1844);
2508 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2509 vc_conn.done;
2510}
Harald Weltee13cfb22019-04-23 16:52:02 +02002511
Harald Weltef640a012018-04-14 17:49:21 +02002512/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002513friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002514 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002515
Harald Weltef640a012018-04-14 17:49:21 +02002516 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002517
Harald Weltef640a012018-04-14 17:49:21 +02002518 /* Perform location update so IMSI is known + registered in MSC/VLR */
2519 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002520
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002521 /* MS/UE submits a MO SMS */
2522 f_establish_fully(EST_TYPE_MO_SMS);
2523 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002524
2525 var SMPP_PDU smpp;
2526 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2527 tr_smpp.body.deliver_sm := {
2528 service_type := "CMT",
2529 source_addr_ton := network_specific,
2530 source_addr_npi := isdn,
2531 source_addr := hex2str(pars.msisdn),
2532 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2533 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2534 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2535 esm_class := '00000001'B,
2536 protocol_id := 0,
2537 priority_flag := 0,
2538 schedule_delivery_time := "",
2539 replace_if_present := 0,
2540 data_coding := '00000001'B,
2541 sm_default_msg_id := 0,
2542 sm_length := ?,
2543 short_message := spars.tp.ud,
2544 opt_pars := {
2545 {
2546 tag := user_message_reference,
2547 len := 2,
2548 opt_value := {
2549 int2_val := oct2int(spars.tp.msg_ref)
2550 }
2551 }
2552 }
2553 };
2554 alt {
2555 [] SMPP.receive(tr_smpp) -> value smpp {
2556 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2557 }
2558 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2559 }
2560
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002561 /* MSC terminates the SMS transaction with RP-ACK */
2562 f_mo_sms_wait_rp_ack(spars);
2563
Harald Weltef640a012018-04-14 17:49:21 +02002564 f_expect_clear();
2565}
2566testcase TC_smpp_mo_sms() runs on MTC_CT {
2567 var BSC_ConnHdlr vc_conn;
2568 f_init();
2569 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2570 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2571 vc_conn.done;
2572 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2573}
2574
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002575/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2576friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2577runs on BSC_ConnHdlr {
2578 var SmsParameters spars := valueof(t_SmsPars);
2579 var SMPP_PDU smpp_pdu;
2580 timer T := 3.0;
2581
2582 f_init_handler(pars);
2583
2584 /* Perform location update */
2585 f_perform_lu();
2586
2587 /* MS/UE submits a MO SMS */
2588 f_establish_fully(EST_TYPE_MO_SMS);
2589 f_mo_sms_submit(spars);
2590
2591 /* ESME responds with an error (Invalid Destination Address) */
2592 T.start;
2593 alt {
2594 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2595 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2596 }
2597 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2598 [] T.timeout {
2599 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2600 mtc.stop;
2601 }
2602 }
2603
2604 /* Expect RP-ERROR on BSSAP interface */
2605 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2606 f_mo_sms_wait_rp_ack(spars);
2607
2608 f_expect_clear();
2609}
2610testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2611 var BSC_ConnHdlr vc_conn;
2612 f_init();
2613 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2614 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2615 vc_conn.done;
2616 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2617}
2618
Harald Weltee13cfb22019-04-23 16:52:02 +02002619
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002620/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002621friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002622runs on BSC_ConnHdlr {
2623 var SmsParameters spars := valueof(t_SmsPars);
2624 var GSUP_PDU gsup_msg_rx;
2625 var octetstring sm_tpdu;
2626
2627 f_init_handler(pars);
2628
2629 /* We need to inspect GSUP activity */
2630 f_create_gsup_expect(hex2str(g_pars.imsi));
2631
2632 /* Perform location update */
2633 f_perform_lu();
2634
2635 /* Send CM Service Request for SMS */
2636 f_establish_fully(EST_TYPE_MO_SMS);
2637
2638 /* Prepare expected SM-RP-UI (SM TPDU) */
2639 enc_TPDU_RP_DATA_MS_SGSN_fast(
2640 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2641 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2642 spars.tp.udl, spars.tp.ud)),
2643 sm_tpdu);
2644
2645 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2646 imsi := g_pars.imsi,
2647 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002648 /* SM-RP-DA: SMSC address */
2649 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2650 number := spars.rp.smsc_addr.rP_NumberDigits,
2651 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2652 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2653 ext := spars.rp.smsc_addr.rP_Ext)),
2654 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2655 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2656 number := g_pars.msisdn,
2657 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2658 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002659 /* TODO: can we use decmatch here? */
2660 sm_rp_ui := sm_tpdu
2661 );
2662
2663 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2664 f_mo_sms_submit(spars);
2665 alt {
2666 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002667 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002668 setverdict(pass);
2669 }
2670 [] GSUP.receive {
2671 log("RX unexpected GSUP message");
2672 setverdict(fail);
2673 mtc.stop;
2674 }
2675 }
2676
2677 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2678 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2679 imsi := g_pars.imsi,
2680 sm_rp_mr := spars.rp.msg_ref)));
2681 /* Expect RP-ACK on DTAP */
2682 f_mo_sms_wait_rp_ack(spars);
2683
2684 f_expect_clear();
2685}
2686testcase TC_gsup_mo_sms() runs on MTC_CT {
2687 var BSC_ConnHdlr vc_conn;
2688 f_init();
2689 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2690 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2691 vc_conn.done;
2692 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2693}
2694
Harald Weltee13cfb22019-04-23 16:52:02 +02002695
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002696/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002697friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002698runs on BSC_ConnHdlr {
2699 var SmsParameters spars := valueof(t_SmsPars);
2700 var GSUP_PDU gsup_msg_rx;
2701
2702 f_init_handler(pars);
2703
2704 /* We need to inspect GSUP activity */
2705 f_create_gsup_expect(hex2str(g_pars.imsi));
2706
2707 /* Perform location update */
2708 f_perform_lu();
2709
2710 /* Send CM Service Request for SMS */
2711 f_establish_fully(EST_TYPE_MO_SMS);
2712
2713 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2714 imsi := g_pars.imsi,
2715 sm_rp_mr := spars.rp.msg_ref,
2716 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2717 );
2718
2719 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2720 f_mo_smma(spars);
2721 alt {
2722 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002723 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002724 setverdict(pass);
2725 }
2726 [] GSUP.receive {
2727 log("RX unexpected GSUP message");
2728 setverdict(fail);
2729 mtc.stop;
2730 }
2731 }
2732
2733 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2734 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2735 imsi := g_pars.imsi,
2736 sm_rp_mr := spars.rp.msg_ref)));
2737 /* Expect RP-ACK on DTAP */
2738 f_mo_sms_wait_rp_ack(spars);
2739
2740 f_expect_clear();
2741}
2742testcase TC_gsup_mo_smma() runs on MTC_CT {
2743 var BSC_ConnHdlr vc_conn;
2744 f_init();
2745 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2746 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2747 vc_conn.done;
2748 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2749}
2750
Harald Weltee13cfb22019-04-23 16:52:02 +02002751
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002752/* Helper for sending MT SMS over GSUP */
2753private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2754runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002755 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002756 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2757 number := spars.rp.smsc_addr.rP_NumberDigits,
2758 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2759 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2760 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002761
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002762 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2763 imsi := g_pars.imsi,
2764 /* NOTE: MSC should assign RP-MR itself */
2765 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002766 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002767 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002768 /* Encoded SMS TPDU (taken from Wireshark)
2769 * FIXME: we should encode spars somehow */
2770 sm_rp_ui := '00068021436500008111328130858200'O,
2771 sm_rp_mms := mms
2772 ));
2773}
2774
2775/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002776friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002777runs on BSC_ConnHdlr {
2778 var SmsParameters spars := valueof(t_SmsPars);
2779
2780 f_init_handler(pars);
2781
2782 /* We need to inspect GSUP activity */
2783 f_create_gsup_expect(hex2str(g_pars.imsi));
2784
2785 /* Perform location update */
2786 f_perform_lu();
2787
2788 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002789 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002790
2791 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2792 imsi := g_pars.imsi,
2793 /* NOTE: MSC should assign RP-MR itself */
2794 sm_rp_mr := ?
2795 );
2796
2797 /* Submit a MT SMS on GSUP */
2798 f_gsup_forwardSM_req(spars);
2799
2800 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002801 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002802 f_establish_fully(EST_TYPE_PAG_RESP);
2803
2804 /* Wait for MT SMS on DTAP */
2805 f_mt_sms_expect(spars);
2806
2807 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2808 f_mt_sms_send_rp_ack(spars);
2809 alt {
2810 [] GSUP.receive(mt_forwardSM_res) {
2811 log("RX MT-forwardSM-Res (RP-ACK)");
2812 setverdict(pass);
2813 }
2814 [] GSUP.receive {
2815 log("RX unexpected GSUP message");
2816 setverdict(fail);
2817 mtc.stop;
2818 }
2819 }
2820
2821 f_expect_clear();
2822}
2823testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2824 var BSC_ConnHdlrPars pars;
2825 var BSC_ConnHdlr vc_conn;
2826 f_init();
2827 pars := f_init_pars(90);
2828 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2829 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2830 vc_conn.done;
2831 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2832}
2833
Harald Weltee13cfb22019-04-23 16:52:02 +02002834
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002835/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002836friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002837runs on BSC_ConnHdlr {
2838 var SmsParameters spars := valueof(t_SmsPars);
2839 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2840
2841 f_init_handler(pars);
2842
2843 /* We need to inspect GSUP activity */
2844 f_create_gsup_expect(hex2str(g_pars.imsi));
2845
2846 /* Perform location update */
2847 f_perform_lu();
2848
2849 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002850 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002851
2852 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2853 imsi := g_pars.imsi,
2854 /* NOTE: MSC should assign RP-MR itself */
2855 sm_rp_mr := ?,
2856 sm_rp_cause := sm_rp_cause
2857 );
2858
2859 /* Submit a MT SMS on GSUP */
2860 f_gsup_forwardSM_req(spars);
2861
2862 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002863 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002864 f_establish_fully(EST_TYPE_PAG_RESP);
2865
2866 /* Wait for MT SMS on DTAP */
2867 f_mt_sms_expect(spars);
2868
2869 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2870 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2871 alt {
2872 [] GSUP.receive(mt_forwardSM_err) {
2873 log("RX MT-forwardSM-Err (RP-ERROR)");
2874 setverdict(pass);
2875 mtc.stop;
2876 }
2877 [] GSUP.receive {
2878 log("RX unexpected GSUP message");
2879 setverdict(fail);
2880 mtc.stop;
2881 }
2882 }
2883
2884 f_expect_clear();
2885}
2886testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2887 var BSC_ConnHdlrPars pars;
2888 var BSC_ConnHdlr vc_conn;
2889 f_init();
2890 pars := f_init_pars(91);
2891 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2892 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2893 vc_conn.done;
2894 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2895}
2896
Harald Weltee13cfb22019-04-23 16:52:02 +02002897
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002898/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002899friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002900runs on BSC_ConnHdlr {
2901 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2902 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2903
2904 f_init_handler(pars);
2905
2906 /* We need to inspect GSUP activity */
2907 f_create_gsup_expect(hex2str(g_pars.imsi));
2908
2909 /* Perform location update */
2910 f_perform_lu();
2911
2912 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002913 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002914
2915 /* Submit the 1st MT SMS on GSUP */
2916 log("TX MT-forwardSM-Req for the 1st SMS");
2917 f_gsup_forwardSM_req(spars1);
2918
2919 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002920 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002921 f_establish_fully(EST_TYPE_PAG_RESP);
2922
2923 /* Wait for 1st MT SMS on DTAP */
2924 f_mt_sms_expect(spars1);
2925 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2926 ", SM-RP-MR is ", spars1.rp.msg_ref);
2927
2928 /* Submit the 2nd MT SMS on GSUP */
2929 log("TX MT-forwardSM-Req for the 2nd SMS");
2930 f_gsup_forwardSM_req(spars2);
2931
2932 /* Wait for 2nd MT SMS on DTAP */
2933 f_mt_sms_expect(spars2);
2934 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2935 ", SM-RP-MR is ", spars2.rp.msg_ref);
2936
2937 /* Both transaction IDs shall be different */
2938 if (spars1.tid == spars2.tid) {
2939 log("Both DTAP transaction IDs shall be different");
2940 setverdict(fail);
2941 }
2942
2943 /* Both SM-RP-MR values shall be different */
2944 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2945 log("Both SM-RP-MR values shall be different");
2946 setverdict(fail);
2947 }
2948
2949 /* Both SM-RP-MR values shall be assigned */
2950 if (spars1.rp.msg_ref == 'FF'O) {
2951 log("Unassigned SM-RP-MR value for the 1st SMS");
2952 setverdict(fail);
2953 }
2954 if (spars2.rp.msg_ref == 'FF'O) {
2955 log("Unassigned SM-RP-MR value for the 2nd SMS");
2956 setverdict(fail);
2957 }
2958
2959 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2960 f_mt_sms_send_rp_ack(spars1);
2961 alt {
2962 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2963 imsi := g_pars.imsi,
2964 sm_rp_mr := spars1.rp.msg_ref
2965 )) {
2966 log("RX MT-forwardSM-Res (RP-ACK)");
2967 setverdict(pass);
2968 }
2969 [] GSUP.receive {
2970 log("RX unexpected GSUP message");
2971 setverdict(fail);
2972 mtc.stop;
2973 }
2974 }
2975
2976 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2977 f_mt_sms_send_rp_ack(spars2);
2978 alt {
2979 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2980 imsi := g_pars.imsi,
2981 sm_rp_mr := spars2.rp.msg_ref
2982 )) {
2983 log("RX MT-forwardSM-Res (RP-ACK)");
2984 setverdict(pass);
2985 }
2986 [] GSUP.receive {
2987 log("RX unexpected GSUP message");
2988 setverdict(fail);
2989 mtc.stop;
2990 }
2991 }
2992
2993 f_expect_clear();
2994}
2995testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2996 var BSC_ConnHdlrPars pars;
2997 var BSC_ConnHdlr vc_conn;
2998 f_init();
2999 pars := f_init_pars(92);
3000 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3001 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
3002 vc_conn.done;
3003 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3004}
3005
Harald Weltee13cfb22019-04-23 16:52:02 +02003006
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003007/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02003008friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003009runs on BSC_ConnHdlr {
3010 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
3011 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
3012
3013 f_init_handler(pars);
3014
3015 /* We need to inspect GSUP activity */
3016 f_create_gsup_expect(hex2str(g_pars.imsi));
3017
3018 /* Perform location update */
3019 f_perform_lu();
3020
3021 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003022 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003023
3024 /* Send CM Service Request for MO SMMA */
3025 f_establish_fully(EST_TYPE_MO_SMS);
3026
3027 /* Submit MO SMMA on DTAP */
3028 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
3029 spars_mo.rp.msg_ref := '00'O;
3030 f_mo_smma(spars_mo);
3031
3032 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
3033 alt {
3034 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
3035 imsi := g_pars.imsi,
3036 sm_rp_mr := spars_mo.rp.msg_ref,
3037 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
3038 )) {
3039 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
3040 setverdict(pass);
3041 }
3042 [] GSUP.receive {
3043 log("RX unexpected GSUP message");
3044 setverdict(fail);
3045 mtc.stop;
3046 }
3047 }
3048
3049 /* Submit MT SMS on GSUP */
3050 log("TX MT-forwardSM-Req for the MT SMS");
3051 f_gsup_forwardSM_req(spars_mt);
3052
3053 /* Wait for MT SMS on DTAP */
3054 f_mt_sms_expect(spars_mt);
3055 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
3056 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
3057
3058 /* Both SM-RP-MR values shall be different */
3059 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
3060 log("Both SM-RP-MR values shall be different");
3061 setverdict(fail);
3062 }
3063
3064 /* SM-RP-MR value for MT SMS shall be assigned */
3065 if (spars_mt.rp.msg_ref == 'FF'O) {
3066 log("Unassigned SM-RP-MR value for the MT SMS");
3067 setverdict(fail);
3068 }
3069
3070 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
3071 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
3072 imsi := g_pars.imsi,
3073 sm_rp_mr := spars_mo.rp.msg_ref)));
3074 /* Expect RP-ACK for MO SMMA on DTAP */
3075 f_mo_sms_wait_rp_ack(spars_mo);
3076
3077 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
3078 f_mt_sms_send_rp_ack(spars_mt);
3079 alt {
3080 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3081 imsi := g_pars.imsi,
3082 sm_rp_mr := spars_mt.rp.msg_ref
3083 )) {
3084 log("RX MT-forwardSM-Res (RP-ACK)");
3085 setverdict(pass);
3086 }
3087 [] GSUP.receive {
3088 log("RX unexpected GSUP message");
3089 setverdict(fail);
3090 mtc.stop;
3091 }
3092 }
3093
3094 f_expect_clear();
3095}
3096testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
3097 var BSC_ConnHdlrPars pars;
3098 var BSC_ConnHdlr vc_conn;
3099 f_init();
3100 pars := f_init_pars(93);
3101 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3102 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
3103 vc_conn.done;
3104 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3105}
3106
Harald Weltee13cfb22019-04-23 16:52:02 +02003107
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003108/* Test multi-part MT-SMS over GSUP */
3109private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
3110runs on BSC_ConnHdlr {
3111 var SmsParameters spars := valueof(t_SmsPars);
3112
3113 f_init_handler(pars);
3114
3115 /* We need to inspect GSUP activity */
3116 f_create_gsup_expect(hex2str(g_pars.imsi));
3117
3118 /* Perform location update */
3119 f_perform_lu();
3120
3121 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003122 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003123
3124 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
3125 imsi := g_pars.imsi,
3126 /* NOTE: MSC should assign RP-MR itself */
3127 sm_rp_mr := ?
3128 );
3129
3130 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
3131 for (var integer i := 3; i >= 0; i := i-1) {
3132 /* Submit a MT SMS on GSUP (MMS is decremented) */
3133 f_gsup_forwardSM_req(spars, int2oct(i, 1));
3134
3135 /* Expect Paging Request and Establish connection */
3136 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02003137 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003138 f_establish_fully(EST_TYPE_PAG_RESP);
3139 }
3140
3141 /* Wait for MT SMS on DTAP */
3142 f_mt_sms_expect(spars);
3143
3144 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
3145 f_mt_sms_send_rp_ack(spars);
3146 alt {
3147 [] GSUP.receive(mt_forwardSM_res) {
3148 log("RX MT-forwardSM-Res (RP-ACK)");
3149 setverdict(pass);
3150 }
3151 [] GSUP.receive {
3152 log("RX unexpected GSUP message");
3153 setverdict(fail);
3154 mtc.stop;
3155 }
3156 }
3157
3158 /* Keep some 'distance' between transmissions */
3159 f_sleep(1.5);
3160 }
3161
3162 f_expect_clear();
3163}
3164testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
3165 var BSC_ConnHdlrPars pars;
3166 var BSC_ConnHdlr vc_conn;
3167 f_init();
3168 pars := f_init_pars(91);
3169 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3170 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
3171 vc_conn.done;
3172 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3173}
3174
Harald Weltef640a012018-04-14 17:49:21 +02003175/* convert GSM L3 TON to SMPP_TON enum */
3176function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
3177 select (ton) {
3178 case ('000'B) { return unknown; }
3179 case ('001'B) { return international; }
3180 case ('010'B) { return national; }
3181 case ('011'B) { return network_specific; }
3182 case ('100'B) { return subscriber_number; }
3183 case ('101'B) { return alphanumeric; }
3184 case ('110'B) { return abbreviated; }
3185 }
3186 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02003187 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003188}
3189/* convert GSM L3 NPI to SMPP_NPI enum */
3190function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
3191 select (npi) {
3192 case ('0000'B) { return unknown; }
3193 case ('0001'B) { return isdn; }
3194 case ('0011'B) { return data; }
3195 case ('0100'B) { return telex; }
3196 case ('0110'B) { return land_mobile; }
3197 case ('1000'B) { return national; }
3198 case ('1001'B) { return private_; }
3199 case ('1010'B) { return ermes; }
3200 }
3201 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02003202 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003203}
3204
3205/* build a SMPP_SM from SmsParameters */
3206function f_mt_sm_from_spars(SmsParameters spars)
3207runs on BSC_ConnHdlr return SMPP_SM {
3208 var SMPP_SM sm := {
3209 service_type := "CMT",
3210 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
3211 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
3212 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
3213 dest_addr_ton := international,
3214 dest_addr_npi := isdn,
3215 destination_addr := hex2str(g_pars.msisdn),
3216 esm_class := '00000001'B,
3217 protocol_id := 0,
3218 priority_flag := 0,
3219 schedule_delivery_time := "",
3220 validity_period := "",
3221 registered_delivery := '00000000'B,
3222 replace_if_present := 0,
3223 data_coding := '00000001'B,
3224 sm_default_msg_id := 0,
3225 sm_length := spars.tp.udl,
3226 short_message := spars.tp.ud,
3227 opt_pars := {}
3228 };
3229 return sm;
3230}
3231
3232/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
3233private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
3234 var SMPP_SM sm := f_mt_sm_from_spars(spars);
3235 if (trans_mode) {
3236 sm.esm_class := '00000010'B;
3237 }
3238
3239 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
3240 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
3241 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3242 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
3243 * before we expect the SMS delivery on the BSC/radio side */
3244 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3245 }
3246
3247 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02003248 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02003249 /* Establish DTAP / BSSAP / SCCP connection */
3250 f_establish_fully(EST_TYPE_PAG_RESP);
3251 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3252
3253 f_mt_sms(spars);
3254
3255 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3256 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3257 }
3258 f_expect_clear();
3259}
3260
3261/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
3262private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3263 f_init_handler(pars);
3264
3265 /* Perform location update so IMSI is known + registered in MSC/VLR */
3266 f_perform_lu();
3267 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3268
3269 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003270 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02003271
3272 var SmsParameters spars := valueof(t_SmsPars);
3273 /* TODO: test with more intelligent user data; test different coding schemes */
3274 spars.tp.ud := '00'O;
3275 spars.tp.udl := 1;
3276
3277 /* first test the non-transaction store+forward mode */
3278 f_smpp_mt_sms(spars, false);
3279
3280 /* then test the transaction mode */
3281 f_smpp_mt_sms(spars, true);
3282}
3283testcase TC_smpp_mt_sms() runs on MTC_CT {
3284 var BSC_ConnHdlr vc_conn;
3285 f_init();
3286 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
3287 vc_conn.done;
3288}
3289
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003290/***********************************************************************
3291 * USSD Testing
3292 ***********************************************************************/
3293
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003294private altstep as_unexp_gsup_or_bssap_msg()
3295runs on BSC_ConnHdlr {
3296 [] GSUP.receive {
3297 setverdict(fail, "Unknown/unexpected GSUP received");
3298 self.stop;
3299 }
3300 [] BSSAP.receive {
3301 setverdict(fail, "Unknown/unexpected BSSAP message received");
3302 self.stop;
3303 }
3304}
3305
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003306private function f_expect_gsup_msg(template GSUP_PDU msg,
3307 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003308runs on BSC_ConnHdlr return GSUP_PDU {
3309 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003310 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003311
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003312 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003313 alt {
3314 [] GSUP.receive(msg) -> value gsup_msg_complete {
3315 setverdict(pass);
3316 }
3317 /* We don't expect anything else */
3318 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003319 [] T.timeout {
3320 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3321 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003322 }
3323
3324 return gsup_msg_complete;
3325}
3326
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003327private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3328 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003329runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3330 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003331 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003332
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003333 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003334 alt {
3335 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3336 setverdict(pass);
3337 }
3338 /* We don't expect anything else */
3339 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003340 [] T.timeout {
3341 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3342 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003343 }
3344
3345 return bssap_msg_complete.dtap;
3346}
3347
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003348/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003349friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003350runs on BSC_ConnHdlr {
3351 f_init_handler(pars);
3352
3353 /* Perform location update */
3354 f_perform_lu();
3355
3356 /* Send CM Service Request for SS/USSD */
3357 f_establish_fully(EST_TYPE_SS_ACT);
3358
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003359 /* We need to inspect GSUP activity */
3360 f_create_gsup_expect(hex2str(g_pars.imsi));
3361
3362 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3363 invoke_id := 5, /* Phone may not start from 0 or 1 */
3364 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3365 ussd_string := "*#100#"
3366 );
3367
3368 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3369 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3370 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3371 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3372 )
3373
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003374 /* Compose a new SS/REGISTER message with request */
3375 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3376 tid := 1, /* We just need a single transaction */
3377 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003378 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003379 );
3380
3381 /* Compose SS/RELEASE_COMPLETE template with expected response */
3382 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3383 tid := 1, /* Response should arrive within the same transaction */
3384 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003385 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003386 );
3387
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003388 /* Compose expected MSC -> HLR message */
3389 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3390 imsi := g_pars.imsi,
3391 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3392 ss := valueof(facility_req)
3393 );
3394
3395 /* To be used for sending response with correct session ID */
3396 var GSUP_PDU gsup_req_complete;
3397
3398 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003399 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003400 /* Expect GSUP message containing the SS payload */
3401 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3402
3403 /* Compose the response from HLR using received session ID */
3404 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3405 imsi := g_pars.imsi,
3406 sid := gsup_req_complete.ies[1].val.session_id,
3407 state := OSMO_GSUP_SESSION_STATE_END,
3408 ss := valueof(facility_rsp)
3409 );
3410
3411 /* Finally, HLR terminates the session */
3412 GSUP.send(gsup_rsp);
3413 /* Expect RELEASE_COMPLETE message with the response */
3414 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003415
3416 f_expect_clear();
3417}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003418testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003419 var BSC_ConnHdlr vc_conn;
3420 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003421 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003422 vc_conn.done;
3423}
3424
Harald Weltee13cfb22019-04-23 16:52:02 +02003425
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003426/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003427friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003428runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003429 timer T := 5.0;
3430
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003431 f_init_handler(pars);
3432
3433 /* Perform location update */
3434 f_perform_lu();
3435
Harald Welte6811d102019-04-14 22:23:14 +02003436 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003437
3438 /* We need to inspect GSUP activity */
3439 f_create_gsup_expect(hex2str(g_pars.imsi));
3440
3441 /* Facility IE with network-originated USSD notification */
3442 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3443 op_code := SS_OP_CODE_USS_NOTIFY,
3444 ussd_string := "Mahlzeit!"
3445 );
3446
3447 /* Facility IE with acknowledgment to the USSD notification */
3448 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3449 /* In case of USSD notification, Return Result is empty */
3450 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3451 );
3452
3453 /* Compose a new MT SS/REGISTER message with USSD notification */
3454 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3455 tid := 0, /* FIXME: most likely, it should be 0 */
3456 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3457 facility := valueof(facility_req)
3458 );
3459
3460 /* Compose HLR -> MSC GSUP message */
3461 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3462 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003463 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003464 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3465 ss := valueof(facility_req)
3466 );
3467
3468 /* Send it to MSC and expect Paging Request */
3469 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003470 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003471 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003472 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3473 setverdict(pass);
3474 }
Harald Welte62113fc2019-05-09 13:04:02 +02003475 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003476 setverdict(pass);
3477 }
3478 /* We don't expect anything else */
3479 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003480 [] T.timeout {
3481 setverdict(fail, "Timeout waiting for Paging Request");
3482 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003483 }
3484
3485 /* Send Paging Response and expect USSD notification */
3486 f_establish_fully(EST_TYPE_PAG_RESP);
3487 /* Expect MT REGISTER message with USSD notification */
3488 f_expect_mt_dtap_msg(ussd_ntf);
3489
3490 /* Compose a new MO SS/FACILITY message with empty response */
3491 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3492 tid := 0, /* FIXME: it shall match the request tid */
3493 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3494 facility := valueof(facility_rsp)
3495 );
3496
3497 /* Compose expected MSC -> HLR GSUP message */
3498 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3499 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003500 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003501 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3502 ss := valueof(facility_rsp)
3503 );
3504
3505 /* MS sends response to the notification */
3506 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3507 /* Expect GSUP message containing the SS payload */
3508 f_expect_gsup_msg(gsup_rsp);
3509
3510 /* Compose expected MT SS/RELEASE COMPLETE message */
3511 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3512 tid := 0, /* FIXME: it shall match the request tid */
3513 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3514 facility := omit
3515 );
3516
3517 /* Compose MSC -> HLR GSUP message */
3518 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3519 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003520 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003521 state := OSMO_GSUP_SESSION_STATE_END
3522 );
3523
3524 /* Finally, HLR terminates the session */
3525 GSUP.send(gsup_term)
3526 /* Expect MT RELEASE COMPLETE without Facility IE */
3527 f_expect_mt_dtap_msg(ussd_term);
3528
3529 f_expect_clear();
3530}
3531testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3532 var BSC_ConnHdlr vc_conn;
3533 f_init();
3534 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3535 vc_conn.done;
3536}
3537
Harald Weltee13cfb22019-04-23 16:52:02 +02003538
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003539/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003540friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003541runs on BSC_ConnHdlr {
3542 f_init_handler(pars);
3543
3544 /* Call parameters taken from f_tc_lu_and_mt_call */
3545 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003546
3547 /* Perform location update */
3548 f_perform_lu();
3549
3550 /* Establish a MT call */
3551 f_mt_call_establish(cpars);
3552
3553 /* Hold the call for some time */
3554 f_sleep(1.0);
3555
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003556 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3557 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3558 ussd_string := "*#100#"
3559 );
3560
3561 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3562 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3563 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3564 )
3565
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003566 /* Compose a new SS/REGISTER message with request */
3567 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3568 tid := 1, /* We just need a single transaction */
3569 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003570 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003571 );
3572
3573 /* Compose SS/RELEASE_COMPLETE template with expected response */
3574 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3575 tid := 1, /* Response should arrive within the same transaction */
3576 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003577 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003578 );
3579
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003580 /* Compose expected MSC -> HLR message */
3581 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3582 imsi := g_pars.imsi,
3583 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3584 ss := valueof(facility_req)
3585 );
3586
3587 /* To be used for sending response with correct session ID */
3588 var GSUP_PDU gsup_req_complete;
3589
3590 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003591 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003592 /* Expect GSUP message containing the SS payload */
3593 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3594
3595 /* Compose the response from HLR using received session ID */
3596 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3597 imsi := g_pars.imsi,
3598 sid := gsup_req_complete.ies[1].val.session_id,
3599 state := OSMO_GSUP_SESSION_STATE_END,
3600 ss := valueof(facility_rsp)
3601 );
3602
3603 /* Finally, HLR terminates the session */
3604 GSUP.send(gsup_rsp);
3605 /* Expect RELEASE_COMPLETE message with the response */
3606 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003607
3608 /* Hold the call for some time */
3609 f_sleep(1.0);
3610
3611 /* Release the call (does Clear Complete itself) */
3612 f_call_hangup(cpars, true);
3613}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003614testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003615 var BSC_ConnHdlr vc_conn;
3616 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003617 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003618 vc_conn.done;
3619}
3620
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003621/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003622friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003623 f_init_handler(pars);
3624 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003625 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003626
3627 f_perform_lu();
3628
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003629 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003630 f_mo_call_establish(cpars);
3631 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003632 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003633
3634 f_sleep(1.0);
3635}
3636testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3637 var BSC_ConnHdlr vc_conn;
3638 f_init();
3639
3640 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3641 vc_conn.done;
3642}
3643
Harald Weltee13cfb22019-04-23 16:52:02 +02003644
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003645/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003646friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003647runs on BSC_ConnHdlr {
3648 f_init_handler(pars);
3649
3650 /* Call parameters taken from f_tc_lu_and_mt_call */
3651 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003652
3653 /* Perform location update */
3654 f_perform_lu();
3655
3656 /* Establish a MT call */
3657 f_mt_call_establish(cpars);
3658
3659 /* Hold the call for some time */
3660 f_sleep(1.0);
3661
3662 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3663 op_code := SS_OP_CODE_USS_REQUEST,
3664 ussd_string := "Please type anything..."
3665 );
3666
3667 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3668 op_code := SS_OP_CODE_USS_REQUEST,
3669 ussd_string := "Nope."
3670 )
3671
3672 /* Compose MT SS/REGISTER message with network-originated request */
3673 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3674 tid := 0, /* FIXME: most likely, it should be 0 */
3675 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3676 facility := valueof(facility_req)
3677 );
3678
3679 /* Compose HLR -> MSC GSUP message */
3680 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3681 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003682 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003683 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3684 ss := valueof(facility_req)
3685 );
3686
3687 /* Send it to MSC */
3688 GSUP.send(gsup_req);
3689 /* Expect MT REGISTER message with USSD request */
3690 f_expect_mt_dtap_msg(ussd_req);
3691
3692 /* Compose a new MO SS/FACILITY message with response */
3693 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3694 tid := 0, /* FIXME: it shall match the request tid */
3695 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3696 facility := valueof(facility_rsp)
3697 );
3698
3699 /* Compose expected MSC -> HLR GSUP message */
3700 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3701 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003702 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003703 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3704 ss := valueof(facility_rsp)
3705 );
3706
3707 /* MS sends response */
3708 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3709 f_expect_gsup_msg(gsup_rsp);
3710
3711 /* Compose expected MT SS/RELEASE COMPLETE message */
3712 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3713 tid := 0, /* FIXME: it shall match the request tid */
3714 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3715 facility := omit
3716 );
3717
3718 /* Compose MSC -> HLR GSUP message */
3719 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3720 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003721 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003722 state := OSMO_GSUP_SESSION_STATE_END
3723 );
3724
3725 /* Finally, HLR terminates the session */
3726 GSUP.send(gsup_term);
3727 /* Expect MT RELEASE COMPLETE without Facility IE */
3728 f_expect_mt_dtap_msg(ussd_term);
3729
3730 /* Hold the call for some time */
3731 f_sleep(1.0);
3732
3733 /* Release the call (does Clear Complete itself) */
3734 f_call_hangup(cpars, true);
3735}
3736testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3737 var BSC_ConnHdlr vc_conn;
3738 f_init();
3739 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3740 vc_conn.done;
3741}
3742
Harald Weltee13cfb22019-04-23 16:52:02 +02003743
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003744/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003745friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003746runs on BSC_ConnHdlr {
3747 f_init_handler(pars);
3748
3749 /* Perform location update */
3750 f_perform_lu();
3751
3752 /* Send CM Service Request for SS/USSD */
3753 f_establish_fully(EST_TYPE_SS_ACT);
3754
3755 /* We need to inspect GSUP activity */
3756 f_create_gsup_expect(hex2str(g_pars.imsi));
3757
3758 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3759 invoke_id := 1, /* Initial request */
3760 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3761 ussd_string := "*6766*266#"
3762 );
3763
3764 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3765 invoke_id := 2, /* Counter request */
3766 op_code := SS_OP_CODE_USS_REQUEST,
3767 ussd_string := "Password?!?"
3768 )
3769
3770 /* Compose MO SS/REGISTER message with request */
3771 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3772 tid := 1, /* We just need a single transaction */
3773 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3774 facility := valueof(facility_ms_req)
3775 );
3776
3777 /* Compose expected MSC -> HLR message */
3778 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3779 imsi := g_pars.imsi,
3780 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3781 ss := valueof(facility_ms_req)
3782 );
3783
3784 /* To be used for sending response with correct session ID */
3785 var GSUP_PDU gsup_ms_req_complete;
3786
3787 /* Initiate a new transaction */
3788 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3789 /* Expect GSUP request with original Facility IE */
3790 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3791
3792 /* Compose the response from HLR using received session ID */
3793 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3794 imsi := g_pars.imsi,
3795 sid := gsup_ms_req_complete.ies[1].val.session_id,
3796 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3797 ss := valueof(facility_net_req)
3798 );
3799
3800 /* Compose expected MT SS/FACILITY template with counter request */
3801 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3802 tid := 1, /* Response should arrive within the same transaction */
3803 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3804 facility := valueof(facility_net_req)
3805 );
3806
3807 /* Send response over GSUP */
3808 GSUP.send(gsup_net_req);
3809 /* Expect MT SS/FACILITY message with counter request */
3810 f_expect_mt_dtap_msg(ussd_net_req);
3811
3812 /* Compose MO SS/RELEASE COMPLETE */
3813 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3814 tid := 1, /* Response should arrive within the same transaction */
3815 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3816 facility := omit
3817 /* TODO: cause? */
3818 );
3819
3820 /* Compose expected HLR -> MSC abort message */
3821 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3822 imsi := g_pars.imsi,
3823 sid := gsup_ms_req_complete.ies[1].val.session_id,
3824 state := OSMO_GSUP_SESSION_STATE_END
3825 );
3826
3827 /* Abort transaction */
3828 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3829 /* Expect GSUP message indicating abort */
3830 f_expect_gsup_msg(gsup_abort);
3831
3832 f_expect_clear();
3833}
3834testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3835 var BSC_ConnHdlr vc_conn;
3836 f_init();
3837 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3838 vc_conn.done;
3839}
3840
Harald Weltee13cfb22019-04-23 16:52:02 +02003841
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003842/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003843friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003844runs on BSC_ConnHdlr {
3845 f_init_handler(pars);
3846
3847 /* Perform location update */
3848 f_perform_lu();
3849
3850 /* Send CM Service Request for SS/USSD */
3851 f_establish_fully(EST_TYPE_SS_ACT);
3852
3853 /* We need to inspect GSUP activity */
3854 f_create_gsup_expect(hex2str(g_pars.imsi));
3855
3856 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3857 invoke_id := 1,
3858 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3859 ussd_string := "#release_me");
3860
3861 /* Compose MO SS/REGISTER message with request */
3862 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3863 tid := 1, /* An arbitrary transaction identifier */
3864 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3865 facility := valueof(facility_ms_req));
3866
3867 /* Compose expected MSC -> HLR message */
3868 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3869 imsi := g_pars.imsi,
3870 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3871 ss := valueof(facility_ms_req));
3872
3873 /* To be used for sending response with correct session ID */
3874 var GSUP_PDU gsup_ms_req_complete;
3875
3876 /* Initiate a new SS transaction */
3877 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3878 /* Expect GSUP request with original Facility IE */
3879 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3880
3881 /* Don't respond, wait for timeout */
3882 f_sleep(3.0);
3883
3884 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3885 tid := 1, /* Should match the request's tid */
3886 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3887 cause := *, /* TODO: expect some specific value */
3888 facility := omit);
3889
3890 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3891 imsi := g_pars.imsi,
3892 sid := gsup_ms_req_complete.ies[1].val.session_id,
3893 state := OSMO_GSUP_SESSION_STATE_END,
3894 cause := ?); /* TODO: expect some specific value */
3895
3896 /* Expect release on both interfaces */
3897 interleave {
3898 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3899 [] GSUP.receive(gsup_rel) { };
3900 }
3901
3902 f_expect_clear();
3903 setverdict(pass);
3904}
3905testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3906 var BSC_ConnHdlr vc_conn;
3907 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003908 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003909 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3910 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003911 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003912}
3913
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003914/* MT (network-originated) USSD for unknown subscriber */
3915friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
3916runs on BSC_ConnHdlr {
3917 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
3918 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003919
3920 f_init_handler(pars);
3921 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
3922 f_create_gsup_expect(hex2str(imsi));
3923
3924 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3925 imsi := imsi,
3926 sid := sid,
3927 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3928 ss := f_rnd_octstring(23)
3929 );
3930
3931 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
3932 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3933 imsi := imsi,
3934 sid := sid,
3935 state := OSMO_GSUP_SESSION_STATE_END,
3936 cause := 2 /* FIXME: introduce an enumerated type! */
3937 );
3938
3939 /* Initiate a MT USSD notification */
3940 GSUP.send(gsup_req);
3941
3942 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07003943 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003944}
3945testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
3946 var BSC_ConnHdlr vc_conn;
3947 f_init();
3948 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
3949 vc_conn.done;
3950}
3951
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003952/* MO (mobile-originated) SS/USSD for unknown transaction */
3953friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
3954runs on BSC_ConnHdlr {
3955 f_init_handler(pars);
3956
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003957 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003958 f_create_gsup_expect(hex2str(g_pars.imsi));
3959
3960 /* Perform location update */
3961 f_perform_lu();
3962
3963 /* Send CM Service Request for SS/USSD */
3964 f_establish_fully(EST_TYPE_SS_ACT);
3965
3966 /* GSM 04.80 FACILITY message for a non-existing transaction */
3967 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
3968 tid := 1, /* An arbitrary transaction identifier */
3969 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3970 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3971 );
3972
3973 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
3974 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
3975 tid := 1, /* An arbitrary transaction identifier */
3976 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3977 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3978 );
3979
3980 /* Expected response from the network */
3981 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3982 tid := 1, /* Same as in the FACILITY message */
3983 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3984 facility := omit
3985 );
3986
3987 /* Send GSM 04.80 FACILITY for non-existing transaction */
3988 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
3989
3990 /* Expect GSM 04.80 RELEASE COMPLETE message */
3991 f_expect_mt_dtap_msg(mt_ss_rel);
3992 f_expect_clear();
3993
3994 /* Send another CM Service Request for SS/USSD */
3995 f_establish_fully(EST_TYPE_SS_ACT);
3996
3997 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
3998 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
3999
4000 /* Expect GSM 04.80 RELEASE COMPLETE message */
4001 f_expect_mt_dtap_msg(mt_ss_rel);
4002 f_expect_clear();
4003}
4004testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
4005 var BSC_ConnHdlr vc_conn;
4006 f_init();
4007 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
4008 vc_conn.done;
4009}
4010
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004011/* MT (network-originated) USSD for unknown session */
4012friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
4013runs on BSC_ConnHdlr {
4014 var OCT4 sid := '20000333'O;
4015
4016 f_init_handler(pars);
4017
4018 /* Perform location update */
4019 f_perform_lu();
4020
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004021 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004022 f_create_gsup_expect(hex2str(g_pars.imsi));
4023
4024 /* Request referencing a non-existing SS session */
4025 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4026 imsi := g_pars.imsi,
4027 sid := sid,
4028 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
4029 ss := f_rnd_octstring(23)
4030 );
4031
4032 /* Error with some cause value */
4033 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4034 imsi := g_pars.imsi,
4035 sid := sid,
4036 state := OSMO_GSUP_SESSION_STATE_END,
4037 cause := ? /* FIXME: introduce an enumerated type! */
4038 );
4039
4040 /* Initiate a MT USSD notification */
4041 GSUP.send(gsup_req);
4042
4043 /* Expect GSUP PROC_SS_ERROR message */
4044 f_expect_gsup_msg(gsup_rsp);
4045}
4046testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
4047 var BSC_ConnHdlr vc_conn;
4048 f_init();
4049 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
4050 vc_conn.done;
4051}
4052
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004053/* MT (network-originated) USSD and no response to Paging Request */
4054friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
4055runs on BSC_ConnHdlr {
4056 timer TP := 2.0; /* Paging timer */
4057
4058 f_init_handler(pars);
4059
4060 /* Perform location update */
4061 f_perform_lu();
4062
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004063 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004064 f_create_gsup_expect(hex2str(g_pars.imsi));
4065
4066 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4067 imsi := g_pars.imsi,
4068 sid := '20000444'O,
4069 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4070 ss := f_rnd_octstring(23)
4071 );
4072
4073 /* Error with some cause value */
4074 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4075 imsi := g_pars.imsi,
4076 sid := '20000444'O,
4077 state := OSMO_GSUP_SESSION_STATE_END,
4078 cause := ? /* FIXME: introduce an enumerated type! */
4079 );
4080
4081 /* Initiate a MT USSD notification */
4082 GSUP.send(gsup_req);
4083
4084 /* Send it to MSC and expect Paging Request */
4085 TP.start;
4086 alt {
4087 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4088 setverdict(pass);
4089 }
4090 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4091 setverdict(pass);
4092 }
4093 /* We don't expect anything else */
4094 [] as_unexp_gsup_or_bssap_msg();
4095 [] TP.timeout {
4096 setverdict(fail, "Timeout waiting for Paging Request");
4097 }
4098 }
4099
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07004100 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
4101 * OsmoMSC waits for Paging Response 10 seconds by default. */
4102 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004103}
4104testcase TC_proc_ss_paging_fail() runs on MTC_CT {
4105 var BSC_ConnHdlr vc_conn;
4106 f_init();
4107 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
4108 vc_conn.done;
4109}
4110
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004111/* MT (network-originated) USSD followed by immediate abort */
4112friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
4113runs on BSC_ConnHdlr {
4114 var octetstring facility := f_rnd_octstring(23);
4115 var OCT4 sid := '20000555'O;
4116 timer TP := 2.0;
4117
4118 f_init_handler(pars);
4119
4120 /* Perform location update */
4121 f_perform_lu();
4122
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004123 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004124 f_create_gsup_expect(hex2str(g_pars.imsi));
4125
4126 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
4127 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4128 imsi := g_pars.imsi, sid := sid,
4129 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4130 ss := facility
4131 );
4132
4133 /* On the MS side, we expect GSM 04.80 REGISTER message */
4134 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
4135 tid := 0, /* Most likely, it should be 0 */
4136 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4137 facility := facility
4138 );
4139
4140 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
4141 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
4142 imsi := g_pars.imsi, sid := sid,
4143 state := OSMO_GSUP_SESSION_STATE_END,
4144 cause := 0 /* FIXME: introduce an enumerated type! */
4145 );
4146
4147 /* On the MS side, we expect GSM 04.80 REGISTER message */
4148 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4149 tid := 0, /* Most likely, it should be 0 */
4150 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4151 cause := *, /* FIXME: expect some specific cause value */
4152 facility := omit
4153 );
4154
4155 /* Initiate a MT USSD with random payload */
4156 GSUP.send(gsup_req);
4157
4158 /* Expect Paging Request */
4159 TP.start;
4160 alt {
4161 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4162 setverdict(pass);
4163 }
4164 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4165 setverdict(pass);
4166 }
4167 /* We don't expect anything else */
4168 [] as_unexp_gsup_or_bssap_msg();
4169 [] TP.timeout {
4170 setverdict(fail, "Timeout waiting for Paging Request");
4171 }
4172 }
4173
4174 /* Send Paging Response and establish connection */
4175 f_establish_fully(EST_TYPE_PAG_RESP);
4176 /* Expect MT REGISTER message with random facility */
4177 f_expect_mt_dtap_msg(dtap_reg);
4178
4179 /* HLR/EUSE decides to abort the session even
4180 * before getting any response from the MS */
4181 /* Initiate a MT USSD with random payload */
4182 GSUP.send(gsup_abort);
4183
4184 /* Expect RELEASE COMPLETE on ths MS side */
4185 f_expect_mt_dtap_msg(dtap_rel);
4186
4187 f_expect_clear();
4188}
4189testcase TC_proc_ss_abort() runs on MTC_CT {
4190 var BSC_ConnHdlr vc_conn;
4191 f_init();
4192 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
4193 vc_conn.done;
4194}
4195
Harald Weltee13cfb22019-04-23 16:52:02 +02004196
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01004197/* Verify multiple concurrent MO SS/USSD transactions
4198 * (one subscriber - one transaction) */
4199testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
4200 var BSC_ConnHdlr vc_conn[16];
4201 var integer i;
4202
4203 f_init();
4204
4205 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4206 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
4207 }
4208
4209 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4210 vc_conn[i].done;
4211 }
4212}
4213
4214/* Verify multiple concurrent MT SS/USSD transactions
4215 * (one subscriber - one transaction) */
4216testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
4217 var BSC_ConnHdlr vc_conn[16];
4218 var integer i;
4219 var OCT4 sid;
4220
4221 f_init();
4222
4223 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4224 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
4225 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
4226 f_init_pars(226 + i, gsup_sid := sid));
4227 }
4228
4229 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4230 vc_conn[i].done;
4231 }
4232}
4233
4234
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004235/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
4236private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4237 pars.net.expect_auth := true;
4238 pars.net.expect_ciph := true;
4239 pars.net.kc_support := '02'O; /* A5/1 only */
4240 f_init_handler(pars);
4241
4242 g_pars.vec := f_gen_auth_vec_2g();
4243
4244 /* Can't use f_perform_lu() directly. Code below is based on it. */
4245
4246 /* tell GSUP dispatcher to send this IMSI to us */
4247 f_create_gsup_expect(hex2str(g_pars.imsi));
4248
4249 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4250 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02004251 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004252
4253 f_mm_auth();
4254
4255 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4256 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4257 alt {
4258 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4259 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
4260 }
4261 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4262 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4263 mtc.stop;
4264 }
4265 [] BSSAP.receive {
4266 setverdict(fail, "Unknown/unexpected BSSAP received");
4267 mtc.stop;
4268 }
4269 }
Harald Welte79f1e452020-08-18 22:55:02 +02004270 f_expect_common_id();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004271
4272 /* Expect LU reject from MSC. */
4273 alt {
4274 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4275 setverdict(pass);
4276 }
4277 [] BSSAP.receive {
4278 setverdict(fail, "Unknown/unexpected BSSAP received");
4279 mtc.stop;
4280 }
4281 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01004282 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004283}
4284
4285testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
4286 var BSC_ConnHdlr vc_conn;
4287 f_init();
4288 f_vty_config(MSCVTY, "network", "encryption a5 1");
4289
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02004290 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52, verify_cell_id := false);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004291 vc_conn.done;
4292}
4293
Harald Welteb2284bd2019-05-10 11:30:43 +02004294/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
4295friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4296 f_init_handler(pars);
4297
4298 /* tell GSUP dispatcher to send this IMSI to us */
4299 f_create_gsup_expect(hex2str(g_pars.imsi));
4300
4301 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4302 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4303
4304 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4305 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4306 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +02004307 f_expect_common_id();
Harald Welteb2284bd2019-05-10 11:30:43 +02004308
4309 /* Expect LU reject from MSC. */
4310 alt {
4311 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4312 setverdict(pass);
4313 }
4314 [] BSSAP.receive {
4315 setverdict(fail, "Unknown/unexpected BSSAP received");
4316 mtc.stop;
4317 }
4318 }
4319 f_expect_clear();
4320}
4321testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4322 var BSC_ConnHdlr vc_conn;
4323 f_init();
4324 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4325 vc_conn.done;
4326}
4327
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004328private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4329 pars.net.expect_auth := true;
4330 pars.net.expect_ciph := true;
4331 pars.net.kc_support := kc_support;
4332 f_init_handler(pars);
4333
4334 g_pars.vec := f_gen_auth_vec_2g();
4335
4336 /* Can't use f_perform_lu() directly. Code below is based on it. */
4337
4338 /* tell GSUP dispatcher to send this IMSI to us */
4339 f_create_gsup_expect(hex2str(g_pars.imsi));
4340
4341 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4342 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4343 f_cl3_or_initial_ue(l3_lu);
4344
4345 f_mm_auth();
4346
4347 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4348 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4349 alt {
4350 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4351 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4352 }
4353 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4354 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4355 repeat;
4356 }
4357 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4358 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4359 mtc.stop;
4360 }
4361 [] BSSAP.receive {
4362 setverdict(fail, "Unknown/unexpected BSSAP received");
4363 mtc.stop;
4364 }
4365 }
Harald Welte79f1e452020-08-18 22:55:02 +02004366 f_expect_common_id();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004367
4368 /* TODO: Verify MSC is using the best cipher available! How? */
4369
4370 f_msc_lu_hlr();
4371 f_accept_reject_lu();
4372 f_expect_clear();
4373 setverdict(pass);
4374}
4375
4376/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4377private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4378 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4379}
4380
4381/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4382private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4383 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4384}
4385
4386/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4387private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4388 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4389}
4390
4391testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4392 var BSC_ConnHdlr vc_conn;
4393 f_init();
4394 f_vty_config(MSCVTY, "network", "encryption a5 1");
4395
4396 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4397 vc_conn.done;
4398}
4399
4400testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4401 var BSC_ConnHdlr vc_conn;
4402 f_init();
4403 f_vty_config(MSCVTY, "network", "encryption a5 3");
4404
4405 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4406 vc_conn.done;
4407}
4408
4409testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4410 var BSC_ConnHdlr vc_conn;
4411 f_init();
4412 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4413
4414 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4415 vc_conn.done;
4416}
Harald Welteb2284bd2019-05-10 11:30:43 +02004417
Harald Weltef640a012018-04-14 17:49:21 +02004418/* TODO (SMS):
4419 * different user data lengths
4420 * SMPP transaction mode with unsuccessful delivery
4421 * queued MT-SMS with no paging response + later delivery
4422 * different data coding schemes
4423 * multi-part SMS
4424 * user-data headers
4425 * TP-PID for SMS to SIM
4426 * behavior if SMS memory is full + RP-SMMA
4427 * delivery reports
4428 * SMPP osmocom extensions
4429 * more-messages-to-send
4430 * SMS during ongoing call (SACCH/SAPI3)
4431 */
4432
4433/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004434 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4435 * malformed messages (missing IE, invalid message type): properly rejected?
4436 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4437 * 3G/2G auth permutations
4438 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004439 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004440 * too long L3 INFO in DTAP
4441 * too long / padded BSSAP
4442 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004443 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004444
Harald Weltee13cfb22019-04-23 16:52:02 +02004445/***********************************************************************
4446 * SGsAP Testing
4447 ***********************************************************************/
4448
Philipp Maier948747b2019-04-02 15:22:33 +02004449/* Check if a subscriber exists in the VLR */
4450private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4451
4452 var CtrlValue active_subsribers;
4453 var integer rc;
4454 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4455
4456 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4457 if (rc < 0) {
4458 return false;
4459 }
4460
4461 return true;
4462}
4463
Harald Welte4263c522018-12-06 11:56:27 +01004464/* Perform a location updatye at the A-Interface and run some checks to confirm
4465 * that everything is back to normal. */
4466private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4467 var SmsParameters spars := valueof(t_SmsPars);
4468
4469 /* Perform a location update, the SGs association is expected to fall
4470 * back to NULL */
4471 f_perform_lu();
4472 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4473
4474 /* Trigger a paging request and expect the paging on BSSMAP, this is
4475 * to make sure that pagings are sent throught the A-Interface again
4476 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004477 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004478 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4479
4480 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004481 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4482 setverdict(pass);
4483 }
Harald Welte62113fc2019-05-09 13:04:02 +02004484 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004485 setverdict(pass);
4486 }
4487 [] SGsAP.receive {
4488 setverdict(fail, "Received unexpected message on SGs");
4489 }
4490 }
4491
4492 /* Send an SMS to make sure that also payload messages are routed
4493 * throught the A-Interface again */
4494 f_establish_fully(EST_TYPE_MO_SMS);
4495 f_mo_sms(spars);
4496 f_expect_clear();
4497}
4498
4499private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4500 var charstring vlr_name;
4501 f_init_handler(pars);
4502
4503 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4504 log("VLR name: ", vlr_name);
4505 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004506 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004507}
4508
4509testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004510 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004511 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004512 f_init(1, true);
4513 pars := f_init_pars(11810, true);
4514 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004515 vc_conn.done;
4516}
4517
4518/* like f_mm_auth() but for SGs */
4519function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4520 if (g_pars.net.expect_auth) {
4521 g_pars.vec := f_gen_auth_vec_3g();
4522 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4523 g_pars.vec.sres,
4524 g_pars.vec.kc,
4525 g_pars.vec.ik,
4526 g_pars.vec.ck,
4527 g_pars.vec.autn,
4528 g_pars.vec.res));
4529 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4530 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4531 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4532 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4533 }
4534}
4535
4536/* like f_perform_lu(), but on SGs rather than BSSAP */
4537function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4538 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4539 var PDU_SGsAP lur;
4540 var PDU_SGsAP lua;
4541 var PDU_SGsAP mm_info;
4542 var octetstring mm_info_dtap;
4543
4544 /* tell GSUP dispatcher to send this IMSI to us */
4545 f_create_gsup_expect(hex2str(g_pars.imsi));
4546
4547 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4548 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4549 /* Old LAI, if MS sends it */
4550 /* TMSI status, if MS has no valid TMSI */
4551 /* IMEISV, if it supports "automatic device detection" */
4552 /* TAI, if available in MME */
4553 /* E-CGI, if available in MME */
4554 SGsAP.send(lur);
4555
4556 /* FIXME: is this really done over SGs? The Ue is already authenticated
4557 * via the MME ... */
4558 f_mm_auth_sgs();
4559
4560 /* Expect MSC to perform LU with HLR */
4561 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4562 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4563 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4564 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4565
4566 alt {
4567 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4568 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4569 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4570 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4571 }
4572 setverdict(pass);
4573 }
4574 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4575 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4576 }
4577 [] SGsAP.receive {
4578 setverdict(fail, "Received unexpected message on SGs");
4579 }
4580 }
4581
4582 /* Check MM information */
4583 if (mp_mm_info == true) {
4584 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4585 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4586 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4587 setverdict(fail, "Unexpected MM Information");
4588 }
4589 }
4590
4591 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4592}
4593
4594private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4595 f_init_handler(pars);
4596 f_sgs_perform_lu();
4597 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4598
4599 f_sgsap_bssmap_screening();
4600
4601 setverdict(pass);
4602}
4603testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004604 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004605 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004606 f_init(1, true);
4607 pars := f_init_pars(11811, true);
4608 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004609 vc_conn.done;
4610}
4611
4612/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4613private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4614 f_init_handler(pars);
4615 var PDU_SGsAP lur;
4616
4617 f_create_gsup_expect(hex2str(g_pars.imsi));
4618 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4619 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4620 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4621 SGsAP.send(lur);
4622
4623 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4624 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4625 alt {
4626 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4627 setverdict(pass);
4628 }
4629 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4630 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4631 mtc.stop;
4632 }
4633 [] SGsAP.receive {
4634 setverdict(fail, "Received unexpected message on SGs");
4635 }
4636 }
4637
4638 f_sgsap_bssmap_screening();
4639
4640 setverdict(pass);
4641}
4642testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004643 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004644 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004645 f_init(1, true);
4646 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004647
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004648 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004649 vc_conn.done;
4650}
4651
4652/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4653private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4654 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4655 var PDU_SGsAP lur;
4656
4657 f_init_handler(pars);
4658
4659 /* tell GSUP dispatcher to send this IMSI to us */
4660 f_create_gsup_expect(hex2str(g_pars.imsi));
4661
4662 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4663 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4664 /* Old LAI, if MS sends it */
4665 /* TMSI status, if MS has no valid TMSI */
4666 /* IMEISV, if it supports "automatic device detection" */
4667 /* TAI, if available in MME */
4668 /* E-CGI, if available in MME */
4669 SGsAP.send(lur);
4670
4671 /* FIXME: is this really done over SGs? The Ue is already authenticated
4672 * via the MME ... */
4673 f_mm_auth_sgs();
4674
4675 /* Expect MSC to perform LU with HLR */
4676 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4677 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4678 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4679 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4680
4681 alt {
4682 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4683 setverdict(pass);
4684 }
4685 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4686 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4687 }
4688 [] SGsAP.receive {
4689 setverdict(fail, "Received unexpected message on SGs");
4690 }
4691 }
4692
4693 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4694
4695 /* Wait until the VLR has abort the TMSI reallocation procedure */
4696 f_sleep(45.0);
4697
4698 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4699 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4700
4701 f_sgsap_bssmap_screening();
4702
4703 setverdict(pass);
4704}
4705testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004706 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004707 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004708 f_init(1, true);
4709 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004710
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004711 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004712 vc_conn.done;
4713}
4714
4715private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4716runs on BSC_ConnHdlr {
4717 f_init_handler(pars);
4718 f_sgs_perform_lu();
4719 f_sleep(3.0);
4720
4721 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4722 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4723 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4724 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4725
4726 f_sgsap_bssmap_screening();
4727
4728 setverdict(pass);
4729}
4730testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004731 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004732 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004733 f_init(1, true);
4734 pars := f_init_pars(11814, true);
4735 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004736 vc_conn.done;
4737}
4738
Philipp Maierfc19f172019-03-21 11:17:54 +01004739private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4740runs on BSC_ConnHdlr {
4741 f_init_handler(pars);
4742 f_sgs_perform_lu();
4743 f_sleep(3.0);
4744
4745 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4746 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4747 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4748 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4749
4750 f_sgsap_bssmap_screening();
4751
4752 setverdict(pass);
4753}
4754testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4755 var BSC_ConnHdlrPars pars;
4756 var BSC_ConnHdlr vc_conn;
4757 f_init(1, true);
4758 pars := f_init_pars(11814, true);
4759 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4760 vc_conn.done;
4761}
4762
Harald Welte4263c522018-12-06 11:56:27 +01004763private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4764runs on BSC_ConnHdlr {
4765 f_init_handler(pars);
4766 f_sgs_perform_lu();
4767 f_sleep(3.0);
4768
4769 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4770 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4771 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004772
4773 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4774 setverdict(fail, "subscriber not removed from VLR");
4775 }
Harald Welte4263c522018-12-06 11:56:27 +01004776
4777 f_sgsap_bssmap_screening();
4778
4779 setverdict(pass);
4780}
4781testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004782 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004783 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004784 f_init(1, true);
4785 pars := f_init_pars(11815, true);
4786 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004787 vc_conn.done;
4788}
4789
Philipp Maier5d812702019-03-21 10:51:26 +01004790private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4791runs on BSC_ConnHdlr {
4792 f_init_handler(pars);
4793 f_sgs_perform_lu();
4794 f_sleep(3.0);
4795
4796 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4797 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4798 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4799
4800 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4801 setverdict(fail, "subscriber not removed from VLR");
4802 }
4803
4804 f_sgsap_bssmap_screening();
4805
4806 setverdict(pass);
4807}
4808testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4809 var BSC_ConnHdlrPars pars;
4810 var BSC_ConnHdlr vc_conn;
4811 f_init(1, true);
4812 pars := f_init_pars(11815, true);
4813 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4814 vc_conn.done;
4815}
4816
Harald Welte4263c522018-12-06 11:56:27 +01004817/* Trigger a paging request via VTY and send a paging reject in response */
4818private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4819runs on BSC_ConnHdlr {
4820 f_init_handler(pars);
4821 f_sgs_perform_lu();
4822 f_sleep(1.0);
4823
4824 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4825 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4826 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4827 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4828
4829 /* Initiate paging via VTY */
4830 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4831 alt {
4832 [] SGsAP.receive(exp_resp) {
4833 setverdict(pass);
4834 }
4835 [] SGsAP.receive {
4836 setverdict(fail, "Received unexpected message on SGs");
4837 }
4838 }
4839
4840 /* Now reject the paging */
4841 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4842
4843 /* Wait for the states inside the MSC to settle and check the state
4844 * of the SGs Association */
4845 f_sleep(1.0);
4846 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4847
4848 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4849 * but we also need to cover tha case where the cause code indicates an
4850 * "IMSI detached for EPS services". In those cases the VLR is expected to
4851 * try paging on tha A/Iu interface. This will be another testcase similar to
4852 * this one, but extended with checks for the presence of the A/Iu paging
4853 * messages. */
4854
4855 f_sgsap_bssmap_screening();
4856
4857 setverdict(pass);
4858}
4859testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004860 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004861 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004862 f_init(1, true);
4863 pars := f_init_pars(11816, true);
4864 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004865 vc_conn.done;
4866}
4867
4868/* Trigger a paging request via VTY and send a paging reject that indicates
4869 * that the subscriber intentionally rejected the call. */
4870private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4871runs on BSC_ConnHdlr {
4872 f_init_handler(pars);
4873 f_sgs_perform_lu();
4874 f_sleep(1.0);
4875
4876 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4877 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4878 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4879 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4880
4881 /* Initiate paging via VTY */
4882 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4883 alt {
4884 [] SGsAP.receive(exp_resp) {
4885 setverdict(pass);
4886 }
4887 [] SGsAP.receive {
4888 setverdict(fail, "Received unexpected message on SGs");
4889 }
4890 }
4891
4892 /* Now reject the paging */
4893 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4894
4895 /* Wait for the states inside the MSC to settle and check the state
4896 * of the SGs Association */
4897 f_sleep(1.0);
4898 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4899
4900 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4901 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4902 * to check back how this works and how it can be tested */
4903
4904 f_sgsap_bssmap_screening();
4905
4906 setverdict(pass);
4907}
4908testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004909 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004910 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004911 f_init(1, true);
4912 pars := f_init_pars(11817, true);
4913 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004914 vc_conn.done;
4915}
4916
4917/* Trigger a paging request via VTY and send an UE unreacable messge in response */
4918private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
4919runs on BSC_ConnHdlr {
4920 f_init_handler(pars);
4921 f_sgs_perform_lu();
4922 f_sleep(1.0);
4923
4924 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4925 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4926 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4927 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4928
4929 /* Initiate paging via VTY */
4930 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4931 alt {
4932 [] SGsAP.receive(exp_resp) {
4933 setverdict(pass);
4934 }
4935 [] SGsAP.receive {
4936 setverdict(fail, "Received unexpected message on SGs");
4937 }
4938 }
4939
4940 /* Now pretend that the UE is unreachable */
4941 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
4942
4943 /* Wait for the states inside the MSC to settle and check the state
4944 * of the SGs Association. */
4945 f_sleep(1.0);
4946 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4947
4948 f_sgsap_bssmap_screening();
4949
4950 setverdict(pass);
4951}
4952testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004953 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004954 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004955 f_init(1, true);
4956 pars := f_init_pars(11818, true);
4957 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004958 vc_conn.done;
4959}
4960
4961/* Trigger a paging request via VTY but don't respond to it */
4962private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
4963runs on BSC_ConnHdlr {
4964 f_init_handler(pars);
4965 f_sgs_perform_lu();
4966 f_sleep(1.0);
4967
4968 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4969 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02004970 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01004971 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4972 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4973
4974 /* Initiate paging via VTY */
4975 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4976 alt {
4977 [] SGsAP.receive(exp_resp) {
4978 setverdict(pass);
4979 }
4980 [] SGsAP.receive {
4981 setverdict(fail, "Received unexpected message on SGs");
4982 }
4983 }
4984
Philipp Maier34218102019-09-24 09:15:49 +02004985 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
4986 * after some time */
4987 timer T := 10.0;
4988 T.start
4989 alt {
4990 [] SGsAP.receive(exp_serv_abrt)
4991 {
4992 setverdict(pass);
4993 }
4994 [] SGsAP.receive {
4995 setverdict(fail, "unexpected SGsAP message received");
4996 self.stop;
4997 }
4998 [] T.timeout {
4999 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
5000 self.stop;
5001 }
5002 }
5003
5004 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01005005 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5006
5007 f_sgsap_bssmap_screening();
5008
5009 setverdict(pass);
5010}
5011testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005012 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005013 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005014 f_init(1, true);
5015 pars := f_init_pars(11819, true);
5016 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005017 vc_conn.done;
5018}
5019
5020/* Trigger a paging request via VTY and slip in an LU */
5021private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
5022runs on BSC_ConnHdlr {
5023 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5024 f_init_handler(pars);
5025
5026 /* First we prepar the situation, where the SGs association is in state
5027 * NULL and the confirmed by radio contact indicator is set to false
5028 * as well. This can be archived by performing an SGs LU and then
5029 * resetting the VLR */
5030 f_sgs_perform_lu();
5031 f_sgsap_reset_mme(mp_mme_name);
5032 f_sleep(1.0);
5033 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5034
5035 /* Perform a paging, expect the paging messages on the SGs interface */
5036 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5037 alt {
5038 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5039 setverdict(pass);
5040 }
5041 [] SGsAP.receive {
5042 setverdict(fail, "Received unexpected message on SGs");
5043 }
5044 }
5045
5046 /* Perform the LU as normal */
5047 f_sgs_perform_lu();
5048 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5049
5050 /* Expect a new paging request right after the LU */
5051 alt {
5052 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5053 setverdict(pass);
5054 }
5055 [] SGsAP.receive {
5056 setverdict(fail, "Received unexpected message on SGs");
5057 }
5058 }
5059
5060 /* Test is done now, lets round everything up by rejecting the paging
5061 * cleanly. */
5062 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
5063 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5064
5065 f_sgsap_bssmap_screening();
5066
5067 setverdict(pass);
5068}
5069testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005070 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005071 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005072 f_init(1, true);
5073 pars := f_init_pars(11820, true);
5074 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005075 vc_conn.done;
5076}
5077
5078/* Send unexpected unit-data through the SGs interface */
5079private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5080 f_init_handler(pars);
5081 f_sleep(1.0);
5082
5083 /* This simulates what happens when a subscriber without SGs
5084 * association gets unitdata via the SGs interface. */
5085
5086 /* Make sure the subscriber exists and the SGs association
5087 * is in NULL state */
5088 f_perform_lu();
5089 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5090
5091 /* Send some random unit data, the MSC/VLR should send a release
5092 * immediately. */
5093 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5094 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
5095
5096 f_sgsap_bssmap_screening();
5097
5098 setverdict(pass);
5099}
5100testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005101 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005102 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005103 f_init(1, true);
5104 pars := f_init_pars(11821, true);
5105 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005106 vc_conn.done;
5107}
5108
5109/* Send unsolicited unit-data through the SGs interface */
5110private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5111 f_init_handler(pars);
5112 f_sleep(1.0);
5113
5114 /* This simulates what happens when the MME attempts to send unitdata
5115 * to a subscriber that is completely unknown to the VLR */
5116
5117 /* Send some random unit data, the MSC/VLR should send a release
5118 * immediately. */
5119 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5120 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
5121
5122 f_sgsap_bssmap_screening();
5123
Harald Welte4d15fa72020-08-19 08:58:28 +02005124 /* clean-up VLR state about this subscriber */
5125 f_imsi_detach_by_imsi();
5126
Harald Welte4263c522018-12-06 11:56:27 +01005127 setverdict(pass);
5128}
5129testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005130 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005131 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005132 f_init(1, true);
5133 pars := f_init_pars(11822, true);
5134 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005135 vc_conn.done;
5136}
5137
5138private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
5139 /* FIXME: Match an actual payload (second questionmark), the type is
5140 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
5141 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
5142 setverdict(fail, "Unexpected SMS related PDU from MSC");
5143 mtc.stop;
5144 }
5145}
5146
5147/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
5148function f_mt_sms_sgs(inout SmsParameters spars)
5149runs on BSC_ConnHdlr {
5150 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5151 var template (value) RPDU_MS_SGSN rp_mo;
5152 var template (value) PDU_ML3_MS_NW l3_mo;
5153
5154 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5155 var template RPDU_SGSN_MS rp_mt;
5156 var template PDU_ML3_NW_MS l3_mt;
5157
5158 var PDU_ML3_NW_MS sgsap_l3_mt;
5159
5160 var default d := activate(as_other_sms_sgs());
5161
5162 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
5163 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09005164 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01005165 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
5166
5167 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
5168
5169 /* Extract relevant identifiers */
5170 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
5171 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
5172
5173 /* send CP-ACK for CP-DATA just received */
5174 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
5175
5176 SGsAP.send(l3_mo);
5177
5178 /* send RP-ACK for RP-DATA */
5179 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
5180 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
5181
5182 SGsAP.send(l3_mo);
5183
5184 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
5185 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
5186
5187 SGsAP.receive(l3_mt);
5188
5189 deactivate(d);
5190
5191 setverdict(pass);
5192}
5193
5194/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
5195function f_mo_sms_sgs(inout SmsParameters spars)
5196runs on BSC_ConnHdlr {
5197 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5198 var template (value) RPDU_MS_SGSN rp_mo;
5199 var template (value) PDU_ML3_MS_NW l3_mo;
5200
5201 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5202 var template RPDU_SGSN_MS rp_mt;
5203 var template PDU_ML3_NW_MS l3_mt;
5204
5205 var default d := activate(as_other_sms_sgs());
5206
5207 /* just in case this is routed to SMPP.. */
5208 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
5209
5210 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
5211 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09005212 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01005213 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
5214
5215 SGsAP.send(l3_mo);
5216
5217 /* receive CP-ACK for CP-DATA above */
5218 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
5219
5220 if (ispresent(spars.exp_rp_err)) {
5221 /* expect an RP-ERROR message from MSC with given cause */
5222 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
5223 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5224 SGsAP.receive(l3_mt);
5225 /* send CP-ACK for CP-DATA just received */
5226 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5227 SGsAP.send(l3_mo);
5228 } else {
5229 /* expect RP-ACK for RP-DATA */
5230 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
5231 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5232 SGsAP.receive(l3_mt);
5233 /* send CP-ACO for CP-DATA just received */
5234 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5235 SGsAP.send(l3_mo);
5236 }
5237
5238 deactivate(d);
5239
5240 setverdict(pass);
5241}
5242
5243private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
5244runs on BSC_ConnHdlr {
5245 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
5246}
5247
5248/* Send a MT SMS via SGs interface */
5249private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5250 f_init_handler(pars);
5251 f_sgs_perform_lu();
5252 f_sleep(1.0);
5253 var SmsParameters spars := valueof(t_SmsPars);
5254 spars.tp.ud := 'C8329BFD064D9B53'O;
5255
5256 /* Trigger SMS via VTY */
5257 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5258 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5259
5260 /* Expect a paging request and respond accordingly with a service request */
5261 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
5262 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
5263
5264 /* Connection is now live, receive the MT-SMS */
5265 f_mt_sms_sgs(spars);
5266
5267 /* Expect a concluding release from the MSC */
5268 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5269
5270 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5271 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5272
5273 f_sgsap_bssmap_screening();
5274
5275 setverdict(pass);
5276}
5277testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005278 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005279 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005280 f_init(1, true);
5281 pars := f_init_pars(11823, true);
5282 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005283 vc_conn.done;
5284}
5285
5286/* Send a MO SMS via SGs interface */
5287private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5288 f_init_handler(pars);
5289 f_sgs_perform_lu();
5290 f_sleep(1.0);
5291 var SmsParameters spars := valueof(t_SmsPars);
5292 spars.tp.ud := 'C8329BFD064D9B53'O;
5293
5294 /* Send the MO-SMS */
5295 f_mo_sms_sgs(spars);
5296
5297 /* Expect a concluding release from the MSC/VLR */
5298 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5299
5300 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5301 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5302
5303 setverdict(pass);
5304
5305 f_sgsap_bssmap_screening()
5306}
5307testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005308 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005309 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005310 f_init(1, true);
5311 pars := f_init_pars(11824, true);
5312 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005313 vc_conn.done;
5314}
5315
5316/* Trigger sending of an MT sms via VTY but never respond to anything */
5317private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5318 f_init_handler(pars, 170.0);
5319 f_sgs_perform_lu();
5320 f_sleep(1.0);
5321
5322 var SmsParameters spars := valueof(t_SmsPars);
5323 spars.tp.ud := 'C8329BFD064D9B53'O;
5324 var integer page_count := 0;
5325 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5326 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5327 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5328 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5329
5330 /* Trigger SMS via VTY */
5331 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5332
Neels Hofmeyr16237742019-03-06 15:34:01 +01005333 /* Expect the MSC/VLR to page exactly once */
5334 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005335
5336 /* Wait some time to make sure the MSC is not delivering any further
5337 * paging messages or anything else that could be unexpected. */
5338 timer T := 20.0;
5339 T.start
5340 alt {
5341 [] SGsAP.receive(exp_pag_req)
5342 {
5343 setverdict(fail, "paging seems not to stop!");
5344 mtc.stop;
5345 }
5346 [] SGsAP.receive {
5347 setverdict(fail, "unexpected SGsAP message received");
5348 self.stop;
5349 }
5350 [] T.timeout {
5351 setverdict(pass);
5352 }
5353 }
5354
5355 /* Even on a failed paging the SGs Association should stay intact */
5356 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5357
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005358 /* Make sure that the SMS we just inserted is cleared and the
5359 * subscriber is expired. This is necessary because otherwise the MSC
5360 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005361
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005362 f_vty_sms_clear(hex2str(g_pars.imsi));
5363
Harald Welte4263c522018-12-06 11:56:27 +01005364 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5365
5366 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005367
5368 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005369}
5370testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005371 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005372 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005373 f_init(1, true);
5374 pars := f_init_pars(11825, true);
5375 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005376 vc_conn.done;
5377}
5378
5379/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5380private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5381 f_init_handler(pars, 150.0);
5382 f_sgs_perform_lu();
5383 f_sleep(1.0);
5384
5385 var SmsParameters spars := valueof(t_SmsPars);
5386 spars.tp.ud := 'C8329BFD064D9B53'O;
5387 var integer page_count := 0;
5388 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5389 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5390 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5391 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5392
5393 /* Trigger SMS via VTY */
5394 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5395
5396 /* Expect a paging request and reject it immediately */
5397 SGsAP.receive(exp_pag_req);
5398 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5399
5400 /* The MSC/VLR should no longer try to page once the paging has been
5401 * rejected. Wait some time and check if there are no unexpected
5402 * messages on the SGs interface. */
5403 timer T := 20.0;
5404 T.start
5405 alt {
5406 [] SGsAP.receive(exp_pag_req)
5407 {
5408 setverdict(fail, "paging seems not to stop!");
5409 mtc.stop;
5410 }
5411 [] SGsAP.receive {
5412 setverdict(fail, "unexpected SGsAP message received");
5413 self.stop;
5414 }
5415 [] T.timeout {
5416 setverdict(pass);
5417 }
5418 }
5419
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005420 f_vty_sms_clear(hex2str(g_pars.imsi));
5421
Harald Welte4263c522018-12-06 11:56:27 +01005422 /* A rejected paging with IMSI_unknown (see above) should always send
5423 * the SGs association to NULL. */
5424 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5425
5426 f_sgsap_bssmap_screening();
5427
Harald Welte4263c522018-12-06 11:56:27 +01005428 setverdict(pass);
5429}
5430testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005431 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005432 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005433 f_init(1, true);
5434 pars := f_init_pars(11826, true);
5435 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005436 vc_conn.done;
5437}
5438
5439/* Perform an MT CSDB call including LU */
5440private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5441 f_init_handler(pars);
5442
5443 /* Be sure that the BSSMAP reset is done before we begin. */
5444 f_sleep(2.0);
5445
5446 /* Testcase variation: See what happens when we do a regular BSSMAP
5447 * LU first (this should not hurt in any way!) */
5448 if (bssmap_lu) {
5449 f_perform_lu();
5450 }
5451
5452 f_sgs_perform_lu();
5453 f_sleep(1.0);
5454
5455 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5456 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005457
5458 /* Initiate a call via MNCC interface */
5459 f_mt_call_initate(cpars);
5460
5461 /* Expect a paging request and respond accordingly with a service request */
5462 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5463 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5464
5465 /* Complete the call, hold it for some time and then tear it down */
5466 f_mt_call_complete(cpars);
5467 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005468 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005469
5470 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5471 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5472
Harald Welte4263c522018-12-06 11:56:27 +01005473 /* Test for successful return by triggering a paging, when the paging
5474 * request is received via SGs, we can be sure that the MSC/VLR has
5475 * recognized that the UE is now back on 4G */
5476 f_sleep(1.0);
5477 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5478 alt {
5479 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5480 setverdict(pass);
5481 }
5482 [] SGsAP.receive {
5483 setverdict(fail, "Received unexpected message on SGs");
5484 }
5485 }
5486
5487 f_sgsap_bssmap_screening();
5488
5489 setverdict(pass);
5490}
5491
5492/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5493private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5494 f_mt_lu_and_csfb_call(id, pars, true);
5495}
5496testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005497 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005498 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005499 f_init(1, true);
5500 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005501
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005502 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005503 vc_conn.done;
5504}
5505
Harald Welte4263c522018-12-06 11:56:27 +01005506/* Perform a SGSAP LU and then make a CSFB call */
5507private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5508 f_mt_lu_and_csfb_call(id, pars, false);
5509}
5510testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005511 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005512 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005513 f_init(1, true);
5514 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005515
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005516 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005517 vc_conn.done;
5518}
5519
Philipp Maier628c0052019-04-09 17:36:57 +02005520/* Simulate an HLR/VLR failure */
5521private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5522 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5523 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5524
5525 var PDU_SGsAP lur;
5526
5527 f_init_handler(pars);
5528
5529 /* Attempt location update (which is expected to fail) */
5530 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5531 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5532 SGsAP.send(lur);
5533
5534 /* Respond to SGsAP-RESET-INDICATION from VLR */
5535 alt {
5536 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5537 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5538 setverdict(pass);
5539 }
5540 [] SGsAP.receive {
5541 setverdict(fail, "Received unexpected message on SGs");
5542 }
5543 }
5544
5545 f_sleep(1.0);
5546 setverdict(pass);
5547}
5548testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5549 var BSC_ConnHdlrPars pars;
5550 var BSC_ConnHdlr vc_conn;
5551 f_init(1, true, false);
5552 pars := f_init_pars(11811, true, false);
5553 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5554 vc_conn.done;
5555}
5556
Harald Welte4263c522018-12-06 11:56:27 +01005557/* SGs TODO:
5558 * LU attempt for IMSI without NAM_PS in HLR
5559 * LU attempt with AUTH FAIL due to invalid RES/SRES
5560 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5561 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5562 * implicit IMSI detach from EPS
5563 * implicit IMSI detach from non-EPS
5564 * MM INFO
5565 *
5566 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005567
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005568private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5569 f_init_handler(pars);
5570 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005571
5572 f_perform_lu();
5573 f_mo_call_establish(cpars);
5574
5575 f_sleep(1.0);
5576
5577 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5578 var BssmapCause cause := enum2int(cause_val);
5579
5580 var template BSSMAP_FIELD_CellIdentificationList cil;
5581 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5582
5583 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5584 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5585
5586 f_call_hangup(cpars, true);
5587}
5588testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5589 var BSC_ConnHdlr vc_conn;
5590 f_init();
5591
5592 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5593 vc_conn.done;
5594}
5595
5596private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5597 var MgcpCommand mgcp_cmd;
5598 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005599 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005600 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005601 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005602 { int2str(cpars.rtp_payload_type) },
5603 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5604 cpars.rtp_sdp_format)),
5605 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005606 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_2.mgcp_connection_id, sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005607 repeat;
5608 }
5609}
5610
5611private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005612 var CallParameters cpars;
5613
5614 cpars := valueof(t_CallParams('12345'H, 0));
5615 if (pars.use_ipv6) {
5616 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5617 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5618 cpars.bss_rtp_ip := "::3";
5619 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005620
5621 f_init_handler(pars);
5622
5623 f_vty_transceive(MSCVTY, "configure terminal");
5624 f_vty_transceive(MSCVTY, "msc");
5625 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
5626 f_vty_transceive(MSCVTY, "neighbor a lac 5 ran-pc 0.24.2");
5627 f_vty_transceive(MSCVTY, "exit");
5628 f_vty_transceive(MSCVTY, "exit");
5629
5630 f_perform_lu();
5631 f_mo_call_establish(cpars);
5632
5633 f_sleep(1.0);
5634
5635 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5636
5637 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5638 var BssmapCause cause := enum2int(cause_val);
5639
5640 var template BSSMAP_FIELD_CellIdentificationList cil;
5641 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 5) } };
5642
5643 /* old BSS sends Handover Required */
5644 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5645
5646 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5647
5648 /* MSC forwards the RR Handover Command to old BSS */
5649 var PDU_BSSAP ho_command;
5650 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5651
5652 log("GOT HandoverCommand", ho_command);
5653
5654 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5655
5656 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5657 f_expect_clear();
5658
5659 log("FIRST inter-BSC Handover done");
5660
5661
5662 /* ------------------------ */
5663
5664 /* Ok, that went well, now the other BSC is handovering back here --
5665 * from now on this here is the new BSS. */
5666 f_create_bssmap_exp_handoverRequest(193);
5667
5668 var PDU_BSSAP ho_request;
5669 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5670
5671 /* new BSS composes a RR Handover Command */
5672 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5673 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005674 var BSSMAP_IE_AoIP_TransportLayerAddress tla tla :=
5675 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005676 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5677 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5678
5679 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5680
5681 f_sleep(0.5);
5682
5683 /* Notify that the MS is now over here */
5684
5685 BSSAP.send(ts_BSSMAP_HandoverDetect);
5686 f_sleep(0.1);
5687 BSSAP.send(ts_BSSMAP_HandoverComplete);
5688
5689 f_sleep(3.0);
5690
5691 deactivate(ack_mdcx);
5692
5693 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5694
5695 /* blatant cheating */
5696 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5697 last_n_sd[0] := 3;
5698 f_bssmap_continue_after_n_sd(last_n_sd);
5699
5700 f_call_hangup(cpars, true);
5701 f_sleep(1.0);
5702 deactivate(ccrel);
5703
5704 setverdict(pass);
5705}
5706private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005707 var charstring bss_rtp_ip;
5708 if (pars.use_ipv6) {
5709 bss_rtp_ip := "::8";
5710 } else {
5711 bss_rtp_ip := "1.2.3.4";
5712 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005713 f_init_handler(pars);
5714 f_create_bssmap_exp_handoverRequest(194);
5715
5716 var PDU_BSSAP ho_request;
5717 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5718
5719 /* new BSS composes a RR Handover Command */
5720 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5721 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005722 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
5723 valueof(f_ts_BSSMAP_IE_AoIP_TLA(bss_rtp_ip, 2342));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005724 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5725 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5726
5727 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5728
5729 f_sleep(0.5);
5730
5731 /* Notify that the MS is now over here */
5732
5733 BSSAP.send(ts_BSSMAP_HandoverDetect);
5734 f_sleep(0.1);
5735 BSSAP.send(ts_BSSMAP_HandoverComplete);
5736
5737 f_sleep(3.0);
5738
5739 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5740 * ... handover back to the first BSC :P */
5741
5742 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5743 var BssmapCause cause := enum2int(cause_val);
5744
5745 var template BSSMAP_FIELD_CellIdentificationList cil;
5746 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('262'H, '42'H, 23) } };
5747
5748 /* old BSS sends Handover Required */
5749 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5750
5751 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5752
5753 /* MSC forwards the RR Handover Command to old BSS */
5754 var PDU_BSSAP ho_command;
5755 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5756
5757 log("GOT HandoverCommand", ho_command);
5758
5759 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5760
5761 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5762 f_expect_clear();
5763 setverdict(pass);
5764}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005765function f_tc_ho_inter_bsc_main(boolean use_ipv6 := false) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005766 var BSC_ConnHdlr vc_conn0;
5767 var BSC_ConnHdlr vc_conn1;
5768 f_init(2);
5769
5770 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005771 pars0.use_ipv6 := use_ipv6;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005772 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005773 pars1.use_ipv6 := use_ipv6;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005774
5775 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0, 0);
5776 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1, 1);
5777 vc_conn0.done;
5778 vc_conn1.done;
5779}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005780testcase TC_ho_inter_bsc() runs on MTC_CT {
5781 f_tc_ho_inter_bsc_main(false);
5782}
5783testcase TC_ho_inter_bsc_ipv6() runs on MTC_CT {
5784 f_tc_ho_inter_bsc_main(true);
5785}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005786
5787function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5788 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5789 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5790 log("MS_NW patched enc_l3: ", enc_l3);
5791}
5792
5793private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005794 var CallParameters cpars;
5795
5796 cpars := valueof(t_CallParams('12345'H, 0));
5797 if (pars.use_ipv6) {
5798 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5799 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5800 cpars.bss_rtp_ip := "::3";
5801 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005802 var hexstring ho_number := f_gen_msisdn(99999);
5803
5804 f_init_handler(pars);
5805
5806 f_create_mncc_expect(hex2str(ho_number));
5807
5808 f_vty_transceive(MSCVTY, "configure terminal");
5809 f_vty_transceive(MSCVTY, "msc");
5810 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
5811 f_vty_transceive(MSCVTY, "exit");
5812 f_vty_transceive(MSCVTY, "exit");
5813
5814 f_perform_lu();
5815 f_mo_call_establish(cpars);
5816
5817 f_sleep(1.0);
5818
5819 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5820
5821 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5822 var BssmapCause cause := enum2int(cause_val);
5823
5824 var template BSSMAP_FIELD_CellIdentificationList cil;
5825 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('017'H, '017'H, 1) } };
5826
5827 /* old BSS sends Handover Required */
5828 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5829
5830 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
5831 * This MSC tries to reach the other MSC via GSUP. */
5832
5833 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
5834 var GSUP_PDU prep_ho_req;
5835 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
5836 pars.imsi, destination_name := remote_msc_name)) -> value prep_ho_req;
5837
5838 var GSUP_IeValue source_name_ie;
5839 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
5840 var octetstring local_msc_name := source_name_ie.source_name;
5841
5842 /* Remote MSC has figured out its BSC and signals success */
5843 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5844 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5845 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5846 aoIPTransportLayer := omit,
5847 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5848 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
5849 pars.imsi,
5850 ho_number,
5851 remote_msc_name, local_msc_name,
5852 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
5853
5854 /* MSC forwards the RR Handover Command to old BSS */
5855 BSSAP.receive(tr_BSSMAP_HandoverCommand);
5856
5857 /* The MS shows up at remote new BSS */
5858
5859 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5860 pars.imsi, remote_msc_name, local_msc_name,
5861 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5862 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
5863 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5864 f_sleep(0.1);
5865
5866 /* Save the MS sequence counters for use on the other connection */
5867 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5868
5869 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
5870 pars.imsi, remote_msc_name, local_msc_name,
5871 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5872 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
5873
5874 /* The local BSS conn clears, all communication goes via remote MSC now */
5875 f_expect_clear();
5876
5877 /**********************************/
5878 /* Play through some signalling across the inter-MSC link.
5879 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
5880
5881 if (false) {
5882 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
5883 invoke_id := 5, /* Phone may not start from 0 or 1 */
5884 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5885 ussd_string := "*#100#"
5886 );
5887
5888 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
5889 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
5890 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5891 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
5892 )
5893
5894 /* Compose a new SS/REGISTER message with request */
5895 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
5896 tid := 1, /* We just need a single transaction */
5897 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
5898 facility := valueof(facility_req)
5899 );
5900 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
5901
5902 /* Compose SS/RELEASE_COMPLETE template with expected response */
5903 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
5904 tid := 1, /* Response should arrive within the same transaction */
5905 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
5906 facility := valueof(facility_rsp)
5907 );
5908
5909 /* Compose expected MSC -> HLR message */
5910 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
5911 imsi := g_pars.imsi,
5912 state := OSMO_GSUP_SESSION_STATE_BEGIN,
5913 ss := valueof(facility_req)
5914 );
5915
5916 /* To be used for sending response with correct session ID */
5917 var GSUP_PDU gsup_req_complete;
5918
5919 /* Request own number */
5920 /* From remote MSC instead of BSSAP directly */
5921 /* Patch the correct N_SD value into the message. */
5922 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
5923 var RAN_Emulation.ConnectionData cd;
5924 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
5925 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5926 pars.imsi, remote_msc_name, local_msc_name,
5927 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5928 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
5929 ))
5930 ));
5931
5932 /* Expect GSUP message containing the SS payload */
5933 gsup_req_complete := f_expect_gsup_msg(gsup_req);
5934
5935 /* Compose the response from HLR using received session ID */
5936 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
5937 imsi := g_pars.imsi,
5938 sid := gsup_req_complete.ies[1].val.session_id,
5939 state := OSMO_GSUP_SESSION_STATE_END,
5940 ss := valueof(facility_rsp)
5941 );
5942
5943 /* Finally, HLR terminates the session */
5944 GSUP.send(gsup_rsp);
5945
5946 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
5947 var GSUP_PDU gsup_ussd_rsp;
5948 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5949 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
5950
5951 var GSUP_IeValue an_apdu;
5952 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
5953 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5954 mtc.stop;
5955 }
5956 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
5957 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
5958 log("Expecting", ussd_rsp);
5959 log("Got", dtap_mt);
5960 if (not match(dtap_mt, ussd_rsp)) {
5961 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5962 mtc.stop;
5963 }
5964 }
5965 /**********************************/
5966
5967
5968 /* inter-MSC handover back to the first MSC */
5969 f_create_bssmap_exp_handoverRequest(193);
5970 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
5971
5972 /* old BSS sends Handover Required, via inter-MSC E link: like
5973 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5974 * but via GSUP */
5975 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
5976 pars.imsi, remote_msc_name, local_msc_name,
5977 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5978 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
5979 ))
5980 ));
5981
5982 /* MSC asks local BSS to prepare Handover to it */
5983 BSSAP.receive(tr_BSSMAP_HandoverRequest);
5984
5985 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
5986 f_bssmap_continue_after_n_sd(last_n_sd);
5987
5988 /* new BSS composes a RR Handover Command */
5989 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5990 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005991 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
5992 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005993 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5994 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5995
5996 /* HandoverCommand goes out via remote MSC-I */
5997 var GSUP_PDU prep_subsq_ho_res;
5998 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
5999 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
6000
6001 /* MS shows up at the local BSS */
6002 BSSAP.send(ts_BSSMAP_HandoverDetect);
6003 f_sleep(0.1);
6004 BSSAP.send(ts_BSSMAP_HandoverComplete);
6005
6006 /* Handover Succeeded message */
6007 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
6008 pars.imsi, destination_name := remote_msc_name));
6009
6010 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
6011 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
6012 pars.imsi, destination_name := remote_msc_name));
6013
6014 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
6015
6016 f_sleep(1.0);
6017 deactivate(ack_mdcx);
6018
6019 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
6020 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
6021 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
6022 MNCC.clear;
6023
6024 var default ccrel := activate(as_optional_cc_rel(cpars, true));
6025 f_call_hangup(cpars, true);
6026 f_sleep(1.0);
6027 deactivate(ccrel);
6028
6029 setverdict(pass);
6030}
6031testcase TC_ho_inter_msc_out() runs on MTC_CT {
6032 var BSC_ConnHdlr vc_conn;
6033 f_init(1);
6034
6035 var BSC_ConnHdlrPars pars := f_init_pars(54);
6036
6037 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
6038 vc_conn.done;
6039}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006040testcase TC_ho_inter_msc_out_ipv6() runs on MTC_CT {
6041 var BSC_ConnHdlr vc_conn;
6042 f_init(1);
6043
6044 var BSC_ConnHdlrPars pars := f_init_pars(54);
6045 pars.use_ipv6 := true;
6046
6047 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
6048 vc_conn.done;
6049}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006050
Oliver Smith1d118ff2019-07-03 10:57:35 +02006051private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6052 pars.net.expect_auth := true;
6053 pars.net.expect_imei := true;
6054 f_init_handler(pars);
6055 f_perform_lu();
6056}
6057testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
6058 var BSC_ConnHdlr vc_conn;
6059 f_init();
6060 f_vty_config(MSCVTY, "network", "authentication required");
6061 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6062
6063 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
6064 vc_conn.done;
6065}
6066
6067private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6068 pars.net.expect_auth := true;
6069 pars.use_umts_aka := true;
6070 pars.net.expect_imei := true;
6071 f_init_handler(pars);
6072 f_perform_lu();
6073}
6074testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
6075 var BSC_ConnHdlr vc_conn;
6076 f_init();
6077 f_vty_config(MSCVTY, "network", "authentication required");
6078 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6079
6080 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
6081 vc_conn.done;
6082}
6083
6084private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6085 pars.net.expect_imei := true;
6086 f_init_handler(pars);
6087 f_perform_lu();
6088}
6089testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
6090 var BSC_ConnHdlr vc_conn;
6091 f_init();
6092 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6093
6094 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
6095 vc_conn.done;
6096}
6097
6098private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6099 pars.net.expect_tmsi := false;
6100 pars.net.expect_imei := true;
6101 f_init_handler(pars);
6102 f_perform_lu();
6103}
6104testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
6105 var BSC_ConnHdlr vc_conn;
6106 f_init();
6107 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6108 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6109
6110 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
6111 vc_conn.done;
6112}
6113
6114private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6115 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006116
6117 pars.net.expect_auth := true;
6118 pars.net.expect_imei := true;
6119 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6120 f_init_handler(pars);
6121
6122 /* Cannot use f_perform_lu() as we expect a reject */
6123 l3_lu := f_build_lu_imsi(g_pars.imsi)
6124 f_create_gsup_expect(hex2str(g_pars.imsi));
6125 f_bssap_compl_l3(l3_lu);
6126 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6127
6128 f_mm_common();
6129 f_msc_lu_hlr();
6130 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006131 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006132 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006133}
6134testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
6135 var BSC_ConnHdlr vc_conn;
6136 f_init();
6137 f_vty_config(MSCVTY, "network", "authentication required");
6138 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6139
6140 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
6141 vc_conn.done;
6142}
6143
6144private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6145 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006146
6147 pars.net.expect_auth := true;
6148 pars.net.expect_imei := true;
6149 pars.net.check_imei_error := true;
6150 f_init_handler(pars);
6151
6152 /* Cannot use f_perform_lu() as we expect a reject */
6153 l3_lu := f_build_lu_imsi(g_pars.imsi)
6154 f_create_gsup_expect(hex2str(g_pars.imsi));
6155 f_bssap_compl_l3(l3_lu);
6156 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6157
6158 f_mm_common();
6159 f_msc_lu_hlr();
6160 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006161 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006162 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006163}
6164testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
6165 var BSC_ConnHdlr vc_conn;
6166 f_init();
6167 f_vty_config(MSCVTY, "network", "authentication required");
6168 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6169
6170 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
6171 vc_conn.done;
6172}
6173
6174private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6175 pars.net.expect_auth := true;
6176 pars.net.expect_imei_early := true;
6177 f_init_handler(pars);
6178 f_perform_lu();
6179}
6180testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
6181 var BSC_ConnHdlr vc_conn;
6182 f_init();
6183 f_vty_config(MSCVTY, "network", "authentication required");
6184 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6185
6186 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
6187 vc_conn.done;
6188}
6189
6190private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6191 pars.net.expect_auth := true;
6192 pars.use_umts_aka := true;
6193 pars.net.expect_imei_early := true;
6194 f_init_handler(pars);
6195 f_perform_lu();
6196}
6197testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
6198 var BSC_ConnHdlr vc_conn;
6199 f_init();
6200 f_vty_config(MSCVTY, "network", "authentication required");
6201 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6202
6203 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
6204 vc_conn.done;
6205}
6206
6207private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6208 pars.net.expect_imei_early := true;
6209 f_init_handler(pars);
6210 f_perform_lu();
6211}
6212testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
6213 var BSC_ConnHdlr vc_conn;
6214 f_init();
6215 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6216
6217 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
6218 vc_conn.done;
6219}
6220
6221private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6222 pars.net.expect_tmsi := false;
6223 pars.net.expect_imei_early := true;
6224 f_init_handler(pars);
6225 f_perform_lu();
6226}
6227testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
6228 var BSC_ConnHdlr vc_conn;
6229 f_init();
6230 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6231 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6232
6233 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
6234 vc_conn.done;
6235}
6236
6237private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6238 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006239
6240 pars.net.expect_auth := true;
6241 pars.net.expect_imei_early := true;
6242 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6243 f_init_handler(pars);
6244
6245 /* Cannot use f_perform_lu() as we expect a reject */
6246 l3_lu := f_build_lu_imsi(g_pars.imsi)
6247 f_create_gsup_expect(hex2str(g_pars.imsi));
6248 f_bssap_compl_l3(l3_lu);
6249 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6250
6251 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006252 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006253 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006254}
6255testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
6256 var BSC_ConnHdlr vc_conn;
6257 f_init();
6258 f_vty_config(MSCVTY, "network", "authentication required");
6259 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6260
6261 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
6262 vc_conn.done;
6263}
6264
6265private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6266 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006267
6268 pars.net.expect_auth := true;
6269 pars.net.expect_imei_early := true;
6270 pars.net.check_imei_error := true;
6271 f_init_handler(pars);
6272
6273 /* Cannot use f_perform_lu() as we expect a reject */
6274 l3_lu := f_build_lu_imsi(g_pars.imsi)
6275 f_create_gsup_expect(hex2str(g_pars.imsi));
6276 f_bssap_compl_l3(l3_lu);
6277 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6278
6279 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006280 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006281 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006282}
6283testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
6284 var BSC_ConnHdlr vc_conn;
6285 f_init();
6286 f_vty_config(MSCVTY, "network", "authentication required");
6287 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6288
6289 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
6290 vc_conn.done;
6291}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006292
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006293friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6294 f_init_handler(pars);
6295 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6296
6297 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
6298 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
6299 * will cause a use-after-free after that event dispatch. */
6300 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
6301 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
6302 cpars.rtp_sdp_format := "FOO/8000";
6303 cpars.expect_release := true;
6304
6305 f_perform_lu();
6306 f_mo_call_establish(cpars);
6307}
6308testcase TC_invalid_mgcp_crash() runs on MTC_CT {
6309 var BSC_ConnHdlr vc_conn;
6310 f_init();
6311
6312 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
6313 vc_conn.done;
6314}
6315
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006316friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
6317runs on BSC_ConnHdlr {
6318 pars.tmsi := 'FFFFFFFF'O;
6319 f_init_handler(pars);
6320
6321 f_create_gsup_expect(hex2str(g_pars.imsi));
6322
6323 /* Initiate Location Updating using an unknown TMSI */
6324 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
6325
6326 /* Expect an Identity Request, send response with no identity */
6327 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
6328 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
6329 lengthIndicator := 1,
6330 mobileIdentityV := {
6331 typeOfIdentity := '000'B,
6332 oddEvenInd_identity := {
6333 no_identity := {
6334 oddevenIndicator := '0'B,
6335 fillerDigits := '00000'H
6336 }
6337 }
6338 }
6339 })));
6340
6341 f_expect_lu_reject();
6342 f_expect_clear();
6343}
6344testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
6345 var BSC_ConnHdlr vc_conn;
6346
6347 f_init();
6348
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006349 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7, verify_cell_id := false);
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006350 vc_conn.done;
6351}
6352
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006353/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6354 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6355 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6356friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6357runs on BSC_ConnHdlr {
6358 var charstring imsi := hex2str(pars.imsi);
6359
6360 f_init_handler(pars);
6361
6362 /* Perform location update */
6363 f_perform_lu();
6364
6365 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6366 f_create_gsup_expect(hex2str(g_pars.imsi));
6367
6368 /* Initiate paging procedure from the VTY */
6369 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6370 f_expect_paging();
6371
6372 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6373 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6374
6375 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6376 f_establish_fully(EST_TYPE_PAG_RESP);
6377
6378 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6379 * In this case we do not send anything and just wait for a Clear Command. */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006380 f_expect_clear(verify_vlr_cell_id := false);
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006381}
6382testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6383 var BSC_ConnHdlr vc_conn;
6384
6385 f_init();
6386
6387 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6388 vc_conn.done;
6389}
6390
Harald Weltef6dd64d2017-11-19 12:09:51 +01006391control {
Philipp Maier328d1662018-03-07 10:40:27 +01006392 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006393 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01006394 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006395 execute( TC_lu_imsi_reject() );
6396 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01006397 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02006398 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01006399 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01006400 execute( TC_cmserv_imsi_unknown() );
Neels Hofmeyr13737fb2020-08-19 13:16:14 +00006401 execute( TC_cmserv_tmsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01006402 execute( TC_lu_and_mo_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006403 execute( TC_lu_and_mo_call_ipv6() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01006404 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01006405 execute( TC_lu_auth_sai_timeout() );
6406 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006407 execute( TC_lu_clear_request() );
Vadim Yanitskiy109e7552021-02-05 05:36:02 +01006408 execute( TC_mo_call_clear_request() );
6409 execute( TC_mt_call_clear_request() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006410 execute( TC_lu_disconnect() );
6411 execute( TC_lu_by_imei() );
6412 execute( TC_lu_by_tmsi_noauth_unknown() );
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00006413 execute( TC_attached_imsi_lu_unknown_tmsi() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006414 execute( TC_imsi_detach_by_imsi() );
6415 execute( TC_imsi_detach_by_tmsi() );
6416 execute( TC_imsi_detach_by_imei() );
6417 execute( TC_emerg_call_imei_reject() );
6418 execute( TC_emerg_call_imsi() );
6419 execute( TC_cm_serv_req_vgcs_reject() );
6420 execute( TC_cm_serv_req_vbs_reject() );
6421 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01006422 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01006423 execute( TC_lu_auth_2G_fail() );
6424 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
6425 execute( TC_cl3_no_payload() );
6426 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01006427 execute( TC_establish_and_nothing() );
6428 execute( TC_mo_setup_and_nothing() );
6429 execute( TC_mo_crcx_ran_timeout() );
6430 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01006431 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01006432 execute( TC_mo_setup_and_dtmf_dup() );
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01006433 execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01006434 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01006435 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
6436 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
6437 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01006438 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01006439 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
6440 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01006441 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01006442 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02006443 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006444
6445 execute( TC_lu_and_mt_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006446 execute( TC_lu_and_mt_call_ipv6() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006447 execute( TC_lu_and_mt_call_already_paging() );
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +02006448 execute( TC_lu_and_mt_call_osmux() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006449
Harald Weltef45efeb2018-04-09 18:19:24 +02006450 execute( TC_lu_and_mo_sms() );
6451 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006452 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01006453 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02006454 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02006455 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07006456 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02006457 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02006458
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006459 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07006460 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07006461 execute( TC_gsup_mt_sms_ack() );
6462 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07006463 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07006464 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07006465 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006466
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006467 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006468 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006469 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006470 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07006471 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07006472 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07006473
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006474 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07006475 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07006476 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07006477 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07006478 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006479
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01006480 execute( TC_multi_lu_and_mo_ussd() );
6481 execute( TC_multi_lu_and_mt_ussd() );
6482
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006483 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01006484 execute( TC_cipher_complete_1_without_cipher() );
6485 execute( TC_cipher_complete_3_without_cipher() );
6486 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02006487 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006488
Harald Welte4263c522018-12-06 11:56:27 +01006489 execute( TC_sgsap_reset() );
6490 execute( TC_sgsap_lu() );
6491 execute( TC_sgsap_lu_imsi_reject() );
6492 execute( TC_sgsap_lu_and_nothing() );
6493 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01006494 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01006495 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01006496 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01006497 execute( TC_sgsap_paging_rej() );
6498 execute( TC_sgsap_paging_subscr_rej() );
6499 execute( TC_sgsap_paging_ue_unr() );
6500 execute( TC_sgsap_paging_and_nothing() );
6501 execute( TC_sgsap_paging_and_lu() );
6502 execute( TC_sgsap_mt_sms() );
6503 execute( TC_sgsap_mo_sms() );
6504 execute( TC_sgsap_mt_sms_and_nothing() );
6505 execute( TC_sgsap_mt_sms_and_reject() );
6506 execute( TC_sgsap_unexp_ud() );
6507 execute( TC_sgsap_unsol_ud() );
6508 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
6509 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02006510 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01006511
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006512 execute( TC_ho_inter_bsc_unknown_cell() );
6513 execute( TC_ho_inter_bsc() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006514 execute( TC_ho_inter_bsc_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006515
6516 execute( TC_ho_inter_msc_out() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006517 execute( TC_ho_inter_msc_out_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006518
Oliver Smith1d118ff2019-07-03 10:57:35 +02006519 execute( TC_lu_imsi_auth_tmsi_check_imei() );
6520 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
6521 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
6522 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
6523 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
6524 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
6525 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
6526 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
6527 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
6528 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
6529 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
6530 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01006531 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Pau Espin Pedrol609f1d62020-09-15 16:01:55 +02006532
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02006533 execute( TC_mo_cc_bssmap_clear() );
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006534 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006535 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006536 execute( TC_lu_and_expire_while_paging() );
Pau Espin Pedrol609f1d62020-09-15 16:01:55 +02006537 if (mp_enable_crashing_tests) {
6538 execute( TC_paging_response_imsi_unknown() );
6539 execute( TC_paging_response_tmsi_unknown() );
6540 }
Harald Weltef6dd64d2017-11-19 12:09:51 +01006541}
6542
6543
6544}