blob: dd31dafc484d17c1c6f2f99b3bfa24123a3d4f60 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
Pau Espin Pedrole979c402021-04-28 17:29:54 +020019import from GSM_Types all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010020
21import from M3UA_Types all;
22import from M3UA_Emulation all;
23
24import from MTP3asp_Types all;
25import from MTP3asp_PortType all;
26
27import from SCCPasp_Types all;
28import from SCCP_Types all;
29import from SCCP_Emulation all;
30
31import from SCTPasp_Types all;
32import from SCTPasp_PortType all;
33
Harald Weltea49e36e2018-01-21 19:29:33 +010034import from Osmocom_CTRL_Functions all;
35import from Osmocom_CTRL_Types all;
36import from Osmocom_CTRL_Adapter all;
37
Harald Welte3ca1c902018-01-24 18:51:27 +010038import from TELNETasp_PortType all;
39import from Osmocom_VTY_Functions all;
40
Harald Weltea49e36e2018-01-21 19:29:33 +010041import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010042import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010043
Harald Welte4aa970c2018-01-26 10:38:09 +010044import from MGCP_Emulation all;
45import from MGCP_Types all;
46import from MGCP_Templates all;
47import from SDP_Types all;
48
Harald Weltea49e36e2018-01-21 19:29:33 +010049import from GSUP_Emulation all;
50import from GSUP_Types all;
51import from IPA_Emulation all;
52
Harald Weltef6dd64d2017-11-19 12:09:51 +010053import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020054import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010055import from BSSAP_CodecPort all;
56import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020057import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010058import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020059import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010060
Harald Welte4263c522018-12-06 11:56:27 +010061import from SGsAP_Templates all;
62import from SGsAP_Types all;
63import from SGsAP_Emulation all;
64
Harald Weltea49e36e2018-01-21 19:29:33 +010065import from MobileL3_Types all;
66import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070067import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010068import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010069import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010070
Harald Weltef640a012018-04-14 17:49:21 +020071import from SMPP_Types all;
72import from SMPP_Templates all;
73import from SMPP_Emulation all;
74
Stefan Sperlingc307e682018-06-14 15:15:46 +020075import from SCCP_Templates all;
76
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070077import from SS_Types all;
78import from SS_Templates all;
79import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010080import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070081
Philipp Maier948747b2019-04-02 15:22:33 +020082import from TCCConversion_Functions all;
83
Harald Welte9b751a62019-04-14 17:39:29 +020084const integer NUM_BSC := 3;
Harald Weltef6dd64d2017-11-19 12:09:51 +010085
Harald Welte4263c522018-12-06 11:56:27 +010086/* Needed for SGsAP SMS */
87import from MobileL3_SMS_Types all;
88
Harald Weltea4ca4462018-02-09 00:17:14 +010089type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010090 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010091
Harald Welte6811d102019-04-14 22:23:14 +020092 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010093
Harald Weltea49e36e2018-01-21 19:29:33 +010094 /* no 'adapter_CT' for MNCC or GSUP */
95 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010096 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010097 var GSUP_Emulation_CT vc_GSUP;
98 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020099 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +0100100 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100101
102 /* only to get events from IPA underneath GSUP */
103 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100104 /* VTY to MSC */
105 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100106
107 /* A port to directly send BSSAP messages. This port is used for
108 * tests that require low level access to sen arbitrary BSSAP
109 * messages. Run f_init_bssap_direct() to connect and initialize */
110 port BSSAP_CODEC_PT BSSAP_DIRECT;
111
112 /* When BSSAP messages are directly sent, then the connection
113 * handler is not active, which means that also no guard timer is
114 * set up. The following timer will serve as a replacement */
115 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100116
117 /* Configure T(tias) over VTY, seconds */
118 var integer g_msc_sccp_timer_ias := 7 * 60;
119 /* Configure T(tiar) over VTY, seconds */
120 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100121}
122
123modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100124 /* remote parameters of IUT */
125 charstring mp_msc_ip := "127.0.0.1";
126 integer mp_msc_ctrl_port := 4255;
127 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100128
Harald Weltea49e36e2018-01-21 19:29:33 +0100129 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100130 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100131 charstring mp_hlr_ip := "127.0.0.1";
132 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100133 charstring mp_mgw_ip := "127.0.0.1";
134 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100135
Harald Weltea49e36e2018-01-21 19:29:33 +0100136 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100137
Harald Weltef640a012018-04-14 17:49:21 +0200138 integer mp_msc_smpp_port := 2775;
139 charstring mp_smpp_system_id := "msc_tester";
140 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100141 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
142 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200143
Harald Welte6811d102019-04-14 22:23:14 +0200144 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200145 {
146 sccp_service_type := "mtp3_itu",
147 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
148 own_pc := 185,
149 own_ssn := 254,
150 peer_pc := 187,
151 peer_ssn := 254,
152 sio := '83'O,
153 rctx := 0
154 },
155 {
156 sccp_service_type := "mtp3_itu",
157 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
158 own_pc := 186,
159 own_ssn := 254,
160 peer_pc := 187,
161 peer_ssn := 254,
162 sio := '83'O,
163 rctx := 1
164 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100165 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100166}
167
Philipp Maier328d1662018-03-07 10:40:27 +0100168/* altstep for the global guard timer (only used when BSSAP_DIRECT
169 * is used for communication */
170private altstep as_Tguard_direct() runs on MTC_CT {
171 [] Tguard_direct.timeout {
172 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200173 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100174 }
175}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100176
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100177private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
178 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
179 if (respond) {
180 var BIT1 tid_remote := '1'B;
181 if (cpars.mo_call) {
182 tid_remote := '0'B;
183 }
184 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
185 }
186 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100187}
188
Harald Weltef640a012018-04-14 17:49:21 +0200189function f_init_smpp(charstring id) runs on MTC_CT {
190 id := id & "-SMPP";
191 var EsmePars pars := {
192 mode := MODE_TRANSCEIVER,
193 bind := {
194 system_id := mp_smpp_system_id,
195 password := mp_smpp_password,
196 system_type := "MSC_Tests",
197 interface_version := hex2int('34'H),
198 addr_ton := unknown,
199 addr_npi := unknown,
200 address_range := ""
201 },
202 esme_role := true
203 }
204
205 vc_SMPP := SMPP_Emulation_CT.create(id);
206 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
Harald Welte4698a4c2020-08-18 22:57:52 +0200207 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", 0));
Harald Weltef640a012018-04-14 17:49:21 +0200208}
209
210
Harald Weltea49e36e2018-01-21 19:29:33 +0100211function f_init_mncc(charstring id) runs on MTC_CT {
212 id := id & "-MNCC";
213 var MnccOps ops := {
214 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
215 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
216 }
217
218 vc_MNCC := MNCC_Emulation_CT.create(id);
219 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
220 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100221}
222
Harald Welte4aa970c2018-01-26 10:38:09 +0100223function f_init_mgcp(charstring id) runs on MTC_CT {
224 id := id & "-MGCP";
225 var MGCPOps ops := {
226 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
227 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
228 }
229 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100230 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100231 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100232 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200233 mgw_udp_port := mp_mgw_port,
234 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100235 }
236
237 vc_MGCP := MGCP_Emulation_CT.create(id);
238 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
239 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
240}
241
Philipp Maierc09a1312019-04-09 16:05:26 +0200242function ForwardUnitdataCallback(PDU_SGsAP msg)
243runs on SGsAP_Emulation_CT return template PDU_SGsAP {
244 SGsAP_CLIENT.send(msg);
245 return omit;
246}
247
Harald Welte4263c522018-12-06 11:56:27 +0100248function f_init_sgsap(charstring id) runs on MTC_CT {
249 id := id & "-SGsAP";
250 var SGsAPOps ops := {
251 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200252 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100253 }
254 var SGsAP_conn_parameters pars := {
255 remote_ip := mp_msc_ip,
256 remote_sctp_port := 29118,
257 local_ip := "",
258 local_sctp_port := -1
259 }
260
261 vc_SGsAP := SGsAP_Emulation_CT.create(id);
262 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
263 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
264}
265
266
Harald Weltea49e36e2018-01-21 19:29:33 +0100267function f_init_gsup(charstring id) runs on MTC_CT {
268 id := id & "-GSUP";
269 var GsupOps ops := {
270 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
271 }
272
273 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
274 vc_GSUP := GSUP_Emulation_CT.create(id);
275
276 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
277 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
278 /* we use this hack to get events like ASP_IPA_EVENT_UP */
279 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
280
281 vc_GSUP.start(GSUP_Emulation.main(ops, id));
282 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
283
284 /* wait for incoming connection to GSUP port before proceeding */
285 timer T := 10.0;
286 T.start;
287 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700288 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100289 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100290 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200291 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100292 }
293 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100294}
295
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200296function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100297
298 if (g_initialized == true) {
299 return;
300 }
301 g_initialized := true;
302
Philipp Maier75932982018-03-27 14:52:35 +0200303 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200304 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200305 }
306
Pau Espin Pedrol9a5b8ff2021-01-04 19:01:31 +0100307 f_ipa_ctrl_start_client(mp_msc_ip, mp_msc_ctrl_port);
Harald Welte3ca1c902018-01-24 18:51:27 +0100308
309 map(self:MSCVTY, system:MSCVTY);
310 f_vty_set_prompts(MSCVTY);
311 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100312
313 /* set some defaults */
314 f_vty_config(MSCVTY, "network", "authentication optional");
315 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200316 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100317 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100318 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
319 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +0200320 if (osmux) {
321 f_vty_config(MSCVTY, "msc", "osmux on");
322 } else {
323 f_vty_config(MSCVTY, "msc", "osmux off");
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200324 }
Daniel Willmann08862152022-02-22 13:21:49 +0100325
326 for (var integer i := 0; i < num_bsc; i := i + 1) {
327 if (isbound(mp_bssap_cfg[i])) {
328 var RanOps ranops := BSC_RanOps;
329 ranops.use_osmux := osmux;
330 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
331 f_ran_adapter_start(g_bssap[i]);
332 } else {
333 testcase.stop("missing BSSAP configuration");
334 }
335 }
336
337 f_init_mncc("MSC_Test");
338 f_init_mgcp("MSC_Test");
339
340 if (gsup == true) {
341 f_init_gsup("MSC_Test");
342 }
343 f_init_smpp("MSC_Test");
344
345 if (sgsap == true) {
346 f_init_sgsap("MSC_Test");
347 }
348
Harald Weltef6dd64d2017-11-19 12:09:51 +0100349}
350
Philipp Maier328d1662018-03-07 10:40:27 +0100351/* Initialize for a direct connection to BSSAP. This function is an alternative
352 * to f_init() when the high level functions of the BSC_ConnectionHandler are
353 * not needed. */
354function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200355 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200356 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100357
358 /* Start guard timer and activate it as default */
359 Tguard_direct.start
360 activate(as_Tguard_direct());
361}
362
Harald Weltea49e36e2018-01-21 19:29:33 +0100363type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100364
Harald Weltea49e36e2018-01-21 19:29:33 +0100365/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200366function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200367 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O,
368 boolean verify_cell_id := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200369runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100370 var BSC_ConnHdlrNetworkPars net_pars := {
371 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
372 expect_tmsi := true,
373 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200374 expect_ciph := false,
375 expect_imei := false,
376 expect_imei_early := false,
377 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
378 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100379 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100380 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200381 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
382 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100383 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100384 imei := f_gen_imei(imsi_suffix),
385 imsi := f_gen_imsi(imsi_suffix),
386 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100387 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100388 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100389 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100390 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100391 vec := omit,
Neels Hofmeyrb00c5b02021-06-23 20:05:25 +0200392 vec_keep := false,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100393 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100394 send_early_cm := true,
395 ipa_ctrl_ip := mp_msc_ip,
396 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100397 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100398 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200399 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200400 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100401 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200402 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200403 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200404 ran_is_geran := ran_is_geran,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200405 use_osmux := use_osmux,
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200406 use_ipv6 := false,
Pau Espin Pedrole979c402021-04-28 17:29:54 +0200407 verify_cell_id := verify_cell_id,
408 common_id_last_eutran_plmn := omit
Harald Weltea49e36e2018-01-21 19:29:33 +0100409 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200410 if (not ran_is_geran) {
411 pars.use_umts_aka := true;
412 pars.net.expect_auth := true;
413 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100414 return pars;
415}
416
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200417function f_start_handler_create(BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100418 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200419 var charstring id := testcasename() & int2str(pars.ran_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100420
421 vc_conn := BSC_ConnHdlr.create(id);
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200422
Harald Weltea49e36e2018-01-21 19:29:33 +0100423 /* BSSMAP part / A interface */
Neels Hofmeyr60122f82021-07-28 17:59:38 +0200424 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx].vc_RAN:CLIENT);
425 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100426 /* MNCC part */
427 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
428 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100429 /* MGCP part */
430 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
431 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100432 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200433 if (pars.gsup_enable == true) {
434 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
435 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
436 }
Harald Weltef640a012018-04-14 17:49:21 +0200437 /* SMPP part */
438 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
439 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100440 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100441 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100442 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
443 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
444 }
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200445 return vc_conn;
446}
Harald Weltea49e36e2018-01-21 19:29:33 +0100447
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200448function f_start_handler_run(BSC_ConnHdlr vc_conn, void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT {
449 var charstring id := testcasename() & int2str(pars.ran_idx);
Harald Weltea10db902018-01-27 12:44:49 +0100450 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
451 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100452 vc_conn.start(derefers(fn)(id, pars));
Neels Hofmeyre1a1b632021-07-28 18:05:43 +0200453}
454
455function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
456 var BSC_ConnHdlr vc_conn;
457 vc_conn := f_start_handler_create(pars);
458 f_start_handler_run(vc_conn, fn, pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100459 return vc_conn;
460}
461
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200462function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false,
463 boolean verify_cell_id := true)
Harald Welte9b751a62019-04-14 17:39:29 +0200464runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200465 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux, verify_cell_id := verify_cell_id));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100466}
467
Harald Weltea49e36e2018-01-21 19:29:33 +0100468private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100469 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100470 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100471}
Harald Weltea49e36e2018-01-21 19:29:33 +0100472testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
473 var BSC_ConnHdlr vc_conn;
474 f_init();
475
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100476 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100477 vc_conn.done;
478}
479
480private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100481 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100482 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100483 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100484}
Harald Weltea49e36e2018-01-21 19:29:33 +0100485testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
486 var BSC_ConnHdlr vc_conn;
487 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100488 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100489
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100490 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100491 vc_conn.done;
492}
493
494/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200495friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100496 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100497 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
498
499 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200500 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100501 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100502 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
503 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
504 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100505 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
506 f_expect_clear();
507 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100508 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
509 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200510 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100511 }
512 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100513}
514testcase TC_lu_imsi_reject() runs on MTC_CT {
515 var BSC_ConnHdlr vc_conn;
516 f_init();
517
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200518 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100519 vc_conn.done;
520}
521
Harald Weltee13cfb22019-04-23 16:52:02 +0200522
523
Harald Weltea49e36e2018-01-21 19:29:33 +0100524/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200525friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100526 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100527 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
528
529 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200530 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100531 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100532 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
533 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
534 alt {
535 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100536 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
537 f_expect_clear();
538 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100539 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
540 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200541 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100542 }
543 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100544}
545testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
546 var BSC_ConnHdlr vc_conn;
547 f_init();
548
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200549 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100550 vc_conn.done;
551}
552
Harald Weltee13cfb22019-04-23 16:52:02 +0200553
Harald Welte7b1b2812018-01-22 21:23:06 +0100554private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100555 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100556 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100557 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100558}
559testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
560 var BSC_ConnHdlr vc_conn;
561 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100562 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100563
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100564 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100565 vc_conn.done;
566}
567
Harald Weltee13cfb22019-04-23 16:52:02 +0200568
569friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200570 pars.net.expect_auth := true;
571 pars.use_umts_aka := true;
572 f_init_handler(pars);
573 f_perform_lu();
574}
575testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
576 var BSC_ConnHdlr vc_conn;
577 f_init();
578 f_vty_config(MSCVTY, "network", "authentication required");
579
580 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
581 vc_conn.done;
582}
Harald Weltea49e36e2018-01-21 19:29:33 +0100583
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100584/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
585 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
586 */
587friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
588
589 f_init_handler(pars);
590
591 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
592 var PDU_DTAP_MT dtap_mt;
593
594 /* tell GSUP dispatcher to send this IMSI to us */
595 f_create_gsup_expect(hex2str(g_pars.imsi));
596
597 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
598 if (g_pars.ran_is_geran) {
599 f_bssap_compl_l3(l3_lu);
600 if (g_pars.send_early_cm) {
601 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
602 }
603 } else {
604 f_ranap_initial_ue(l3_lu);
605 }
606
607 f_mm_imei_early();
608 f_mm_common();
609 f_msc_lu_hlr();
610 f_mm_imei();
611
612 alt {
613 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
614 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
615 setverdict(fail, "Expected LU ACK, but received LU REJ");
616 mtc.stop;
617 }
618 }
619
620 /* currently (due to bug OS#4337), an extra LU reject is received before
621 terminating the connection. Enabling following line makes the test
622 pass: */
623 //f_expect_lu_reject('16'O); /* Cause: congestion */
624
625 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
626 extra time to avoid race conditons... */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200627 f_expect_clear(7.0, verify_vlr_cell_id := false);
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100628
629 setverdict(pass);
630}
631testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
632 var BSC_ConnHdlr vc_conn;
633 f_init();
634
635 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
636 vc_conn.done;
637}
638
Harald Weltee13cfb22019-04-23 16:52:02 +0200639
Harald Weltea49e36e2018-01-21 19:29:33 +0100640/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200641friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100642runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100643 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100644
645 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100646 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100647 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100648
649 f_create_gsup_expect(hex2str(g_pars.imsi));
650
651 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200652 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200653 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100654
655 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100656 T.start;
657 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100658 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
659 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200660 [] BSSAP.receive {
661 setverdict(fail, "Received unexpected BSSAP");
662 mtc.stop;
663 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100664 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
665 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200666 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100667 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200668 [] T.timeout {
Neels Hofmeyrf1c3c212020-08-19 13:15:32 +0000669 setverdict(fail, "Timeout waiting for CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200670 mtc.stop;
671 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100672 }
673
Harald Welte1ddc7162018-01-27 14:25:46 +0100674 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100675}
Harald Weltea49e36e2018-01-21 19:29:33 +0100676testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
677 var BSC_ConnHdlr vc_conn;
678 f_init();
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200679 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100680 vc_conn.done;
681}
682
Harald Weltee13cfb22019-04-23 16:52:02 +0200683
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000684/* Send CM SERVICE REQ for TMSI that has never performed LU before */
685friend function f_tc_cmserv_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
686runs on BSC_ConnHdlr {
687 f_init_handler(pars);
688
689 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('57111111'O));
690 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
691 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
692
693 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
694 f_cl3_or_initial_ue(l3_info);
695 f_mm_auth();
696
697 timer T := 10.0;
698 T.start;
699 alt {
700 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
701 [] BSSAP.receive {
702 setverdict(fail, "Received unexpected BSSAP");
703 mtc.stop;
704 }
705 [] T.timeout {
706 setverdict(fail, "Timeout waiting for CM SERV REJ");
707 mtc.stop;
708 }
709 }
710
711 f_expect_clear();
712}
713testcase TC_cmserv_tmsi_unknown() runs on MTC_CT {
714 var BSC_ConnHdlr vc_conn;
715 f_init();
716 vc_conn := f_start_handler(refers(f_tc_cmserv_tmsi_unknown), 57, verify_cell_id := false);
717 vc_conn.done;
718}
719
Neels Hofmeyr14d0b132020-08-19 13:49:05 +0000720/* Send Paging Response for IMSI that has never performed LU before */
721friend function f_tc_paging_response_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
722runs on BSC_ConnHdlr {
723 f_init_handler(pars);
724
725 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
726 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
727 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
728
729 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
730 f_cl3_or_initial_ue(l3_info);
731
732 /* The Paging Response gets rejected by a direct Clear Command */
733 f_expect_clear();
734}
735testcase TC_paging_response_imsi_unknown() runs on MTC_CT {
736 var BSC_ConnHdlr vc_conn;
737 f_init();
738 vc_conn := f_start_handler(refers(f_tc_paging_response_imsi_unknown), 58, verify_cell_id := false);
739 vc_conn.done;
740}
741
742/* Send Paging Response for TMSI that has never performed LU before */
743friend function f_tc_paging_response_tmsi_unknown(charstring id, BSC_ConnHdlrPars pars)
744runs on BSC_ConnHdlr {
745 f_init_handler(pars);
746
747 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('59111111'O));
748 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
749 var PDU_ML3_MS_NW l3_info := valueof(ts_PAG_RESP(mi));
750
751 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
752 f_cl3_or_initial_ue(l3_info);
753
754 /* The Paging Response gets rejected by a direct Clear Command */
755 f_expect_clear();
756}
757testcase TC_paging_response_tmsi_unknown() runs on MTC_CT {
758 var BSC_ConnHdlr vc_conn;
759 f_init();
760 vc_conn := f_start_handler(refers(f_tc_paging_response_tmsi_unknown), 59, verify_cell_id := false);
761 vc_conn.done;
762}
763
Neels Hofmeyr13737fb2020-08-19 13:16:14 +0000764
Harald Weltee13cfb22019-04-23 16:52:02 +0200765friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100766 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200767 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100768 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100769 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100770}
771testcase TC_lu_and_mo_call() runs on MTC_CT {
772 var BSC_ConnHdlr vc_conn;
773 f_init();
774
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100775 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100776 vc_conn.done;
777}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +0200778friend function f_tc_lu_and_mo_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
779 f_init_handler(pars);
780 var CallParameters cpars := valueof(t_CallParams);
781 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
782 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
783 cpars.bss_rtp_ip := "::3";
784 f_perform_lu();
785 f_mo_call(cpars);
786}
787testcase TC_lu_and_mo_call_ipv6() runs on MTC_CT {
788 var BSC_ConnHdlr vc_conn;
789 f_init();
790
791 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call_ipv6), 7);
792 vc_conn.done;
793}
Harald Welte071ed732018-01-23 19:53:52 +0100794
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100795/* Verify T(iar) triggers and releases the channel */
796friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
797 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
798 f_init_handler(pars);
799 var CallParameters cpars := valueof(t_CallParams);
800 f_perform_lu();
801 f_mo_call_establish(cpars);
802
803 /* Expect the channel cleared upon T(iar) triggered: */
804 T_wait_iar.start;
805 alt {
806 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
807 T_wait_iar.stop
808 setverdict(pass);
809 }
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100810 [] T_wait_iar.timeout {
811 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
812 mtc.stop;
813 }
814 }
Harald Welte4a3fa712020-08-19 08:57:33 +0200815 /* DLCX for both directions; if we don't do this, we might receive either of the two during
816 * shutdown causing race conditions */
817 MGCP.receive(tr_DLCX(?));
818 MGCP.receive(tr_DLCX(?));
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100819
820 setverdict(pass);
821}
822testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
823 var BSC_ConnHdlr vc_conn;
824
825 /* Set T(iar) in MSC low enough that it will trigger before other side
826 has time to keep alive with a T(ias). Keep recommended ratio of
827 T(iar) >= T(ias)*2 */
828 g_msc_sccp_timer_ias := 2;
829 g_msc_sccp_timer_iar := 5;
830
831 f_init();
832
833 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
834 vc_conn.done;
835}
836
Harald Weltee13cfb22019-04-23 16:52:02 +0200837
Harald Welte071ed732018-01-23 19:53:52 +0100838/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200839friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100840 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100841
842 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
843 var PDU_DTAP_MT dtap_mt;
844
845 /* tell GSUP dispatcher to send this IMSI to us */
846 f_create_gsup_expect(hex2str(g_pars.imsi));
847
848 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200849 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100850
851 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200852 if (pars.ran_is_geran) {
853 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
854 }
Harald Welte071ed732018-01-23 19:53:52 +0100855
856 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
857 /* The HLR would normally return an auth vector here, but we fail to do so. */
858
859 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100860 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100861}
862testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
863 var BSC_ConnHdlr vc_conn;
864 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100865 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100866
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200867 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8, verify_cell_id := false);
Harald Welte071ed732018-01-23 19:53:52 +0100868 vc_conn.done;
869}
870
Harald Weltee13cfb22019-04-23 16:52:02 +0200871
Harald Welte071ed732018-01-23 19:53:52 +0100872/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200873friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100874 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100875
876 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
877 var PDU_DTAP_MT dtap_mt;
878
879 /* tell GSUP dispatcher to send this IMSI to us */
880 f_create_gsup_expect(hex2str(g_pars.imsi));
881
882 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200883 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100884
885 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200886 if (pars.ran_is_geran) {
887 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
888 }
Harald Welte071ed732018-01-23 19:53:52 +0100889
890 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
891 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
892
893 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100894 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100895}
896testcase TC_lu_auth_sai_err() runs on MTC_CT {
897 var BSC_ConnHdlr vc_conn;
898 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100899 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100900
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200901 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9, verify_cell_id := false);
Harald Welte2bb825f2018-01-22 11:31:18 +0100902 vc_conn.done;
903}
Harald Weltea49e36e2018-01-21 19:29:33 +0100904
Harald Weltee13cfb22019-04-23 16:52:02 +0200905
Harald Weltebc881782018-01-23 20:09:15 +0100906/* Test LU but BSC will send a clear request in the middle */
907private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100908 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100909
910 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
911 var PDU_DTAP_MT dtap_mt;
912
913 /* tell GSUP dispatcher to send this IMSI to us */
914 f_create_gsup_expect(hex2str(g_pars.imsi));
915
916 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200917 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +0200918 f_expect_common_id();
Harald Weltebc881782018-01-23 20:09:15 +0100919
920 /* Send Early Classmark, just for the fun of it */
921 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
922
923 f_sleep(1.0);
924 /* send clear request in the middle of the LU */
925 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200926 alt {
927 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
928 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
929 }
Harald Weltebc881782018-01-23 20:09:15 +0100930 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100931 alt {
932 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200933 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
934 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200935 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200936 repeat;
937 }
Harald Welte6811d102019-04-14 22:23:14 +0200938 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100939 }
Harald Weltebc881782018-01-23 20:09:15 +0100940 setverdict(pass);
941}
942testcase TC_lu_clear_request() runs on MTC_CT {
943 var BSC_ConnHdlr vc_conn;
944 f_init();
945
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100946 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100947 vc_conn.done;
948}
949
Vadim Yanitskiy109e7552021-02-05 05:36:02 +0100950/* Test reaction on Clear Request during a MO Call */
951friend function f_TC_mo_mt_call_clear_request(charstring id, BSC_ConnHdlrPars pars)
952runs on BSC_ConnHdlr {
953 var CallParameters cpars := valueof(t_CallParams);
954 var MNCC_PDU mncc_pdu;
955 timer T := 2.0;
956
957 f_init_handler(pars);
958
959 f_perform_lu();
960
961 /* HACK: reducing code duplication ('66'H - MO, '68'H - MT) */
962 if (pars.imsi == '262420002532766'H)
963 { f_mo_call_establish(cpars); }
964 else
965 { f_mt_call_establish(cpars); }
966
967 /* Hold the line for a while... */
968 f_sleep(2.0);
969
970 /* BSC sends BSSMAP Clear Request (e.g. due to RR failure) */
971 BSSAP.send(ts_BSSMAP_ClearRequest(1));
972
973 /* Expect (optional) CC RELEASE and Clear Command */
974 var default ccrel := activate(as_optional_cc_rel(cpars));
975 f_expect_clear();
976 deactivate(ccrel);
977
978 /* Expect RELease indication on the MNCC socket */
979 T.start;
980 alt {
981 [] MNCC.receive(tr_MNCC_REL_ind(cpars.mncc_callref)) -> value mncc_pdu {
982 log("Rx MNCC REL.ind, cause := ", mncc_pdu.u.signal.cause);
983 setverdict(pass);
984 }
985 [] MNCC.receive(MNCC_PDU:?) -> value mncc_pdu {
986 setverdict(fail, "Rx unexpected MNCC PDU: ", mncc_pdu);
987 }
988 [] T.timeout {
989 setverdict(fail, "Timeout waiting for MNCC REL.ind");
990 }
991 }
992}
993testcase TC_mo_call_clear_request() runs on MTC_CT {
994 var BSC_ConnHdlr vc_conn;
995
996 f_init();
997
998 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532766); // '66'H - MO
999 vc_conn.done;
1000}
1001testcase TC_mt_call_clear_request() runs on MTC_CT {
1002 var BSC_ConnHdlr vc_conn;
1003
1004 f_init();
1005
1006 vc_conn := f_start_handler(refers(f_TC_mo_mt_call_clear_request), 2532768); // '68'H - MT
1007 vc_conn.done;
1008}
1009
Harald Welte66af9e62018-01-24 17:28:21 +01001010/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +02001011friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001012 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +01001013
1014 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1015 var PDU_DTAP_MT dtap_mt;
1016
1017 /* tell GSUP dispatcher to send this IMSI to us */
1018 f_create_gsup_expect(hex2str(g_pars.imsi));
1019
1020 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001021 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +01001022
1023 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001024 if (pars.ran_is_geran) {
1025 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1026 }
Harald Welte66af9e62018-01-24 17:28:21 +01001027
1028 f_sleep(1.0);
1029 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +02001030 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +01001031 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +01001032 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +01001033}
1034testcase TC_lu_disconnect() runs on MTC_CT {
1035 var BSC_ConnHdlr vc_conn;
1036 f_init();
1037
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001038 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +01001039 vc_conn.done;
1040}
1041
Harald Welteba7b6d92018-01-23 21:32:34 +01001042/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +02001043friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001044 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001045
Harald Welte256571e2018-01-24 18:47:19 +01001046 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +01001047 var PDU_DTAP_MT dtap_mt;
1048
1049 /* tell GSUP dispatcher to send this IMSI to us */
1050 f_create_gsup_expect(hex2str(g_pars.imsi));
1051
1052 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001053 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001054
1055 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +02001056 if (pars.ran_is_geran) {
1057 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1058 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001059 /* wait for LU reject, ignore any ID REQ */
1060 alt {
1061 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
1062 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
1063 }
1064 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001065 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001066}
1067testcase TC_lu_by_imei() runs on MTC_CT {
1068 var BSC_ConnHdlr vc_conn;
1069 f_init();
1070
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001071 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12, verify_cell_id := false);
Harald Welteba7b6d92018-01-23 21:32:34 +01001072 vc_conn.done;
1073}
1074
Harald Weltee13cfb22019-04-23 16:52:02 +02001075
Harald Welteba7b6d92018-01-23 21:32:34 +01001076/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
1077private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001078 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
1079 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +01001080 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +01001081
1082 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
1083 var PDU_DTAP_MT dtap_mt;
1084
1085 /* tell GSUP dispatcher to send this IMSI to us */
1086 f_create_gsup_expect(hex2str(g_pars.imsi));
1087
1088 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001089 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +01001090
1091 /* Send Early Classmark, just for the fun of it */
1092 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1093
1094 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +02001095 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +02001096 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +01001097 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
Harald Welte79f1e452020-08-18 22:55:02 +02001098 f_expect_common_id();
Harald Welteba7b6d92018-01-23 21:32:34 +01001099
1100 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1101 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1102 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1103 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1104 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1105
1106 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +01001107 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1108 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1109 }
Harald Welteba7b6d92018-01-23 21:32:34 +01001110 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1111 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001112 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +01001113 }
1114 }
1115
Philipp Maier9b690e42018-12-21 11:50:03 +01001116 /* Wait for MM-Information (if enabled) */
1117 f_expect_mm_info();
1118
Harald Welteba7b6d92018-01-23 21:32:34 +01001119 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001120 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +01001121}
1122testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
1123 var BSC_ConnHdlr vc_conn;
1124 f_init();
1125
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001126 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +01001127 vc_conn.done;
1128}
1129
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00001130/* Test LU by unknown TMSI, while the IMSI is already attached: osmo-msc should switch to the attached vlr_subscr. */
1131private function f_tc_attached_imsi_lu_unknown_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1132 f_init_handler(pars);
1133
1134 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('56111111'O);
1135 var PDU_DTAP_MT dtap_mt;
1136
1137 /* tell GSUP dispatcher to send this IMSI to us */
1138 f_create_gsup_expect(hex2str(g_pars.imsi));
1139
1140 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1141 f_cl3_or_initial_ue(l3_lu);
1142
1143 /* Send Early Classmark, just for the fun of it */
1144 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1145
1146 /* Wait for + respond to ID REQ (IMSI) */
1147 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1148 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1149 f_expect_common_id();
1150
1151 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1152 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1153 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1154 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1155 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1156
1157 alt {
1158 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1159 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1160 }
1161 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1162 setverdict(fail, "Expected LU ACK, but received REJ");
1163 mtc.stop;
1164 }
1165 }
1166
1167 /* Wait for MM-Information (if enabled) */
1168 f_expect_mm_info();
1169
1170 /* wait for normal teardown */
1171 f_expect_clear();
1172
1173 /* Now the same IMSI is still attached in the VLR, and a LU with an unknown TMSI reveals the same IMSI only
1174 * later during ID Response. osmo-msc first creates a new vlr_subscr for the unknown TMSI, and as soon as the
1175 * IMSI becomes known, must notice that this IMSI is still regarded as attached, and must not create evil twins.
1176 */
1177
1178 /* (since the TMSI Reallocation happened, we could do this with exactly the same TMSI as above, but for test
1179 * readability just use a different one.) */
1180 l3_lu := f_build_lu_tmsi('56222222'O);
1181 f_cl3_or_initial_ue(l3_lu);
1182
1183 /* Wait for + respond to ID REQ (IMSI) */
1184 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
1185 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
1186 f_expect_common_id();
1187
1188 /* Expect MSC to do UpdateLocation to HLR; respond to it */
1189 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
1190 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
1191 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
1192 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
1193
1194 alt {
1195 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
1196 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
1197 }
1198 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1199 setverdict(fail, "Expected LU ACK, but received REJ");
1200 mtc.stop;
1201 }
1202 }
1203
1204 /* Wait for MM-Information (if enabled) */
1205 f_expect_mm_info();
1206
1207 /* wait for normal teardown */
1208 f_expect_clear();
1209}
1210testcase TC_attached_imsi_lu_unknown_tmsi() runs on MTC_CT {
1211 var BSC_ConnHdlr vc_conn;
1212 f_init();
1213
1214 vc_conn := f_start_handler(refers(f_tc_attached_imsi_lu_unknown_tmsi), 56);
1215 vc_conn.done;
1216}
1217
Harald Welte4d15fa72020-08-19 08:58:28 +02001218friend function f_imsi_detach_by_imsi() runs on BSC_ConnHdlr {
Harald Welte45164da2018-01-24 12:51:27 +01001219 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1220
1221 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001222 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001223
1224 /* Send Early Classmark, just for the fun of it? */
Harald Welte4d15fa72020-08-19 08:58:28 +02001225 if (g_pars.ran_is_geran) {
Harald Weltee13cfb22019-04-23 16:52:02 +02001226 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1227 }
Harald Welte45164da2018-01-24 12:51:27 +01001228
1229 /* wait for normal teardown */
Harald Welte4d15fa72020-08-19 08:58:28 +02001230 f_expect_clear(verify_vlr_cell_id := false);
1231}
1232
1233
1234/* Test IMSI DETACH (MI=IMSI) */
1235friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1236 f_init_handler(pars);
1237
1238 f_imsi_detach_by_imsi();
Harald Welte45164da2018-01-24 12:51:27 +01001239}
1240testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
1241 var BSC_ConnHdlr vc_conn;
1242 f_init();
1243
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001244 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001245 vc_conn.done;
1246}
1247
Harald Weltee13cfb22019-04-23 16:52:02 +02001248
Harald Welte45164da2018-01-24 12:51:27 +01001249/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001250friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001251 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001252
1253 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
1254
1255 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001256 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001257
1258 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001259 if (pars.ran_is_geran) {
1260 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1261 }
Harald Welte45164da2018-01-24 12:51:27 +01001262
1263 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001264 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001265}
1266testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1267 var BSC_ConnHdlr vc_conn;
1268 f_init();
1269
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001270 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001271 vc_conn.done;
1272}
1273
Harald Weltee13cfb22019-04-23 16:52:02 +02001274
Harald Welte45164da2018-01-24 12:51:27 +01001275/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001276friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001277 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001278
Harald Welte256571e2018-01-24 18:47:19 +01001279 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001280
1281 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001282 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001283
1284 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001285 if (pars.ran_is_geran) {
1286 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1287 }
Harald Welte45164da2018-01-24 12:51:27 +01001288
1289 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001290 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001291}
1292testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1293 var BSC_ConnHdlr vc_conn;
1294 f_init();
1295
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001296 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001297 vc_conn.done;
1298}
1299
1300
1301/* helper function for an emergency call. caller passes in mobile identity to use */
1302private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001303 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1304 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001305
Harald Welte0bef21e2018-02-10 09:48:23 +01001306 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001307}
1308
1309/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001310friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001311 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001312
Harald Welte256571e2018-01-24 18:47:19 +01001313 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001314 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001315 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001316 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001317 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001318}
1319testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1320 var BSC_ConnHdlr vc_conn;
1321 f_init();
1322
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001323 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001324 vc_conn.done;
1325}
1326
Harald Weltee13cfb22019-04-23 16:52:02 +02001327
Harald Welted5b91402018-01-24 18:48:16 +01001328/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001329friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001330 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001331 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001332 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001333 /* Then issue emergency call identified by IMSI */
1334 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1335}
1336testcase TC_emerg_call_imsi() runs on MTC_CT {
1337 var BSC_ConnHdlr vc_conn;
1338 f_init();
1339
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001340 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001341 vc_conn.done;
1342}
1343
Harald Weltee13cfb22019-04-23 16:52:02 +02001344
Harald Welte45164da2018-01-24 12:51:27 +01001345/* CM Service Request for VGCS -> reject */
1346private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001347 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001348
1349 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001350 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001351
1352 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001353 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001354 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001355 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001356 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001357}
1358testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1359 var BSC_ConnHdlr vc_conn;
1360 f_init();
1361
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001362 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001363 vc_conn.done;
1364}
1365
1366/* CM Service Request for VBS -> reject */
1367private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001368 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001369
1370 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001371 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001372
1373 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001374 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001375 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001376 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001377 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001378}
1379testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1380 var BSC_ConnHdlr vc_conn;
1381 f_init();
1382
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001383 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001384 vc_conn.done;
1385}
1386
1387/* CM Service Request for LCS -> reject */
1388private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001389 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001390
1391 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001392 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001393
1394 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001395 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001396 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001397 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001398 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001399}
1400testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1401 var BSC_ConnHdlr vc_conn;
1402 f_init();
1403
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001404 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001405 vc_conn.done;
1406}
1407
Harald Welte0195ab12018-01-24 21:50:20 +01001408/* CM Re-Establishment Request */
1409private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001410 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001411
1412 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001413 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001414
1415 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1416 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001417 f_cl3_or_initial_ue(l3_info);
Neels Hofmeyr49bbb512021-07-29 22:51:08 +02001418 /* Older osmo-msc returns: GSM48_REJECT_SRV_OPT_NOT_SUPPORTED = 32,
1419 * newer osmo-msc with CM Re-Establish support returns: GSM48_REJECT_CALL_CAN_NOT_BE_IDENTIFIED = 38 */
1420 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ( (int2oct(32,1), int2oct(38,1)) )));
Harald Welte1ddc7162018-01-27 14:25:46 +01001421 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001422}
1423testcase TC_cm_reest_req_reject() runs on MTC_CT {
1424 var BSC_ConnHdlr vc_conn;
1425 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001426
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001427 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001428 vc_conn.done;
1429}
1430
Harald Weltec638f4d2018-01-24 22:00:36 +01001431/* Test LU (with authentication enabled), with wrong response from MS */
1432private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001433 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001434
1435 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1436
1437 /* tell GSUP dispatcher to send this IMSI to us */
1438 f_create_gsup_expect(hex2str(g_pars.imsi));
1439
1440 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001441 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001442
1443 /* Send Early Classmark, just for the fun of it */
1444 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1445
1446 var AuthVector vec := f_gen_auth_vec_2g();
1447 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1448 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1449 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1450
1451 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1452 /* Send back wrong auth response */
1453 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1454
1455 /* Expect GSUP AUTH FAIL REP to HLR */
1456 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1457
1458 /* Expect LU REJECT with Cause == Illegal MS */
1459 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001460 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001461}
1462testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1463 var BSC_ConnHdlr vc_conn;
1464 f_init();
1465 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001466
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001467 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23, verify_cell_id := false);
Harald Weltec638f4d2018-01-24 22:00:36 +01001468 vc_conn.done;
1469}
1470
Harald Weltede371492018-01-27 23:44:41 +01001471/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001472private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001473 pars.net.expect_auth := true;
1474 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001475 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001476 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001477}
1478testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1479 var BSC_ConnHdlr vc_conn;
1480 f_init();
1481 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001482 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1483
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001484 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001485 vc_conn.done;
1486}
1487
Harald Welte1af6ea82018-01-25 18:33:15 +01001488/* Test Complete L3 without payload */
1489private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001490 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001491
1492 /* Send Complete L3 Info with empty L3 frame */
1493 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1494 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1495
Harald Weltef466eb42018-01-27 14:26:54 +01001496 timer T := 5.0;
1497 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001498 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001499 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001500 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001501 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001502 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001503 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001504 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001505 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001506 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001507 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001508 }
1509 setverdict(pass);
1510}
1511testcase TC_cl3_no_payload() runs on MTC_CT {
1512 var BSC_ConnHdlr vc_conn;
1513 f_init();
1514
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001515 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001516 vc_conn.done;
1517}
1518
1519/* Test Complete L3 with random payload */
1520private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001521 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001522
Daniel Willmannaa14a382018-07-26 08:29:45 +02001523 /* length is limited by PDU_BSSAP length field which includes some
1524 * other fields beside l3info payload. So payl can only be 240 bytes
1525 * Since rnd() returns values < 1 multiply with 241
1526 */
1527 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001528 var octetstring payl := f_rnd_octstring(len);
1529
1530 /* Send Complete L3 Info with empty L3 frame */
1531 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1532 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1533
Harald Weltef466eb42018-01-27 14:26:54 +01001534 timer T := 5.0;
1535 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001536 alt {
1537 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001538 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001539 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001540 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001541 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001542 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001543 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001544 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001545 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001546 }
1547 setverdict(pass);
1548}
1549testcase TC_cl3_rnd_payload() runs on MTC_CT {
1550 var BSC_ConnHdlr vc_conn;
1551 f_init();
1552
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001553 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001554 vc_conn.done;
1555}
1556
Harald Welte116e4332018-01-26 22:17:48 +01001557/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001558friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001559 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001560
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001561 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001562
Harald Welteb9e86fa2018-04-09 18:18:31 +02001563 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001564 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001565}
1566testcase TC_establish_and_nothing() runs on MTC_CT {
1567 var BSC_ConnHdlr vc_conn;
1568 f_init();
1569
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001570 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001571 vc_conn.done;
1572}
1573
Harald Weltee13cfb22019-04-23 16:52:02 +02001574
Harald Welte12510c52018-01-26 22:26:24 +01001575/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001576friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001577 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001578
Harald Welte12510c52018-01-26 22:26:24 +01001579 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001580 cpars.mgw_conn_2.resp := 0;
1581 cpars.stop_after_cc_setup := true;
1582
1583 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001584
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001585 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001586
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001587 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001588
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001589 var default ccrel := activate(as_optional_cc_rel(cpars));
1590
Philipp Maier109e6aa2018-10-17 10:53:32 +02001591 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001592
1593 deactivate(ccrel);
1594
1595 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001596}
1597testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1598 var BSC_ConnHdlr vc_conn;
1599 f_init();
1600
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001601 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001602 vc_conn.done;
1603}
1604
Harald Weltee13cfb22019-04-23 16:52:02 +02001605
Harald Welte3ab88002018-01-26 22:37:25 +01001606/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001607friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001608 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001609 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1610 var MNCC_PDU mncc;
1611 var MgcpCommand mgcp_cmd;
1612
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001613 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001614 /* Do not respond to the second CRCX */
1615 cpars.mgw_conn_2.resp := 0;
1616 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001617
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001618 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001619
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001620 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001621
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001622 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001623}
1624testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1625 var BSC_ConnHdlr vc_conn;
1626 f_init();
1627
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001628 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001629 vc_conn.done;
1630}
1631
Harald Weltee13cfb22019-04-23 16:52:02 +02001632
Harald Welte0cc82d92018-01-26 22:52:34 +01001633/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001634friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001635 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001636
Harald Welte0cc82d92018-01-26 22:52:34 +01001637 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001638
1639 /* Respond with error for the first CRCX */
1640 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001641
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001642 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001643 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001644
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001645 var default ccrel := activate(as_optional_cc_rel(cpars));
1646 f_expect_clear(60.0);
1647 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001648}
1649testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1650 var BSC_ConnHdlr vc_conn;
1651 f_init();
1652
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001653 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001654 vc_conn.done;
1655}
1656
Harald Welte3ab88002018-01-26 22:37:25 +01001657
Harald Welte812f7a42018-01-27 00:49:18 +01001658/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1659private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1660 var MNCC_PDU mncc;
1661 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001662
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001663 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001664 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001665
1666 /* Allocate call reference and send SETUP via MNCC to MSC */
1667 cpars.mncc_callref := f_rnd_int(2147483648);
1668 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1669 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1670
1671 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001672 f_expect_paging();
1673
Harald Welte812f7a42018-01-27 00:49:18 +01001674 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001675 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001676
1677 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1678
1679 /* MSC->MS: SETUP */
1680 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1681}
1682
1683/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001684friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001685 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001686 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1687 var MNCC_PDU mncc;
1688 var MgcpCommand mgcp_cmd;
1689
1690 f_mt_call_start(cpars);
1691
1692 /* MS->MSC: CALL CONFIRMED */
1693 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1694
1695 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1696
1697 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1698 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001699
1700 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1701 * set an endpoint name that fits the pattern. If not, just use the
1702 * endpoint name from the request */
1703 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1704 cpars.mgcp_ep := "rtpbridge/1@mgw";
1705 } else {
1706 cpars.mgcp_ep := mgcp_cmd.line.ep;
1707 }
1708
Harald Welte812f7a42018-01-27 00:49:18 +01001709 /* Respond to CRCX with error */
1710 var MgcpResponse mgcp_rsp := {
1711 line := {
1712 code := "542",
1713 trans_id := mgcp_cmd.line.trans_id,
1714 string := "FORCED_FAIL"
1715 },
Harald Welte812f7a42018-01-27 00:49:18 +01001716 sdp := omit
1717 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001718 var MgcpParameter mgcp_rsp_param := {
1719 code := "Z",
1720 val := cpars.mgcp_ep
1721 };
1722 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001723 MGCP.send(mgcp_rsp);
1724
1725 timer T := 30.0;
1726 T.start;
1727 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001728 [] T.timeout {
1729 setverdict(fail, "Timeout waiting for channel release");
1730 mtc.stop;
1731 }
Harald Welte812f7a42018-01-27 00:49:18 +01001732 [] MNCC.receive { repeat; }
1733 [] GSUP.receive { repeat; }
1734 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1735 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1736 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1737 repeat;
1738 }
1739 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001740 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001741 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001742 }
1743}
1744testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1745 var BSC_ConnHdlr vc_conn;
1746 f_init();
1747
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001748 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001749 vc_conn.done;
1750}
1751
1752
Harald Weltee13cfb22019-04-23 16:52:02 +02001753
Harald Welte812f7a42018-01-27 00:49:18 +01001754/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001755friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte812f7a42018-01-27 00:49:18 +01001756 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Harald Welte812f7a42018-01-27 00:49:18 +01001757 var MgcpCommand mgcp_cmd;
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001758 var PDU_BSSAP bssap;
1759 timer T310;
Harald Welte812f7a42018-01-27 00:49:18 +01001760
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001761 f_init_handler(pars);
1762
1763 /* Initiate a MT call, establish connection */
Harald Welte812f7a42018-01-27 00:49:18 +01001764 f_mt_call_start(cpars);
1765
1766 /* MS->MSC: CALL CONFIRMED */
1767 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1768 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1769
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001770 /* NOTE: MSC is expected to start T310 here */
Harald Welte812f7a42018-01-27 00:49:18 +01001771
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001772 /* MSC->MGW: CRCX (first) */
1773 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1774 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
1775
1776 /* BSC->BSC: BSSMAP ASSIGNMENT REQ */
1777 BSSAP.receive(tr_BSSMAP_AssignmentReq(omit, ?)) -> value bssap;
1778 BSSAP.send(ts_BSSMAP_AssignmentComplete(omit,
1779 aoip := f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port),
1780 speechCodec := ts_BSSMAP_IE_SpeechCodec({ ts_CodecFR })));
1781
1782 /* MSC->MGW: MDCX */
1783 MGCP.receive(tr_MDCX) -> value mgcp_cmd;
1784 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_1.mgcp_connection_id,
1785 sdp := omit));
1786
1787 /* MSC->MGW: CRCX (second) */
1788 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1789 f_handle_crcx(cpars, mgcp_cmd); /* MSC<-MGW: OK */
1790 MNCC.receive(tr_MNCC_RTP_CREATE(cpars.mncc_callref));
1791
1792 /* Reschedule the guard timeout */
1793 g_Tguard.start(30.0 + 10.0);
1794
1795 /* NOTE: the BSC is expected to respond with CC ALERTING at this state, so
1796 * the MSC would stop T310. However, the idea is to verify T310 expiration
1797 * here, so grab some popcorn and wait for MNCC DISC.ind. */
1798 T310.start(30.0 + 2.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001799 alt {
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001800 [] T310.timeout {
1801 setverdict(fail, "Timeout waiting for MNCC DISC.ind due to T310");
Daniel Willmannafce8662018-07-06 23:11:32 +02001802 mtc.stop;
1803 }
Harald Welte812f7a42018-01-27 00:49:18 +01001804 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1805 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001806 log("Rx MNCC DISC.ind, T310.read yelds ", T310.read);
1807 setverdict(pass);
Harald Welte812f7a42018-01-27 00:49:18 +01001808 }
1809 }
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001810
Harald Welte812f7a42018-01-27 00:49:18 +01001811 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1812 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001813 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, '1'B)));
Harald Welte812f7a42018-01-27 00:49:18 +01001814
1815 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001816 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1817 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01001818 // FIXME: f_create_mgcp_delete_ep(cpars.mgcp_ep);
Harald Welte812f7a42018-01-27 00:49:18 +01001819 repeat;
1820 }
Harald Welte5946b332018-03-18 23:32:21 +01001821 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001822 }
1823}
1824testcase TC_mt_t310() runs on MTC_CT {
1825 var BSC_ConnHdlr vc_conn;
1826 f_init();
1827
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001828 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001829 vc_conn.done;
1830}
1831
Harald Weltee13cfb22019-04-23 16:52:02 +02001832
Harald Welte167458a2018-01-27 15:58:16 +01001833/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001834friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001835 f_init_handler(pars);
1836 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001837
1838 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001839 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001840
1841 /* First MO call should succeed */
1842 f_mo_call(cpars);
1843
1844 /* Cancel the subscriber in the VLR */
1845 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1846 alt {
1847 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1848 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1849 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001850 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001851 }
1852 }
1853
1854 /* Follow-up transactions should fail */
1855 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1856 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001857 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001858 alt {
1859 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1860 [] BSSAP.receive {
1861 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001862 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001863 }
1864 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001865
1866 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001867 setverdict(pass);
1868}
1869testcase TC_gsup_cancel() runs on MTC_CT {
1870 var BSC_ConnHdlr vc_conn;
1871 f_init();
1872
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001873 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33, verify_cell_id := false);
Harald Welte167458a2018-01-27 15:58:16 +01001874 vc_conn.done;
1875}
1876
Harald Weltee13cfb22019-04-23 16:52:02 +02001877
Harald Welte9de84792018-01-28 01:06:35 +01001878/* A5/1 only permitted on network side, and MS capable to do it */
1879private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1880 pars.net.expect_auth := true;
1881 pars.net.expect_ciph := true;
1882 pars.net.kc_support := '02'O; /* A5/1 only */
1883 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001884 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001885}
1886testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1887 var BSC_ConnHdlr vc_conn;
1888 f_init();
1889 f_vty_config(MSCVTY, "network", "authentication required");
1890 f_vty_config(MSCVTY, "network", "encryption a5 1");
1891
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001892 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001893 vc_conn.done;
1894}
1895
1896/* A5/3 only permitted on network side, and MS capable to do it */
1897private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1898 pars.net.expect_auth := true;
1899 pars.net.expect_ciph := true;
1900 pars.net.kc_support := '08'O; /* A5/3 only */
1901 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001902 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001903}
1904testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1905 var BSC_ConnHdlr vc_conn;
1906 f_init();
1907 f_vty_config(MSCVTY, "network", "authentication required");
1908 f_vty_config(MSCVTY, "network", "encryption a5 3");
1909
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001910 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001911 vc_conn.done;
1912}
1913
1914/* A5/3 only permitted on network side, and MS with only A5/1 support */
1915private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1916 pars.net.expect_auth := true;
1917 pars.net.expect_ciph := true;
1918 pars.net.kc_support := '08'O; /* A5/3 only */
1919 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1920 f_init_handler(pars, 15.0);
1921
1922 /* cannot use f_perform_lu() as we expect a reject */
1923 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1924 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001925 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001926 if (pars.send_early_cm) {
1927 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1928 } else {
1929 pars.cm1.esind := '0'B;
1930 }
Harald Welte9de84792018-01-28 01:06:35 +01001931 f_mm_auth();
1932 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001933 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1934 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1935 repeat;
1936 }
Harald Welte5946b332018-03-18 23:32:21 +01001937 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1938 f_expect_clear();
1939 }
Harald Welte9de84792018-01-28 01:06:35 +01001940 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1941 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001942 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001943 }
1944 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001945 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001946 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001947 }
1948 }
1949 setverdict(pass);
1950}
1951testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1952 var BSC_ConnHdlr vc_conn;
1953 f_init();
1954 f_vty_config(MSCVTY, "network", "authentication required");
1955 f_vty_config(MSCVTY, "network", "encryption a5 3");
1956
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001957 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001958 vc_conn.done;
1959}
1960testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1961 var BSC_ConnHdlrPars pars;
1962 var BSC_ConnHdlr vc_conn;
1963 f_init();
1964 f_vty_config(MSCVTY, "network", "authentication required");
1965 f_vty_config(MSCVTY, "network", "encryption a5 3");
1966
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001967 pars := f_init_pars(361, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001968 pars.send_early_cm := false;
1969 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001970 vc_conn.done;
1971}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001972testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1973 var BSC_ConnHdlr vc_conn;
1974 f_init();
1975 f_vty_config(MSCVTY, "network", "authentication required");
1976 f_vty_config(MSCVTY, "network", "encryption a5 3");
1977
1978 /* Make sure the MSC category is on DEBUG level to trigger the log
1979 * message that is reported in OS#2947 to trigger the segfault */
1980 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1981
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001982 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362, verify_cell_id := false);
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001983 vc_conn.done;
1984}
Harald Welte9de84792018-01-28 01:06:35 +01001985
1986/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1987private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1988 pars.net.expect_auth := true;
1989 pars.net.expect_ciph := true;
1990 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1991 pars.cm1.a5_1 := '1'B;
1992 pars.cm2.a5_1 := '1'B;
1993 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1994 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1995 f_init_handler(pars, 15.0);
1996
1997 /* cannot use f_perform_lu() as we expect a reject */
1998 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1999 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02002000 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01002001 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
2002 f_mm_auth();
2003 alt {
Harald Welte5946b332018-03-18 23:32:21 +01002004 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
2005 f_expect_clear();
2006 }
Harald Welte9de84792018-01-28 01:06:35 +01002007 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
2008 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02002009 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01002010 }
2011 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01002012 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02002013 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01002014 }
2015 }
2016 setverdict(pass);
2017}
2018testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
2019 var BSC_ConnHdlr vc_conn;
2020 f_init();
2021 f_vty_config(MSCVTY, "network", "authentication required");
2022 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
2023
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02002024 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37, verify_cell_id := false);
Harald Welte9de84792018-01-28 01:06:35 +01002025 vc_conn.done;
2026}
2027
Eric Wild26f4a622021-05-17 15:27:05 +02002028/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with only A5/1 support */
2029private function f_tc_lu_imsi_auth_tmsi_encr_0134_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2030 pars.net.expect_auth := true;
2031 pars.net.expect_ciph := true;
2032 pars.net.kc_support := '03'O; /* A5/0 + A5/1 */
2033 pars.cm1.a5_1 := '0'B;
2034 pars.cm2.a5_1 := '0'B;
2035 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2036 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2037 pars.cm2.classmarkInformationType2_oct5.cm3 := '0'B;
2038 pars.cm3 := omit;
2039 pars.use_umts_aka := true;
2040
2041 f_init_handler(pars, 15.0);
2042 f_perform_lu();
2043}
2044testcase TC_lu_imsi_auth_tmsi_encr_0134_1() runs on MTC_CT {
2045 var BSC_ConnHdlr vc_conn;
2046 f_init();
2047 f_vty_config(MSCVTY, "network", "authentication required");
2048 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2049
2050 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_1), 39);
2051 vc_conn.done;
2052}
2053
2054/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with A5/3 + A5/4 support */
2055private function f_tc_lu_imsi_auth_tmsi_encr_0134_34(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2056 pars.net.expect_auth := true;
2057 pars.net.expect_ciph := true;
2058 pars.net.kc_support := '19'O; /* A5/3 + A5/4 */
2059 pars.cm1.a5_1 := '1'B;
2060 pars.cm2.a5_1 := '1'B;
2061 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
2062 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2063 pars.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
2064 pars.cm3 := valueof(ts_CM3_default);
2065 pars.use_umts_aka := true;
2066
2067 f_init_handler(pars, 15.0);
2068 f_perform_lu();
2069}
2070testcase TC_lu_imsi_auth_tmsi_encr_0134_34() runs on MTC_CT {
2071 var BSC_ConnHdlr vc_conn;
2072 f_init();
2073 f_vty_config(MSCVTY, "network", "authentication required");
2074 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2075
2076 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_34), 40);
2077 vc_conn.done;
2078}
2079
2080/* A5/0 + A5/1 + A5/3 + a5/4 only permitted on network side, and MS with A5/3 support but no CM3 */
2081private function f_tc_lu_imsi_auth_tmsi_encr_0134_34_no_cm3(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2082 pars.net.expect_auth := true;
2083 pars.net.expect_ciph := true;
2084 pars.net.kc_support := '19'O; /* A5/3 + A5/4 */
2085 pars.cm1.a5_1 := '1'B;
2086 pars.cm2.a5_1 := '1'B;
2087 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
2088 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
2089 pars.cm2.classmarkInformationType2_oct5.cm3 := '0'B;
2090 pars.cm3 := omit;
2091 pars.use_umts_aka := true;
2092
2093 f_init_handler(pars, 15.0);
2094 f_perform_lu();
2095}
2096testcase TC_lu_imsi_auth_tmsi_encr_0134_34_no_cm3() runs on MTC_CT {
2097 var BSC_ConnHdlr vc_conn;
2098 f_init();
2099 f_vty_config(MSCVTY, "network", "authentication required");
2100 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3 4");
2101
2102 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_0134_34_no_cm3), 41);
2103 vc_conn.done;
2104}
2105
Harald Welte9de84792018-01-28 01:06:35 +01002106/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
2107private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2108 pars.net.expect_auth := true;
2109 pars.net.expect_ciph := true;
2110 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
2111 pars.cm1.a5_1 := '1'B;
2112 pars.cm2.a5_1 := '1'B;
2113 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
2114 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
2115 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002116 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01002117}
2118testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
2119 var BSC_ConnHdlr vc_conn;
2120 f_init();
2121 f_vty_config(MSCVTY, "network", "authentication required");
2122 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
2123
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002124 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01002125 vc_conn.done;
2126}
2127
Harald Welte33ec09b2018-02-10 15:34:46 +01002128/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01002129friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01002130 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002131 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002132 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01002133
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002134 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01002135 f_mt_call(cpars);
2136}
2137testcase TC_lu_and_mt_call() runs on MTC_CT {
2138 var BSC_ConnHdlr vc_conn;
2139 f_init();
2140
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002141 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01002142 vc_conn.done;
2143}
2144
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002145testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
2146 var BSC_ConnHdlr vc_conn;
2147 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02002148
2149 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
2150 vc_conn.done;
2151}
2152
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002153/* LU followed by MT call (including paging) */
2154friend function f_tc_lu_and_mt_call_ipv6(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2155 f_init_handler(pars);
2156 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2157 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
2158 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
2159 cpars.bss_rtp_ip := "::3";
Pau Espin Pedrol563b3d02020-09-09 20:19:52 +02002160 cpars.mncc_rtp_ip := "::9";
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02002161 f_perform_lu();
2162 f_mt_call(cpars);
2163}
2164testcase TC_lu_and_mt_call_ipv6() runs on MTC_CT {
2165 var BSC_ConnHdlr vc_conn;
2166 f_init();
2167
2168 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_ipv6), 39);
2169 vc_conn.done;
2170}
2171
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002172/* MT call while already Paging */
2173friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2174 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
2175 var SmsParameters spars := valueof(t_SmsPars);
2176 var OCT4 tmsi;
2177
2178 f_init_handler(pars);
2179
2180 /* Perform location update */
2181 f_perform_lu();
2182
2183 /* register an 'expect' for given IMSI (+TMSI) */
2184 if (isvalue(g_pars.tmsi)) {
2185 tmsi := g_pars.tmsi;
2186 } else {
2187 tmsi := 'FFFFFFFF'O;
2188 }
2189 f_ran_register_imsi(g_pars.imsi, tmsi);
2190
2191 log("start Paging by an SMS");
2192 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2193
2194 /* MSC->BSC: expect PAGING from MSC */
2195 f_expect_paging();
2196
2197 log("MNCC signals MT call, before Paging Response");
2198 f_mt_call_initate(cpars);
2199 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
2200
2201 f_sleep(0.5);
2202 log("phone answers Paging, expecting both SMS and MT call to be established");
2203 f_establish_fully(EST_TYPE_PAG_RESP);
2204 spars.tp.ud := 'C8329BFD064D9B53'O;
2205 interleave {
2206 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
2207 log("Got SMS-DELIVER");
2208 };
2209 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
2210 log("Got CC Setup");
2211 };
2212 }
2213 setverdict(pass);
2214 log("success, tear down");
2215 var default ccrel := activate(as_optional_cc_rel(cpars));
2216 if (g_pars.ran_is_geran) {
2217 BSSAP.send(ts_BSSMAP_ClearRequest(0));
2218 } else {
2219 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
2220 }
2221 f_expect_clear();
2222 deactivate(ccrel);
2223 f_vty_sms_clear(hex2str(g_pars.imsi));
2224}
2225testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
2226 var BSC_ConnHdlrPars pars;
2227 var BSC_ConnHdlr vc_conn;
2228 f_init();
2229 pars := f_init_pars(391);
2230 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
2231 vc_conn.done;
2232}
2233
Daniel Willmann8b084372018-02-04 13:35:26 +01002234/* Test MO Call SETUP with DTMF */
2235private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2236 f_init_handler(pars);
2237 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01002238
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01002239 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01002240 f_mo_seq_dtmf_dup(cpars);
2241}
2242testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
2243 var BSC_ConnHdlr vc_conn;
2244 f_init();
2245
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01002246 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01002247 vc_conn.done;
2248}
Harald Welte9de84792018-01-28 01:06:35 +01002249
Philipp Maier328d1662018-03-07 10:40:27 +01002250testcase TC_cr_before_reset() runs on MTC_CT {
2251 timer T := 4.0;
2252 var boolean reset_ack_seen := false;
2253 f_init_bssap_direct();
2254
Harald Welte3ca0ce12019-04-23 17:18:48 +02002255 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02002256
Daniel Willmanne8018962018-08-21 14:18:00 +02002257 f_sleep(3.0);
2258
Philipp Maier328d1662018-03-07 10:40:27 +01002259 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02002260 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01002261
2262 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02002263 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01002264 T.start
2265 alt {
2266 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
2267 reset_ack_seen := true;
2268 repeat;
2269 }
2270
2271 /* Acknowledge MSC sided reset requests */
2272 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02002273 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01002274 repeat;
2275 }
2276
2277 /* Ignore all other messages (e.g CR from the connection request) */
2278 [] BSSAP_DIRECT.receive { repeat }
2279
2280 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
2281 * deadlock situation. The MSC is then unable to respond to any
2282 * further BSSMAP RESET or any other sort of traffic. */
2283 [reset_ack_seen == true] T.timeout { setverdict(pass) }
2284 [reset_ack_seen == false] T.timeout {
2285 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02002286 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01002287 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01002288 }
Philipp Maier328d1662018-03-07 10:40:27 +01002289}
Harald Welte9de84792018-01-28 01:06:35 +01002290
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002291/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02002292friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002293 f_init_handler(pars);
2294 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2295 var MNCC_PDU mncc;
2296 var MgcpCommand mgcp_cmd;
2297
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002298 /* Do not respond to the second CRCX */
2299 cpars.mgw_conn_2.resp := 0;
2300
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002301 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02002302 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002303
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002304 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002305
2306 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01002307
2308 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002309}
2310testcase TC_mo_release_timeout() runs on MTC_CT {
2311 var BSC_ConnHdlr vc_conn;
2312 f_init();
2313
2314 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
2315 vc_conn.done;
2316}
2317
Harald Welte12510c52018-01-26 22:26:24 +01002318
Philipp Maier2a98a732018-03-19 16:06:12 +01002319/* LU followed by MT call (including paging) */
2320private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2321 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01002322 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01002323
2324 /* Intentionally disable the CRCX response */
2325 cpars.mgw_drop_dlcx := true;
2326
2327 /* Perform location update and call */
2328 f_perform_lu();
2329 f_mt_call(cpars);
2330}
2331testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
2332 var BSC_ConnHdlr vc_conn;
2333 f_init();
2334
2335 /* Perform an almost normal looking locationupdate + mt-call, but do
2336 * not respond to the DLCX at the end of the call */
2337 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
2338 vc_conn.done;
2339
2340 /* Wait a guard period until the MGCP layer in the MSC times out,
2341 * if the MSC is vulnerable to the use-after-free situation that is
2342 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
2343 * segfault now */
2344 f_sleep(6.0);
2345
2346 /* Run the init procedures once more. If the MSC has crashed, this
2347 * this will fail */
2348 f_init();
2349}
Harald Welte45164da2018-01-24 12:51:27 +01002350
Philipp Maier75932982018-03-27 14:52:35 +02002351/* Two BSSMAP resets from two different BSCs */
2352testcase TC_reset_two() runs on MTC_CT {
2353 var BSC_ConnHdlr vc_conn;
2354 f_init(2);
2355 f_sleep(2.0);
2356 setverdict(pass);
2357}
2358
Harald Weltee13cfb22019-04-23 16:52:02 +02002359/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
2360testcase TC_reset_two_1iu() runs on MTC_CT {
2361 var BSC_ConnHdlr vc_conn;
2362 f_init(3);
2363 f_sleep(2.0);
2364 setverdict(pass);
2365}
2366
Harald Weltef640a012018-04-14 17:49:21 +02002367/***********************************************************************
2368 * SMS Testing
2369 ***********************************************************************/
2370
Harald Weltef45efeb2018-04-09 18:19:24 +02002371/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002372friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002373 var SmsParameters spars := valueof(t_SmsPars);
2374
2375 f_init_handler(pars);
2376
2377 /* Perform location update and call */
2378 f_perform_lu();
2379
2380 f_establish_fully(EST_TYPE_MO_SMS);
2381
2382 //spars.exp_rp_err := 96; /* invalid mandatory information */
2383 f_mo_sms(spars);
2384
2385 f_expect_clear();
2386}
2387testcase TC_lu_and_mo_sms() runs on MTC_CT {
2388 var BSC_ConnHdlr vc_conn;
2389 f_init();
2390 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2391 vc_conn.done;
2392}
2393
Harald Weltee13cfb22019-04-23 16:52:02 +02002394
Harald Weltef45efeb2018-04-09 18:19:24 +02002395private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002396runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002397 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2398}
2399
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002400/* Remove still pending SMS */
2401private function f_vty_sms_clear(charstring imsi)
2402runs on BSC_ConnHdlr {
2403 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2404 f_vty_transceive(MSCVTY, "sms-queue clear");
2405}
2406
Harald Weltef45efeb2018-04-09 18:19:24 +02002407/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002408friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002409 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002410
2411 f_init_handler(pars);
2412
2413 /* Perform location update and call */
2414 f_perform_lu();
2415
2416 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002417 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002418
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002419 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002420
2421 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002422 f_expect_paging();
2423
Harald Weltef45efeb2018-04-09 18:19:24 +02002424 /* Establish DTAP / BSSAP / SCCP connection */
2425 f_establish_fully(EST_TYPE_PAG_RESP);
2426
2427 spars.tp.ud := 'C8329BFD064D9B53'O;
2428 f_mt_sms(spars);
2429
2430 f_expect_clear();
2431}
2432testcase TC_lu_and_mt_sms() runs on MTC_CT {
2433 var BSC_ConnHdlrPars pars;
2434 var BSC_ConnHdlr vc_conn;
2435 f_init();
2436 pars := f_init_pars(43);
2437 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002438 vc_conn.done;
2439}
2440
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002441/* SMS added while already Paging */
2442friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2443 var SmsParameters spars := valueof(t_SmsPars);
2444 var OCT4 tmsi;
2445
2446 f_init_handler(pars);
2447
2448 f_perform_lu();
2449
2450 /* register an 'expect' for given IMSI (+TMSI) */
2451 if (isvalue(g_pars.tmsi)) {
2452 tmsi := g_pars.tmsi;
2453 } else {
2454 tmsi := 'FFFFFFFF'O;
2455 }
2456 f_ran_register_imsi(g_pars.imsi, tmsi);
2457
2458 log("first SMS");
2459 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2460
2461 /* MSC->BSC: expect PAGING from MSC */
2462 f_expect_paging();
2463
2464 log("second SMS");
2465 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2466 * with the pending paging. Another SMS: */
2467 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2468
2469 /* Establish DTAP / BSSAP / SCCP connection */
2470 f_establish_fully(EST_TYPE_PAG_RESP);
2471
2472 spars.tp.ud := 'C8329BFD064D9B53'O;
2473 f_mt_sms(spars);
2474
2475 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2476 f_mt_sms(spars);
2477
2478 f_expect_clear();
2479}
2480testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2481 var BSC_ConnHdlrPars pars;
2482 var BSC_ConnHdlr vc_conn;
2483 f_init();
2484 pars := f_init_pars(44);
2485 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2486 vc_conn.done;
2487}
Harald Weltee13cfb22019-04-23 16:52:02 +02002488
Philipp Maier3983e702018-11-22 19:01:33 +01002489/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002490friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002491 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002492
Philipp Maier3983e702018-11-22 19:01:33 +01002493 f_init_handler(pars, 150.0);
2494
2495 /* Perform location update */
2496 f_perform_lu();
2497
2498 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002499 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002500
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002501 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2502
Neels Hofmeyr16237742019-03-06 15:34:01 +01002503 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002504 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002505
2506 /* Wait some time to make sure the MSC is not delivering any further
2507 * paging messages or anything else that could be unexpected. */
2508 timer T := 20.0;
2509 T.start
2510 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002511 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2512 setverdict(fail, "paging seems not to stop!");
2513 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002514 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002515 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2516 setverdict(fail, "paging seems not to stop!");
2517 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002518 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002519 [] BSSAP.receive {
2520 setverdict(fail, "unexpected BSSAP message received");
2521 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002522 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002523 [] T.timeout {
2524 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002525 }
2526 }
2527
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002528 f_vty_sms_clear(hex2str(g_pars.imsi));
2529
Philipp Maier3983e702018-11-22 19:01:33 +01002530 setverdict(pass);
2531}
2532testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2533 var BSC_ConnHdlrPars pars;
2534 var BSC_ConnHdlr vc_conn;
2535 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002536 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002537 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002538 vc_conn.done;
2539}
2540
Alexander Couzensfc02f242019-09-12 03:43:18 +02002541/* LU followed by MT SMS with repeated paging */
2542friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2543 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002544
2545 f_init_handler(pars);
2546
2547 /* Perform location update and call */
2548 f_perform_lu();
2549
2550 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002551 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002552
2553 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2554
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002555 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002556 /* MSC->BSC: expect PAGING from MSC */
2557 f_expect_paging();
2558
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002559 if (g_pars.ran_is_geran) {
2560 log("GERAN: expect no further Paging");
2561 } else {
2562 log("UTRAN: expect more Paging");
2563 }
2564
2565 timer T := 5.0;
2566 T.start;
2567 alt {
2568 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2569 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2570 mtc.stop;
2571 }
2572 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2573 log("UTRAN: second Paging received, as expected");
2574 setverdict(pass);
2575 }
2576 [] T.timeout {
2577 if (g_pars.ran_is_geran) {
2578 log("GERAN: No further Paging received, as expected");
2579 setverdict(pass);
2580 } else {
2581 setverdict(fail, "UTRAN: Expected a second Paging");
2582 mtc.stop;
2583 }
2584 }
2585 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002586
2587 /* Establish DTAP / BSSAP / SCCP connection */
2588 f_establish_fully(EST_TYPE_PAG_RESP);
2589
2590 spars.tp.ud := 'C8329BFD064D9B53'O;
2591 f_mt_sms(spars);
2592
2593 f_expect_clear();
2594}
2595testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2596 var BSC_ConnHdlrPars pars;
2597 var BSC_ConnHdlr vc_conn;
2598 f_init();
2599 pars := f_init_pars(1844);
2600 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2601 vc_conn.done;
2602}
Harald Weltee13cfb22019-04-23 16:52:02 +02002603
Harald Weltef640a012018-04-14 17:49:21 +02002604/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002605friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002606 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002607
Harald Weltef640a012018-04-14 17:49:21 +02002608 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002609
Harald Weltef640a012018-04-14 17:49:21 +02002610 /* Perform location update so IMSI is known + registered in MSC/VLR */
2611 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002612
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002613 /* MS/UE submits a MO SMS */
2614 f_establish_fully(EST_TYPE_MO_SMS);
2615 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002616
2617 var SMPP_PDU smpp;
2618 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2619 tr_smpp.body.deliver_sm := {
2620 service_type := "CMT",
2621 source_addr_ton := network_specific,
2622 source_addr_npi := isdn,
2623 source_addr := hex2str(pars.msisdn),
2624 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2625 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2626 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2627 esm_class := '00000001'B,
2628 protocol_id := 0,
2629 priority_flag := 0,
2630 schedule_delivery_time := "",
2631 replace_if_present := 0,
2632 data_coding := '00000001'B,
2633 sm_default_msg_id := 0,
2634 sm_length := ?,
2635 short_message := spars.tp.ud,
2636 opt_pars := {
2637 {
2638 tag := user_message_reference,
2639 len := 2,
2640 opt_value := {
2641 int2_val := oct2int(spars.tp.msg_ref)
2642 }
2643 }
2644 }
2645 };
2646 alt {
2647 [] SMPP.receive(tr_smpp) -> value smpp {
2648 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2649 }
2650 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2651 }
2652
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002653 /* MSC terminates the SMS transaction with RP-ACK */
2654 f_mo_sms_wait_rp_ack(spars);
2655
Harald Weltef640a012018-04-14 17:49:21 +02002656 f_expect_clear();
2657}
2658testcase TC_smpp_mo_sms() runs on MTC_CT {
2659 var BSC_ConnHdlr vc_conn;
2660 f_init();
2661 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2662 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2663 vc_conn.done;
2664 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2665}
2666
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002667/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2668friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2669runs on BSC_ConnHdlr {
2670 var SmsParameters spars := valueof(t_SmsPars);
2671 var SMPP_PDU smpp_pdu;
2672 timer T := 3.0;
2673
2674 f_init_handler(pars);
2675
2676 /* Perform location update */
2677 f_perform_lu();
2678
2679 /* MS/UE submits a MO SMS */
2680 f_establish_fully(EST_TYPE_MO_SMS);
2681 f_mo_sms_submit(spars);
2682
2683 /* ESME responds with an error (Invalid Destination Address) */
2684 T.start;
2685 alt {
2686 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2687 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2688 }
2689 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2690 [] T.timeout {
2691 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2692 mtc.stop;
2693 }
2694 }
2695
2696 /* Expect RP-ERROR on BSSAP interface */
2697 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2698 f_mo_sms_wait_rp_ack(spars);
2699
2700 f_expect_clear();
2701}
2702testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2703 var BSC_ConnHdlr vc_conn;
2704 f_init();
2705 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2706 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2707 vc_conn.done;
2708 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2709}
2710
Harald Weltee13cfb22019-04-23 16:52:02 +02002711
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002712/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002713friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002714runs on BSC_ConnHdlr {
2715 var SmsParameters spars := valueof(t_SmsPars);
2716 var GSUP_PDU gsup_msg_rx;
2717 var octetstring sm_tpdu;
2718
2719 f_init_handler(pars);
2720
2721 /* We need to inspect GSUP activity */
2722 f_create_gsup_expect(hex2str(g_pars.imsi));
2723
2724 /* Perform location update */
2725 f_perform_lu();
2726
2727 /* Send CM Service Request for SMS */
2728 f_establish_fully(EST_TYPE_MO_SMS);
2729
2730 /* Prepare expected SM-RP-UI (SM TPDU) */
2731 enc_TPDU_RP_DATA_MS_SGSN_fast(
2732 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2733 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2734 spars.tp.udl, spars.tp.ud)),
2735 sm_tpdu);
2736
2737 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2738 imsi := g_pars.imsi,
2739 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002740 /* SM-RP-DA: SMSC address */
2741 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2742 number := spars.rp.smsc_addr.rP_NumberDigits,
2743 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2744 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2745 ext := spars.rp.smsc_addr.rP_Ext)),
2746 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2747 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2748 number := g_pars.msisdn,
2749 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2750 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002751 /* TODO: can we use decmatch here? */
2752 sm_rp_ui := sm_tpdu
2753 );
2754
2755 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2756 f_mo_sms_submit(spars);
2757 alt {
2758 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002759 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002760 setverdict(pass);
2761 }
2762 [] GSUP.receive {
2763 log("RX unexpected GSUP message");
2764 setverdict(fail);
2765 mtc.stop;
2766 }
2767 }
2768
2769 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2770 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2771 imsi := g_pars.imsi,
2772 sm_rp_mr := spars.rp.msg_ref)));
2773 /* Expect RP-ACK on DTAP */
2774 f_mo_sms_wait_rp_ack(spars);
2775
2776 f_expect_clear();
2777}
2778testcase TC_gsup_mo_sms() runs on MTC_CT {
2779 var BSC_ConnHdlr vc_conn;
2780 f_init();
2781 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2782 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2783 vc_conn.done;
2784 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2785}
2786
Harald Weltee13cfb22019-04-23 16:52:02 +02002787
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002788/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002789friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002790runs on BSC_ConnHdlr {
2791 var SmsParameters spars := valueof(t_SmsPars);
2792 var GSUP_PDU gsup_msg_rx;
2793
2794 f_init_handler(pars);
2795
2796 /* We need to inspect GSUP activity */
2797 f_create_gsup_expect(hex2str(g_pars.imsi));
2798
2799 /* Perform location update */
2800 f_perform_lu();
2801
2802 /* Send CM Service Request for SMS */
2803 f_establish_fully(EST_TYPE_MO_SMS);
2804
2805 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2806 imsi := g_pars.imsi,
2807 sm_rp_mr := spars.rp.msg_ref,
2808 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2809 );
2810
2811 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2812 f_mo_smma(spars);
2813 alt {
2814 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002815 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002816 setverdict(pass);
2817 }
2818 [] GSUP.receive {
2819 log("RX unexpected GSUP message");
2820 setverdict(fail);
2821 mtc.stop;
2822 }
2823 }
2824
2825 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2826 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2827 imsi := g_pars.imsi,
2828 sm_rp_mr := spars.rp.msg_ref)));
2829 /* Expect RP-ACK on DTAP */
2830 f_mo_sms_wait_rp_ack(spars);
2831
2832 f_expect_clear();
2833}
2834testcase TC_gsup_mo_smma() runs on MTC_CT {
2835 var BSC_ConnHdlr vc_conn;
2836 f_init();
2837 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2838 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2839 vc_conn.done;
2840 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2841}
2842
Harald Weltee13cfb22019-04-23 16:52:02 +02002843
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002844/* Helper for sending MT SMS over GSUP */
2845private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2846runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002847 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002848 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2849 number := spars.rp.smsc_addr.rP_NumberDigits,
2850 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2851 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2852 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002853
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002854 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2855 imsi := g_pars.imsi,
2856 /* NOTE: MSC should assign RP-MR itself */
2857 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002858 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002859 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002860 /* Encoded SMS TPDU (taken from Wireshark)
2861 * FIXME: we should encode spars somehow */
2862 sm_rp_ui := '00068021436500008111328130858200'O,
2863 sm_rp_mms := mms
2864 ));
2865}
2866
2867/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002868friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002869runs on BSC_ConnHdlr {
2870 var SmsParameters spars := valueof(t_SmsPars);
2871
2872 f_init_handler(pars);
2873
2874 /* We need to inspect GSUP activity */
2875 f_create_gsup_expect(hex2str(g_pars.imsi));
2876
2877 /* Perform location update */
2878 f_perform_lu();
2879
2880 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002881 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002882
2883 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2884 imsi := g_pars.imsi,
2885 /* NOTE: MSC should assign RP-MR itself */
2886 sm_rp_mr := ?
2887 );
2888
2889 /* Submit a MT SMS on GSUP */
2890 f_gsup_forwardSM_req(spars);
2891
2892 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002893 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002894 f_establish_fully(EST_TYPE_PAG_RESP);
2895
2896 /* Wait for MT SMS on DTAP */
2897 f_mt_sms_expect(spars);
2898
2899 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2900 f_mt_sms_send_rp_ack(spars);
2901 alt {
2902 [] GSUP.receive(mt_forwardSM_res) {
2903 log("RX MT-forwardSM-Res (RP-ACK)");
2904 setverdict(pass);
2905 }
2906 [] GSUP.receive {
2907 log("RX unexpected GSUP message");
2908 setverdict(fail);
2909 mtc.stop;
2910 }
2911 }
2912
2913 f_expect_clear();
2914}
2915testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2916 var BSC_ConnHdlrPars pars;
2917 var BSC_ConnHdlr vc_conn;
2918 f_init();
2919 pars := f_init_pars(90);
2920 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2921 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2922 vc_conn.done;
2923 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2924}
2925
Harald Weltee13cfb22019-04-23 16:52:02 +02002926
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002927/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002928friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002929runs on BSC_ConnHdlr {
2930 var SmsParameters spars := valueof(t_SmsPars);
2931 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2932
2933 f_init_handler(pars);
2934
2935 /* We need to inspect GSUP activity */
2936 f_create_gsup_expect(hex2str(g_pars.imsi));
2937
2938 /* Perform location update */
2939 f_perform_lu();
2940
2941 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002942 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002943
2944 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2945 imsi := g_pars.imsi,
2946 /* NOTE: MSC should assign RP-MR itself */
2947 sm_rp_mr := ?,
2948 sm_rp_cause := sm_rp_cause
2949 );
2950
2951 /* Submit a MT SMS on GSUP */
2952 f_gsup_forwardSM_req(spars);
2953
2954 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002955 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002956 f_establish_fully(EST_TYPE_PAG_RESP);
2957
2958 /* Wait for MT SMS on DTAP */
2959 f_mt_sms_expect(spars);
2960
2961 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2962 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2963 alt {
2964 [] GSUP.receive(mt_forwardSM_err) {
2965 log("RX MT-forwardSM-Err (RP-ERROR)");
2966 setverdict(pass);
2967 mtc.stop;
2968 }
2969 [] GSUP.receive {
2970 log("RX unexpected GSUP message");
2971 setverdict(fail);
2972 mtc.stop;
2973 }
2974 }
2975
2976 f_expect_clear();
2977}
2978testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2979 var BSC_ConnHdlrPars pars;
2980 var BSC_ConnHdlr vc_conn;
2981 f_init();
2982 pars := f_init_pars(91);
2983 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2984 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2985 vc_conn.done;
2986 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2987}
2988
Harald Weltee13cfb22019-04-23 16:52:02 +02002989
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002990/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002991friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002992runs on BSC_ConnHdlr {
2993 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2994 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2995
2996 f_init_handler(pars);
2997
2998 /* We need to inspect GSUP activity */
2999 f_create_gsup_expect(hex2str(g_pars.imsi));
3000
3001 /* Perform location update */
3002 f_perform_lu();
3003
3004 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003005 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003006
3007 /* Submit the 1st MT SMS on GSUP */
3008 log("TX MT-forwardSM-Req for the 1st SMS");
3009 f_gsup_forwardSM_req(spars1);
3010
3011 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02003012 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07003013 f_establish_fully(EST_TYPE_PAG_RESP);
3014
3015 /* Wait for 1st MT SMS on DTAP */
3016 f_mt_sms_expect(spars1);
3017 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
3018 ", SM-RP-MR is ", spars1.rp.msg_ref);
3019
3020 /* Submit the 2nd MT SMS on GSUP */
3021 log("TX MT-forwardSM-Req for the 2nd SMS");
3022 f_gsup_forwardSM_req(spars2);
3023
3024 /* Wait for 2nd MT SMS on DTAP */
3025 f_mt_sms_expect(spars2);
3026 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
3027 ", SM-RP-MR is ", spars2.rp.msg_ref);
3028
3029 /* Both transaction IDs shall be different */
3030 if (spars1.tid == spars2.tid) {
3031 log("Both DTAP transaction IDs shall be different");
3032 setverdict(fail);
3033 }
3034
3035 /* Both SM-RP-MR values shall be different */
3036 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
3037 log("Both SM-RP-MR values shall be different");
3038 setverdict(fail);
3039 }
3040
3041 /* Both SM-RP-MR values shall be assigned */
3042 if (spars1.rp.msg_ref == 'FF'O) {
3043 log("Unassigned SM-RP-MR value for the 1st SMS");
3044 setverdict(fail);
3045 }
3046 if (spars2.rp.msg_ref == 'FF'O) {
3047 log("Unassigned SM-RP-MR value for the 2nd SMS");
3048 setverdict(fail);
3049 }
3050
3051 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
3052 f_mt_sms_send_rp_ack(spars1);
3053 alt {
3054 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3055 imsi := g_pars.imsi,
3056 sm_rp_mr := spars1.rp.msg_ref
3057 )) {
3058 log("RX MT-forwardSM-Res (RP-ACK)");
3059 setverdict(pass);
3060 }
3061 [] GSUP.receive {
3062 log("RX unexpected GSUP message");
3063 setverdict(fail);
3064 mtc.stop;
3065 }
3066 }
3067
3068 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
3069 f_mt_sms_send_rp_ack(spars2);
3070 alt {
3071 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3072 imsi := g_pars.imsi,
3073 sm_rp_mr := spars2.rp.msg_ref
3074 )) {
3075 log("RX MT-forwardSM-Res (RP-ACK)");
3076 setverdict(pass);
3077 }
3078 [] GSUP.receive {
3079 log("RX unexpected GSUP message");
3080 setverdict(fail);
3081 mtc.stop;
3082 }
3083 }
3084
3085 f_expect_clear();
3086}
3087testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
3088 var BSC_ConnHdlrPars pars;
3089 var BSC_ConnHdlr vc_conn;
3090 f_init();
3091 pars := f_init_pars(92);
3092 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3093 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
3094 vc_conn.done;
3095 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3096}
3097
Harald Weltee13cfb22019-04-23 16:52:02 +02003098
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003099/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02003100friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003101runs on BSC_ConnHdlr {
3102 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
3103 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
3104
3105 f_init_handler(pars);
3106
3107 /* We need to inspect GSUP activity */
3108 f_create_gsup_expect(hex2str(g_pars.imsi));
3109
3110 /* Perform location update */
3111 f_perform_lu();
3112
3113 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003114 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07003115
3116 /* Send CM Service Request for MO SMMA */
3117 f_establish_fully(EST_TYPE_MO_SMS);
3118
3119 /* Submit MO SMMA on DTAP */
3120 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
3121 spars_mo.rp.msg_ref := '00'O;
3122 f_mo_smma(spars_mo);
3123
3124 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
3125 alt {
3126 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
3127 imsi := g_pars.imsi,
3128 sm_rp_mr := spars_mo.rp.msg_ref,
3129 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
3130 )) {
3131 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
3132 setverdict(pass);
3133 }
3134 [] GSUP.receive {
3135 log("RX unexpected GSUP message");
3136 setverdict(fail);
3137 mtc.stop;
3138 }
3139 }
3140
3141 /* Submit MT SMS on GSUP */
3142 log("TX MT-forwardSM-Req for the MT SMS");
3143 f_gsup_forwardSM_req(spars_mt);
3144
3145 /* Wait for MT SMS on DTAP */
3146 f_mt_sms_expect(spars_mt);
3147 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
3148 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
3149
3150 /* Both SM-RP-MR values shall be different */
3151 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
3152 log("Both SM-RP-MR values shall be different");
3153 setverdict(fail);
3154 }
3155
3156 /* SM-RP-MR value for MT SMS shall be assigned */
3157 if (spars_mt.rp.msg_ref == 'FF'O) {
3158 log("Unassigned SM-RP-MR value for the MT SMS");
3159 setverdict(fail);
3160 }
3161
3162 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
3163 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
3164 imsi := g_pars.imsi,
3165 sm_rp_mr := spars_mo.rp.msg_ref)));
3166 /* Expect RP-ACK for MO SMMA on DTAP */
3167 f_mo_sms_wait_rp_ack(spars_mo);
3168
3169 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
3170 f_mt_sms_send_rp_ack(spars_mt);
3171 alt {
3172 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
3173 imsi := g_pars.imsi,
3174 sm_rp_mr := spars_mt.rp.msg_ref
3175 )) {
3176 log("RX MT-forwardSM-Res (RP-ACK)");
3177 setverdict(pass);
3178 }
3179 [] GSUP.receive {
3180 log("RX unexpected GSUP message");
3181 setverdict(fail);
3182 mtc.stop;
3183 }
3184 }
3185
3186 f_expect_clear();
3187}
3188testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
3189 var BSC_ConnHdlrPars pars;
3190 var BSC_ConnHdlr vc_conn;
3191 f_init();
3192 pars := f_init_pars(93);
3193 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3194 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
3195 vc_conn.done;
3196 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3197}
3198
Harald Weltee13cfb22019-04-23 16:52:02 +02003199
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003200/* Test multi-part MT-SMS over GSUP */
3201private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
3202runs on BSC_ConnHdlr {
3203 var SmsParameters spars := valueof(t_SmsPars);
3204
3205 f_init_handler(pars);
3206
3207 /* We need to inspect GSUP activity */
3208 f_create_gsup_expect(hex2str(g_pars.imsi));
3209
3210 /* Perform location update */
3211 f_perform_lu();
3212
3213 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003214 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003215
3216 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
3217 imsi := g_pars.imsi,
3218 /* NOTE: MSC should assign RP-MR itself */
3219 sm_rp_mr := ?
3220 );
3221
3222 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
3223 for (var integer i := 3; i >= 0; i := i-1) {
3224 /* Submit a MT SMS on GSUP (MMS is decremented) */
3225 f_gsup_forwardSM_req(spars, int2oct(i, 1));
3226
3227 /* Expect Paging Request and Establish connection */
3228 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02003229 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07003230 f_establish_fully(EST_TYPE_PAG_RESP);
3231 }
3232
3233 /* Wait for MT SMS on DTAP */
3234 f_mt_sms_expect(spars);
3235
3236 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
3237 f_mt_sms_send_rp_ack(spars);
3238 alt {
3239 [] GSUP.receive(mt_forwardSM_res) {
3240 log("RX MT-forwardSM-Res (RP-ACK)");
3241 setverdict(pass);
3242 }
3243 [] GSUP.receive {
3244 log("RX unexpected GSUP message");
3245 setverdict(fail);
3246 mtc.stop;
3247 }
3248 }
3249
3250 /* Keep some 'distance' between transmissions */
3251 f_sleep(1.5);
3252 }
3253
3254 f_expect_clear();
3255}
3256testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
3257 var BSC_ConnHdlrPars pars;
3258 var BSC_ConnHdlr vc_conn;
3259 f_init();
3260 pars := f_init_pars(91);
3261 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
3262 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
3263 vc_conn.done;
3264 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
3265}
3266
Harald Weltef640a012018-04-14 17:49:21 +02003267/* convert GSM L3 TON to SMPP_TON enum */
3268function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
3269 select (ton) {
3270 case ('000'B) { return unknown; }
3271 case ('001'B) { return international; }
3272 case ('010'B) { return national; }
3273 case ('011'B) { return network_specific; }
3274 case ('100'B) { return subscriber_number; }
3275 case ('101'B) { return alphanumeric; }
3276 case ('110'B) { return abbreviated; }
3277 }
3278 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02003279 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003280}
3281/* convert GSM L3 NPI to SMPP_NPI enum */
3282function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
3283 select (npi) {
3284 case ('0000'B) { return unknown; }
3285 case ('0001'B) { return isdn; }
3286 case ('0011'B) { return data; }
3287 case ('0100'B) { return telex; }
3288 case ('0110'B) { return land_mobile; }
3289 case ('1000'B) { return national; }
3290 case ('1001'B) { return private_; }
3291 case ('1010'B) { return ermes; }
3292 }
3293 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02003294 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02003295}
3296
3297/* build a SMPP_SM from SmsParameters */
3298function f_mt_sm_from_spars(SmsParameters spars)
3299runs on BSC_ConnHdlr return SMPP_SM {
3300 var SMPP_SM sm := {
3301 service_type := "CMT",
3302 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
3303 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
3304 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
3305 dest_addr_ton := international,
3306 dest_addr_npi := isdn,
3307 destination_addr := hex2str(g_pars.msisdn),
3308 esm_class := '00000001'B,
3309 protocol_id := 0,
3310 priority_flag := 0,
3311 schedule_delivery_time := "",
3312 validity_period := "",
3313 registered_delivery := '00000000'B,
3314 replace_if_present := 0,
3315 data_coding := '00000001'B,
3316 sm_default_msg_id := 0,
3317 sm_length := spars.tp.udl,
3318 short_message := spars.tp.ud,
3319 opt_pars := {}
3320 };
3321 return sm;
3322}
3323
3324/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
3325private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
3326 var SMPP_SM sm := f_mt_sm_from_spars(spars);
3327 if (trans_mode) {
3328 sm.esm_class := '00000010'B;
3329 }
3330
3331 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
3332 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
3333 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3334 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
3335 * before we expect the SMS delivery on the BSC/radio side */
3336 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3337 }
3338
3339 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02003340 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02003341 /* Establish DTAP / BSSAP / SCCP connection */
3342 f_establish_fully(EST_TYPE_PAG_RESP);
3343 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3344
3345 f_mt_sms(spars);
3346
3347 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
3348 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
3349 }
3350 f_expect_clear();
3351}
3352
3353/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
3354private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3355 f_init_handler(pars);
3356
3357 /* Perform location update so IMSI is known + registered in MSC/VLR */
3358 f_perform_lu();
3359 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
3360
3361 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01003362 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02003363
3364 var SmsParameters spars := valueof(t_SmsPars);
3365 /* TODO: test with more intelligent user data; test different coding schemes */
3366 spars.tp.ud := '00'O;
3367 spars.tp.udl := 1;
3368
3369 /* first test the non-transaction store+forward mode */
3370 f_smpp_mt_sms(spars, false);
3371
3372 /* then test the transaction mode */
3373 f_smpp_mt_sms(spars, true);
3374}
3375testcase TC_smpp_mt_sms() runs on MTC_CT {
3376 var BSC_ConnHdlr vc_conn;
3377 f_init();
3378 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
3379 vc_conn.done;
3380}
3381
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003382/***********************************************************************
3383 * USSD Testing
3384 ***********************************************************************/
3385
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003386private altstep as_unexp_gsup_or_bssap_msg()
3387runs on BSC_ConnHdlr {
3388 [] GSUP.receive {
3389 setverdict(fail, "Unknown/unexpected GSUP received");
3390 self.stop;
3391 }
3392 [] BSSAP.receive {
3393 setverdict(fail, "Unknown/unexpected BSSAP message received");
3394 self.stop;
3395 }
3396}
3397
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003398private function f_expect_gsup_msg(template GSUP_PDU msg,
3399 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003400runs on BSC_ConnHdlr return GSUP_PDU {
3401 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003402 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003403
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003404 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003405 alt {
3406 [] GSUP.receive(msg) -> value gsup_msg_complete {
3407 setverdict(pass);
3408 }
3409 /* We don't expect anything else */
3410 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003411 [] T.timeout {
3412 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3413 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003414 }
3415
3416 return gsup_msg_complete;
3417}
3418
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003419private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3420 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003421runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3422 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003423 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003424
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003425 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003426 alt {
3427 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3428 setverdict(pass);
3429 }
3430 /* We don't expect anything else */
3431 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003432 [] T.timeout {
3433 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3434 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003435 }
3436
3437 return bssap_msg_complete.dtap;
3438}
3439
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003440/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003441friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003442runs on BSC_ConnHdlr {
3443 f_init_handler(pars);
3444
3445 /* Perform location update */
3446 f_perform_lu();
3447
3448 /* Send CM Service Request for SS/USSD */
3449 f_establish_fully(EST_TYPE_SS_ACT);
3450
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003451 /* We need to inspect GSUP activity */
3452 f_create_gsup_expect(hex2str(g_pars.imsi));
3453
3454 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3455 invoke_id := 5, /* Phone may not start from 0 or 1 */
3456 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3457 ussd_string := "*#100#"
3458 );
3459
3460 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3461 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3462 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3463 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3464 )
3465
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003466 /* Compose a new SS/REGISTER message with request */
3467 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3468 tid := 1, /* We just need a single transaction */
3469 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003470 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003471 );
3472
3473 /* Compose SS/RELEASE_COMPLETE template with expected response */
3474 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3475 tid := 1, /* Response should arrive within the same transaction */
3476 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003477 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003478 );
3479
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003480 /* Compose expected MSC -> HLR message */
3481 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3482 imsi := g_pars.imsi,
3483 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3484 ss := valueof(facility_req)
3485 );
3486
3487 /* To be used for sending response with correct session ID */
3488 var GSUP_PDU gsup_req_complete;
3489
3490 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003491 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003492 /* Expect GSUP message containing the SS payload */
3493 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3494
3495 /* Compose the response from HLR using received session ID */
3496 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3497 imsi := g_pars.imsi,
3498 sid := gsup_req_complete.ies[1].val.session_id,
3499 state := OSMO_GSUP_SESSION_STATE_END,
3500 ss := valueof(facility_rsp)
3501 );
3502
3503 /* Finally, HLR terminates the session */
3504 GSUP.send(gsup_rsp);
3505 /* Expect RELEASE_COMPLETE message with the response */
3506 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003507
3508 f_expect_clear();
3509}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003510testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003511 var BSC_ConnHdlr vc_conn;
3512 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003513 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003514 vc_conn.done;
3515}
3516
Harald Weltee13cfb22019-04-23 16:52:02 +02003517
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003518/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003519friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003520runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003521 timer T := 5.0;
3522
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003523 f_init_handler(pars);
3524
3525 /* Perform location update */
3526 f_perform_lu();
3527
Harald Welte6811d102019-04-14 22:23:14 +02003528 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003529
3530 /* We need to inspect GSUP activity */
3531 f_create_gsup_expect(hex2str(g_pars.imsi));
3532
3533 /* Facility IE with network-originated USSD notification */
3534 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3535 op_code := SS_OP_CODE_USS_NOTIFY,
3536 ussd_string := "Mahlzeit!"
3537 );
3538
3539 /* Facility IE with acknowledgment to the USSD notification */
3540 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3541 /* In case of USSD notification, Return Result is empty */
3542 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3543 );
3544
3545 /* Compose a new MT SS/REGISTER message with USSD notification */
3546 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3547 tid := 0, /* FIXME: most likely, it should be 0 */
3548 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3549 facility := valueof(facility_req)
3550 );
3551
3552 /* Compose HLR -> MSC GSUP message */
3553 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3554 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003555 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003556 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3557 ss := valueof(facility_req)
3558 );
3559
3560 /* Send it to MSC and expect Paging Request */
3561 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003562 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003563 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003564 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3565 setverdict(pass);
3566 }
Harald Welte62113fc2019-05-09 13:04:02 +02003567 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003568 setverdict(pass);
3569 }
3570 /* We don't expect anything else */
3571 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003572 [] T.timeout {
3573 setverdict(fail, "Timeout waiting for Paging Request");
3574 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003575 }
3576
3577 /* Send Paging Response and expect USSD notification */
3578 f_establish_fully(EST_TYPE_PAG_RESP);
3579 /* Expect MT REGISTER message with USSD notification */
3580 f_expect_mt_dtap_msg(ussd_ntf);
3581
3582 /* Compose a new MO SS/FACILITY message with empty response */
3583 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3584 tid := 0, /* FIXME: it shall match the request tid */
3585 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3586 facility := valueof(facility_rsp)
3587 );
3588
3589 /* Compose expected MSC -> HLR GSUP message */
3590 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3591 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003592 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003593 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3594 ss := valueof(facility_rsp)
3595 );
3596
3597 /* MS sends response to the notification */
3598 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3599 /* Expect GSUP message containing the SS payload */
3600 f_expect_gsup_msg(gsup_rsp);
3601
3602 /* Compose expected MT SS/RELEASE COMPLETE message */
3603 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3604 tid := 0, /* FIXME: it shall match the request tid */
3605 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3606 facility := omit
3607 );
3608
3609 /* Compose MSC -> HLR GSUP message */
3610 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3611 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003612 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003613 state := OSMO_GSUP_SESSION_STATE_END
3614 );
3615
3616 /* Finally, HLR terminates the session */
3617 GSUP.send(gsup_term)
3618 /* Expect MT RELEASE COMPLETE without Facility IE */
3619 f_expect_mt_dtap_msg(ussd_term);
3620
3621 f_expect_clear();
3622}
3623testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3624 var BSC_ConnHdlr vc_conn;
3625 f_init();
3626 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3627 vc_conn.done;
3628}
3629
Harald Weltee13cfb22019-04-23 16:52:02 +02003630
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003631/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003632friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003633runs on BSC_ConnHdlr {
3634 f_init_handler(pars);
3635
3636 /* Call parameters taken from f_tc_lu_and_mt_call */
3637 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003638
3639 /* Perform location update */
3640 f_perform_lu();
3641
3642 /* Establish a MT call */
3643 f_mt_call_establish(cpars);
3644
3645 /* Hold the call for some time */
3646 f_sleep(1.0);
3647
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003648 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3649 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3650 ussd_string := "*#100#"
3651 );
3652
3653 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3654 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3655 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3656 )
3657
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003658 /* Compose a new SS/REGISTER message with request */
3659 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3660 tid := 1, /* We just need a single transaction */
3661 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003662 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003663 );
3664
3665 /* Compose SS/RELEASE_COMPLETE template with expected response */
3666 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3667 tid := 1, /* Response should arrive within the same transaction */
3668 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003669 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003670 );
3671
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003672 /* Compose expected MSC -> HLR message */
3673 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3674 imsi := g_pars.imsi,
3675 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3676 ss := valueof(facility_req)
3677 );
3678
3679 /* To be used for sending response with correct session ID */
3680 var GSUP_PDU gsup_req_complete;
3681
3682 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003683 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003684 /* Expect GSUP message containing the SS payload */
3685 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3686
3687 /* Compose the response from HLR using received session ID */
3688 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3689 imsi := g_pars.imsi,
3690 sid := gsup_req_complete.ies[1].val.session_id,
3691 state := OSMO_GSUP_SESSION_STATE_END,
3692 ss := valueof(facility_rsp)
3693 );
3694
3695 /* Finally, HLR terminates the session */
3696 GSUP.send(gsup_rsp);
3697 /* Expect RELEASE_COMPLETE message with the response */
3698 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003699
3700 /* Hold the call for some time */
3701 f_sleep(1.0);
3702
3703 /* Release the call (does Clear Complete itself) */
3704 f_call_hangup(cpars, true);
3705}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003706testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003707 var BSC_ConnHdlr vc_conn;
3708 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003709 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003710 vc_conn.done;
3711}
3712
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003713/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003714friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003715 f_init_handler(pars);
3716 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003717 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003718
3719 f_perform_lu();
3720
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003721 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003722 f_mo_call_establish(cpars);
3723 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003724 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003725
3726 f_sleep(1.0);
3727}
3728testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3729 var BSC_ConnHdlr vc_conn;
3730 f_init();
3731
3732 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3733 vc_conn.done;
3734}
3735
Harald Weltee13cfb22019-04-23 16:52:02 +02003736
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003737/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003738friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003739runs on BSC_ConnHdlr {
3740 f_init_handler(pars);
3741
3742 /* Call parameters taken from f_tc_lu_and_mt_call */
3743 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003744
3745 /* Perform location update */
3746 f_perform_lu();
3747
3748 /* Establish a MT call */
3749 f_mt_call_establish(cpars);
3750
3751 /* Hold the call for some time */
3752 f_sleep(1.0);
3753
3754 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3755 op_code := SS_OP_CODE_USS_REQUEST,
3756 ussd_string := "Please type anything..."
3757 );
3758
3759 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3760 op_code := SS_OP_CODE_USS_REQUEST,
3761 ussd_string := "Nope."
3762 )
3763
3764 /* Compose MT SS/REGISTER message with network-originated request */
3765 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3766 tid := 0, /* FIXME: most likely, it should be 0 */
3767 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3768 facility := valueof(facility_req)
3769 );
3770
3771 /* Compose HLR -> MSC GSUP message */
3772 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3773 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003774 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003775 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3776 ss := valueof(facility_req)
3777 );
3778
3779 /* Send it to MSC */
3780 GSUP.send(gsup_req);
3781 /* Expect MT REGISTER message with USSD request */
3782 f_expect_mt_dtap_msg(ussd_req);
3783
3784 /* Compose a new MO SS/FACILITY message with response */
3785 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3786 tid := 0, /* FIXME: it shall match the request tid */
3787 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3788 facility := valueof(facility_rsp)
3789 );
3790
3791 /* Compose expected MSC -> HLR GSUP message */
3792 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3793 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003794 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003795 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3796 ss := valueof(facility_rsp)
3797 );
3798
3799 /* MS sends response */
3800 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3801 f_expect_gsup_msg(gsup_rsp);
3802
3803 /* Compose expected MT SS/RELEASE COMPLETE message */
3804 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3805 tid := 0, /* FIXME: it shall match the request tid */
3806 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3807 facility := omit
3808 );
3809
3810 /* Compose MSC -> HLR GSUP message */
3811 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3812 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003813 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003814 state := OSMO_GSUP_SESSION_STATE_END
3815 );
3816
3817 /* Finally, HLR terminates the session */
3818 GSUP.send(gsup_term);
3819 /* Expect MT RELEASE COMPLETE without Facility IE */
3820 f_expect_mt_dtap_msg(ussd_term);
3821
3822 /* Hold the call for some time */
3823 f_sleep(1.0);
3824
3825 /* Release the call (does Clear Complete itself) */
3826 f_call_hangup(cpars, true);
3827}
3828testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3829 var BSC_ConnHdlr vc_conn;
3830 f_init();
3831 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3832 vc_conn.done;
3833}
3834
Harald Weltee13cfb22019-04-23 16:52:02 +02003835
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003836/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003837friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003838runs on BSC_ConnHdlr {
3839 f_init_handler(pars);
3840
3841 /* Perform location update */
3842 f_perform_lu();
3843
3844 /* Send CM Service Request for SS/USSD */
3845 f_establish_fully(EST_TYPE_SS_ACT);
3846
3847 /* We need to inspect GSUP activity */
3848 f_create_gsup_expect(hex2str(g_pars.imsi));
3849
3850 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3851 invoke_id := 1, /* Initial request */
3852 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3853 ussd_string := "*6766*266#"
3854 );
3855
3856 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3857 invoke_id := 2, /* Counter request */
3858 op_code := SS_OP_CODE_USS_REQUEST,
3859 ussd_string := "Password?!?"
3860 )
3861
3862 /* Compose MO SS/REGISTER message with request */
3863 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3864 tid := 1, /* We just need a single transaction */
3865 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3866 facility := valueof(facility_ms_req)
3867 );
3868
3869 /* Compose expected MSC -> HLR message */
3870 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3871 imsi := g_pars.imsi,
3872 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3873 ss := valueof(facility_ms_req)
3874 );
3875
3876 /* To be used for sending response with correct session ID */
3877 var GSUP_PDU gsup_ms_req_complete;
3878
3879 /* Initiate a new transaction */
3880 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3881 /* Expect GSUP request with original Facility IE */
3882 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3883
3884 /* Compose the response from HLR using received session ID */
3885 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3886 imsi := g_pars.imsi,
3887 sid := gsup_ms_req_complete.ies[1].val.session_id,
3888 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3889 ss := valueof(facility_net_req)
3890 );
3891
3892 /* Compose expected MT SS/FACILITY template with counter request */
3893 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3894 tid := 1, /* Response should arrive within the same transaction */
3895 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3896 facility := valueof(facility_net_req)
3897 );
3898
3899 /* Send response over GSUP */
3900 GSUP.send(gsup_net_req);
3901 /* Expect MT SS/FACILITY message with counter request */
3902 f_expect_mt_dtap_msg(ussd_net_req);
3903
3904 /* Compose MO SS/RELEASE COMPLETE */
3905 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3906 tid := 1, /* Response should arrive within the same transaction */
3907 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3908 facility := omit
3909 /* TODO: cause? */
3910 );
3911
3912 /* Compose expected HLR -> MSC abort message */
3913 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3914 imsi := g_pars.imsi,
3915 sid := gsup_ms_req_complete.ies[1].val.session_id,
3916 state := OSMO_GSUP_SESSION_STATE_END
3917 );
3918
3919 /* Abort transaction */
3920 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3921 /* Expect GSUP message indicating abort */
3922 f_expect_gsup_msg(gsup_abort);
3923
3924 f_expect_clear();
3925}
3926testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3927 var BSC_ConnHdlr vc_conn;
3928 f_init();
3929 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3930 vc_conn.done;
3931}
3932
Harald Weltee13cfb22019-04-23 16:52:02 +02003933
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003934/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003935friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003936runs on BSC_ConnHdlr {
3937 f_init_handler(pars);
3938
3939 /* Perform location update */
3940 f_perform_lu();
3941
3942 /* Send CM Service Request for SS/USSD */
3943 f_establish_fully(EST_TYPE_SS_ACT);
3944
3945 /* We need to inspect GSUP activity */
3946 f_create_gsup_expect(hex2str(g_pars.imsi));
3947
3948 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3949 invoke_id := 1,
3950 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3951 ussd_string := "#release_me");
3952
3953 /* Compose MO SS/REGISTER message with request */
3954 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3955 tid := 1, /* An arbitrary transaction identifier */
3956 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3957 facility := valueof(facility_ms_req));
3958
3959 /* Compose expected MSC -> HLR message */
3960 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3961 imsi := g_pars.imsi,
3962 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3963 ss := valueof(facility_ms_req));
3964
3965 /* To be used for sending response with correct session ID */
3966 var GSUP_PDU gsup_ms_req_complete;
3967
3968 /* Initiate a new SS transaction */
3969 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3970 /* Expect GSUP request with original Facility IE */
3971 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3972
3973 /* Don't respond, wait for timeout */
3974 f_sleep(3.0);
3975
3976 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3977 tid := 1, /* Should match the request's tid */
3978 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3979 cause := *, /* TODO: expect some specific value */
3980 facility := omit);
3981
3982 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3983 imsi := g_pars.imsi,
3984 sid := gsup_ms_req_complete.ies[1].val.session_id,
3985 state := OSMO_GSUP_SESSION_STATE_END,
3986 cause := ?); /* TODO: expect some specific value */
3987
3988 /* Expect release on both interfaces */
3989 interleave {
3990 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3991 [] GSUP.receive(gsup_rel) { };
3992 }
3993
3994 f_expect_clear();
3995 setverdict(pass);
3996}
3997testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3998 var BSC_ConnHdlr vc_conn;
3999 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07004000 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07004001 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
4002 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07004003 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07004004}
4005
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004006/* MT (network-originated) USSD for unknown subscriber */
4007friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
4008runs on BSC_ConnHdlr {
4009 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
4010 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004011
4012 f_init_handler(pars);
4013 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
4014 f_create_gsup_expect(hex2str(imsi));
4015
4016 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4017 imsi := imsi,
4018 sid := sid,
4019 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4020 ss := f_rnd_octstring(23)
4021 );
4022
4023 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
4024 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4025 imsi := imsi,
4026 sid := sid,
4027 state := OSMO_GSUP_SESSION_STATE_END,
4028 cause := 2 /* FIXME: introduce an enumerated type! */
4029 );
4030
4031 /* Initiate a MT USSD notification */
4032 GSUP.send(gsup_req);
4033
4034 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07004035 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07004036}
4037testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
4038 var BSC_ConnHdlr vc_conn;
4039 f_init();
4040 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
4041 vc_conn.done;
4042}
4043
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07004044/* MO (mobile-originated) SS/USSD for unknown transaction */
4045friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
4046runs on BSC_ConnHdlr {
4047 f_init_handler(pars);
4048
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004049 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07004050 f_create_gsup_expect(hex2str(g_pars.imsi));
4051
4052 /* Perform location update */
4053 f_perform_lu();
4054
4055 /* Send CM Service Request for SS/USSD */
4056 f_establish_fully(EST_TYPE_SS_ACT);
4057
4058 /* GSM 04.80 FACILITY message for a non-existing transaction */
4059 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
4060 tid := 1, /* An arbitrary transaction identifier */
4061 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4062 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
4063 );
4064
4065 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
4066 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
4067 tid := 1, /* An arbitrary transaction identifier */
4068 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4069 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
4070 );
4071
4072 /* Expected response from the network */
4073 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4074 tid := 1, /* Same as in the FACILITY message */
4075 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
4076 facility := omit
4077 );
4078
4079 /* Send GSM 04.80 FACILITY for non-existing transaction */
4080 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
4081
4082 /* Expect GSM 04.80 RELEASE COMPLETE message */
4083 f_expect_mt_dtap_msg(mt_ss_rel);
4084 f_expect_clear();
4085
4086 /* Send another CM Service Request for SS/USSD */
4087 f_establish_fully(EST_TYPE_SS_ACT);
4088
4089 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
4090 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
4091
4092 /* Expect GSM 04.80 RELEASE COMPLETE message */
4093 f_expect_mt_dtap_msg(mt_ss_rel);
4094 f_expect_clear();
4095}
4096testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
4097 var BSC_ConnHdlr vc_conn;
4098 f_init();
4099 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
4100 vc_conn.done;
4101}
4102
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004103/* MT (network-originated) USSD for unknown session */
4104friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
4105runs on BSC_ConnHdlr {
4106 var OCT4 sid := '20000333'O;
4107
4108 f_init_handler(pars);
4109
4110 /* Perform location update */
4111 f_perform_lu();
4112
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004113 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07004114 f_create_gsup_expect(hex2str(g_pars.imsi));
4115
4116 /* Request referencing a non-existing SS session */
4117 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4118 imsi := g_pars.imsi,
4119 sid := sid,
4120 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
4121 ss := f_rnd_octstring(23)
4122 );
4123
4124 /* Error with some cause value */
4125 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4126 imsi := g_pars.imsi,
4127 sid := sid,
4128 state := OSMO_GSUP_SESSION_STATE_END,
4129 cause := ? /* FIXME: introduce an enumerated type! */
4130 );
4131
4132 /* Initiate a MT USSD notification */
4133 GSUP.send(gsup_req);
4134
4135 /* Expect GSUP PROC_SS_ERROR message */
4136 f_expect_gsup_msg(gsup_rsp);
4137}
4138testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
4139 var BSC_ConnHdlr vc_conn;
4140 f_init();
4141 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
4142 vc_conn.done;
4143}
4144
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004145/* MT (network-originated) USSD and no response to Paging Request */
4146friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
4147runs on BSC_ConnHdlr {
4148 timer TP := 2.0; /* Paging timer */
4149
4150 f_init_handler(pars);
4151
4152 /* Perform location update */
4153 f_perform_lu();
4154
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004155 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004156 f_create_gsup_expect(hex2str(g_pars.imsi));
4157
4158 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4159 imsi := g_pars.imsi,
4160 sid := '20000444'O,
4161 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4162 ss := f_rnd_octstring(23)
4163 );
4164
4165 /* Error with some cause value */
4166 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
4167 imsi := g_pars.imsi,
4168 sid := '20000444'O,
4169 state := OSMO_GSUP_SESSION_STATE_END,
4170 cause := ? /* FIXME: introduce an enumerated type! */
4171 );
4172
4173 /* Initiate a MT USSD notification */
4174 GSUP.send(gsup_req);
4175
4176 /* Send it to MSC and expect Paging Request */
4177 TP.start;
4178 alt {
4179 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4180 setverdict(pass);
4181 }
4182 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4183 setverdict(pass);
4184 }
4185 /* We don't expect anything else */
4186 [] as_unexp_gsup_or_bssap_msg();
4187 [] TP.timeout {
4188 setverdict(fail, "Timeout waiting for Paging Request");
4189 }
4190 }
4191
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07004192 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
4193 * OsmoMSC waits for Paging Response 10 seconds by default. */
4194 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07004195}
4196testcase TC_proc_ss_paging_fail() runs on MTC_CT {
4197 var BSC_ConnHdlr vc_conn;
4198 f_init();
4199 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
4200 vc_conn.done;
4201}
4202
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004203/* MT (network-originated) USSD followed by immediate abort */
4204friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
4205runs on BSC_ConnHdlr {
4206 var octetstring facility := f_rnd_octstring(23);
4207 var OCT4 sid := '20000555'O;
4208 timer TP := 2.0;
4209
4210 f_init_handler(pars);
4211
4212 /* Perform location update */
4213 f_perform_lu();
4214
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01004215 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07004216 f_create_gsup_expect(hex2str(g_pars.imsi));
4217
4218 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
4219 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
4220 imsi := g_pars.imsi, sid := sid,
4221 state := OSMO_GSUP_SESSION_STATE_BEGIN,
4222 ss := facility
4223 );
4224
4225 /* On the MS side, we expect GSM 04.80 REGISTER message */
4226 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
4227 tid := 0, /* Most likely, it should be 0 */
4228 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4229 facility := facility
4230 );
4231
4232 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
4233 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
4234 imsi := g_pars.imsi, sid := sid,
4235 state := OSMO_GSUP_SESSION_STATE_END,
4236 cause := 0 /* FIXME: introduce an enumerated type! */
4237 );
4238
4239 /* On the MS side, we expect GSM 04.80 REGISTER message */
4240 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
4241 tid := 0, /* Most likely, it should be 0 */
4242 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
4243 cause := *, /* FIXME: expect some specific cause value */
4244 facility := omit
4245 );
4246
4247 /* Initiate a MT USSD with random payload */
4248 GSUP.send(gsup_req);
4249
4250 /* Expect Paging Request */
4251 TP.start;
4252 alt {
4253 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
4254 setverdict(pass);
4255 }
4256 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
4257 setverdict(pass);
4258 }
4259 /* We don't expect anything else */
4260 [] as_unexp_gsup_or_bssap_msg();
4261 [] TP.timeout {
4262 setverdict(fail, "Timeout waiting for Paging Request");
4263 }
4264 }
4265
4266 /* Send Paging Response and establish connection */
4267 f_establish_fully(EST_TYPE_PAG_RESP);
4268 /* Expect MT REGISTER message with random facility */
4269 f_expect_mt_dtap_msg(dtap_reg);
4270
4271 /* HLR/EUSE decides to abort the session even
4272 * before getting any response from the MS */
4273 /* Initiate a MT USSD with random payload */
4274 GSUP.send(gsup_abort);
4275
4276 /* Expect RELEASE COMPLETE on ths MS side */
4277 f_expect_mt_dtap_msg(dtap_rel);
4278
4279 f_expect_clear();
4280}
4281testcase TC_proc_ss_abort() runs on MTC_CT {
4282 var BSC_ConnHdlr vc_conn;
4283 f_init();
4284 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
4285 vc_conn.done;
4286}
4287
Harald Weltee13cfb22019-04-23 16:52:02 +02004288
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01004289/* Verify multiple concurrent MO SS/USSD transactions
4290 * (one subscriber - one transaction) */
4291testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
4292 var BSC_ConnHdlr vc_conn[16];
4293 var integer i;
4294
4295 f_init();
4296
4297 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4298 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
4299 }
4300
4301 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4302 vc_conn[i].done;
4303 }
4304}
4305
4306/* Verify multiple concurrent MT SS/USSD transactions
4307 * (one subscriber - one transaction) */
4308testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
4309 var BSC_ConnHdlr vc_conn[16];
4310 var integer i;
4311 var OCT4 sid;
4312
4313 f_init();
4314
4315 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4316 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
4317 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
4318 f_init_pars(226 + i, gsup_sid := sid));
4319 }
4320
4321 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
4322 vc_conn[i].done;
4323 }
4324}
4325
4326
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004327/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
4328private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4329 pars.net.expect_auth := true;
4330 pars.net.expect_ciph := true;
4331 pars.net.kc_support := '02'O; /* A5/1 only */
4332 f_init_handler(pars);
4333
4334 g_pars.vec := f_gen_auth_vec_2g();
4335
4336 /* Can't use f_perform_lu() directly. Code below is based on it. */
4337
4338 /* tell GSUP dispatcher to send this IMSI to us */
4339 f_create_gsup_expect(hex2str(g_pars.imsi));
4340
4341 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4342 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02004343 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004344
4345 f_mm_auth();
4346
4347 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4348 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4349 alt {
4350 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4351 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
4352 }
4353 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4354 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4355 mtc.stop;
4356 }
4357 [] BSSAP.receive {
4358 setverdict(fail, "Unknown/unexpected BSSAP received");
4359 mtc.stop;
4360 }
4361 }
Harald Welte79f1e452020-08-18 22:55:02 +02004362 f_expect_common_id();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004363
4364 /* Expect LU reject from MSC. */
4365 alt {
4366 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4367 setverdict(pass);
4368 }
4369 [] BSSAP.receive {
4370 setverdict(fail, "Unknown/unexpected BSSAP received");
4371 mtc.stop;
4372 }
4373 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01004374 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004375}
4376
4377testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
4378 var BSC_ConnHdlr vc_conn;
4379 f_init();
4380 f_vty_config(MSCVTY, "network", "encryption a5 1");
4381
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02004382 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52, verify_cell_id := false);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01004383 vc_conn.done;
4384}
4385
Harald Welteb2284bd2019-05-10 11:30:43 +02004386/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
4387friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4388 f_init_handler(pars);
4389
4390 /* tell GSUP dispatcher to send this IMSI to us */
4391 f_create_gsup_expect(hex2str(g_pars.imsi));
4392
4393 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4394 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4395
4396 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4397 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4398 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +02004399 f_expect_common_id();
Harald Welteb2284bd2019-05-10 11:30:43 +02004400
4401 /* Expect LU reject from MSC. */
4402 alt {
4403 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4404 setverdict(pass);
4405 }
4406 [] BSSAP.receive {
4407 setverdict(fail, "Unknown/unexpected BSSAP received");
4408 mtc.stop;
4409 }
4410 }
4411 f_expect_clear();
4412}
4413testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4414 var BSC_ConnHdlr vc_conn;
4415 f_init();
4416 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4417 vc_conn.done;
4418}
4419
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004420private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4421 pars.net.expect_auth := true;
4422 pars.net.expect_ciph := true;
4423 pars.net.kc_support := kc_support;
4424 f_init_handler(pars);
4425
4426 g_pars.vec := f_gen_auth_vec_2g();
4427
4428 /* Can't use f_perform_lu() directly. Code below is based on it. */
4429
4430 /* tell GSUP dispatcher to send this IMSI to us */
4431 f_create_gsup_expect(hex2str(g_pars.imsi));
4432
4433 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4434 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4435 f_cl3_or_initial_ue(l3_lu);
4436
4437 f_mm_auth();
4438
4439 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4440 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4441 alt {
4442 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4443 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4444 }
4445 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4446 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4447 repeat;
4448 }
4449 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4450 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4451 mtc.stop;
4452 }
4453 [] BSSAP.receive {
4454 setverdict(fail, "Unknown/unexpected BSSAP received");
4455 mtc.stop;
4456 }
4457 }
Harald Welte79f1e452020-08-18 22:55:02 +02004458 f_expect_common_id();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004459
4460 /* TODO: Verify MSC is using the best cipher available! How? */
4461
4462 f_msc_lu_hlr();
4463 f_accept_reject_lu();
4464 f_expect_clear();
4465 setverdict(pass);
4466}
4467
4468/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4469private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4470 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4471}
4472
4473/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4474private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4475 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4476}
4477
4478/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4479private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4480 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4481}
4482
4483testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4484 var BSC_ConnHdlr vc_conn;
4485 f_init();
4486 f_vty_config(MSCVTY, "network", "encryption a5 1");
4487
4488 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4489 vc_conn.done;
4490}
4491
4492testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4493 var BSC_ConnHdlr vc_conn;
4494 f_init();
4495 f_vty_config(MSCVTY, "network", "encryption a5 3");
4496
4497 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4498 vc_conn.done;
4499}
4500
4501testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4502 var BSC_ConnHdlr vc_conn;
4503 f_init();
4504 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4505
4506 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4507 vc_conn.done;
4508}
Harald Welteb2284bd2019-05-10 11:30:43 +02004509
Harald Weltef640a012018-04-14 17:49:21 +02004510/* TODO (SMS):
4511 * different user data lengths
4512 * SMPP transaction mode with unsuccessful delivery
4513 * queued MT-SMS with no paging response + later delivery
4514 * different data coding schemes
4515 * multi-part SMS
4516 * user-data headers
4517 * TP-PID for SMS to SIM
4518 * behavior if SMS memory is full + RP-SMMA
4519 * delivery reports
4520 * SMPP osmocom extensions
4521 * more-messages-to-send
4522 * SMS during ongoing call (SACCH/SAPI3)
4523 */
4524
4525/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004526 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4527 * malformed messages (missing IE, invalid message type): properly rejected?
4528 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4529 * 3G/2G auth permutations
4530 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004531 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004532 * too long L3 INFO in DTAP
4533 * too long / padded BSSAP
4534 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004535 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004536
Harald Weltee13cfb22019-04-23 16:52:02 +02004537/***********************************************************************
4538 * SGsAP Testing
4539 ***********************************************************************/
4540
Philipp Maier948747b2019-04-02 15:22:33 +02004541/* Check if a subscriber exists in the VLR */
4542private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4543
4544 var CtrlValue active_subsribers;
4545 var integer rc;
4546 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4547
4548 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4549 if (rc < 0) {
4550 return false;
4551 }
4552
4553 return true;
4554}
4555
Pau Espin Pedrolcefe9da2021-07-02 18:38:27 +02004556/* Perform a Location Update at the A-Interface and run some checks to confirm
Harald Welte4263c522018-12-06 11:56:27 +01004557 * that everything is back to normal. */
4558private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4559 var SmsParameters spars := valueof(t_SmsPars);
4560
Pau Espin Pedrol7593a8a2021-07-02 18:55:16 +02004561 /* From now on, since we initiated LU from A-Interface, we expect no
4562 * LastEutranPLMNId on Common Id, since the SGs interface should be gone
4563 */
4564 g_pars.common_id_last_eutran_plmn := omit;
4565
Harald Welte4263c522018-12-06 11:56:27 +01004566 /* Perform a location update, the SGs association is expected to fall
4567 * back to NULL */
4568 f_perform_lu();
4569 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4570
4571 /* Trigger a paging request and expect the paging on BSSMAP, this is
4572 * to make sure that pagings are sent throught the A-Interface again
4573 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004574 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004575 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4576
4577 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004578 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4579 setverdict(pass);
4580 }
Harald Welte62113fc2019-05-09 13:04:02 +02004581 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004582 setverdict(pass);
4583 }
4584 [] SGsAP.receive {
4585 setverdict(fail, "Received unexpected message on SGs");
4586 }
4587 }
4588
4589 /* Send an SMS to make sure that also payload messages are routed
4590 * throught the A-Interface again */
4591 f_establish_fully(EST_TYPE_MO_SMS);
4592 f_mo_sms(spars);
4593 f_expect_clear();
4594}
4595
4596private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4597 var charstring vlr_name;
4598 f_init_handler(pars);
4599
4600 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4601 log("VLR name: ", vlr_name);
4602 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004603 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004604}
4605
4606testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004607 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004608 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004609 f_init(1, true);
4610 pars := f_init_pars(11810, true);
4611 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004612 vc_conn.done;
4613}
4614
4615/* like f_mm_auth() but for SGs */
4616function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4617 if (g_pars.net.expect_auth) {
4618 g_pars.vec := f_gen_auth_vec_3g();
4619 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4620 g_pars.vec.sres,
4621 g_pars.vec.kc,
4622 g_pars.vec.ik,
4623 g_pars.vec.ck,
4624 g_pars.vec.autn,
4625 g_pars.vec.res));
4626 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4627 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4628 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4629 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4630 }
4631}
4632
4633/* like f_perform_lu(), but on SGs rather than BSSAP */
4634function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4635 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4636 var PDU_SGsAP lur;
4637 var PDU_SGsAP lua;
4638 var PDU_SGsAP mm_info;
4639 var octetstring mm_info_dtap;
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004640 var GsmMcc mcc;
4641 var GsmMnc mnc;
4642 var template (omit) TrackingAreaIdentityValue tai := omit;
Harald Welte4263c522018-12-06 11:56:27 +01004643
4644 /* tell GSUP dispatcher to send this IMSI to us */
4645 f_create_gsup_expect(hex2str(g_pars.imsi));
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004646 if (g_pars.common_id_last_eutran_plmn != omit) {
4647 f_dec_mcc_mnc(g_pars.common_id_last_eutran_plmn, mcc, mnc);
4648 tai := ts_SGsAP_TAI(mcc, mnc, 555);
4649 }
Harald Welte4263c522018-12-06 11:56:27 +01004650 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
Pau Espin Pedrol3768a6f2021-04-28 14:24:23 +02004651 ts_SGsAP_LAI('901'H, '70'H, 2342),
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004652 tai));
Harald Welte4263c522018-12-06 11:56:27 +01004653 /* Old LAI, if MS sends it */
4654 /* TMSI status, if MS has no valid TMSI */
4655 /* IMEISV, if it supports "automatic device detection" */
4656 /* TAI, if available in MME */
4657 /* E-CGI, if available in MME */
4658 SGsAP.send(lur);
4659
4660 /* FIXME: is this really done over SGs? The Ue is already authenticated
4661 * via the MME ... */
4662 f_mm_auth_sgs();
4663
4664 /* Expect MSC to perform LU with HLR */
4665 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4666 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4667 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4668 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4669
4670 alt {
4671 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4672 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4673 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4674 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4675 }
4676 setverdict(pass);
4677 }
4678 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4679 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4680 }
4681 [] SGsAP.receive {
4682 setverdict(fail, "Received unexpected message on SGs");
4683 }
4684 }
4685
4686 /* Check MM information */
4687 if (mp_mm_info == true) {
4688 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4689 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4690 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4691 setverdict(fail, "Unexpected MM Information");
4692 }
4693 }
4694
4695 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4696}
4697
4698private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4699 f_init_handler(pars);
4700 f_sgs_perform_lu();
4701 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4702
4703 f_sgsap_bssmap_screening();
4704
4705 setverdict(pass);
4706}
4707testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004708 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004709 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004710 f_init(1, true);
4711 pars := f_init_pars(11811, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004712 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004713 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004714 vc_conn.done;
4715}
4716
4717/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4718private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4719 f_init_handler(pars);
4720 var PDU_SGsAP lur;
4721
4722 f_create_gsup_expect(hex2str(g_pars.imsi));
4723 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4724 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4725 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4726 SGsAP.send(lur);
4727
4728 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4729 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4730 alt {
4731 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4732 setverdict(pass);
4733 }
4734 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4735 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4736 mtc.stop;
4737 }
4738 [] SGsAP.receive {
4739 setverdict(fail, "Received unexpected message on SGs");
4740 }
4741 }
4742
4743 f_sgsap_bssmap_screening();
4744
4745 setverdict(pass);
4746}
4747testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004748 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004749 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004750 f_init(1, true);
4751 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004752
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004753 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004754 vc_conn.done;
4755}
4756
4757/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4758private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4759 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4760 var PDU_SGsAP lur;
4761
4762 f_init_handler(pars);
4763
4764 /* tell GSUP dispatcher to send this IMSI to us */
4765 f_create_gsup_expect(hex2str(g_pars.imsi));
4766
4767 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4768 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4769 /* Old LAI, if MS sends it */
4770 /* TMSI status, if MS has no valid TMSI */
4771 /* IMEISV, if it supports "automatic device detection" */
4772 /* TAI, if available in MME */
4773 /* E-CGI, if available in MME */
4774 SGsAP.send(lur);
4775
4776 /* FIXME: is this really done over SGs? The Ue is already authenticated
4777 * via the MME ... */
4778 f_mm_auth_sgs();
4779
4780 /* Expect MSC to perform LU with HLR */
4781 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4782 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4783 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4784 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4785
4786 alt {
4787 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4788 setverdict(pass);
4789 }
4790 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4791 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4792 }
4793 [] SGsAP.receive {
4794 setverdict(fail, "Received unexpected message on SGs");
4795 }
4796 }
4797
4798 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4799
4800 /* Wait until the VLR has abort the TMSI reallocation procedure */
4801 f_sleep(45.0);
4802
4803 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4804 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4805
4806 f_sgsap_bssmap_screening();
4807
4808 setverdict(pass);
4809}
4810testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004811 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004812 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004813 f_init(1, true);
4814 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004815
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004816 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004817 vc_conn.done;
4818}
4819
4820private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4821runs on BSC_ConnHdlr {
4822 f_init_handler(pars);
4823 f_sgs_perform_lu();
4824 f_sleep(3.0);
4825
4826 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4827 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4828 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4829 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4830
4831 f_sgsap_bssmap_screening();
4832
4833 setverdict(pass);
4834}
4835testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004836 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004837 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004838 f_init(1, true);
4839 pars := f_init_pars(11814, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004840 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004841 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004842 vc_conn.done;
4843}
4844
Philipp Maierfc19f172019-03-21 11:17:54 +01004845private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4846runs on BSC_ConnHdlr {
4847 f_init_handler(pars);
4848 f_sgs_perform_lu();
4849 f_sleep(3.0);
4850
4851 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4852 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4853 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4854 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4855
4856 f_sgsap_bssmap_screening();
4857
4858 setverdict(pass);
4859}
4860testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4861 var BSC_ConnHdlrPars pars;
4862 var BSC_ConnHdlr vc_conn;
4863 f_init(1, true);
4864 pars := f_init_pars(11814, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004865 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maierfc19f172019-03-21 11:17:54 +01004866 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4867 vc_conn.done;
4868}
4869
Harald Welte4263c522018-12-06 11:56:27 +01004870private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4871runs on BSC_ConnHdlr {
4872 f_init_handler(pars);
4873 f_sgs_perform_lu();
4874 f_sleep(3.0);
4875
4876 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4877 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4878 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004879
4880 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4881 setverdict(fail, "subscriber not removed from VLR");
4882 }
Harald Welte4263c522018-12-06 11:56:27 +01004883
4884 f_sgsap_bssmap_screening();
4885
4886 setverdict(pass);
4887}
4888testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004889 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004890 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004891 f_init(1, true);
4892 pars := f_init_pars(11815, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004893 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004894 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004895 vc_conn.done;
4896}
4897
Philipp Maier5d812702019-03-21 10:51:26 +01004898private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4899runs on BSC_ConnHdlr {
4900 f_init_handler(pars);
4901 f_sgs_perform_lu();
4902 f_sleep(3.0);
4903
4904 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4905 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4906 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4907
4908 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4909 setverdict(fail, "subscriber not removed from VLR");
4910 }
4911
4912 f_sgsap_bssmap_screening();
4913
4914 setverdict(pass);
4915}
4916testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4917 var BSC_ConnHdlrPars pars;
4918 var BSC_ConnHdlr vc_conn;
4919 f_init(1, true);
4920 pars := f_init_pars(11815, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004921 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier5d812702019-03-21 10:51:26 +01004922 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4923 vc_conn.done;
4924}
4925
Harald Welte4263c522018-12-06 11:56:27 +01004926/* Trigger a paging request via VTY and send a paging reject in response */
4927private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4928runs on BSC_ConnHdlr {
4929 f_init_handler(pars);
4930 f_sgs_perform_lu();
4931 f_sleep(1.0);
4932
4933 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4934 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4935 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4936 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4937
4938 /* Initiate paging via VTY */
4939 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4940 alt {
4941 [] SGsAP.receive(exp_resp) {
4942 setverdict(pass);
4943 }
4944 [] SGsAP.receive {
4945 setverdict(fail, "Received unexpected message on SGs");
4946 }
4947 }
4948
4949 /* Now reject the paging */
4950 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4951
4952 /* Wait for the states inside the MSC to settle and check the state
4953 * of the SGs Association */
4954 f_sleep(1.0);
4955 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4956
4957 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4958 * but we also need to cover tha case where the cause code indicates an
4959 * "IMSI detached for EPS services". In those cases the VLR is expected to
4960 * try paging on tha A/Iu interface. This will be another testcase similar to
4961 * this one, but extended with checks for the presence of the A/Iu paging
4962 * messages. */
4963
4964 f_sgsap_bssmap_screening();
4965
4966 setverdict(pass);
4967}
4968testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004969 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004970 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004971 f_init(1, true);
4972 pars := f_init_pars(11816, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02004973 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004974 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004975 vc_conn.done;
4976}
4977
4978/* Trigger a paging request via VTY and send a paging reject that indicates
4979 * that the subscriber intentionally rejected the call. */
4980private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4981runs on BSC_ConnHdlr {
4982 f_init_handler(pars);
4983 f_sgs_perform_lu();
4984 f_sleep(1.0);
4985
4986 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4987 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4988 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4989 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4990
4991 /* Initiate paging via VTY */
4992 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4993 alt {
4994 [] SGsAP.receive(exp_resp) {
4995 setverdict(pass);
4996 }
4997 [] SGsAP.receive {
4998 setverdict(fail, "Received unexpected message on SGs");
4999 }
5000 }
5001
5002 /* Now reject the paging */
5003 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
5004
5005 /* Wait for the states inside the MSC to settle and check the state
5006 * of the SGs Association */
5007 f_sleep(1.0);
5008 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5009
5010 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
5011 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
5012 * to check back how this works and how it can be tested */
5013
5014 f_sgsap_bssmap_screening();
5015
5016 setverdict(pass);
5017}
5018testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005019 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005020 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005021 f_init(1, true);
5022 pars := f_init_pars(11817, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005023 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005024 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005025 vc_conn.done;
5026}
5027
5028/* Trigger a paging request via VTY and send an UE unreacable messge in response */
5029private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
5030runs on BSC_ConnHdlr {
5031 f_init_handler(pars);
5032 f_sgs_perform_lu();
5033 f_sleep(1.0);
5034
5035 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5036 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
5037 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5038 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5039
5040 /* Initiate paging via VTY */
5041 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5042 alt {
5043 [] SGsAP.receive(exp_resp) {
5044 setverdict(pass);
5045 }
5046 [] SGsAP.receive {
5047 setverdict(fail, "Received unexpected message on SGs");
5048 }
5049 }
5050
5051 /* Now pretend that the UE is unreachable */
5052 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
5053
5054 /* Wait for the states inside the MSC to settle and check the state
5055 * of the SGs Association. */
5056 f_sleep(1.0);
5057 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5058
5059 f_sgsap_bssmap_screening();
5060
5061 setverdict(pass);
5062}
5063testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005064 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005065 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005066 f_init(1, true);
5067 pars := f_init_pars(11818, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005068 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005069 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005070 vc_conn.done;
5071}
5072
5073/* Trigger a paging request via VTY but don't respond to it */
5074private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
5075runs on BSC_ConnHdlr {
5076 f_init_handler(pars);
5077 f_sgs_perform_lu();
5078 f_sleep(1.0);
5079
5080 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5081 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02005082 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01005083 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5084 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5085
5086 /* Initiate paging via VTY */
5087 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5088 alt {
5089 [] SGsAP.receive(exp_resp) {
5090 setverdict(pass);
5091 }
5092 [] SGsAP.receive {
5093 setverdict(fail, "Received unexpected message on SGs");
5094 }
5095 }
5096
Philipp Maier34218102019-09-24 09:15:49 +02005097 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
5098 * after some time */
5099 timer T := 10.0;
5100 T.start
5101 alt {
5102 [] SGsAP.receive(exp_serv_abrt)
5103 {
5104 setverdict(pass);
5105 }
5106 [] SGsAP.receive {
5107 setverdict(fail, "unexpected SGsAP message received");
5108 self.stop;
5109 }
5110 [] T.timeout {
5111 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
5112 self.stop;
5113 }
5114 }
5115
5116 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01005117 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5118
5119 f_sgsap_bssmap_screening();
5120
5121 setverdict(pass);
5122}
5123testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005124 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005125 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005126 f_init(1, true);
5127 pars := f_init_pars(11819, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005128 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005129 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005130 vc_conn.done;
5131}
5132
5133/* Trigger a paging request via VTY and slip in an LU */
5134private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
5135runs on BSC_ConnHdlr {
5136 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5137 f_init_handler(pars);
5138
5139 /* First we prepar the situation, where the SGs association is in state
5140 * NULL and the confirmed by radio contact indicator is set to false
5141 * as well. This can be archived by performing an SGs LU and then
5142 * resetting the VLR */
5143 f_sgs_perform_lu();
5144 f_sgsap_reset_mme(mp_mme_name);
5145 f_sleep(1.0);
5146 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5147
5148 /* Perform a paging, expect the paging messages on the SGs interface */
5149 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5150 alt {
5151 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5152 setverdict(pass);
5153 }
5154 [] SGsAP.receive {
5155 setverdict(fail, "Received unexpected message on SGs");
5156 }
5157 }
5158
5159 /* Perform the LU as normal */
5160 f_sgs_perform_lu();
5161 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5162
5163 /* Expect a new paging request right after the LU */
5164 alt {
5165 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5166 setverdict(pass);
5167 }
5168 [] SGsAP.receive {
5169 setverdict(fail, "Received unexpected message on SGs");
5170 }
5171 }
5172
5173 /* Test is done now, lets round everything up by rejecting the paging
5174 * cleanly. */
5175 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
5176 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5177
5178 f_sgsap_bssmap_screening();
5179
5180 setverdict(pass);
5181}
5182testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005183 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005184 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005185 f_init(1, true);
5186 pars := f_init_pars(11820, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005187 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005188 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005189 vc_conn.done;
5190}
5191
5192/* Send unexpected unit-data through the SGs interface */
5193private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5194 f_init_handler(pars);
5195 f_sleep(1.0);
5196
5197 /* This simulates what happens when a subscriber without SGs
5198 * association gets unitdata via the SGs interface. */
5199
5200 /* Make sure the subscriber exists and the SGs association
5201 * is in NULL state */
5202 f_perform_lu();
5203 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5204
5205 /* Send some random unit data, the MSC/VLR should send a release
5206 * immediately. */
5207 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5208 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
5209
5210 f_sgsap_bssmap_screening();
5211
5212 setverdict(pass);
5213}
5214testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005215 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005216 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005217 f_init(1, true);
5218 pars := f_init_pars(11821, true);
5219 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005220 vc_conn.done;
5221}
5222
5223/* Send unsolicited unit-data through the SGs interface */
5224private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5225 f_init_handler(pars);
5226 f_sleep(1.0);
5227
5228 /* This simulates what happens when the MME attempts to send unitdata
5229 * to a subscriber that is completely unknown to the VLR */
5230
5231 /* Send some random unit data, the MSC/VLR should send a release
5232 * immediately. */
5233 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
5234 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
5235
5236 f_sgsap_bssmap_screening();
5237
Harald Welte4d15fa72020-08-19 08:58:28 +02005238 /* clean-up VLR state about this subscriber */
5239 f_imsi_detach_by_imsi();
5240
Harald Welte4263c522018-12-06 11:56:27 +01005241 setverdict(pass);
5242}
5243testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005244 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005245 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005246 f_init(1, true);
5247 pars := f_init_pars(11822, true);
5248 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005249 vc_conn.done;
5250}
5251
5252private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
5253 /* FIXME: Match an actual payload (second questionmark), the type is
5254 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
5255 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
5256 setverdict(fail, "Unexpected SMS related PDU from MSC");
5257 mtc.stop;
5258 }
5259}
5260
5261/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
5262function f_mt_sms_sgs(inout SmsParameters spars)
5263runs on BSC_ConnHdlr {
5264 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5265 var template (value) RPDU_MS_SGSN rp_mo;
5266 var template (value) PDU_ML3_MS_NW l3_mo;
5267
5268 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5269 var template RPDU_SGSN_MS rp_mt;
5270 var template PDU_ML3_NW_MS l3_mt;
5271
5272 var PDU_ML3_NW_MS sgsap_l3_mt;
5273
5274 var default d := activate(as_other_sms_sgs());
5275
5276 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
5277 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09005278 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01005279 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
5280
5281 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
5282
5283 /* Extract relevant identifiers */
5284 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
5285 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
5286
5287 /* send CP-ACK for CP-DATA just received */
5288 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
5289
5290 SGsAP.send(l3_mo);
5291
5292 /* send RP-ACK for RP-DATA */
5293 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
5294 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
5295
5296 SGsAP.send(l3_mo);
5297
5298 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
5299 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
5300
5301 SGsAP.receive(l3_mt);
5302
5303 deactivate(d);
5304
5305 setverdict(pass);
5306}
5307
5308/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
5309function f_mo_sms_sgs(inout SmsParameters spars)
5310runs on BSC_ConnHdlr {
5311 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
5312 var template (value) RPDU_MS_SGSN rp_mo;
5313 var template (value) PDU_ML3_MS_NW l3_mo;
5314
5315 var template TPDU_RP_DATA_SGSN_MS tp_mt;
5316 var template RPDU_SGSN_MS rp_mt;
5317 var template PDU_ML3_NW_MS l3_mt;
5318
5319 var default d := activate(as_other_sms_sgs());
5320
5321 /* just in case this is routed to SMPP.. */
5322 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
5323
5324 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
5325 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09005326 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01005327 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
5328
5329 SGsAP.send(l3_mo);
5330
5331 /* receive CP-ACK for CP-DATA above */
5332 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
5333
5334 if (ispresent(spars.exp_rp_err)) {
5335 /* expect an RP-ERROR message from MSC with given cause */
5336 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
5337 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5338 SGsAP.receive(l3_mt);
5339 /* send CP-ACK for CP-DATA just received */
5340 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5341 SGsAP.send(l3_mo);
5342 } else {
5343 /* expect RP-ACK for RP-DATA */
5344 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
5345 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
5346 SGsAP.receive(l3_mt);
5347 /* send CP-ACO for CP-DATA just received */
5348 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
5349 SGsAP.send(l3_mo);
5350 }
5351
5352 deactivate(d);
5353
5354 setverdict(pass);
5355}
5356
5357private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
5358runs on BSC_ConnHdlr {
5359 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
5360}
5361
5362/* Send a MT SMS via SGs interface */
5363private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5364 f_init_handler(pars);
5365 f_sgs_perform_lu();
5366 f_sleep(1.0);
5367 var SmsParameters spars := valueof(t_SmsPars);
5368 spars.tp.ud := 'C8329BFD064D9B53'O;
5369
5370 /* Trigger SMS via VTY */
5371 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5372 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5373
5374 /* Expect a paging request and respond accordingly with a service request */
5375 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
5376 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
5377
5378 /* Connection is now live, receive the MT-SMS */
5379 f_mt_sms_sgs(spars);
5380
5381 /* Expect a concluding release from the MSC */
5382 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5383
5384 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5385 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5386
5387 f_sgsap_bssmap_screening();
5388
5389 setverdict(pass);
5390}
5391testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005392 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005393 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005394 f_init(1, true);
5395 pars := f_init_pars(11823, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005396 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005397 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005398 vc_conn.done;
5399}
5400
5401/* Send a MO SMS via SGs interface */
5402private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5403 f_init_handler(pars);
5404 f_sgs_perform_lu();
5405 f_sleep(1.0);
5406 var SmsParameters spars := valueof(t_SmsPars);
5407 spars.tp.ud := 'C8329BFD064D9B53'O;
5408
5409 /* Send the MO-SMS */
5410 f_mo_sms_sgs(spars);
5411
5412 /* Expect a concluding release from the MSC/VLR */
5413 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5414
5415 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5416 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5417
5418 setverdict(pass);
5419
5420 f_sgsap_bssmap_screening()
5421}
5422testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005423 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005424 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005425 f_init(1, true);
5426 pars := f_init_pars(11824, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005427 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005428 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005429 vc_conn.done;
5430}
5431
5432/* Trigger sending of an MT sms via VTY but never respond to anything */
5433private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5434 f_init_handler(pars, 170.0);
5435 f_sgs_perform_lu();
5436 f_sleep(1.0);
5437
5438 var SmsParameters spars := valueof(t_SmsPars);
5439 spars.tp.ud := 'C8329BFD064D9B53'O;
5440 var integer page_count := 0;
5441 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5442 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5443 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5444 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5445
5446 /* Trigger SMS via VTY */
5447 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5448
Neels Hofmeyr16237742019-03-06 15:34:01 +01005449 /* Expect the MSC/VLR to page exactly once */
5450 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005451
5452 /* Wait some time to make sure the MSC is not delivering any further
5453 * paging messages or anything else that could be unexpected. */
5454 timer T := 20.0;
5455 T.start
5456 alt {
5457 [] SGsAP.receive(exp_pag_req)
5458 {
5459 setverdict(fail, "paging seems not to stop!");
5460 mtc.stop;
5461 }
5462 [] SGsAP.receive {
5463 setverdict(fail, "unexpected SGsAP message received");
5464 self.stop;
5465 }
5466 [] T.timeout {
5467 setverdict(pass);
5468 }
5469 }
5470
5471 /* Even on a failed paging the SGs Association should stay intact */
5472 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5473
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005474 /* Make sure that the SMS we just inserted is cleared and the
5475 * subscriber is expired. This is necessary because otherwise the MSC
5476 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005477
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005478 f_vty_sms_clear(hex2str(g_pars.imsi));
5479
Harald Welte4263c522018-12-06 11:56:27 +01005480 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5481
5482 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005483
5484 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005485}
5486testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005487 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005488 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005489 f_init(1, true);
5490 pars := f_init_pars(11825, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005491 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005492 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005493 vc_conn.done;
5494}
5495
5496/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5497private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5498 f_init_handler(pars, 150.0);
5499 f_sgs_perform_lu();
5500 f_sleep(1.0);
5501
5502 var SmsParameters spars := valueof(t_SmsPars);
5503 spars.tp.ud := 'C8329BFD064D9B53'O;
5504 var integer page_count := 0;
5505 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5506 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5507 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5508 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5509
5510 /* Trigger SMS via VTY */
5511 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5512
5513 /* Expect a paging request and reject it immediately */
5514 SGsAP.receive(exp_pag_req);
5515 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5516
5517 /* The MSC/VLR should no longer try to page once the paging has been
5518 * rejected. Wait some time and check if there are no unexpected
5519 * messages on the SGs interface. */
5520 timer T := 20.0;
5521 T.start
5522 alt {
5523 [] SGsAP.receive(exp_pag_req)
5524 {
5525 setverdict(fail, "paging seems not to stop!");
5526 mtc.stop;
5527 }
5528 [] SGsAP.receive {
5529 setverdict(fail, "unexpected SGsAP message received");
5530 self.stop;
5531 }
5532 [] T.timeout {
5533 setverdict(pass);
5534 }
5535 }
5536
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005537 f_vty_sms_clear(hex2str(g_pars.imsi));
5538
Harald Welte4263c522018-12-06 11:56:27 +01005539 /* A rejected paging with IMSI_unknown (see above) should always send
5540 * the SGs association to NULL. */
5541 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5542
5543 f_sgsap_bssmap_screening();
5544
Harald Welte4263c522018-12-06 11:56:27 +01005545 setverdict(pass);
5546}
5547testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005548 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005549 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005550 f_init(1, true);
5551 pars := f_init_pars(11826, true);
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005552 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005553 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005554 vc_conn.done;
5555}
5556
Pau Espin Pedrol3acd19e2021-04-28 12:59:52 +02005557/* Perform an MT CSFB call including LU */
Harald Welte4263c522018-12-06 11:56:27 +01005558private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5559 f_init_handler(pars);
5560
5561 /* Be sure that the BSSMAP reset is done before we begin. */
5562 f_sleep(2.0);
5563
5564 /* Testcase variation: See what happens when we do a regular BSSMAP
5565 * LU first (this should not hurt in any way!) */
5566 if (bssmap_lu) {
5567 f_perform_lu();
5568 }
Pau Espin Pedrole979c402021-04-28 17:29:54 +02005569 pars.common_id_last_eutran_plmn := f_enc_mcc_mnc('901'H, '70'H);
Harald Welte4263c522018-12-06 11:56:27 +01005570
5571 f_sgs_perform_lu();
5572 f_sleep(1.0);
5573
5574 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5575 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005576
5577 /* Initiate a call via MNCC interface */
5578 f_mt_call_initate(cpars);
5579
5580 /* Expect a paging request and respond accordingly with a service request */
5581 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5582 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5583
5584 /* Complete the call, hold it for some time and then tear it down */
5585 f_mt_call_complete(cpars);
5586 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005587 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005588
5589 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5590 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5591
Harald Welte4263c522018-12-06 11:56:27 +01005592 /* Test for successful return by triggering a paging, when the paging
5593 * request is received via SGs, we can be sure that the MSC/VLR has
5594 * recognized that the UE is now back on 4G */
5595 f_sleep(1.0);
5596 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5597 alt {
5598 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5599 setverdict(pass);
5600 }
5601 [] SGsAP.receive {
5602 setverdict(fail, "Received unexpected message on SGs");
5603 }
5604 }
5605
5606 f_sgsap_bssmap_screening();
5607
5608 setverdict(pass);
5609}
5610
5611/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5612private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5613 f_mt_lu_and_csfb_call(id, pars, true);
5614}
5615testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005616 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005617 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005618 f_init(1, true);
5619 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005620
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005621 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005622 vc_conn.done;
5623}
5624
Harald Welte4263c522018-12-06 11:56:27 +01005625/* Perform a SGSAP LU and then make a CSFB call */
5626private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5627 f_mt_lu_and_csfb_call(id, pars, false);
5628}
5629testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005630 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005631 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005632 f_init(1, true);
5633 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005634
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005635 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005636 vc_conn.done;
5637}
5638
Philipp Maier628c0052019-04-09 17:36:57 +02005639/* Simulate an HLR/VLR failure */
5640private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5641 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5642 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5643
5644 var PDU_SGsAP lur;
5645
5646 f_init_handler(pars);
5647
5648 /* Attempt location update (which is expected to fail) */
5649 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5650 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5651 SGsAP.send(lur);
5652
5653 /* Respond to SGsAP-RESET-INDICATION from VLR */
5654 alt {
5655 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5656 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5657 setverdict(pass);
5658 }
5659 [] SGsAP.receive {
5660 setverdict(fail, "Received unexpected message on SGs");
5661 }
5662 }
5663
5664 f_sleep(1.0);
5665 setverdict(pass);
5666}
5667testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5668 var BSC_ConnHdlrPars pars;
5669 var BSC_ConnHdlr vc_conn;
5670 f_init(1, true, false);
5671 pars := f_init_pars(11811, true, false);
5672 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5673 vc_conn.done;
5674}
5675
Harald Welte4263c522018-12-06 11:56:27 +01005676/* SGs TODO:
5677 * LU attempt for IMSI without NAM_PS in HLR
5678 * LU attempt with AUTH FAIL due to invalid RES/SRES
5679 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5680 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5681 * implicit IMSI detach from EPS
5682 * implicit IMSI detach from non-EPS
5683 * MM INFO
5684 *
5685 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005686
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005687private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5688 f_init_handler(pars);
5689 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005690
5691 f_perform_lu();
5692 f_mo_call_establish(cpars);
5693
5694 f_sleep(1.0);
5695
5696 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5697 var BssmapCause cause := enum2int(cause_val);
5698
5699 var template BSSMAP_FIELD_CellIdentificationList cil;
5700 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5701
5702 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5703 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5704
5705 f_call_hangup(cpars, true);
5706}
5707testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5708 var BSC_ConnHdlr vc_conn;
5709 f_init();
5710
5711 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5712 vc_conn.done;
5713}
5714
5715private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5716 var MgcpCommand mgcp_cmd;
5717 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr8913b9e2021-07-27 22:33:45 +02005718 var charstring conn_id;
5719 f_mgcp_find_param_entry(mgcp_cmd.params, "I", conn_id);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005720 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005721 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005722 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005723 { int2str(cpars.rtp_payload_type) },
5724 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5725 cpars.rtp_sdp_format)),
5726 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr8913b9e2021-07-27 22:33:45 +02005727 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, str2hex(conn_id), sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005728 repeat;
5729 }
5730}
5731
Neels Hofmeyr8853afb2021-07-27 22:34:15 +02005732private altstep as_mgcp_ack_all_dlcx(CallParameters cpars) runs on BSC_ConnHdlr {
5733 var MgcpCommand mgcp_cmd;
5734 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
5735 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
5736 repeat;
5737 }
5738}
5739
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005740private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005741 var CallParameters cpars;
5742
5743 cpars := valueof(t_CallParams('12345'H, 0));
5744 if (pars.use_ipv6) {
5745 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5746 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5747 cpars.bss_rtp_ip := "::3";
5748 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005749
5750 f_init_handler(pars);
5751
5752 f_vty_transceive(MSCVTY, "configure terminal");
5753 f_vty_transceive(MSCVTY, "msc");
5754 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005755 f_vty_transceive(MSCVTY, "neighbor a cgi 023 42 5 6 ran-pc 0.24.2");
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005756 f_vty_transceive(MSCVTY, "exit");
5757 f_vty_transceive(MSCVTY, "exit");
5758
5759 f_perform_lu();
5760 f_mo_call_establish(cpars);
5761
5762 f_sleep(1.0);
5763
5764 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5765
5766 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5767 var BssmapCause cause := enum2int(cause_val);
5768
5769 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005770 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('023'H, '42'H, 5, 6) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005771
5772 /* old BSS sends Handover Required */
5773 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5774
5775 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5776
5777 /* MSC forwards the RR Handover Command to old BSS */
5778 var PDU_BSSAP ho_command;
5779 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5780
5781 log("GOT HandoverCommand", ho_command);
5782
5783 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5784
5785 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5786 f_expect_clear();
5787
5788 log("FIRST inter-BSC Handover done");
5789
5790
5791 /* ------------------------ */
5792
5793 /* Ok, that went well, now the other BSC is handovering back here --
5794 * from now on this here is the new BSS. */
5795 f_create_bssmap_exp_handoverRequest(193);
5796
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005797 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
5798 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
5799 var template BSSMAP_IE_KC128 kC128;
5800 var OCT1 a5_perm_alg;
5801 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
5802 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005803 var PDU_BSSAP ho_request;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005804 alt {
5805 [] BSSAP.receive(expect_ho_request);
5806 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
5807 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
5808 " got ", ho_request);
5809 setverdict(fail, "Wrong handoverRequest received");
5810 mtc.stop;
5811 }
5812 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005813
5814 /* new BSS composes a RR Handover Command */
5815 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5816 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005817 var BSSMAP_IE_AoIP_TransportLayerAddress tla tla :=
5818 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005819 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5820 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5821
5822 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5823
5824 f_sleep(0.5);
5825
5826 /* Notify that the MS is now over here */
5827
5828 BSSAP.send(ts_BSSMAP_HandoverDetect);
5829 f_sleep(0.1);
5830 BSSAP.send(ts_BSSMAP_HandoverComplete);
5831
5832 f_sleep(3.0);
5833
5834 deactivate(ack_mdcx);
5835
5836 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5837
5838 /* blatant cheating */
5839 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5840 last_n_sd[0] := 3;
5841 f_bssmap_continue_after_n_sd(last_n_sd);
5842
5843 f_call_hangup(cpars, true);
5844 f_sleep(1.0);
5845 deactivate(ccrel);
5846
5847 setverdict(pass);
5848}
5849private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005850 var charstring bss_rtp_ip;
5851 if (pars.use_ipv6) {
5852 bss_rtp_ip := "::8";
5853 } else {
5854 bss_rtp_ip := "1.2.3.4";
5855 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005856 f_init_handler(pars);
5857 f_create_bssmap_exp_handoverRequest(194);
5858
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005859 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
5860 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
5861 var template BSSMAP_IE_KC128 kC128;
5862 var OCT1 a5_perm_alg;
5863 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
5864 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005865 var PDU_BSSAP ho_request;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005866 alt {
5867 [] BSSAP.receive(expect_ho_request);
5868 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
5869 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
5870 " got ", ho_request);
5871 setverdict(fail, "Wrong handoverRequest received");
5872 mtc.stop;
5873 }
5874 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005875 /* new BSS composes a RR Handover Command */
5876 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5877 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005878 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
5879 valueof(f_ts_BSSMAP_IE_AoIP_TLA(bss_rtp_ip, 2342));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005880 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5881 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5882
5883 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5884
5885 f_sleep(0.5);
5886
5887 /* Notify that the MS is now over here */
5888
5889 BSSAP.send(ts_BSSMAP_HandoverDetect);
5890 f_sleep(0.1);
5891 BSSAP.send(ts_BSSMAP_HandoverComplete);
5892
5893 f_sleep(3.0);
5894
5895 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5896 * ... handover back to the first BSC :P */
5897
5898 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5899 var BssmapCause cause := enum2int(cause_val);
5900
5901 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr2822d072021-06-23 03:20:32 +02005902 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005903
5904 /* old BSS sends Handover Required */
5905 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5906
5907 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5908
5909 /* MSC forwards the RR Handover Command to old BSS */
5910 var PDU_BSSAP ho_command;
5911 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5912
5913 log("GOT HandoverCommand", ho_command);
5914
5915 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5916
5917 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5918 f_expect_clear();
5919 setverdict(pass);
5920}
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005921function f_tc_ho_inter_bsc_main(boolean use_ipv6 := false, integer a5_n := 0) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005922 var BSC_ConnHdlr vc_conn0;
5923 var BSC_ConnHdlr vc_conn1;
5924 f_init(2);
5925
5926 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005927 pars0.use_ipv6 := use_ipv6;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005928 pars0.net.expect_ciph := a5_n > 0;
5929 pars0.net.expect_auth := pars0.net.expect_ciph;
5930 pars0.net.kc_support := bit2oct('00000001'B << a5_n);
5931 pars0.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
5932 pars0.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
5933 pars0.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
5934 pars0.cm3 := valueof(ts_CM3_default);
5935 pars0.use_umts_aka := true;
5936 pars0.vec := f_gen_auth_vec_3g();
5937 pars0.vec_keep := true;
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005938 pars0.ran_idx := 0;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005939
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005940 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005941 pars1.use_ipv6 := use_ipv6;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005942 pars1.net.expect_ciph := pars0.net.expect_ciph;
5943 pars1.net.expect_auth := pars0.net.expect_ciph;
5944 pars1.net.kc_support := bit2oct('00000001'B << a5_n);
5945 pars1.cm2 := pars0.cm2;
5946 pars1.cm3 := pars0.cm3;
5947 pars1.use_umts_aka := true;
5948 /* Both components need the same auth vector info because we expect f_tc_ho_inter_bsc0's ciphering key to be
5949 * identical to the one that shows up in f_tc_ho_inter_bsc1. Can only do that by feeding in a vector to both
5950 * components and then not overwriting it in BSC_ConnectionHandler. */
5951 pars1.vec := pars0.vec;
5952 pars1.vec_keep := true;
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005953 pars1.ran_idx := 1;
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005954
5955 if (a5_n > 0) {
5956 f_vty_config(MSCVTY, "network", "authentication required");
5957 }
5958 f_vty_config(MSCVTY, "network", "encryption a5 " & int2str(a5_n));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005959
Neels Hofmeyr60122f82021-07-28 17:59:38 +02005960 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0);
5961 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005962 vc_conn0.done;
5963 vc_conn1.done;
5964}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005965testcase TC_ho_inter_bsc() runs on MTC_CT {
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02005966 f_tc_ho_inter_bsc_main(false, a5_n := 0);
5967}
5968testcase TC_ho_inter_bsc_a5_1() runs on MTC_CT {
5969 f_tc_ho_inter_bsc_main(false, a5_n := 1);
5970}
5971testcase TC_ho_inter_bsc_a5_3() runs on MTC_CT {
5972 f_tc_ho_inter_bsc_main(false, a5_n := 3);
5973}
5974testcase TC_ho_inter_bsc_a5_4() runs on MTC_CT {
5975 f_tc_ho_inter_bsc_main(false, a5_n := 4);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005976}
5977testcase TC_ho_inter_bsc_ipv6() runs on MTC_CT {
5978 f_tc_ho_inter_bsc_main(true);
5979}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005980
5981function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5982 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5983 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5984 log("MS_NW patched enc_l3: ", enc_l3);
5985}
5986
5987private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005988 var CallParameters cpars;
Neels Hofmeyr906af102021-07-01 12:08:35 +02005989 var PDU_BSSAP ho_request;
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02005990
5991 cpars := valueof(t_CallParams('12345'H, 0));
5992 if (pars.use_ipv6) {
5993 cpars.mgw_conn_1.mgw_rtp_ip := "::1";
5994 cpars.mgw_conn_2.mgw_rtp_ip := "::2";
5995 cpars.bss_rtp_ip := "::3";
5996 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005997 var hexstring ho_number := f_gen_msisdn(99999);
5998
5999 f_init_handler(pars);
6000
6001 f_create_mncc_expect(hex2str(ho_number));
6002
6003 f_vty_transceive(MSCVTY, "configure terminal");
6004 f_vty_transceive(MSCVTY, "msc");
6005 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
6006 f_vty_transceive(MSCVTY, "exit");
6007 f_vty_transceive(MSCVTY, "exit");
6008
6009 f_perform_lu();
6010 f_mo_call_establish(cpars);
6011
6012 f_sleep(1.0);
6013
6014 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
6015
6016 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
6017 var BssmapCause cause := enum2int(cause_val);
6018
6019 var template BSSMAP_FIELD_CellIdentificationList cil;
Neels Hofmeyr36ebc332021-06-23 03:20:32 +02006020 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('017'H, '017'H, 1, 1) } };
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006021
6022 /* old BSS sends Handover Required */
6023 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
6024
6025 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
6026 * This MSC tries to reach the other MSC via GSUP. */
6027
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006028 var template BSSMAP_IE_EncryptionInformation encryptionInformation;
6029 var template BSSMAP_IE_ChosenEncryptionAlgorithm chosenEncryptionAlgorithm;
6030 var template BSSMAP_IE_KC128 kC128;
6031 var OCT1 a5_perm_alg;
6032 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
6033 var template PDU_BSSAP expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
6034
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006035 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
6036 var GSUP_PDU prep_ho_req;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006037 alt {
6038 [] GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
6039 pars.imsi, destination_name := remote_msc_name,
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006040 an_apdu := t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, pdu := ?))) -> value prep_ho_req;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006041 [] GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST)) {
6042 setverdict(fail, "Wrong OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST message received");
6043 mtc.stop;
6044 }
6045 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006046
6047 var GSUP_IeValue source_name_ie;
6048 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
6049 var octetstring local_msc_name := source_name_ie.source_name;
6050
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006051 /* Decode PDU to 1) match with expect_ho_request and 2) to forward the actual chosen encryption algorithm. */
Neels Hofmeyr906af102021-07-01 12:08:35 +02006052 var GSUP_IeValue an_apdu_ie;
6053 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_AN_APDU_IE, an_apdu_ie);
6054 ho_request := dec_PDU_BSSAP(an_apdu_ie.an_apdu.pdu);
Neels Hofmeyrec2e1f72021-07-02 02:08:32 +02006055 if (not match(ho_request, expect_ho_request)) {
6056 setverdict(fail, "Wrong PDU in OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST message received");
6057 mtc.stop;
6058 }
Neels Hofmeyr906af102021-07-01 12:08:35 +02006059
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006060 /* Remote MSC has figured out its BSC and signals success */
6061 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
6062 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
6063 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
Neels Hofmeyr906af102021-07-01 12:08:35 +02006064 aoIPTransportLayer := omit,
6065 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}),
6066 chosenEncryptionAlgorithm := ho_request.pdu.bssmap.handoverRequest.chosenEncryptionAlgorithm));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006067 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
6068 pars.imsi,
6069 ho_number,
6070 remote_msc_name, local_msc_name,
6071 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
6072
6073 /* MSC forwards the RR Handover Command to old BSS */
6074 BSSAP.receive(tr_BSSMAP_HandoverCommand);
6075
6076 /* The MS shows up at remote new BSS */
6077
6078 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
6079 pars.imsi, remote_msc_name, local_msc_name,
6080 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6081 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
6082 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
6083 f_sleep(0.1);
6084
6085 /* Save the MS sequence counters for use on the other connection */
6086 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
6087
6088 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
6089 pars.imsi, remote_msc_name, local_msc_name,
6090 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6091 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
6092
6093 /* The local BSS conn clears, all communication goes via remote MSC now */
6094 f_expect_clear();
6095
6096 /**********************************/
6097 /* Play through some signalling across the inter-MSC link.
6098 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
6099
6100 if (false) {
6101 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
6102 invoke_id := 5, /* Phone may not start from 0 or 1 */
6103 op_code := SS_OP_CODE_PROCESS_USS_REQ,
6104 ussd_string := "*#100#"
6105 );
6106
6107 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
6108 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
6109 op_code := SS_OP_CODE_PROCESS_USS_REQ,
6110 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
6111 )
6112
6113 /* Compose a new SS/REGISTER message with request */
6114 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
6115 tid := 1, /* We just need a single transaction */
6116 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
6117 facility := valueof(facility_req)
6118 );
6119 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
6120
6121 /* Compose SS/RELEASE_COMPLETE template with expected response */
6122 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
6123 tid := 1, /* Response should arrive within the same transaction */
6124 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
6125 facility := valueof(facility_rsp)
6126 );
6127
6128 /* Compose expected MSC -> HLR message */
6129 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
6130 imsi := g_pars.imsi,
6131 state := OSMO_GSUP_SESSION_STATE_BEGIN,
6132 ss := valueof(facility_req)
6133 );
6134
6135 /* To be used for sending response with correct session ID */
6136 var GSUP_PDU gsup_req_complete;
6137
6138 /* Request own number */
6139 /* From remote MSC instead of BSSAP directly */
6140 /* Patch the correct N_SD value into the message. */
6141 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
6142 var RAN_Emulation.ConnectionData cd;
6143 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
6144 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
6145 pars.imsi, remote_msc_name, local_msc_name,
6146 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6147 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
6148 ))
6149 ));
6150
6151 /* Expect GSUP message containing the SS payload */
6152 gsup_req_complete := f_expect_gsup_msg(gsup_req);
6153
6154 /* Compose the response from HLR using received session ID */
6155 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
6156 imsi := g_pars.imsi,
6157 sid := gsup_req_complete.ies[1].val.session_id,
6158 state := OSMO_GSUP_SESSION_STATE_END,
6159 ss := valueof(facility_rsp)
6160 );
6161
6162 /* Finally, HLR terminates the session */
6163 GSUP.send(gsup_rsp);
6164
6165 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
6166 var GSUP_PDU gsup_ussd_rsp;
6167 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
6168 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
6169
6170 var GSUP_IeValue an_apdu;
6171 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
6172 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
6173 mtc.stop;
6174 }
6175 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
6176 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
6177 log("Expecting", ussd_rsp);
6178 log("Got", dtap_mt);
6179 if (not match(dtap_mt, ussd_rsp)) {
6180 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
6181 mtc.stop;
6182 }
6183 }
6184 /**********************************/
6185
6186
6187 /* inter-MSC handover back to the first MSC */
6188 f_create_bssmap_exp_handoverRequest(193);
6189 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
6190
6191 /* old BSS sends Handover Required, via inter-MSC E link: like
6192 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
6193 * but via GSUP */
6194 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
6195 pars.imsi, remote_msc_name, local_msc_name,
6196 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
6197 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
6198 ))
6199 ));
6200
6201 /* MSC asks local BSS to prepare Handover to it */
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006202 f_get_expected_encryption(encryptionInformation, chosenEncryptionAlgorithm, kC128, a5_perm_alg);
6203 expect_ho_request := tr_BSSMAP_HandoverRequest(encryptionInformation, chosenEncryptionAlgorithm, kC128);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006204 alt {
Neels Hofmeyr906af102021-07-01 12:08:35 +02006205 [] BSSAP.receive(expect_ho_request) -> value ho_request;
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006206 [] BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request {
6207 log("Error: Wrong handoverRequest received. Expected: ", expect_ho_request,
6208 " got ", ho_request);
6209 setverdict(fail, "Wrong handoverRequest received");
6210 mtc.stop;
6211 }
6212 }
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006213
6214 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
6215 f_bssmap_continue_after_n_sd(last_n_sd);
6216
6217 /* new BSS composes a RR Handover Command */
6218 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
6219 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006220 var BSSMAP_IE_AoIP_TransportLayerAddress tla :=
6221 valueof(f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006222 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
Neels Hofmeyr906af102021-07-01 12:08:35 +02006223 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}),
6224 chosenEncryptionAlgorithm := ho_request.pdu.bssmap.handoverRequest.chosenEncryptionAlgorithm));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006225
6226 /* HandoverCommand goes out via remote MSC-I */
6227 var GSUP_PDU prep_subsq_ho_res;
6228 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
6229 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
6230
6231 /* MS shows up at the local BSS */
6232 BSSAP.send(ts_BSSMAP_HandoverDetect);
6233 f_sleep(0.1);
6234 BSSAP.send(ts_BSSMAP_HandoverComplete);
6235
6236 /* Handover Succeeded message */
6237 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
6238 pars.imsi, destination_name := remote_msc_name));
6239
6240 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
6241 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
6242 pars.imsi, destination_name := remote_msc_name));
6243
6244 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
6245
6246 f_sleep(1.0);
6247 deactivate(ack_mdcx);
6248
6249 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
6250 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
6251 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
6252 MNCC.clear;
6253
6254 var default ccrel := activate(as_optional_cc_rel(cpars, true));
6255 f_call_hangup(cpars, true);
6256 f_sleep(1.0);
6257 deactivate(ccrel);
6258
6259 setverdict(pass);
6260}
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006261function f_tc_ho_inter_msc_out_a5(integer a5_n) runs on MTC_CT {
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006262 var BSC_ConnHdlr vc_conn;
6263 f_init(1);
6264
6265 var BSC_ConnHdlrPars pars := f_init_pars(54);
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006266 pars.net.expect_ciph := a5_n > 0;
6267 pars.net.expect_auth := pars.net.expect_ciph;
6268 pars.net.kc_support := bit2oct('00000001'B << a5_n);
6269 pars.cm2.classmarkInformationType2_oct5.a5_3 := '1'B;
6270 pars.cm2.classmarkInformationType2_oct5.a5_2 := '0'B;
6271 pars.cm2.classmarkInformationType2_oct5.cm3 := '1'B;
6272 pars.cm3 := valueof(ts_CM3_default);
6273 pars.use_umts_aka := true;
6274
6275 if (a5_n > 0) {
6276 f_vty_config(MSCVTY, "network", "authentication required");
6277 }
6278 f_vty_config(MSCVTY, "network", "encryption a5 " & int2str(a5_n));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006279
Neels Hofmeyr60122f82021-07-28 17:59:38 +02006280 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars);
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006281 vc_conn.done;
6282}
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006283testcase TC_ho_inter_msc_out() runs on MTC_CT {
6284 f_tc_ho_inter_msc_out_a5(0);
6285}
6286testcase TC_ho_inter_msc_out_a5_1() runs on MTC_CT {
6287 f_tc_ho_inter_msc_out_a5(1);
6288}
6289testcase TC_ho_inter_msc_out_a5_3() runs on MTC_CT {
6290 f_tc_ho_inter_msc_out_a5(3);
6291}
6292testcase TC_ho_inter_msc_out_a5_4() runs on MTC_CT {
6293 f_tc_ho_inter_msc_out_a5(4);
6294}
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006295testcase TC_ho_inter_msc_out_ipv6() runs on MTC_CT {
6296 var BSC_ConnHdlr vc_conn;
6297 f_init(1);
6298
6299 var BSC_ConnHdlrPars pars := f_init_pars(54);
6300 pars.use_ipv6 := true;
6301
Neels Hofmeyr60122f82021-07-28 17:59:38 +02006302 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars);
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006303 vc_conn.done;
6304}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006305
Oliver Smith1d118ff2019-07-03 10:57:35 +02006306private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6307 pars.net.expect_auth := true;
6308 pars.net.expect_imei := true;
6309 f_init_handler(pars);
6310 f_perform_lu();
6311}
6312testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
6313 var BSC_ConnHdlr vc_conn;
6314 f_init();
6315 f_vty_config(MSCVTY, "network", "authentication required");
6316 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6317
6318 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
6319 vc_conn.done;
6320}
6321
6322private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6323 pars.net.expect_auth := true;
6324 pars.use_umts_aka := true;
6325 pars.net.expect_imei := true;
6326 f_init_handler(pars);
6327 f_perform_lu();
6328}
6329testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
6330 var BSC_ConnHdlr vc_conn;
6331 f_init();
6332 f_vty_config(MSCVTY, "network", "authentication required");
6333 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6334
6335 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
6336 vc_conn.done;
6337}
6338
6339private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6340 pars.net.expect_imei := true;
6341 f_init_handler(pars);
6342 f_perform_lu();
6343}
6344testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
6345 var BSC_ConnHdlr vc_conn;
6346 f_init();
6347 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6348
6349 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
6350 vc_conn.done;
6351}
6352
6353private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6354 pars.net.expect_tmsi := false;
6355 pars.net.expect_imei := true;
6356 f_init_handler(pars);
6357 f_perform_lu();
6358}
6359testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
6360 var BSC_ConnHdlr vc_conn;
6361 f_init();
6362 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6363 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6364
6365 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
6366 vc_conn.done;
6367}
6368
6369private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6370 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006371
6372 pars.net.expect_auth := true;
6373 pars.net.expect_imei := true;
6374 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6375 f_init_handler(pars);
6376
6377 /* Cannot use f_perform_lu() as we expect a reject */
6378 l3_lu := f_build_lu_imsi(g_pars.imsi)
6379 f_create_gsup_expect(hex2str(g_pars.imsi));
6380 f_bssap_compl_l3(l3_lu);
6381 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6382
6383 f_mm_common();
6384 f_msc_lu_hlr();
6385 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006386 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006387 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006388}
6389testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
6390 var BSC_ConnHdlr vc_conn;
6391 f_init();
6392 f_vty_config(MSCVTY, "network", "authentication required");
6393 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6394
6395 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
6396 vc_conn.done;
6397}
6398
6399private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6400 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006401
6402 pars.net.expect_auth := true;
6403 pars.net.expect_imei := true;
6404 pars.net.check_imei_error := true;
6405 f_init_handler(pars);
6406
6407 /* Cannot use f_perform_lu() as we expect a reject */
6408 l3_lu := f_build_lu_imsi(g_pars.imsi)
6409 f_create_gsup_expect(hex2str(g_pars.imsi));
6410 f_bssap_compl_l3(l3_lu);
6411 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6412
6413 f_mm_common();
6414 f_msc_lu_hlr();
6415 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006416 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006417 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006418}
6419testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
6420 var BSC_ConnHdlr vc_conn;
6421 f_init();
6422 f_vty_config(MSCVTY, "network", "authentication required");
6423 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
6424
6425 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
6426 vc_conn.done;
6427}
6428
6429private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6430 pars.net.expect_auth := true;
6431 pars.net.expect_imei_early := true;
6432 f_init_handler(pars);
6433 f_perform_lu();
6434}
6435testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
6436 var BSC_ConnHdlr vc_conn;
6437 f_init();
6438 f_vty_config(MSCVTY, "network", "authentication required");
6439 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6440
6441 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
6442 vc_conn.done;
6443}
6444
6445private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6446 pars.net.expect_auth := true;
6447 pars.use_umts_aka := true;
6448 pars.net.expect_imei_early := true;
6449 f_init_handler(pars);
6450 f_perform_lu();
6451}
6452testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
6453 var BSC_ConnHdlr vc_conn;
6454 f_init();
6455 f_vty_config(MSCVTY, "network", "authentication required");
6456 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6457
6458 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
6459 vc_conn.done;
6460}
6461
6462private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6463 pars.net.expect_imei_early := true;
6464 f_init_handler(pars);
6465 f_perform_lu();
6466}
6467testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
6468 var BSC_ConnHdlr vc_conn;
6469 f_init();
6470 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6471
6472 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
6473 vc_conn.done;
6474}
6475
6476private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6477 pars.net.expect_tmsi := false;
6478 pars.net.expect_imei_early := true;
6479 f_init_handler(pars);
6480 f_perform_lu();
6481}
6482testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
6483 var BSC_ConnHdlr vc_conn;
6484 f_init();
6485 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
6486 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6487
6488 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
6489 vc_conn.done;
6490}
6491
6492private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6493 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006494
6495 pars.net.expect_auth := true;
6496 pars.net.expect_imei_early := true;
6497 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
6498 f_init_handler(pars);
6499
6500 /* Cannot use f_perform_lu() as we expect a reject */
6501 l3_lu := f_build_lu_imsi(g_pars.imsi)
6502 f_create_gsup_expect(hex2str(g_pars.imsi));
6503 f_bssap_compl_l3(l3_lu);
6504 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6505
6506 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006507 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006508 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006509}
6510testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
6511 var BSC_ConnHdlr vc_conn;
6512 f_init();
6513 f_vty_config(MSCVTY, "network", "authentication required");
6514 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6515
6516 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
6517 vc_conn.done;
6518}
6519
6520private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6521 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02006522
6523 pars.net.expect_auth := true;
6524 pars.net.expect_imei_early := true;
6525 pars.net.check_imei_error := true;
6526 f_init_handler(pars);
6527
6528 /* Cannot use f_perform_lu() as we expect a reject */
6529 l3_lu := f_build_lu_imsi(g_pars.imsi)
6530 f_create_gsup_expect(hex2str(g_pars.imsi));
6531 f_bssap_compl_l3(l3_lu);
6532 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
6533
6534 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02006535 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02006536 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02006537}
6538testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
6539 var BSC_ConnHdlr vc_conn;
6540 f_init();
6541 f_vty_config(MSCVTY, "network", "authentication required");
6542 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
6543
6544 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
6545 vc_conn.done;
6546}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006547
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006548friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
6549 f_init_handler(pars);
6550 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6551
6552 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
6553 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
6554 * will cause a use-after-free after that event dispatch. */
6555 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
6556 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
6557 cpars.rtp_sdp_format := "FOO/8000";
6558 cpars.expect_release := true;
6559
6560 f_perform_lu();
6561 f_mo_call_establish(cpars);
6562}
6563testcase TC_invalid_mgcp_crash() runs on MTC_CT {
6564 var BSC_ConnHdlr vc_conn;
6565 f_init();
6566
6567 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
6568 vc_conn.done;
6569}
6570
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006571friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
6572runs on BSC_ConnHdlr {
6573 pars.tmsi := 'FFFFFFFF'O;
6574 f_init_handler(pars);
6575
6576 f_create_gsup_expect(hex2str(g_pars.imsi));
6577
6578 /* Initiate Location Updating using an unknown TMSI */
6579 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
6580
6581 /* Expect an Identity Request, send response with no identity */
6582 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
6583 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
6584 lengthIndicator := 1,
6585 mobileIdentityV := {
6586 typeOfIdentity := '000'B,
6587 oddEvenInd_identity := {
6588 no_identity := {
6589 oddevenIndicator := '0'B,
6590 fillerDigits := '00000'H
6591 }
6592 }
6593 }
6594 })));
6595
6596 f_expect_lu_reject();
6597 f_expect_clear();
6598}
6599testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
6600 var BSC_ConnHdlr vc_conn;
6601
6602 f_init();
6603
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006604 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7, verify_cell_id := false);
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006605 vc_conn.done;
6606}
6607
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006608/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6609 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6610 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6611friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6612runs on BSC_ConnHdlr {
6613 var charstring imsi := hex2str(pars.imsi);
6614
6615 f_init_handler(pars);
6616
6617 /* Perform location update */
6618 f_perform_lu();
6619
6620 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6621 f_create_gsup_expect(hex2str(g_pars.imsi));
6622
6623 /* Initiate paging procedure from the VTY */
6624 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6625 f_expect_paging();
6626
6627 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6628 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6629
6630 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6631 f_establish_fully(EST_TYPE_PAG_RESP);
6632
6633 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6634 * In this case we do not send anything and just wait for a Clear Command. */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006635 f_expect_clear(verify_vlr_cell_id := false);
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006636}
6637testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6638 var BSC_ConnHdlr vc_conn;
6639
6640 f_init();
6641
6642 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6643 vc_conn.done;
6644}
6645
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006646const charstring REEST_LOST_CONNECTION := "REEST_LOST_CONNECTION";
6647const charstring REEST_CLEARED := "REEST_CLEARED";
6648
6649friend function f_tc_call_re_establishment_1(charstring id, BSC_ConnHdlrPars pars)
6650 runs on BSC_ConnHdlr {
6651 f_init_handler(pars, t_guard := 30.0);
6652
6653 f_perform_lu();
6654
6655 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
6656 f_mo_call_establish(cpars);
6657 f_sleep(3.0);
6658 COORD.send(REEST_LOST_CONNECTION);
6659 COORD.send(cpars);
6660 f_expect_clear(verify_vlr_cell_id := false);
6661 COORD.send(REEST_CLEARED);
6662}
6663
6664friend function f_tc_call_re_establishment_2(charstring id, BSC_ConnHdlrPars pars)
6665 runs on BSC_ConnHdlr {
6666 f_init_handler(pars, t_guard := 30.0);
6667 var CallParameters cpars;
6668
6669 COORD.receive(REEST_LOST_CONNECTION);
6670 COORD.receive(tr_CallParams) -> value cpars;
6671
6672 f_gsup_change_connhdlr(hex2str(g_pars.imsi));
6673 f_create_smpp_expect(hex2str(pars.msisdn));
6674
6675 /* The MS has lost the first channel and decides to show up on a new conn (on a nearby neighbor cell) to ask for
6676 * CM Re-Establishment. Send a Complete Layer 3 to osmo-msc with a CM Re-Establishment Request. */
6677 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
6678 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REESTABL_REQ(mi));
6679 f_cl3_or_initial_ue(l3_info);
6680
6681 /* At this point the other test component should receive the Clear Command for the first A connection. */
6682
6683 /* This new connection continues with Authentication... */
6684 f_mm_common();
6685
6686 /* ...and with Assignment of a voice channel. */
6687 var template BSSMAP_IE_AoIP_TransportLayerAddress tla_ass :=
6688 f_tr_BSSMAP_IE_AoIP_TLA(cpars.mgw_conn_1.mgw_rtp_ip, ?);
6689 BSSAP.receive(tr_BSSMAP_AssignmentReq(omit, tla_ass));
6690 /* By this Assignment Request, the CM Re-Establishment Request is implicitly accepted. */
6691
6692 /* Send Assignment Complete from BSC */
6693 var template BSSMAP_IE_AoIP_TransportLayerAddress tla;
6694 tla := f_ts_BSSMAP_IE_AoIP_TLA(cpars.bss_rtp_ip, cpars.bss_rtp_port);
6695 var BSSMAP_IE_SpeechCodec codec;
6696 codec := valueof(ts_BSSMAP_IE_SpeechCodec({ts_CodecFR}));
6697
6698 /* Make really sure the other component is done with its MGCP */
6699 COORD.receive(REEST_CLEARED);
6700
6701 /* Transfer state for this call over to this test component so we can resolve MNCC and MGCP in this function. */
6702 f_mncc_change_connhdlr(cpars.mncc_callref);
6703 f_mgcp_change_connhdlr(cpars.mgcp_ep);
6704
6705 /* osmo-msc may redirect the MGW endpoint to the newly allocated channel.
6706 * Apparently osmo-msc currently also sends an MDCX to the CN side, just repeating the same configuration that
6707 * is already in use. This test accepts any number of or even lack of MDCX. */
6708 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
6709
6710 BSSAP.send(ts_BSSMAP_AssignmentComplete(omit, tla, codec));
6711 /* The call has been fully re-established.
6712 * Let a bit of time pass before hanging up, for everything to settle. */
6713 f_sleep(3.0);
6714
6715 deactivate(ack_mdcx);
6716
6717 /* Hang up the call and clear the new, second A connection */
6718 var default ack_dlcx := activate(as_mgcp_ack_all_dlcx(cpars));
6719
6720 /* CC release. This is the proper MS initiated release sequence as shown by
6721 * https://git.osmocom.org/osmo-msc/tree/doc/sequence_charts/voice_call_full.msc?id=e53ecde83e4fb2470209e818e9ad76a2d6a19190
6722 * f_call_hangup() seems a bit mixed up, so here a "proper" sequence. Fix of f_call_hangup() pending. */
6723 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_DISC(cpars.transaction_id, '0'B, '0000000'B)));
6724 MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref));
6725 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
6726 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
6727 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, '0'B)));
6728 MNCC.receive(tr_MNCC_REL_cnf(cpars.mncc_callref, cause := *));
6729
6730 /* BSSAP clear */
6731 interleave {
6732 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
6733 BSSAP.send(ts_BSSMAP_ClearComplete);
6734 }
6735 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND);
6736 }
6737
6738 f_sleep(1.0);
6739 deactivate(ack_dlcx);
6740}
6741
6742testcase TC_call_re_establishment() runs on MTC_CT {
6743 var BSC_ConnHdlr vc_conn1;
6744 var BSC_ConnHdlr vc_conn2;
6745 f_init();
6746
6747 var BSC_ConnHdlrPars pars1 := f_init_pars(91);
6748 var BSC_ConnHdlrPars pars2 := pars1;
6749
6750 vc_conn1 := f_start_handler_create(pars1);
6751 vc_conn2 := f_start_handler_create(pars2);
6752 connect(vc_conn1:COORD, vc_conn2:COORD);
6753 f_start_handler_run(vc_conn1, refers(f_tc_call_re_establishment_1), pars1);
6754 f_start_handler_run(vc_conn2, refers(f_tc_call_re_establishment_2), pars2);
6755 vc_conn1.done;
6756 vc_conn2.done;
6757}
6758
Neels Hofmeyra9b2dcf2021-07-28 00:57:58 +02006759testcase TC_call_re_establishment_auth() runs on MTC_CT {
6760 var BSC_ConnHdlr vc_conn1;
6761 var BSC_ConnHdlr vc_conn2;
6762 f_init();
6763
6764 f_vty_config(MSCVTY, "network", "authentication required");
6765
6766 var BSC_ConnHdlrPars pars1 := f_init_pars(92);
6767 pars1.net.expect_auth := true;
6768 var BSC_ConnHdlrPars pars2 := pars1;
6769
6770 vc_conn1 := f_start_handler_create(pars1);
6771 vc_conn2 := f_start_handler_create(pars2);
6772 connect(vc_conn1:COORD, vc_conn2:COORD);
6773 f_start_handler_run(vc_conn1, refers(f_tc_call_re_establishment_1), pars1);
6774 f_start_handler_run(vc_conn2, refers(f_tc_call_re_establishment_2), pars2);
6775 vc_conn1.done;
6776 vc_conn2.done;
6777}
6778
Neels Hofmeyr48e4d7d2021-07-28 00:57:58 +02006779testcase TC_call_re_establishment_ciph() runs on MTC_CT {
6780 var BSC_ConnHdlr vc_conn1;
6781 var BSC_ConnHdlr vc_conn2;
6782 f_init();
6783
6784 f_vty_config(MSCVTY, "network", "authentication required");
6785 f_vty_config(MSCVTY, "network", "encryption a5 3");
6786
6787 var BSC_ConnHdlrPars pars1 := f_init_pars(92);
6788 pars1.net.expect_auth := true;
6789 pars1.net.expect_ciph := true;
6790 pars1.net.kc_support := '08'O; /* A5/3 only */
6791 var BSC_ConnHdlrPars pars2 := pars1;
6792
6793 vc_conn1 := f_start_handler_create(pars1);
6794 vc_conn2 := f_start_handler_create(pars2);
6795 connect(vc_conn1:COORD, vc_conn2:COORD);
6796 f_start_handler_run(vc_conn1, refers(f_tc_call_re_establishment_1), pars1);
6797 f_start_handler_run(vc_conn2, refers(f_tc_call_re_establishment_2), pars2);
6798 vc_conn1.done;
6799 vc_conn2.done;
6800}
6801
Harald Weltef6dd64d2017-11-19 12:09:51 +01006802control {
Philipp Maier328d1662018-03-07 10:40:27 +01006803 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006804 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01006805 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006806 execute( TC_lu_imsi_reject() );
6807 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01006808 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02006809 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01006810 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01006811 execute( TC_cmserv_imsi_unknown() );
Neels Hofmeyr13737fb2020-08-19 13:16:14 +00006812 execute( TC_cmserv_tmsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01006813 execute( TC_lu_and_mo_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006814 execute( TC_lu_and_mo_call_ipv6() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01006815 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01006816 execute( TC_lu_auth_sai_timeout() );
6817 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006818 execute( TC_lu_clear_request() );
Vadim Yanitskiy109e7552021-02-05 05:36:02 +01006819 execute( TC_mo_call_clear_request() );
6820 execute( TC_mt_call_clear_request() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006821 execute( TC_lu_disconnect() );
6822 execute( TC_lu_by_imei() );
6823 execute( TC_lu_by_tmsi_noauth_unknown() );
Neels Hofmeyrfc06c732020-08-19 12:52:28 +00006824 execute( TC_attached_imsi_lu_unknown_tmsi() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006825 execute( TC_imsi_detach_by_imsi() );
6826 execute( TC_imsi_detach_by_tmsi() );
6827 execute( TC_imsi_detach_by_imei() );
6828 execute( TC_emerg_call_imei_reject() );
6829 execute( TC_emerg_call_imsi() );
6830 execute( TC_cm_serv_req_vgcs_reject() );
6831 execute( TC_cm_serv_req_vbs_reject() );
6832 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01006833 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01006834 execute( TC_lu_auth_2G_fail() );
6835 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
6836 execute( TC_cl3_no_payload() );
6837 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01006838 execute( TC_establish_and_nothing() );
6839 execute( TC_mo_setup_and_nothing() );
6840 execute( TC_mo_crcx_ran_timeout() );
6841 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01006842 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01006843 execute( TC_mo_setup_and_dtmf_dup() );
Vadim Yanitskiyb56701e2021-02-05 01:54:07 +01006844 execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01006845 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01006846 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
6847 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
6848 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01006849 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01006850 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
6851 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Eric Wild26f4a622021-05-17 15:27:05 +02006852 execute( TC_lu_imsi_auth_tmsi_encr_0134_1() );
6853 execute( TC_lu_imsi_auth_tmsi_encr_0134_34() );
6854 execute( TC_lu_imsi_auth_tmsi_encr_0134_34_no_cm3() );
6855
Philipp Maier94f3f1b2018-03-15 18:54:13 +01006856 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01006857 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02006858 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006859
6860 execute( TC_lu_and_mt_call() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006861 execute( TC_lu_and_mt_call_ipv6() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006862 execute( TC_lu_and_mt_call_already_paging() );
Pau Espin Pedrol9a732a42020-09-15 15:56:33 +02006863 execute( TC_lu_and_mt_call_osmux() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006864
Harald Weltef45efeb2018-04-09 18:19:24 +02006865 execute( TC_lu_and_mo_sms() );
6866 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006867 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01006868 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02006869 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02006870 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07006871 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02006872 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02006873
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006874 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07006875 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07006876 execute( TC_gsup_mt_sms_ack() );
6877 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07006878 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07006879 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07006880 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006881
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006882 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006883 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006884 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006885 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07006886 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07006887 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07006888
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006889 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07006890 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07006891 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07006892 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07006893 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006894
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01006895 execute( TC_multi_lu_and_mo_ussd() );
6896 execute( TC_multi_lu_and_mt_ussd() );
6897
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006898 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01006899 execute( TC_cipher_complete_1_without_cipher() );
6900 execute( TC_cipher_complete_3_without_cipher() );
6901 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02006902 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006903
Harald Welte4263c522018-12-06 11:56:27 +01006904 execute( TC_sgsap_reset() );
6905 execute( TC_sgsap_lu() );
6906 execute( TC_sgsap_lu_imsi_reject() );
6907 execute( TC_sgsap_lu_and_nothing() );
6908 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01006909 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01006910 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01006911 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01006912 execute( TC_sgsap_paging_rej() );
6913 execute( TC_sgsap_paging_subscr_rej() );
6914 execute( TC_sgsap_paging_ue_unr() );
6915 execute( TC_sgsap_paging_and_nothing() );
6916 execute( TC_sgsap_paging_and_lu() );
6917 execute( TC_sgsap_mt_sms() );
6918 execute( TC_sgsap_mo_sms() );
6919 execute( TC_sgsap_mt_sms_and_nothing() );
6920 execute( TC_sgsap_mt_sms_and_reject() );
6921 execute( TC_sgsap_unexp_ud() );
6922 execute( TC_sgsap_unsol_ud() );
6923 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
6924 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02006925 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01006926
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006927 execute( TC_ho_inter_bsc_unknown_cell() );
6928 execute( TC_ho_inter_bsc() );
Neels Hofmeyr0d841d92021-06-21 22:27:21 +02006929 execute( TC_ho_inter_bsc_a5_1() );
6930 execute( TC_ho_inter_bsc_a5_3() );
6931 execute( TC_ho_inter_bsc_a5_4() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006932 execute( TC_ho_inter_bsc_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006933
6934 execute( TC_ho_inter_msc_out() );
Neels Hofmeyr666d39a2021-06-21 22:27:21 +02006935 execute( TC_ho_inter_msc_out_a5_1() );
6936 execute( TC_ho_inter_msc_out_a5_3() );
6937 execute( TC_ho_inter_msc_out_a5_4() );
Pau Espin Pedrol833174e2020-09-03 16:46:02 +02006938 execute( TC_ho_inter_msc_out_ipv6() );
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006939
Oliver Smith1d118ff2019-07-03 10:57:35 +02006940 execute( TC_lu_imsi_auth_tmsi_check_imei() );
6941 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
6942 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
6943 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
6944 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
6945 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
6946 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
6947 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
6948 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
6949 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
6950 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
6951 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01006952 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Pau Espin Pedrol609f1d62020-09-15 16:01:55 +02006953
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02006954 execute( TC_mo_cc_bssmap_clear() );
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006955 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006956 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006957 execute( TC_lu_and_expire_while_paging() );
Pau Espin Pedrol174fac22021-02-26 13:20:10 +01006958 execute( TC_paging_response_imsi_unknown() );
6959 execute( TC_paging_response_tmsi_unknown() );
Neels Hofmeyr4f099b42021-07-27 03:45:26 +02006960
6961 execute( TC_call_re_establishment() );
Neels Hofmeyra9b2dcf2021-07-28 00:57:58 +02006962 execute( TC_call_re_establishment_auth() );
Neels Hofmeyr48e4d7d2021-07-28 00:57:58 +02006963 execute( TC_call_re_establishment_ciph() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01006964}
6965
6966
6967}