blob: a18b9b0684110810edd9bf2c906ac0f6d3e2dbd4 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
3import from General_Types all;
4import from Osmocom_Types all;
5
6import from M3UA_Types all;
7import from M3UA_Emulation all;
8
9import from MTP3asp_Types all;
10import from MTP3asp_PortType all;
11
12import from SCCPasp_Types all;
13import from SCCP_Types all;
14import from SCCP_Emulation all;
15
16import from SCTPasp_Types all;
17import from SCTPasp_PortType all;
18
Harald Weltea49e36e2018-01-21 19:29:33 +010019import from Osmocom_CTRL_Functions all;
20import from Osmocom_CTRL_Types all;
21import from Osmocom_CTRL_Adapter all;
22
Harald Welte3ca1c902018-01-24 18:51:27 +010023import from TELNETasp_PortType all;
24import from Osmocom_VTY_Functions all;
25
Harald Weltea49e36e2018-01-21 19:29:33 +010026import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010027import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010028
Harald Welte4aa970c2018-01-26 10:38:09 +010029import from MGCP_Emulation all;
30import from MGCP_Types all;
31import from MGCP_Templates all;
32import from SDP_Types all;
33
Harald Weltea49e36e2018-01-21 19:29:33 +010034import from GSUP_Emulation all;
35import from GSUP_Types all;
36import from IPA_Emulation all;
37
Harald Weltef6dd64d2017-11-19 12:09:51 +010038import from BSSAP_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010039import from BSSAP_Adapter all;
40import from BSSAP_CodecPort all;
41import from BSSMAP_Templates all;
42import from BSSMAP_Emulation all;
43import from BSC_ConnectionHandler all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010044
Harald Weltea49e36e2018-01-21 19:29:33 +010045import from MobileL3_Types all;
46import from MobileL3_CommonIE_Types all;
47import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010048import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010049
Harald Weltef640a012018-04-14 17:49:21 +020050import from SMPP_Types all;
51import from SMPP_Templates all;
52import from SMPP_Emulation all;
53
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070054import from SS_Types all;
55import from SS_Templates all;
56import from USSD_Helpers all;
57
Philipp Maier75932982018-03-27 14:52:35 +020058const integer NUM_BSC := 2;
59type record of BSSAP_Configuration BSSAP_Configurations;
Harald Weltef6dd64d2017-11-19 12:09:51 +010060
Harald Weltea4ca4462018-02-09 00:17:14 +010061type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010062 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010063
Philipp Maier75932982018-03-27 14:52:35 +020064 var BSSAP_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010065
Harald Weltea49e36e2018-01-21 19:29:33 +010066 /* no 'adapter_CT' for MNCC or GSUP */
67 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010068 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010069 var GSUP_Emulation_CT vc_GSUP;
70 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020071 var SMPP_Emulation_CT vc_SMPP;
Harald Weltea49e36e2018-01-21 19:29:33 +010072
73 /* only to get events from IPA underneath GSUP */
74 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +010075 /* VTY to MSC */
76 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +010077
78 /* A port to directly send BSSAP messages. This port is used for
79 * tests that require low level access to sen arbitrary BSSAP
80 * messages. Run f_init_bssap_direct() to connect and initialize */
81 port BSSAP_CODEC_PT BSSAP_DIRECT;
82
83 /* When BSSAP messages are directly sent, then the connection
84 * handler is not active, which means that also no guard timer is
85 * set up. The following timer will serve as a replacement */
86 timer Tguard_direct := 60.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +010087}
88
89modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +010090 /* remote parameters of IUT */
91 charstring mp_msc_ip := "127.0.0.1";
92 integer mp_msc_ctrl_port := 4255;
93 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +010094
Harald Weltea49e36e2018-01-21 19:29:33 +010095 /* local parameters of emulated HLR */
96 charstring mp_hlr_ip := "127.0.0.1";
97 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +010098 charstring mp_mgw_ip := "127.0.0.1";
99 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100100
Harald Weltea49e36e2018-01-21 19:29:33 +0100101 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100102
Harald Weltef640a012018-04-14 17:49:21 +0200103 integer mp_msc_smpp_port := 2775;
104 charstring mp_smpp_system_id := "msc_tester";
105 charstring mp_smpp_password := "osmocom1";
106
Philipp Maier75932982018-03-27 14:52:35 +0200107 BSSAP_Configurations mp_bssap_cfg := {
108 {
109 sccp_service_type := "mtp3_itu",
110 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
111 own_pc := 185,
112 own_ssn := 254,
113 peer_pc := 187,
114 peer_ssn := 254,
115 sio := '83'O,
116 rctx := 0
117 },
118 {
119 sccp_service_type := "mtp3_itu",
120 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
121 own_pc := 186,
122 own_ssn := 254,
123 peer_pc := 187,
124 peer_ssn := 254,
125 sio := '83'O,
126 rctx := 1
127 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100128 };
Harald Weltef6dd64d2017-11-19 12:09:51 +0100129}
130
Philipp Maier328d1662018-03-07 10:40:27 +0100131/* altstep for the global guard timer (only used when BSSAP_DIRECT
132 * is used for communication */
133private altstep as_Tguard_direct() runs on MTC_CT {
134 [] Tguard_direct.timeout {
135 setverdict(fail, "Tguard timeout");
136 self.stop;
137 }
138}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100139
Harald Weltef640a012018-04-14 17:49:21 +0200140function f_init_smpp(charstring id) runs on MTC_CT {
141 id := id & "-SMPP";
142 var EsmePars pars := {
143 mode := MODE_TRANSCEIVER,
144 bind := {
145 system_id := mp_smpp_system_id,
146 password := mp_smpp_password,
147 system_type := "MSC_Tests",
148 interface_version := hex2int('34'H),
149 addr_ton := unknown,
150 addr_npi := unknown,
151 address_range := ""
152 },
153 esme_role := true
154 }
155
156 vc_SMPP := SMPP_Emulation_CT.create(id);
157 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
158 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", -1));
159}
160
161
Harald Weltea49e36e2018-01-21 19:29:33 +0100162function f_init_mncc(charstring id) runs on MTC_CT {
163 id := id & "-MNCC";
164 var MnccOps ops := {
165 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
166 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
167 }
168
169 vc_MNCC := MNCC_Emulation_CT.create(id);
170 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
171 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100172}
173
Harald Welte4aa970c2018-01-26 10:38:09 +0100174function f_init_mgcp(charstring id) runs on MTC_CT {
175 id := id & "-MGCP";
176 var MGCPOps ops := {
177 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
178 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
179 }
180 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100181 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100182 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100183 mgw_ip := mp_mgw_ip,
184 mgw_udp_port := mp_mgw_port
Harald Welte4aa970c2018-01-26 10:38:09 +0100185 }
186
187 vc_MGCP := MGCP_Emulation_CT.create(id);
188 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
189 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
190}
191
Harald Weltea49e36e2018-01-21 19:29:33 +0100192function f_init_gsup(charstring id) runs on MTC_CT {
193 id := id & "-GSUP";
194 var GsupOps ops := {
195 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
196 }
197
198 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
199 vc_GSUP := GSUP_Emulation_CT.create(id);
200
201 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
202 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
203 /* we use this hack to get events like ASP_IPA_EVENT_UP */
204 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
205
206 vc_GSUP.start(GSUP_Emulation.main(ops, id));
207 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
208
209 /* wait for incoming connection to GSUP port before proceeding */
210 timer T := 10.0;
211 T.start;
212 alt {
213 [] GSUP_IPA_EVENT.receive(t_ASP_IPA_EVT_UD(ASP_IPA_EVENT_UP)) { }
214 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100215 setverdict(fail, "No connection to GSUP Port");
Harald Weltea49e36e2018-01-21 19:29:33 +0100216 self.stop
217 }
218 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100219}
220
Philipp Maier75932982018-03-27 14:52:35 +0200221function f_init(integer num_bsc := 1) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100222
223 if (g_initialized == true) {
224 return;
225 }
226 g_initialized := true;
227
Philipp Maier75932982018-03-27 14:52:35 +0200228 if (num_bsc > NUM_BSC) {
229 setverdict(fail, "excess number of BSC instances requested");
230 }
231
232 for (var integer i := 0; i < num_bsc; i := i + 1) {
233 if (isbound(mp_bssap_cfg[i])) {
Philipp Maierdefd9482018-05-16 16:44:37 +0200234 f_bssap_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), BSC_BssmapOps);
Harald Welted5833a82018-05-27 16:52:56 +0200235 f_bssap_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200236 } else {
237 setverdict(fail, "missing BSSAP configuration");
238 }
239 }
240
Harald Weltea49e36e2018-01-21 19:29:33 +0100241 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
242 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100243 f_init_mgcp("MSC_Test");
Harald Weltea49e36e2018-01-21 19:29:33 +0100244 f_init_gsup("MSC_Test");
Harald Weltef640a012018-04-14 17:49:21 +0200245 f_init_smpp("MSC_Test");
Harald Welte3ca1c902018-01-24 18:51:27 +0100246
247 map(self:MSCVTY, system:MSCVTY);
248 f_vty_set_prompts(MSCVTY);
249 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100250
251 /* set some defaults */
252 f_vty_config(MSCVTY, "network", "authentication optional");
253 f_vty_config(MSCVTY, "msc", "assign-tmsi");
254 f_vty_config(MSCVTY, "network", "encryption a5 0");
Harald Weltef6dd64d2017-11-19 12:09:51 +0100255}
256
Philipp Maier328d1662018-03-07 10:40:27 +0100257/* Initialize for a direct connection to BSSAP. This function is an alternative
258 * to f_init() when the high level functions of the BSC_ConnectionHandler are
259 * not needed. */
260function f_init_bssap_direct() runs on MTC_CT {
Philipp Maier75932982018-03-27 14:52:35 +0200261 f_bssap_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
262 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100263
264 /* Start guard timer and activate it as default */
265 Tguard_direct.start
266 activate(as_Tguard_direct());
267}
268
Harald Weltef6dd64d2017-11-19 12:09:51 +0100269template PDU_BSSAP ts_BSSAP_BSSMAP := {
270 discriminator := '0'B,
271 spare := '0000000'B,
272 dlci := omit,
273 lengthIndicator := 0, /* overwritten by codec */
274 pdu := ?
275}
276
277template PDU_BSSAP tr_BSSAP_BSSMAP := {
278 discriminator := '0'B,
279 spare := '0000000'B,
280 dlci := omit,
281 lengthIndicator := ?,
282 pdu := {
283 bssmap := ?
284 }
285}
286
287
288type integer BssmapCause;
289
290template (value) BSSMAP_IE_Cause ts_BSSMAP_IE_Cause(BssmapCause val) := {
291 elementIdentifier := '04'O,
292 lengthIndicator := 0,
293 causeValue := int2bit(val, 7),
294 extensionCauseValue := '0'B,
295 spare1 := omit
296}
297
298template (value) PDU_BSSAP ts_BSSMAP_Reset(BssmapCause cause) modifies ts_BSSAP_BSSMAP := {
299 pdu := {
300 bssmap := {
301 reset := {
302 messageType := '30'O,
303 cause := ts_BSSMAP_IE_Cause(cause),
304 a_InterfaceSelectorForReset := omit
305 }
306 }
307 }
308}
309
310template (value) PDU_BSSAP ts_BSSMAP_ResetAck modifies ts_BSSAP_BSSMAP := {
311 pdu := {
312 bssmap := {
313 resetAck := {
314 messageType := '31'O,
315 a_InterfaceSelectorForReset := omit
316 }
317 }
318 }
319}
320
321template PDU_BSSAP tr_BSSMAP_ResetAck modifies tr_BSSAP_BSSMAP := {
322 pdu := {
323 bssmap := {
324 resetAck := {
325 messageType := '31'O,
326 a_InterfaceSelectorForReset := *
327 }
328 }
329 }
330}
331
332template BSSMAP_IE_CellIdentifier ts_BSSMAP_IE_CellID := {
333 elementIdentifier := '05'O,
334 lengthIndicator := 0,
335 cellIdentifierDiscriminator := '0000'B,
336 spare1_4 := '0000'B,
337 cellIdentification := ?
338}
339
340type uint16_t BssmapLAC;
341type uint16_t BssmapCI;
342
343/*
344template BSSMAP_IE_CellIdentifier ts_CellId_CGI(mcc, mnc, lac, ci)
345modifies ts_BSSMAP_IE_CellID := {
346 cellIdentification := {
347 cI_LAC_CGI := {
348 mnc_mcc := FIXME,
349 lac := int2oct(lac, 2),
350 ci := int2oct(ci, 2)
351 }
352 }
353}
354*/
355
356template BSSMAP_IE_CellIdentifier ts_CellID_LAC_CI(BssmapLAC lac, BssmapCI ci)
357modifies ts_BSSMAP_IE_CellID := {
358 cellIdentification := {
359 cI_LAC_CI := {
360 lac := int2oct(lac, 2),
361 ci := int2oct(ci, 2)
362 }
363 }
364}
365
366template BSSMAP_IE_CellIdentifier ts_CellId_CI(BssmapCI ci)
367modifies ts_BSSMAP_IE_CellID := {
368 cellIdentification := {
369 cI_CI := int2oct(ci, 2)
370 }
371}
372
373template BSSMAP_IE_CellIdentifier ts_CellId_none
374modifies ts_BSSMAP_IE_CellID := {
375 cellIdentification := {
376 cI_noCell := ''O
377 }
378}
379
380
381template BSSMAP_IE_Layer3Information ts_BSSMAP_IE_L3Info(octetstring l3info) := {
382 elementIdentifier := '17'O,
383 lengthIndicator := 0,
384 layer3info := l3info
385}
386
387template PDU_BSSAP ts_BSSMAP_ComplL3(BSSMAP_IE_CellIdentifier cell_id, octetstring l3_info)
388modifies ts_BSSAP_BSSMAP := {
389 pdu := {
390 bssmap := {
391 completeLayer3Information := {
392 messageType := '57'O,
393 cellIdentifier := cell_id,
394 layer3Information := ts_BSSMAP_IE_L3Info(l3_info),
395 chosenChannel := omit,
396 lSAIdentifier := omit,
397 aPDU := omit,
398 codecList := omit,
399 redirectAttemptFlag := omit,
400 sendSequenceNumber := omit,
401 iMSI := omit
402 }
403 }
404 }
405}
406
407template PDU_BSSAP ts_BSSMAP_HandoReq(BssmapCause cause, BSSMAP_IE_CellIdentifierList cid_list)
408modifies ts_BSSAP_BSSMAP := {
409 pdu := {
410 bssmap := {
411 handoverRequired := {
412 messageType := '11'O,
413 cause := ts_BSSMAP_IE_Cause(cause),
414 responseRequest := omit,
415 cellIdentifierList := cid_list,
416 circuitPoolList := omit,
417 currentChannelType1 := omit,
418 speechVersion := omit,
419 queueingIndicator := omit,
420 oldToNewBSSInfo := omit,
421 sourceToTargetRNCTransparentInfo := omit,
422 sourceToTargetRNCTransparentInfoCDMA := omit,
423 gERANClassmark := omit,
424 talkerPriority := omit,
425 speechCodec := omit,
426 cSG_Identifier := omit
427 }
428 }
429 }
430}
431
Harald Weltea49e36e2018-01-21 19:29:33 +0100432type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100433
Harald Weltea49e36e2018-01-21 19:29:33 +0100434/* FIXME: move into BSC_ConnectionHandler? */
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100435function f_init_pars(integer imsi_suffix) runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100436 var BSC_ConnHdlrNetworkPars net_pars := {
437 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
438 expect_tmsi := true,
439 expect_auth := false,
440 expect_ciph := false
441 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100442 var BSC_ConnHdlrPars pars := {
Philipp Maier75932982018-03-27 14:52:35 +0200443 sccp_addr_own := g_bssap[0].sccp_addr_own,
444 sccp_addr_peer := g_bssap[0].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100445 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100446 imei := f_gen_imei(imsi_suffix),
447 imsi := f_gen_imsi(imsi_suffix),
448 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100449 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100450 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100451 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100452 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100453 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100454 net := net_pars,
455 send_early_cm := true
Harald Weltea49e36e2018-01-21 19:29:33 +0100456 };
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100457 return pars;
458}
459
460function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars) runs on MTC_CT return BSC_ConnHdlr {
461 var BSC_ConnHdlr vc_conn;
462 var charstring id := testcasename();
Harald Weltea49e36e2018-01-21 19:29:33 +0100463
464 vc_conn := BSC_ConnHdlr.create(id);
465 /* BSSMAP part / A interface */
Philipp Maier75932982018-03-27 14:52:35 +0200466 connect(vc_conn:BSSAP, g_bssap[0].vc_BSSMAP:CLIENT);
467 connect(vc_conn:BSSAP_PROC, g_bssap[0].vc_BSSMAP:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100468 /* MNCC part */
469 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
470 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100471 /* MGCP part */
472 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
473 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100474 /* GSUP part */
475 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
476 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
Harald Weltef640a012018-04-14 17:49:21 +0200477 /* SMPP part */
478 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
479 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100480
Harald Weltea10db902018-01-27 12:44:49 +0100481 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
482 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100483 vc_conn.start(derefers(fn)(id, pars));
484 return vc_conn;
485}
486
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100487function f_start_handler(void_fn fn, integer imsi_suffix) runs on MTC_CT return BSC_ConnHdlr {
488 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix));
489}
490
Harald Weltea49e36e2018-01-21 19:29:33 +0100491private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100492 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100493 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100494}
Harald Weltea49e36e2018-01-21 19:29:33 +0100495testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
496 var BSC_ConnHdlr vc_conn;
497 f_init();
498
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100499 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100500 vc_conn.done;
501}
502
503private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100504 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100505 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100506 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100507}
Harald Weltea49e36e2018-01-21 19:29:33 +0100508testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
509 var BSC_ConnHdlr vc_conn;
510 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100511 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100512
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100513 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100514 vc_conn.done;
515}
516
517/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
518private function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100519 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100520 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
521
522 f_create_gsup_expect(hex2str(g_pars.imsi));
523 f_bssap_compl_l3(l3_lu);
524 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
525 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
526 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100527 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
528 f_expect_clear();
529 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100530 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
531 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
532 self.stop;
533 }
534 }
Harald Welte1ddc7162018-01-27 14:25:46 +0100535 f_expect_clear();
Harald Weltea49e36e2018-01-21 19:29:33 +0100536}
537testcase TC_lu_imsi_reject() runs on MTC_CT {
538 var BSC_ConnHdlr vc_conn;
539 f_init();
540
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100541 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3);
Harald Weltea49e36e2018-01-21 19:29:33 +0100542 vc_conn.done;
543}
544
545/* Do LU by IMSI, timeout on GSUP */
546private function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100547 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100548 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
549
550 f_create_gsup_expect(hex2str(g_pars.imsi));
551 f_bssap_compl_l3(l3_lu);
552 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
553 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
554 alt {
555 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100556 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
557 f_expect_clear();
558 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100559 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
560 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
561 self.stop;
562 }
563 }
Harald Welte1ddc7162018-01-27 14:25:46 +0100564 f_expect_clear();
Harald Weltea49e36e2018-01-21 19:29:33 +0100565}
566testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
567 var BSC_ConnHdlr vc_conn;
568 f_init();
569
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100570 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4);
Harald Weltea49e36e2018-01-21 19:29:33 +0100571 vc_conn.done;
572}
573
Harald Welte7b1b2812018-01-22 21:23:06 +0100574private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100575 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100576 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100577 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100578}
579testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
580 var BSC_ConnHdlr vc_conn;
581 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100582 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100583
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100584 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100585 vc_conn.done;
586}
587
Harald Weltea49e36e2018-01-21 19:29:33 +0100588
589/* Send CM SERVICE REQ for IMSI that has never performed LU before */
590private function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
591runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100592 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100593
594 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100595 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100596 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100597
598 f_create_gsup_expect(hex2str(g_pars.imsi));
599
600 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
601 f_bssap_compl_l3(l3_info);
602
603 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100604 T.start;
605 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100606 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
607 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
608 [] BSSAP.receive { setverdict(fail, "Received unexpected BSSAP"); }
609 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
610 setverdict(fail, "Unexpected GSUP UL REQ");
611 }
Daniel Willmann90829d62018-02-15 17:45:14 +0100612 [] T.timeout { setverdict(fail, "Timeout waiting for CM SERV REQ"); }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100613 }
614
Harald Welte1ddc7162018-01-27 14:25:46 +0100615 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100616}
Harald Weltea49e36e2018-01-21 19:29:33 +0100617testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
618 var BSC_ConnHdlr vc_conn;
619 f_init();
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100620 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6);
Harald Weltea49e36e2018-01-21 19:29:33 +0100621 vc_conn.done;
622}
623
Harald Welte2bb825f2018-01-22 11:31:18 +0100624private function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100625 f_init_handler(pars);
Harald Welteb71901a2018-01-26 19:16:05 +0100626 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
627 cpars.bss_rtp_port := 1110;
628 cpars.mgcp_connection_id_bss := '22222'H;
629 cpars.mgcp_connection_id_mss := '33333'H;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100630 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte2bb825f2018-01-22 11:31:18 +0100631
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100632 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100633 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100634}
635testcase TC_lu_and_mo_call() runs on MTC_CT {
636 var BSC_ConnHdlr vc_conn;
637 f_init();
638
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100639 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100640 vc_conn.done;
641}
642
643/* Test LU (with authentication enabled), where HLR times out sending SAI response */
644private function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100645 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100646
647 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
648 var PDU_DTAP_MT dtap_mt;
649
650 /* tell GSUP dispatcher to send this IMSI to us */
651 f_create_gsup_expect(hex2str(g_pars.imsi));
652
653 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
654 f_bssap_compl_l3(l3_lu);
655
656 /* Send Early Classmark, just for the fun of it */
657 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
658
659 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
660 /* The HLR would normally return an auth vector here, but we fail to do so. */
661
662 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100663 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100664}
665testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
666 var BSC_ConnHdlr vc_conn;
667 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100668 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100669
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100670 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8);
Harald Welte071ed732018-01-23 19:53:52 +0100671 vc_conn.done;
672}
673
674/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
675private function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100676 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100677
678 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
679 var PDU_DTAP_MT dtap_mt;
680
681 /* tell GSUP dispatcher to send this IMSI to us */
682 f_create_gsup_expect(hex2str(g_pars.imsi));
683
684 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
685 f_bssap_compl_l3(l3_lu);
686
687 /* Send Early Classmark, just for the fun of it */
688 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
689
690 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
691 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
692
693 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100694 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100695}
696testcase TC_lu_auth_sai_err() runs on MTC_CT {
697 var BSC_ConnHdlr vc_conn;
698 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100699 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100700
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100701 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9);
Harald Welte2bb825f2018-01-22 11:31:18 +0100702 vc_conn.done;
703}
Harald Weltea49e36e2018-01-21 19:29:33 +0100704
Harald Weltebc881782018-01-23 20:09:15 +0100705/* Test LU but BSC will send a clear request in the middle */
706private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100707 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100708
709 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
710 var PDU_DTAP_MT dtap_mt;
711
712 /* tell GSUP dispatcher to send this IMSI to us */
713 f_create_gsup_expect(hex2str(g_pars.imsi));
714
715 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
716 f_bssap_compl_l3(l3_lu);
717
718 /* Send Early Classmark, just for the fun of it */
719 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
720
721 f_sleep(1.0);
722 /* send clear request in the middle of the LU */
723 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200724 alt {
725 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
726 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
727 }
Harald Weltebc881782018-01-23 20:09:15 +0100728 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100729 alt {
730 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200731 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
732 setverdict(fail, "Got a second Clear Command, only one expected");
733 repeat;
734 }
Harald Welte89a32492018-01-27 19:07:28 +0100735 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
736 }
Harald Weltebc881782018-01-23 20:09:15 +0100737 setverdict(pass);
738}
739testcase TC_lu_clear_request() runs on MTC_CT {
740 var BSC_ConnHdlr vc_conn;
741 f_init();
742
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100743 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100744 vc_conn.done;
745}
746
Harald Welte66af9e62018-01-24 17:28:21 +0100747/* Test LU but BSC will send a clear request in the middle */
748private function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100749 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100750
751 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
752 var PDU_DTAP_MT dtap_mt;
753
754 /* tell GSUP dispatcher to send this IMSI to us */
755 f_create_gsup_expect(hex2str(g_pars.imsi));
756
757 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
758 f_bssap_compl_l3(l3_lu);
759
760 /* Send Early Classmark, just for the fun of it */
761 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
762
763 f_sleep(1.0);
764 /* send clear request in the middle of the LU */
765 BSSAP.send(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
766 setverdict(pass);
767}
768testcase TC_lu_disconnect() runs on MTC_CT {
769 var BSC_ConnHdlr vc_conn;
770 f_init();
771
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100772 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100773 vc_conn.done;
774}
775
776
Harald Welteba7b6d92018-01-23 21:32:34 +0100777/* Test LU but with illegal mobile identity type = IMEI */
778private function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100779 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100780
Harald Welte256571e2018-01-24 18:47:19 +0100781 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100782 var PDU_DTAP_MT dtap_mt;
783
784 /* tell GSUP dispatcher to send this IMSI to us */
785 f_create_gsup_expect(hex2str(g_pars.imsi));
786
787 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
788 f_bssap_compl_l3(l3_lu);
789
790 /* Send Early Classmark, just for the fun of it */
791 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
792 /* wait for LU reject, ignore any ID REQ */
793 alt {
794 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
795 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
796 }
797 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100798 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100799}
800testcase TC_lu_by_imei() runs on MTC_CT {
801 var BSC_ConnHdlr vc_conn;
802 f_init();
803
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100804 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12);
Harald Welteba7b6d92018-01-23 21:32:34 +0100805 vc_conn.done;
806}
807
808/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
809private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200810 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
811 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100812 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100813
814 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
815 var PDU_DTAP_MT dtap_mt;
816
817 /* tell GSUP dispatcher to send this IMSI to us */
818 f_create_gsup_expect(hex2str(g_pars.imsi));
819
820 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
821 f_bssap_compl_l3(l3_lu);
822
823 /* Send Early Classmark, just for the fun of it */
824 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
825
826 /* Wait for + respond to ID REQ (IMSI) */
827 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req('001'B)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200828 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100829 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
830
831 /* Expect MSC to do UpdateLocation to HLR; respond to it */
832 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
833 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
834 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
835 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
836
837 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100838 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
839 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
840 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100841 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
842 setverdict(fail, "Expected LU ACK, but received REJ");
843 }
844 }
845
846 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100847 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100848}
849testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
850 var BSC_ConnHdlr vc_conn;
851 f_init();
852
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100853 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100854 vc_conn.done;
855}
856
857
Harald Welte45164da2018-01-24 12:51:27 +0100858/* Test IMSI DETACH (MI=IMSI) */
859private function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100860 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100861
862 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
863
864 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
865 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
866
867 /* Send Early Classmark, just for the fun of it? */
868 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
869
870 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100871 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100872}
873testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
874 var BSC_ConnHdlr vc_conn;
875 f_init();
876
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100877 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14);
Harald Welte45164da2018-01-24 12:51:27 +0100878 vc_conn.done;
879}
880
881/* Test IMSI DETACH (MI=TMSI) */
882private function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100883 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100884
885 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
886
887 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
888 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
889
890 /* Send Early Classmark, just for the fun of it? */
891 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
892
893 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100894 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100895}
896testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
897 var BSC_ConnHdlr vc_conn;
898 f_init();
899
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100900 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15);
Harald Welte45164da2018-01-24 12:51:27 +0100901 vc_conn.done;
902}
903
904/* Test IMSI DETACH (MI=IMEI), which is illegal */
905private function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100906 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100907
Harald Welte256571e2018-01-24 18:47:19 +0100908 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +0100909
910 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
911 f_bssap_compl_l3(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
912
913 /* Send Early Classmark, just for the fun of it? */
914 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
915
916 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100917 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100918}
919testcase TC_imsi_detach_by_imei() runs on MTC_CT {
920 var BSC_ConnHdlr vc_conn;
921 f_init();
922
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100923 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16);
Harald Welte45164da2018-01-24 12:51:27 +0100924 vc_conn.done;
925}
926
927
928/* helper function for an emergency call. caller passes in mobile identity to use */
929private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +0100930 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
931 cpars.emergency := true;
Philipp Maierf1e02bb2018-03-15 16:30:00 +0100932 cpars.mgcp_ep := "rtpbridge/1@mgw";
Harald Welte45164da2018-01-24 12:51:27 +0100933
Harald Welte0bef21e2018-02-10 09:48:23 +0100934 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +0100935}
936
937/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
938private function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100939 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100940
Harald Welte256571e2018-01-24 18:47:19 +0100941 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100942 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Welte45164da2018-01-24 12:51:27 +0100943 f_bssap_compl_l3(l3_info);
944 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +0100945 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100946}
947testcase TC_emerg_call_imei_reject() runs on MTC_CT {
948 var BSC_ConnHdlr vc_conn;
949 f_init();
950
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100951 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17);
Harald Welte45164da2018-01-24 12:51:27 +0100952 vc_conn.done;
953}
954
Harald Welted5b91402018-01-24 18:48:16 +0100955/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Welte45164da2018-01-24 12:51:27 +0100956private function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100957 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100958 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100959 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +0100960 /* Then issue emergency call identified by IMSI */
961 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
962}
963testcase TC_emerg_call_imsi() runs on MTC_CT {
964 var BSC_ConnHdlr vc_conn;
965 f_init();
966
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100967 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +0100968 vc_conn.done;
969}
970
971/* CM Service Request for VGCS -> reject */
972private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100973 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100974
975 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100976 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +0100977
978 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100979 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Welte45164da2018-01-24 12:51:27 +0100980 f_bssap_compl_l3(l3_info);
981 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +0100982 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100983}
984testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
985 var BSC_ConnHdlr vc_conn;
986 f_init();
987
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100988 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +0100989 vc_conn.done;
990}
991
992/* CM Service Request for VBS -> reject */
993private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100994 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100995
996 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100997 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +0100998
999 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001000 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001001 f_bssap_compl_l3(l3_info);
1002 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001003 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001004}
1005testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1006 var BSC_ConnHdlr vc_conn;
1007 f_init();
1008
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001009 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001010 vc_conn.done;
1011}
1012
1013/* CM Service Request for LCS -> reject */
1014private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001015 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001016
1017 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001018 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001019
1020 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001021 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Welte45164da2018-01-24 12:51:27 +01001022 f_bssap_compl_l3(l3_info);
1023 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001024 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001025}
1026testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1027 var BSC_ConnHdlr vc_conn;
1028 f_init();
1029
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001030 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001031 vc_conn.done;
1032}
1033
Harald Welte0195ab12018-01-24 21:50:20 +01001034/* CM Re-Establishment Request */
1035private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001036 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001037
1038 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001039 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001040
1041 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1042 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
1043 f_bssap_compl_l3(l3_info);
1044 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001045 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001046}
1047testcase TC_cm_reest_req_reject() runs on MTC_CT {
1048 var BSC_ConnHdlr vc_conn;
1049 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001050
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001051 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001052 vc_conn.done;
1053}
1054
Harald Weltec638f4d2018-01-24 22:00:36 +01001055/* Test LU (with authentication enabled), with wrong response from MS */
1056private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001057 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001058
1059 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1060
1061 /* tell GSUP dispatcher to send this IMSI to us */
1062 f_create_gsup_expect(hex2str(g_pars.imsi));
1063
1064 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
1065 f_bssap_compl_l3(l3_lu);
1066
1067 /* Send Early Classmark, just for the fun of it */
1068 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1069
1070 var AuthVector vec := f_gen_auth_vec_2g();
1071 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1072 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1073 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1074
1075 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1076 /* Send back wrong auth response */
1077 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1078
1079 /* Expect GSUP AUTH FAIL REP to HLR */
1080 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1081
1082 /* Expect LU REJECT with Cause == Illegal MS */
1083 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001084 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001085}
1086testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1087 var BSC_ConnHdlr vc_conn;
1088 f_init();
1089 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001090
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001091 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23);
Harald Weltec638f4d2018-01-24 22:00:36 +01001092 vc_conn.done;
1093}
1094
Harald Weltede371492018-01-27 23:44:41 +01001095/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001096private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001097 pars.net.expect_auth := true;
1098 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001099 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001100 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001101}
1102testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1103 var BSC_ConnHdlr vc_conn;
1104 f_init();
1105 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001106 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1107
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001108 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001109 vc_conn.done;
1110}
1111
Harald Welte1af6ea82018-01-25 18:33:15 +01001112/* Test Complete L3 without payload */
1113private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001114 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001115
1116 /* Send Complete L3 Info with empty L3 frame */
1117 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1118 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1119
Harald Weltef466eb42018-01-27 14:26:54 +01001120 timer T := 5.0;
1121 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001122 alt {
1123 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
1124 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001125 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
1126 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001127 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001128 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001129 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Harald Weltef466eb42018-01-27 14:26:54 +01001130 self.stop;
1131 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001132 }
1133 setverdict(pass);
1134}
1135testcase TC_cl3_no_payload() runs on MTC_CT {
1136 var BSC_ConnHdlr vc_conn;
1137 f_init();
1138
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001139 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001140 vc_conn.done;
1141}
1142
1143/* Test Complete L3 with random payload */
1144private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001145 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001146
1147 var integer len := float2int(rnd() * 256.0);
1148 var octetstring payl := f_rnd_octstring(len);
1149
1150 /* Send Complete L3 Info with empty L3 frame */
1151 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1152 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1153
Harald Weltef466eb42018-01-27 14:26:54 +01001154 timer T := 5.0;
1155 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001156 alt {
1157 /* Immediate disconnect */
1158 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001159 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Weltebdb3c452018-03-18 22:43:06 +01001160 [] BSSAP.receive(BSSAP_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001161 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001162 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001163 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Harald Weltef466eb42018-01-27 14:26:54 +01001164 self.stop;
1165 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001166 }
1167 setverdict(pass);
1168}
1169testcase TC_cl3_rnd_payload() runs on MTC_CT {
1170 var BSC_ConnHdlr vc_conn;
1171 f_init();
1172
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001173 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001174 vc_conn.done;
1175}
1176
Harald Welte116e4332018-01-26 22:17:48 +01001177/* Test Complete L3 with random payload */
1178private function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001179 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001180
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001181 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001182
Harald Welteb9e86fa2018-04-09 18:18:31 +02001183 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001184 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001185}
1186testcase TC_establish_and_nothing() runs on MTC_CT {
1187 var BSC_ConnHdlr vc_conn;
1188 f_init();
1189
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001190 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001191 vc_conn.done;
1192}
1193
Harald Welte12510c52018-01-26 22:26:24 +01001194/* Test MO Call SETUP with no response from MNCC */
1195private function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001196 f_init_handler(pars);
1197
Harald Welte12510c52018-01-26 22:26:24 +01001198 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1199
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001200 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001201
Harald Welteb9e86fa2018-04-09 18:18:31 +02001202 f_establish_fully();
Harald Welte12510c52018-01-26 22:26:24 +01001203 f_create_mncc_expect(hex2str(cpars.called_party));
1204 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1205
1206 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1207
Harald Welte1ddc7162018-01-27 14:25:46 +01001208 f_expect_clear(30.0);
Harald Welte12510c52018-01-26 22:26:24 +01001209}
1210testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1211 var BSC_ConnHdlr vc_conn;
1212 f_init();
1213
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001214 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001215 vc_conn.done;
1216}
1217
Harald Welte3ab88002018-01-26 22:37:25 +01001218/* Test MO Call with no response to RAN-side CRCX */
1219private function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001220 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001221 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1222 var MNCC_PDU mncc;
1223 var MgcpCommand mgcp_cmd;
1224
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001225 f_perform_lu();
Harald Welte3ab88002018-01-26 22:37:25 +01001226
Harald Welteb9e86fa2018-04-09 18:18:31 +02001227 f_establish_fully();
Harald Welte3ab88002018-01-26 22:37:25 +01001228 f_create_mncc_expect(hex2str(cpars.called_party));
1229 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1230
1231 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1232 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1233 cpars.mncc_callref := mncc.u.signal.callref;
1234 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1235 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1236
1237 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Harald Welte1852a842018-01-26 22:53:36 +01001238 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1239 cpars.mgcp_ep := mgcp_cmd.line.ep;
Harald Welte3ab88002018-01-26 22:37:25 +01001240 /* never respond to this */
1241
Philipp Maier8e58f592018-03-14 11:10:56 +01001242 /* When the connection with the MGW fails, the MSC will first request
1243 * a release via call control. We will answer this request normally. */
1244 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1245 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1246
Harald Welte1ddc7162018-01-27 14:25:46 +01001247 f_expect_clear(30.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001248}
1249testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1250 var BSC_ConnHdlr vc_conn;
1251 f_init();
1252
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001253 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001254 vc_conn.done;
1255}
1256
Harald Welte0cc82d92018-01-26 22:52:34 +01001257/* Test MO Call with reject to RAN-side CRCX */
1258private function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001259 f_init_handler(pars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001260 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1261 var MNCC_PDU mncc;
1262 var MgcpCommand mgcp_cmd;
1263
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001264 f_perform_lu();
Harald Welte0cc82d92018-01-26 22:52:34 +01001265
Harald Welteb9e86fa2018-04-09 18:18:31 +02001266 f_establish_fully();
Harald Welte0cc82d92018-01-26 22:52:34 +01001267 f_create_mncc_expect(hex2str(cpars.called_party));
1268 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1269
1270 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1271 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1272 cpars.mncc_callref := mncc.u.signal.callref;
1273 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1274 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1275
1276 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001277
1278 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1279 * set an endpoint name that fits the pattern. If not, just use the
1280 * endpoint name from the request */
1281 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1282 cpars.mgcp_ep := "rtpbridge/1@mgw";
1283 } else {
1284 cpars.mgcp_ep := mgcp_cmd.line.ep;
1285 }
1286
Harald Welte0cc82d92018-01-26 22:52:34 +01001287 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001288
Harald Welte0cc82d92018-01-26 22:52:34 +01001289 /* Respond to CRCX with error */
1290 var MgcpResponse mgcp_rsp := {
1291 line := {
1292 code := "542",
1293 trans_id := mgcp_cmd.line.trans_id,
1294 string := "FORCED_FAIL"
1295 },
Harald Welte0cc82d92018-01-26 22:52:34 +01001296 sdp := omit
1297 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001298 var MgcpParameter mgcp_rsp_param := {
1299 code := "Z",
1300 val := cpars.mgcp_ep
1301 };
1302 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte0cc82d92018-01-26 22:52:34 +01001303 MGCP.send(mgcp_rsp);
1304
1305 timer T := 30.0;
1306 T.start;
1307 alt {
1308 [] T.timeout { setverdict(fail, "Timeout waiting for channel release"); self.stop; }
Daniel Willmann5868e622018-02-15 17:42:59 +01001309 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
1310 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1311 repeat;
1312 }
Harald Welte0cc82d92018-01-26 22:52:34 +01001313 [] MNCC.receive { repeat; }
1314 [] GSUP.receive { repeat; }
Philipp Maierc6e06f72018-04-11 18:12:23 +02001315 /* Note: As we did not respond properly to the CRCX from the MSC we
1316 * expect the MSC to omit any further MGCP operation (At least in the
1317 * the current implementation, there is no recovery mechanism implemented
1318 * and a DLCX can not be performed as the MSC does not know a specific
1319 * endpoint yet. */
1320 [] MGCP.receive { setverdict(fail, "Unexpected MGCP message"); self.stop; }
Harald Welte5946b332018-03-18 23:32:21 +01001321 [] as_clear_cmd_compl_disc();
Harald Welte0cc82d92018-01-26 22:52:34 +01001322 }
1323}
1324testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1325 var BSC_ConnHdlr vc_conn;
1326 f_init();
1327
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001328 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001329 vc_conn.done;
1330}
1331
Harald Welte3ab88002018-01-26 22:37:25 +01001332
Harald Welte812f7a42018-01-27 00:49:18 +01001333/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1334private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1335 var MNCC_PDU mncc;
1336 var MgcpCommand mgcp_cmd;
1337 var OCT4 tmsi;
1338
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001339 f_perform_lu();
Harald Welte812f7a42018-01-27 00:49:18 +01001340 if (isvalue(g_pars.tmsi)) {
1341 tmsi := g_pars.tmsi;
1342 } else {
1343 tmsi := 'FFFFFFFF'O;
1344 }
1345 f_bssmap_register_imsi(g_pars.imsi, tmsi);
1346
1347 /* Allocate call reference and send SETUP via MNCC to MSC */
1348 cpars.mncc_callref := f_rnd_int(2147483648);
1349 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1350 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1351
1352 /* MSC->BSC: expect PAGING from MSC */
1353 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
1354 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001355 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001356
1357 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1358
1359 /* MSC->MS: SETUP */
1360 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1361}
1362
1363/* Test MT Call */
1364private function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001365 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001366 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1367 var MNCC_PDU mncc;
1368 var MgcpCommand mgcp_cmd;
1369
1370 f_mt_call_start(cpars);
1371
1372 /* MS->MSC: CALL CONFIRMED */
1373 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1374
1375 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1376
1377 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1378 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001379
1380 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1381 * set an endpoint name that fits the pattern. If not, just use the
1382 * endpoint name from the request */
1383 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1384 cpars.mgcp_ep := "rtpbridge/1@mgw";
1385 } else {
1386 cpars.mgcp_ep := mgcp_cmd.line.ep;
1387 }
1388
Harald Welte812f7a42018-01-27 00:49:18 +01001389 /* Respond to CRCX with error */
1390 var MgcpResponse mgcp_rsp := {
1391 line := {
1392 code := "542",
1393 trans_id := mgcp_cmd.line.trans_id,
1394 string := "FORCED_FAIL"
1395 },
Harald Welte812f7a42018-01-27 00:49:18 +01001396 sdp := omit
1397 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001398 var MgcpParameter mgcp_rsp_param := {
1399 code := "Z",
1400 val := cpars.mgcp_ep
1401 };
1402 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001403 MGCP.send(mgcp_rsp);
1404
1405 timer T := 30.0;
1406 T.start;
1407 alt {
1408 [] T.timeout { setverdict(fail, "Timeout waiting for channel release"); self.stop; }
Harald Welte812f7a42018-01-27 00:49:18 +01001409 [] BSSAP.receive { repeat; }
1410 [] MNCC.receive { repeat; }
1411 [] GSUP.receive { repeat; }
1412 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1413 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1414 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1415 repeat;
1416 }
1417 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001418 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001419 }
1420}
1421testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1422 var BSC_ConnHdlr vc_conn;
1423 f_init();
1424
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001425 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001426 vc_conn.done;
1427}
1428
1429
1430/* Test MT Call T310 timer */
1431private function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001432 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001433 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1434 var MNCC_PDU mncc;
1435 var MgcpCommand mgcp_cmd;
1436
1437 f_mt_call_start(cpars);
1438
1439 /* MS->MSC: CALL CONFIRMED */
1440 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1441 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1442
1443 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1444 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1445 cpars.mgcp_ep := mgcp_cmd.line.ep;
1446 /* FIXME: Respond to CRCX */
1447
1448 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1449 timer T := 190.0;
1450 T.start;
1451 alt {
1452 [] T.timeout { setverdict(fail, "Timeout waiting for T310"); self.stop; }
1453 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1454 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1455 }
1456 }
1457 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1458 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1459 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1460 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1461
1462 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001463 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1464 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1465 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1466 repeat;
1467 }
Harald Welte5946b332018-03-18 23:32:21 +01001468 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001469 }
1470}
1471testcase TC_mt_t310() runs on MTC_CT {
1472 var BSC_ConnHdlr vc_conn;
1473 f_init();
1474
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001475 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001476 vc_conn.done;
1477}
1478
Harald Welte167458a2018-01-27 15:58:16 +01001479/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
1480private function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1481 f_init_handler(pars);
1482 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1483 cpars.bss_rtp_port := 1110;
1484 cpars.mgcp_connection_id_bss := '22222'H;
1485 cpars.mgcp_connection_id_mss := '33333'H;
1486
1487 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001488 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001489
1490 /* First MO call should succeed */
1491 f_mo_call(cpars);
1492
1493 /* Cancel the subscriber in the VLR */
1494 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1495 alt {
1496 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1497 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1498 setverdict(fail, "Received GSUP Location Cancel Error");
1499 self.stop;
1500 }
1501 }
1502
1503 /* Follow-up transactions should fail */
1504 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1505 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
1506 f_bssap_compl_l3(l3_info);
1507 alt {
1508 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1509 [] BSSAP.receive {
1510 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
1511 self.stop;
1512 }
1513 }
1514 setverdict(pass);
1515}
1516testcase TC_gsup_cancel() runs on MTC_CT {
1517 var BSC_ConnHdlr vc_conn;
1518 f_init();
1519
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001520 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33);
Harald Welte167458a2018-01-27 15:58:16 +01001521 vc_conn.done;
1522}
1523
Harald Welte9de84792018-01-28 01:06:35 +01001524/* A5/1 only permitted on network side, and MS capable to do it */
1525private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1526 pars.net.expect_auth := true;
1527 pars.net.expect_ciph := true;
1528 pars.net.kc_support := '02'O; /* A5/1 only */
1529 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001530 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001531}
1532testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1533 var BSC_ConnHdlr vc_conn;
1534 f_init();
1535 f_vty_config(MSCVTY, "network", "authentication required");
1536 f_vty_config(MSCVTY, "network", "encryption a5 1");
1537
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001538 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001539 vc_conn.done;
1540}
1541
1542/* A5/3 only permitted on network side, and MS capable to do it */
1543private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1544 pars.net.expect_auth := true;
1545 pars.net.expect_ciph := true;
1546 pars.net.kc_support := '08'O; /* A5/3 only */
1547 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001548 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001549}
1550testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1551 var BSC_ConnHdlr vc_conn;
1552 f_init();
1553 f_vty_config(MSCVTY, "network", "authentication required");
1554 f_vty_config(MSCVTY, "network", "encryption a5 3");
1555
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001556 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001557 vc_conn.done;
1558}
1559
1560/* A5/3 only permitted on network side, and MS with only A5/1 support */
1561private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1562 pars.net.expect_auth := true;
1563 pars.net.expect_ciph := true;
1564 pars.net.kc_support := '08'O; /* A5/3 only */
1565 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1566 f_init_handler(pars, 15.0);
1567
1568 /* cannot use f_perform_lu() as we expect a reject */
1569 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1570 f_create_gsup_expect(hex2str(g_pars.imsi));
1571 f_bssap_compl_l3(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001572 if (pars.send_early_cm) {
1573 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1574 } else {
1575 pars.cm1.esind := '0'B;
1576 }
Harald Welte9de84792018-01-28 01:06:35 +01001577 f_mm_auth();
1578 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001579 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1580 f_expect_clear();
1581 }
Harald Welte9de84792018-01-28 01:06:35 +01001582 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1583 setverdict(fail, "CipherModeCommand despite no A5 intersection");
1584 self.stop;
1585 }
1586 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001587 setverdict(fail, "Unknown/unexpected BSSAP received");
Harald Welte9de84792018-01-28 01:06:35 +01001588 self.stop;
1589 }
1590 }
1591 setverdict(pass);
1592}
1593testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1594 var BSC_ConnHdlr vc_conn;
1595 f_init();
1596 f_vty_config(MSCVTY, "network", "authentication required");
1597 f_vty_config(MSCVTY, "network", "encryption a5 3");
1598
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001599 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360);
1600 vc_conn.done;
1601}
1602testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1603 var BSC_ConnHdlrPars pars;
1604 var BSC_ConnHdlr vc_conn;
1605 f_init();
1606 f_vty_config(MSCVTY, "network", "authentication required");
1607 f_vty_config(MSCVTY, "network", "encryption a5 3");
1608
1609 pars := f_init_pars(361);
1610 pars.send_early_cm := false;
1611 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001612 vc_conn.done;
1613}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001614testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1615 var BSC_ConnHdlr vc_conn;
1616 f_init();
1617 f_vty_config(MSCVTY, "network", "authentication required");
1618 f_vty_config(MSCVTY, "network", "encryption a5 3");
1619
1620 /* Make sure the MSC category is on DEBUG level to trigger the log
1621 * message that is reported in OS#2947 to trigger the segfault */
1622 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1623
1624 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362);
1625 vc_conn.done;
1626}
Harald Welte9de84792018-01-28 01:06:35 +01001627
1628/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1629private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1630 pars.net.expect_auth := true;
1631 pars.net.expect_ciph := true;
1632 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1633 pars.cm1.a5_1 := '1'B;
1634 pars.cm2.a5_1 := '1'B;
1635 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1636 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1637 f_init_handler(pars, 15.0);
1638
1639 /* cannot use f_perform_lu() as we expect a reject */
1640 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1641 f_create_gsup_expect(hex2str(g_pars.imsi));
1642 f_bssap_compl_l3(l3_lu);
1643 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1644 f_mm_auth();
1645 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001646 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1647 f_expect_clear();
1648 }
Harald Welte9de84792018-01-28 01:06:35 +01001649 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1650 setverdict(fail, "CipherModeCommand despite no A5 intersection");
1651 self.stop;
1652 }
1653 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001654 setverdict(fail, "Unknown/unexpected BSSAP received");
Harald Welte9de84792018-01-28 01:06:35 +01001655 self.stop;
1656 }
1657 }
1658 setverdict(pass);
1659}
1660testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1661 var BSC_ConnHdlr vc_conn;
1662 f_init();
1663 f_vty_config(MSCVTY, "network", "authentication required");
1664 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1665
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001666 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37);
Harald Welte9de84792018-01-28 01:06:35 +01001667 vc_conn.done;
1668}
1669
1670/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1671private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1672 pars.net.expect_auth := true;
1673 pars.net.expect_ciph := true;
1674 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1675 pars.cm1.a5_1 := '1'B;
1676 pars.cm2.a5_1 := '1'B;
1677 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1678 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1679 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001680 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001681}
1682testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1683 var BSC_ConnHdlr vc_conn;
1684 f_init();
1685 f_vty_config(MSCVTY, "network", "authentication required");
1686 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1687
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001688 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001689 vc_conn.done;
1690}
1691
Harald Welte33ec09b2018-02-10 15:34:46 +01001692/* LU followed by MT call (including paging) */
1693private function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1694 f_init_handler(pars);
1695 //FIXME: odd digits var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1696 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1697 cpars.bss_rtp_port := 1110;
1698 cpars.mgcp_connection_id_bss := '10004'H;
1699 cpars.mgcp_connection_id_mss := '10005'H;
1700
Philipp Maier4b2692d2018-03-14 16:37:48 +01001701 /* Note: This is an optional parameter. When the call-agent (MSC) does
1702 * supply a full endpoint name this setting will be overwritten. */
1703 cpars.mgcp_ep := "rtpbridge/1@mgw";
1704
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001705 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001706 f_mt_call(cpars);
1707}
1708testcase TC_lu_and_mt_call() runs on MTC_CT {
1709 var BSC_ConnHdlr vc_conn;
1710 f_init();
1711
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001712 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001713 vc_conn.done;
1714}
1715
Daniel Willmann8b084372018-02-04 13:35:26 +01001716/* Test MO Call SETUP with DTMF */
1717private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1718 f_init_handler(pars);
1719 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1720 cpars.bss_rtp_port := 1110;
1721 cpars.mgcp_connection_id_bss := '22222'H;
1722 cpars.mgcp_connection_id_mss := '33333'H;
1723
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001724 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001725 f_mo_seq_dtmf_dup(cpars);
1726}
1727testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1728 var BSC_ConnHdlr vc_conn;
1729 f_init();
1730
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001731 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001732 vc_conn.done;
1733}
Harald Welte9de84792018-01-28 01:06:35 +01001734
Philipp Maier328d1662018-03-07 10:40:27 +01001735testcase TC_cr_before_reset() runs on MTC_CT {
1736 timer T := 4.0;
1737 var boolean reset_ack_seen := false;
1738 f_init_bssap_direct();
1739
1740 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001741 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001742
1743 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001744 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001745 T.start
1746 alt {
1747 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1748 reset_ack_seen := true;
1749 repeat;
1750 }
1751
1752 /* Acknowledge MSC sided reset requests */
1753 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001754 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001755 repeat;
1756 }
1757
1758 /* Ignore all other messages (e.g CR from the connection request) */
1759 [] BSSAP_DIRECT.receive { repeat }
1760
1761 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1762 * deadlock situation. The MSC is then unable to respond to any
1763 * further BSSMAP RESET or any other sort of traffic. */
1764 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1765 [reset_ack_seen == false] T.timeout {
1766 setverdict(fail, "no BSSMAP RESET ACK seen!");
1767 }
1768 }
1769}
Harald Welte9de84792018-01-28 01:06:35 +01001770
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001771/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
1772private function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1773 f_init_handler(pars);
1774 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1775 var MNCC_PDU mncc;
1776 var MgcpCommand mgcp_cmd;
1777
1778 f_perform_lu();
1779
Harald Welteb9e86fa2018-04-09 18:18:31 +02001780 f_establish_fully();
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001781 f_create_mncc_expect(hex2str(cpars.called_party));
1782 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1783
1784 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
1785 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
1786 cpars.mncc_callref := mncc.u.signal.callref;
1787 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
1788 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
1789
1790 /* Drop CRCX */
1791 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1792
1793 /* Drop DTAP Release */
1794 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1795
1796 /* Drop resent DTAP Release */
1797 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1798
1799 f_expect_clear(60.0);
1800}
1801testcase TC_mo_release_timeout() runs on MTC_CT {
1802 var BSC_ConnHdlr vc_conn;
1803 f_init();
1804
1805 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1806 vc_conn.done;
1807}
1808
Harald Welte12510c52018-01-26 22:26:24 +01001809
Philipp Maier2a98a732018-03-19 16:06:12 +01001810/* LU followed by MT call (including paging) */
1811private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1812 f_init_handler(pars);
1813 //FIXME: odd digits var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1814 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1815 cpars.bss_rtp_port := 1110;
1816 cpars.mgcp_connection_id_bss := '10004'H;
1817 cpars.mgcp_connection_id_mss := '10005'H;
1818
1819 /* Note: This is an optional parameter. When the call-agent (MSC) does
1820 * supply a full endpoint name this setting will be overwritten. */
1821 cpars.mgcp_ep := "rtpbridge/1@mgw";
1822
1823 /* Intentionally disable the CRCX response */
1824 cpars.mgw_drop_dlcx := true;
1825
1826 /* Perform location update and call */
1827 f_perform_lu();
1828 f_mt_call(cpars);
1829}
1830testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
1831 var BSC_ConnHdlr vc_conn;
1832 f_init();
1833
1834 /* Perform an almost normal looking locationupdate + mt-call, but do
1835 * not respond to the DLCX at the end of the call */
1836 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
1837 vc_conn.done;
1838
1839 /* Wait a guard period until the MGCP layer in the MSC times out,
1840 * if the MSC is vulnerable to the use-after-free situation that is
1841 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
1842 * segfault now */
1843 f_sleep(6.0);
1844
1845 /* Run the init procedures once more. If the MSC has crashed, this
1846 * this will fail */
1847 f_init();
1848}
Harald Welte45164da2018-01-24 12:51:27 +01001849
Philipp Maier75932982018-03-27 14:52:35 +02001850/* Two BSSMAP resets from two different BSCs */
1851testcase TC_reset_two() runs on MTC_CT {
1852 var BSC_ConnHdlr vc_conn;
1853 f_init(2);
1854 f_sleep(2.0);
1855 setverdict(pass);
1856}
1857
Harald Weltef640a012018-04-14 17:49:21 +02001858/***********************************************************************
1859 * SMS Testing
1860 ***********************************************************************/
1861
Harald Weltef45efeb2018-04-09 18:19:24 +02001862/* LU followed by MO SMS */
1863private function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1864 var SmsParameters spars := valueof(t_SmsPars);
1865
1866 f_init_handler(pars);
1867
1868 /* Perform location update and call */
1869 f_perform_lu();
1870
1871 f_establish_fully(EST_TYPE_MO_SMS);
1872
1873 //spars.exp_rp_err := 96; /* invalid mandatory information */
1874 f_mo_sms(spars);
1875
1876 f_expect_clear();
1877}
1878testcase TC_lu_and_mo_sms() runs on MTC_CT {
1879 var BSC_ConnHdlr vc_conn;
1880 f_init();
1881 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
1882 vc_conn.done;
1883}
1884
1885private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
1886runs on MTC_CT {
1887 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
1888}
1889
1890/* LU followed by MT SMS */
1891private function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1892 var SmsParameters spars := valueof(t_SmsPars);
1893 var OCT4 tmsi;
1894
1895 f_init_handler(pars);
1896
1897 /* Perform location update and call */
1898 f_perform_lu();
1899
1900 /* register an 'expect' for given IMSI (+TMSI) */
1901 if (isvalue(g_pars.tmsi)) {
1902 tmsi := g_pars.tmsi;
1903 } else {
1904 tmsi := 'FFFFFFFF'O;
1905 }
1906 f_bssmap_register_imsi(g_pars.imsi, tmsi);
1907
1908 /* FIXME: actually cause MSC to send a SMS via VTY or SMPP */
1909
1910 /* MSC->BSC: expect PAGING from MSC */
1911 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
1912 /* Establish DTAP / BSSAP / SCCP connection */
1913 f_establish_fully(EST_TYPE_PAG_RESP);
1914
1915 spars.tp.ud := 'C8329BFD064D9B53'O;
1916 f_mt_sms(spars);
1917
1918 f_expect_clear();
1919}
1920testcase TC_lu_and_mt_sms() runs on MTC_CT {
1921 var BSC_ConnHdlrPars pars;
1922 var BSC_ConnHdlr vc_conn;
1923 f_init();
1924 pars := f_init_pars(43);
1925 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
1926 f_sleep(2.0);
1927 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
1928 vc_conn.done;
1929}
1930
Harald Weltef640a012018-04-14 17:49:21 +02001931/* mobile originated SMS from MS/BTS/BSC side to SMPP */
1932private function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1933 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02001934
Harald Weltef640a012018-04-14 17:49:21 +02001935 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02001936
Harald Weltef640a012018-04-14 17:49:21 +02001937 /* Perform location update so IMSI is known + registered in MSC/VLR */
1938 f_perform_lu();
1939 f_establish_fully(EST_TYPE_MO_SMS);
1940
1941 f_mo_sms(spars);
1942
1943 var SMPP_PDU smpp;
1944 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
1945 tr_smpp.body.deliver_sm := {
1946 service_type := "CMT",
1947 source_addr_ton := network_specific,
1948 source_addr_npi := isdn,
1949 source_addr := hex2str(pars.msisdn),
1950 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
1951 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
1952 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
1953 esm_class := '00000001'B,
1954 protocol_id := 0,
1955 priority_flag := 0,
1956 schedule_delivery_time := "",
1957 replace_if_present := 0,
1958 data_coding := '00000001'B,
1959 sm_default_msg_id := 0,
1960 sm_length := ?,
1961 short_message := spars.tp.ud,
1962 opt_pars := {
1963 {
1964 tag := user_message_reference,
1965 len := 2,
1966 opt_value := {
1967 int2_val := oct2int(spars.tp.msg_ref)
1968 }
1969 }
1970 }
1971 };
1972 alt {
1973 [] SMPP.receive(tr_smpp) -> value smpp {
1974 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
1975 }
1976 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
1977 }
1978
1979 f_expect_clear();
1980}
1981testcase TC_smpp_mo_sms() runs on MTC_CT {
1982 var BSC_ConnHdlr vc_conn;
1983 f_init();
1984 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
1985 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
1986 vc_conn.done;
1987 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
1988}
1989
1990/* convert GSM L3 TON to SMPP_TON enum */
1991function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
1992 select (ton) {
1993 case ('000'B) { return unknown; }
1994 case ('001'B) { return international; }
1995 case ('010'B) { return national; }
1996 case ('011'B) { return network_specific; }
1997 case ('100'B) { return subscriber_number; }
1998 case ('101'B) { return alphanumeric; }
1999 case ('110'B) { return abbreviated; }
2000 }
2001 setverdict(fail, "Unknown TON ", ton);
2002 self.stop;
2003}
2004/* convert GSM L3 NPI to SMPP_NPI enum */
2005function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2006 select (npi) {
2007 case ('0000'B) { return unknown; }
2008 case ('0001'B) { return isdn; }
2009 case ('0011'B) { return data; }
2010 case ('0100'B) { return telex; }
2011 case ('0110'B) { return land_mobile; }
2012 case ('1000'B) { return national; }
2013 case ('1001'B) { return private_; }
2014 case ('1010'B) { return ermes; }
2015 }
2016 setverdict(fail, "Unknown NPI ", npi);
2017 self.stop;
2018}
2019
2020/* build a SMPP_SM from SmsParameters */
2021function f_mt_sm_from_spars(SmsParameters spars)
2022runs on BSC_ConnHdlr return SMPP_SM {
2023 var SMPP_SM sm := {
2024 service_type := "CMT",
2025 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2026 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2027 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2028 dest_addr_ton := international,
2029 dest_addr_npi := isdn,
2030 destination_addr := hex2str(g_pars.msisdn),
2031 esm_class := '00000001'B,
2032 protocol_id := 0,
2033 priority_flag := 0,
2034 schedule_delivery_time := "",
2035 validity_period := "",
2036 registered_delivery := '00000000'B,
2037 replace_if_present := 0,
2038 data_coding := '00000001'B,
2039 sm_default_msg_id := 0,
2040 sm_length := spars.tp.udl,
2041 short_message := spars.tp.ud,
2042 opt_pars := {}
2043 };
2044 return sm;
2045}
2046
2047/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2048private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2049 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2050 if (trans_mode) {
2051 sm.esm_class := '00000010'B;
2052 }
2053
2054 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2055 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2056 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2057 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2058 * before we expect the SMS delivery on the BSC/radio side */
2059 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2060 }
2061
2062 /* MSC->BSC: expect PAGING from MSC */
2063 BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi));
2064 /* Establish DTAP / BSSAP / SCCP connection */
2065 f_establish_fully(EST_TYPE_PAG_RESP);
2066 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2067
2068 f_mt_sms(spars);
2069
2070 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2071 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2072 }
2073 f_expect_clear();
2074}
2075
2076/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2077private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2078 f_init_handler(pars);
2079
2080 /* Perform location update so IMSI is known + registered in MSC/VLR */
2081 f_perform_lu();
2082 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2083
2084 /* register an 'expect' for given IMSI (+TMSI) */
2085 var OCT4 tmsi;
2086 if (isvalue(g_pars.tmsi)) {
2087 tmsi := g_pars.tmsi;
2088 } else {
2089 tmsi := 'FFFFFFFF'O;
2090 }
2091 f_bssmap_register_imsi(g_pars.imsi, tmsi);
2092
2093 var SmsParameters spars := valueof(t_SmsPars);
2094 /* TODO: test with more intelligent user data; test different coding schemes */
2095 spars.tp.ud := '00'O;
2096 spars.tp.udl := 1;
2097
2098 /* first test the non-transaction store+forward mode */
2099 f_smpp_mt_sms(spars, false);
2100
2101 /* then test the transaction mode */
2102 f_smpp_mt_sms(spars, true);
2103}
2104testcase TC_smpp_mt_sms() runs on MTC_CT {
2105 var BSC_ConnHdlr vc_conn;
2106 f_init();
2107 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
2108 vc_conn.done;
2109}
2110
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002111/***********************************************************************
2112 * USSD Testing
2113 ***********************************************************************/
2114
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002115/* LU followed by MO USSD request */
2116private function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002117runs on BSC_ConnHdlr {
2118 f_init_handler(pars);
2119
2120 /* Perform location update */
2121 f_perform_lu();
2122
2123 /* Send CM Service Request for SS/USSD */
2124 f_establish_fully(EST_TYPE_SS_ACT);
2125
2126 /* Compose a new SS/REGISTER message with request */
2127 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
2128 tid := 1, /* We just need a single transaction */
2129 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
2130 facility := f_USSD_FACILITY_IE_INVOKE(
2131 invoke_id := 5, /* Phone may not start from 0 or 1 */
2132 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2133 ussd_string := "*#100#"
2134 )
2135 );
2136
2137 /* Compose SS/RELEASE_COMPLETE template with expected response */
2138 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
2139 tid := 1, /* Response should arrive within the same transaction */
2140 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
2141 facility := f_USSD_FACILITY_IE_RETURN_RESULT(
2142 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
2143 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2144 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
2145 )
2146 );
2147
2148 /* Request own number request */
2149 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
2150 alt {
2151 /* We expect RELEASE_COMPLETE message with the response */
2152 [] BSSAP.receive(tr_PDU_DTAP_MT(ussd_rsp)) {
2153 setverdict(pass);
2154 }
2155 [] BSSAP.receive {
2156 setverdict(fail, "Unknown/unexpected BSSAP received");
2157 self.stop;
2158 }
2159 }
2160
2161 f_expect_clear();
2162}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002163testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002164 var BSC_ConnHdlr vc_conn;
2165 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002166 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002167 vc_conn.done;
2168}
2169
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002170/* LU followed by MT call and MO USSD request during this call */
2171private function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07002172runs on BSC_ConnHdlr {
2173 f_init_handler(pars);
2174
2175 /* Call parameters taken from f_tc_lu_and_mt_call */
2176 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
2177 cpars.mgcp_connection_id_bss := '10004'H;
2178 cpars.mgcp_connection_id_mss := '10005'H;
2179 cpars.mgcp_ep := "rtpbridge/1@mgw";
2180 cpars.bss_rtp_port := 1110;
2181
2182 /* Perform location update */
2183 f_perform_lu();
2184
2185 /* Establish a MT call */
2186 f_mt_call_establish(cpars);
2187
2188 /* Hold the call for some time */
2189 f_sleep(1.0);
2190
2191 /* Compose a new SS/REGISTER message with request */
2192 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
2193 tid := 1, /* We just need a single transaction */
2194 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
2195 facility := f_USSD_FACILITY_IE_INVOKE(
2196 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2197 ussd_string := "*#100#"
2198 )
2199 );
2200
2201 /* Compose SS/RELEASE_COMPLETE template with expected response */
2202 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
2203 tid := 1, /* Response should arrive within the same transaction */
2204 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
2205 facility := f_USSD_FACILITY_IE_RETURN_RESULT(
2206 op_code := SS_OP_CODE_PROCESS_USS_REQ,
2207 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
2208 )
2209 );
2210
2211 /* Request own number request */
2212 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
2213 alt {
2214 /* We expect RELEASE_COMPLETE message with the response */
2215 [] BSSAP.receive(tr_PDU_DTAP_MT(ussd_rsp)) {
2216 setverdict(pass);
2217 }
2218 [] BSSAP.receive {
2219 setverdict(fail, "Unknown/unexpected BSSAP received");
2220 self.stop;
2221 }
2222 }
2223
2224 /* Hold the call for some time */
2225 f_sleep(1.0);
2226
2227 /* Release the call (does Clear Complete itself) */
2228 f_call_hangup(cpars, true);
2229}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002230testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07002231 var BSC_ConnHdlr vc_conn;
2232 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002233 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07002234 vc_conn.done;
2235}
2236
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02002237/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
2238private function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2239 f_init_handler(pars);
2240 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
2241 var MNCC_PDU mncc;
2242 var MgcpCommand mgcp_cmd;
2243
2244 f_perform_lu();
2245
2246 f_establish_fully();
2247 f_create_mncc_expect(hex2str(cpars.called_party));
2248 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
2249
2250 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_SETUP(cpars.transaction_id, cpars.called_party)));
2251 MNCC.receive(tr_MNCC_SETUP_ind(?, tr_MNCC_number(hex2str(cpars.called_party)))) -> value mncc;
2252 cpars.mncc_callref := mncc.u.signal.callref;
2253 log("mncc_callref=", cpars.mncc_callref);
2254 MNCC.send(ts_MNCC_CALL_PROC_req(cpars.mncc_callref, cpars.mncc_bearer_cap));
2255 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_CALL_PROC(cpars.transaction_id)));
2256
2257 MNCC.send(ts_MNCC_ALERT_req(cpars.mncc_callref));
2258 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_ALERTING(cpars.transaction_id)));
2259 MGCP.receive(tr_CRCX);
2260
2261 f_sleep(1.0);
2262 BSSAP.send(ts_BSSMAP_ClearRequest(0));
2263
2264 MNCC.receive(tr_MNCC_REL_ind(?, ?)) -> value mncc;
2265
2266 BSSAP.receive(tr_BSSMAP_ClearCommand);
2267 BSSAP.send(ts_BSSMAP_ClearComplete);
2268
2269 f_sleep(1.0);
2270}
2271testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
2272 var BSC_ConnHdlr vc_conn;
2273 f_init();
2274
2275 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
2276 vc_conn.done;
2277}
2278
Harald Weltef640a012018-04-14 17:49:21 +02002279/* TODO (SMS):
2280 * different user data lengths
2281 * SMPP transaction mode with unsuccessful delivery
2282 * queued MT-SMS with no paging response + later delivery
2283 * different data coding schemes
2284 * multi-part SMS
2285 * user-data headers
2286 * TP-PID for SMS to SIM
2287 * behavior if SMS memory is full + RP-SMMA
2288 * delivery reports
2289 * SMPP osmocom extensions
2290 * more-messages-to-send
2291 * SMS during ongoing call (SACCH/SAPI3)
2292 */
2293
2294/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01002295 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
2296 * malformed messages (missing IE, invalid message type): properly rejected?
2297 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
2298 * 3G/2G auth permutations
2299 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01002300 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01002301 * too long L3 INFO in DTAP
2302 * too long / padded BSSAP
2303 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01002304 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01002305
2306
2307control {
Philipp Maier328d1662018-03-07 10:40:27 +01002308 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01002309 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01002310 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01002311 execute( TC_lu_imsi_reject() );
2312 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01002313 execute( TC_lu_imsi_auth_tmsi() );
2314 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01002315 execute( TC_lu_and_mo_call() );
Harald Welte071ed732018-01-23 19:53:52 +01002316 execute( TC_lu_auth_sai_timeout() );
2317 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01002318 execute( TC_lu_clear_request() );
2319 execute( TC_lu_disconnect() );
2320 execute( TC_lu_by_imei() );
2321 execute( TC_lu_by_tmsi_noauth_unknown() );
2322 execute( TC_imsi_detach_by_imsi() );
2323 execute( TC_imsi_detach_by_tmsi() );
2324 execute( TC_imsi_detach_by_imei() );
2325 execute( TC_emerg_call_imei_reject() );
2326 execute( TC_emerg_call_imsi() );
2327 execute( TC_cm_serv_req_vgcs_reject() );
2328 execute( TC_cm_serv_req_vbs_reject() );
2329 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01002330 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01002331 execute( TC_lu_auth_2G_fail() );
2332 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
2333 execute( TC_cl3_no_payload() );
2334 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01002335 execute( TC_establish_and_nothing() );
2336 execute( TC_mo_setup_and_nothing() );
2337 execute( TC_mo_crcx_ran_timeout() );
2338 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01002339 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01002340 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01002341 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01002342 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01002343 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
2344 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
2345 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01002346 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01002347 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
2348 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01002349 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01002350 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02002351 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01002352
2353 execute( TC_lu_and_mt_call() );
2354
Harald Weltef45efeb2018-04-09 18:19:24 +02002355 execute( TC_lu_and_mo_sms() );
2356 execute( TC_lu_and_mt_sms() );
Harald Weltef640a012018-04-14 17:49:21 +02002357 execute( TC_smpp_mo_sms() );
2358 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02002359
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07002360 execute( TC_lu_and_mo_ussd_single_request() );
2361 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002362
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01002363 /* Run this last: at the time of writing this test crashes the MSC */
2364 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02002365 execute( TC_mo_cc_bssmap_clear() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01002366}
2367
2368
2369}