blob: 63e90f49f6ecc42aa0de84ed871d16f84f53e714 [file] [log] [blame]
Harald Weltef6dd64d2017-11-19 12:09:51 +01001module MSC_Tests {
2
Harald Welte34b5a952019-05-27 11:54:11 +02003/* Osmocom MSC test suite in in TTCN-3
4 * (C) 2017-2019 Harald Welte <laforge@gnumonks.org>
5 * (C) 2018-2019 sysmocom - s.f.m.c. GmbH
6 * (C) 2018-2019 Vadim Yanitskiy <axilirator@gmail.com>
7 * All rights reserved.
8 *
9 * Released under the terms of GNU General Public License, Version 2 or
10 * (at your option) any later version.
11 *
12 * SPDX-License-Identifier: GPL-2.0-or-later
13 */
14
Harald Weltee13cfb22019-04-23 16:52:02 +020015friend module MSC_Tests_Iu;
16
Harald Weltef6dd64d2017-11-19 12:09:51 +010017import from General_Types all;
18import from Osmocom_Types all;
19
20import from M3UA_Types all;
21import from M3UA_Emulation all;
22
23import from MTP3asp_Types all;
24import from MTP3asp_PortType all;
25
26import from SCCPasp_Types all;
27import from SCCP_Types all;
28import from SCCP_Emulation all;
29
30import from SCTPasp_Types all;
31import from SCTPasp_PortType all;
32
Harald Weltea49e36e2018-01-21 19:29:33 +010033import from Osmocom_CTRL_Functions all;
34import from Osmocom_CTRL_Types all;
35import from Osmocom_CTRL_Adapter all;
36
Harald Welte3ca1c902018-01-24 18:51:27 +010037import from TELNETasp_PortType all;
38import from Osmocom_VTY_Functions all;
39
Harald Weltea49e36e2018-01-21 19:29:33 +010040import from MNCC_Emulation all;
Harald Welte2bb825f2018-01-22 11:31:18 +010041import from MNCC_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010042
Harald Welte4aa970c2018-01-26 10:38:09 +010043import from MGCP_Emulation all;
44import from MGCP_Types all;
45import from MGCP_Templates all;
46import from SDP_Types all;
47
Harald Weltea49e36e2018-01-21 19:29:33 +010048import from GSUP_Emulation all;
49import from GSUP_Types all;
50import from IPA_Emulation all;
51
Harald Weltef6dd64d2017-11-19 12:09:51 +010052import from BSSAP_Types all;
Harald Welte6811d102019-04-14 22:23:14 +020053import from RAN_Adapter all;
Harald Weltea49e36e2018-01-21 19:29:33 +010054import from BSSAP_CodecPort all;
55import from BSSMAP_Templates all;
Harald Welte6811d102019-04-14 22:23:14 +020056import from RAN_Emulation all;
Harald Weltea49e36e2018-01-21 19:29:33 +010057import from BSC_ConnectionHandler all;
Harald Weltee13cfb22019-04-23 16:52:02 +020058import from RANAP_Templates all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010059
Harald Welte4263c522018-12-06 11:56:27 +010060import from SGsAP_Templates all;
61import from SGsAP_Types all;
62import from SGsAP_Emulation all;
63
Harald Weltea49e36e2018-01-21 19:29:33 +010064import from MobileL3_Types all;
65import from MobileL3_CommonIE_Types all;
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +070066import from MobileL3_SMS_Types all;
Harald Weltea49e36e2018-01-21 19:29:33 +010067import from L3_Templates all;
Harald Welte158a7ca2018-02-16 18:11:31 +010068import from L3_Common all;
Harald Weltef6dd64d2017-11-19 12:09:51 +010069
Harald Weltef640a012018-04-14 17:49:21 +020070import from SMPP_Types all;
71import from SMPP_Templates all;
72import from SMPP_Emulation all;
73
Stefan Sperlingc307e682018-06-14 15:15:46 +020074import from SCCP_Templates all;
75
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070076import from SS_Types all;
77import from SS_Templates all;
78import from USSD_Helpers all;
Harald Welte4263c522018-12-06 11:56:27 +010079import from DNS_Helpers all;
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +070080
Philipp Maier948747b2019-04-02 15:22:33 +020081import from TCCConversion_Functions all;
82
Harald Welte9b751a62019-04-14 17:39:29 +020083const integer NUM_BSC := 3;
Harald Weltef6dd64d2017-11-19 12:09:51 +010084
Harald Welte4263c522018-12-06 11:56:27 +010085/* Needed for SGsAP SMS */
86import from MobileL3_SMS_Types all;
87
Harald Weltea4ca4462018-02-09 00:17:14 +010088type component MTC_CT extends CTRL_Adapter_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +010089 var boolean g_initialized := false;
Harald Weltea49e36e2018-01-21 19:29:33 +010090
Harald Welte6811d102019-04-14 22:23:14 +020091 var RAN_Adapter g_bssap[NUM_BSC];
Harald Weltea4ca4462018-02-09 00:17:14 +010092
Harald Weltea49e36e2018-01-21 19:29:33 +010093 /* no 'adapter_CT' for MNCC or GSUP */
94 var MNCC_Emulation_CT vc_MNCC;
Harald Welte4aa970c2018-01-26 10:38:09 +010095 var MGCP_Emulation_CT vc_MGCP;
Harald Weltea49e36e2018-01-21 19:29:33 +010096 var GSUP_Emulation_CT vc_GSUP;
97 var IPA_Emulation_CT vc_GSUP_IPA;
Harald Weltef640a012018-04-14 17:49:21 +020098 var SMPP_Emulation_CT vc_SMPP;
Harald Welte4263c522018-12-06 11:56:27 +010099 var SGsAP_Emulation_CT vc_SGsAP;
Harald Weltea49e36e2018-01-21 19:29:33 +0100100
101 /* only to get events from IPA underneath GSUP */
102 port IPA_CTRL_PT GSUP_IPA_EVENT;
Harald Welte3ca1c902018-01-24 18:51:27 +0100103 /* VTY to MSC */
104 port TELNETasp_PT MSCVTY;
Philipp Maier328d1662018-03-07 10:40:27 +0100105
106 /* A port to directly send BSSAP messages. This port is used for
107 * tests that require low level access to sen arbitrary BSSAP
108 * messages. Run f_init_bssap_direct() to connect and initialize */
109 port BSSAP_CODEC_PT BSSAP_DIRECT;
110
111 /* When BSSAP messages are directly sent, then the connection
112 * handler is not active, which means that also no guard timer is
113 * set up. The following timer will serve as a replacement */
114 timer Tguard_direct := 60.0;
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100115
116 /* Configure T(tias) over VTY, seconds */
117 var integer g_msc_sccp_timer_ias := 7 * 60;
118 /* Configure T(tiar) over VTY, seconds */
119 var integer g_msc_sccp_timer_iar := 15 * 60;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100120}
121
122modulepar {
Harald Weltea49e36e2018-01-21 19:29:33 +0100123 /* remote parameters of IUT */
124 charstring mp_msc_ip := "127.0.0.1";
125 integer mp_msc_ctrl_port := 4255;
126 integer mp_msc_vty_port := 4254;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100127
Harald Weltea49e36e2018-01-21 19:29:33 +0100128 /* local parameters of emulated HLR */
Philipp Maier9b690e42018-12-21 11:50:03 +0100129 boolean mp_mm_info := false;
Harald Weltea49e36e2018-01-21 19:29:33 +0100130 charstring mp_hlr_ip := "127.0.0.1";
131 integer mp_hlr_port := 4222;
Harald Welte6126fb02018-01-27 20:08:24 +0100132 charstring mp_mgw_ip := "127.0.0.1";
133 integer mp_mgw_port := 2427;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100134
Harald Weltea49e36e2018-01-21 19:29:33 +0100135 charstring mp_msc_mncc := "/tmp/mncc";
Harald Weltea4ca4462018-02-09 00:17:14 +0100136
Harald Weltef640a012018-04-14 17:49:21 +0200137 integer mp_msc_smpp_port := 2775;
138 charstring mp_smpp_system_id := "msc_tester";
139 charstring mp_smpp_password := "osmocom1";
Harald Welte4263c522018-12-06 11:56:27 +0100140 charstring mp_mme_name := "mmec01.mmegi0001.mme.epc.mnc070.mcc901.3gppnetwork.org";
141 charstring mp_vlr_name := "vlr.example.net";
Harald Weltef640a012018-04-14 17:49:21 +0200142
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200143 /* Whether to enable osmux tests. Can be dropped completely and enable
144 unconditionally once new version of osmo-msc is released (current
145 version: 1.3.1) */
146 boolean mp_enable_osmux_test := true;
147
Harald Welte6811d102019-04-14 22:23:14 +0200148 RAN_Configurations mp_bssap_cfg := {
Philipp Maier75932982018-03-27 14:52:35 +0200149 {
150 sccp_service_type := "mtp3_itu",
151 sctp_addr := { 23905, "127.0.0.1", 2905, "127.0.0.1" },
152 own_pc := 185,
153 own_ssn := 254,
154 peer_pc := 187,
155 peer_ssn := 254,
156 sio := '83'O,
157 rctx := 0
158 },
159 {
160 sccp_service_type := "mtp3_itu",
161 sctp_addr := { 23906, "127.0.0.1", 2905, "127.0.0.1" },
162 own_pc := 186,
163 own_ssn := 254,
164 peer_pc := 187,
165 peer_ssn := 254,
166 sio := '83'O,
167 rctx := 1
168 }
Harald Weltea4ca4462018-02-09 00:17:14 +0100169 };
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200170
171 boolean mp_enable_cell_id_test := true;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100172}
173
Philipp Maier328d1662018-03-07 10:40:27 +0100174/* altstep for the global guard timer (only used when BSSAP_DIRECT
175 * is used for communication */
176private altstep as_Tguard_direct() runs on MTC_CT {
177 [] Tguard_direct.timeout {
178 setverdict(fail, "Tguard timeout");
Daniel Willmannafce8662018-07-06 23:11:32 +0200179 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +0100180 }
181}
Harald Weltef6dd64d2017-11-19 12:09:51 +0100182
Neels Hofmeyr2ca1ab42019-03-08 03:45:43 +0100183private altstep as_optional_cc_rel(CallParameters cpars, boolean respond := false) runs on BSC_ConnHdlr {
184 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id))) {
185 if (respond) {
186 var BIT1 tid_remote := '1'B;
187 if (cpars.mo_call) {
188 tid_remote := '0'B;
189 }
190 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id, tid_remote)));
191 }
192 }
Neels Hofmeyrde76f052019-02-26 05:02:46 +0100193}
194
Harald Weltef640a012018-04-14 17:49:21 +0200195function f_init_smpp(charstring id) runs on MTC_CT {
196 id := id & "-SMPP";
197 var EsmePars pars := {
198 mode := MODE_TRANSCEIVER,
199 bind := {
200 system_id := mp_smpp_system_id,
201 password := mp_smpp_password,
202 system_type := "MSC_Tests",
203 interface_version := hex2int('34'H),
204 addr_ton := unknown,
205 addr_npi := unknown,
206 address_range := ""
207 },
208 esme_role := true
209 }
210
211 vc_SMPP := SMPP_Emulation_CT.create(id);
212 map(vc_SMPP:SMPP_PORT, system:SMPP_PORT);
Harald Welte4698a4c2020-08-18 22:57:52 +0200213 vc_SMPP.start(SMPP_Emulation.main_client(pars, mp_msc_ip, mp_msc_smpp_port, "", 0));
Harald Weltef640a012018-04-14 17:49:21 +0200214}
215
216
Harald Weltea49e36e2018-01-21 19:29:33 +0100217function f_init_mncc(charstring id) runs on MTC_CT {
218 id := id & "-MNCC";
219 var MnccOps ops := {
220 create_cb := refers(MNCC_Emulation.ExpectedCreateCallback),
221 unitdata_cb := refers(MNCC_Emulation.DummyUnitdataCallback)
222 }
223
224 vc_MNCC := MNCC_Emulation_CT.create(id);
225 map(vc_MNCC:MNCC, system:MNCC_CODEC_PT);
226 vc_MNCC.start(MNCC_Emulation.main(ops, id, mp_msc_mncc));
Harald Weltef6dd64d2017-11-19 12:09:51 +0100227}
228
Harald Welte4aa970c2018-01-26 10:38:09 +0100229function f_init_mgcp(charstring id) runs on MTC_CT {
230 id := id & "-MGCP";
231 var MGCPOps ops := {
232 create_cb := refers(MGCP_Emulation.ExpectedCreateCallback),
233 unitdata_cb := refers(MGCP_Emulation.DummyUnitdataCallback)
234 }
235 var MGCP_conn_parameters pars := {
Harald Welte6126fb02018-01-27 20:08:24 +0100236 callagent_ip := mp_msc_ip,
Harald Welte4aa970c2018-01-26 10:38:09 +0100237 callagent_udp_port := -1,
Harald Welte6126fb02018-01-27 20:08:24 +0100238 mgw_ip := mp_mgw_ip,
Pau Espin Pedrol1a026a52019-06-18 17:21:52 +0200239 mgw_udp_port := mp_mgw_port,
240 multi_conn_mode := false
Harald Welte4aa970c2018-01-26 10:38:09 +0100241 }
242
243 vc_MGCP := MGCP_Emulation_CT.create(id);
244 map(vc_MGCP:MGCP, system:MGCP_CODEC_PT);
245 vc_MGCP.start(MGCP_Emulation.main(ops, pars, id));
246}
247
Philipp Maierc09a1312019-04-09 16:05:26 +0200248function ForwardUnitdataCallback(PDU_SGsAP msg)
249runs on SGsAP_Emulation_CT return template PDU_SGsAP {
250 SGsAP_CLIENT.send(msg);
251 return omit;
252}
253
Harald Welte4263c522018-12-06 11:56:27 +0100254function f_init_sgsap(charstring id) runs on MTC_CT {
255 id := id & "-SGsAP";
256 var SGsAPOps ops := {
257 create_cb := refers(SGsAP_Emulation.ExpectedCreateCallback),
Philipp Maierc09a1312019-04-09 16:05:26 +0200258 unitdata_cb := refers(ForwardUnitdataCallback)
Harald Welte4263c522018-12-06 11:56:27 +0100259 }
260 var SGsAP_conn_parameters pars := {
261 remote_ip := mp_msc_ip,
262 remote_sctp_port := 29118,
263 local_ip := "",
264 local_sctp_port := -1
265 }
266
267 vc_SGsAP := SGsAP_Emulation_CT.create(id);
268 map(vc_SGsAP:SGsAP, system:SGsAP_CODEC_PT);
269 vc_SGsAP.start(SGsAP_Emulation.main(ops, pars, id));
270}
271
272
Harald Weltea49e36e2018-01-21 19:29:33 +0100273function f_init_gsup(charstring id) runs on MTC_CT {
274 id := id & "-GSUP";
275 var GsupOps ops := {
276 create_cb := refers(GSUP_Emulation.ExpectedCreateCallback)
277 }
278
279 vc_GSUP_IPA := IPA_Emulation_CT.create(id & "-IPA");
280 vc_GSUP := GSUP_Emulation_CT.create(id);
281
282 map(vc_GSUP_IPA:IPA_PORT, system:IPA_CODEC_PT);
283 connect(vc_GSUP:GSUP, vc_GSUP_IPA:IPA_GSUP_PORT);
284 /* we use this hack to get events like ASP_IPA_EVENT_UP */
285 connect(vc_GSUP_IPA:IPA_CTRL_PORT, self:GSUP_IPA_EVENT);
286
287 vc_GSUP.start(GSUP_Emulation.main(ops, id));
288 vc_GSUP_IPA.start(IPA_Emulation.main_server(mp_hlr_ip, mp_hlr_port));
289
290 /* wait for incoming connection to GSUP port before proceeding */
291 timer T := 10.0;
292 T.start;
293 alt {
Vadim Yanitskiy61564be2020-05-18 20:44:14 +0700294 [] GSUP_IPA_EVENT.receive(tr_ASP_IPA_EV(ASP_IPA_EVENT_UP)) { }
Harald Weltea49e36e2018-01-21 19:29:33 +0100295 [] T.timeout {
Harald Welte458fd372018-03-21 11:26:23 +0100296 setverdict(fail, "No connection to GSUP Port");
Daniel Willmannafce8662018-07-06 23:11:32 +0200297 mtc.stop
Harald Weltea49e36e2018-01-21 19:29:33 +0100298 }
299 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100300}
301
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200302function f_init(integer num_bsc := 1, boolean sgsap := false, boolean gsup := true, boolean osmux := false) runs on MTC_CT {
Harald Weltef6dd64d2017-11-19 12:09:51 +0100303
304 if (g_initialized == true) {
305 return;
306 }
307 g_initialized := true;
308
Philipp Maier75932982018-03-27 14:52:35 +0200309 if (num_bsc > NUM_BSC) {
Daniel Willmannafce8662018-07-06 23:11:32 +0200310 testcase.stop("excess number of BSC instances requested");
Philipp Maier75932982018-03-27 14:52:35 +0200311 }
312
313 for (var integer i := 0; i < num_bsc; i := i + 1) {
314 if (isbound(mp_bssap_cfg[i])) {
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200315 var RanOps ranops := BSC_RanOps;
316 ranops.use_osmux := osmux;
317 f_ran_adapter_init(g_bssap[i], mp_bssap_cfg[i], "MSC_Test_" & int2str(i), ranops);
Harald Welte3ca0ce12019-04-23 17:18:48 +0200318 f_ran_adapter_start(g_bssap[i]);
Philipp Maier75932982018-03-27 14:52:35 +0200319 } else {
Daniel Willmannafce8662018-07-06 23:11:32 +0200320 testcase.stop("missing BSSAP configuration");
Philipp Maier75932982018-03-27 14:52:35 +0200321 }
322 }
323
Harald Weltea49e36e2018-01-21 19:29:33 +0100324 f_ipa_ctrl_start(mp_msc_ip, mp_msc_ctrl_port);
325 f_init_mncc("MSC_Test");
Harald Welte4aa970c2018-01-26 10:38:09 +0100326 f_init_mgcp("MSC_Test");
Philipp Maierc09a1312019-04-09 16:05:26 +0200327
328 if (gsup == true) {
329 f_init_gsup("MSC_Test");
330 }
Harald Weltef640a012018-04-14 17:49:21 +0200331 f_init_smpp("MSC_Test");
Philipp Maier57865482019-01-07 18:33:13 +0100332
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100333 if (sgsap == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100334 f_init_sgsap("MSC_Test");
335 }
Harald Welte3ca1c902018-01-24 18:51:27 +0100336
337 map(self:MSCVTY, system:MSCVTY);
338 f_vty_set_prompts(MSCVTY);
339 f_vty_transceive(MSCVTY, "enable");
Harald Welteb14c77a2018-01-25 17:25:44 +0100340
341 /* set some defaults */
342 f_vty_config(MSCVTY, "network", "authentication optional");
343 f_vty_config(MSCVTY, "msc", "assign-tmsi");
Oliver Smith1d118ff2019-07-03 10:57:35 +0200344 f_vty_config(MSCVTY, "msc", "check-imei-rqd 0");
Harald Welteb14c77a2018-01-25 17:25:44 +0100345 f_vty_config(MSCVTY, "network", "encryption a5 0");
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100346 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer ias " & int2str(g_msc_sccp_timer_ias));
347 f_vty_config(MSCVTY, "cs7 instance 0", "sccp-timer iar " & int2str(g_msc_sccp_timer_iar));
Pau Espin Pedrol690d6592019-05-31 17:56:32 +0200348 if (mp_enable_osmux_test) {
349 if (osmux) {
350 f_vty_config(MSCVTY, "msc", "osmux on");
351 } else {
352 f_vty_config(MSCVTY, "msc", "osmux off");
353 }
Pau Espin Pedrol3dd33bc2019-05-31 17:51:20 +0200354 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100355}
356
Philipp Maier328d1662018-03-07 10:40:27 +0100357/* Initialize for a direct connection to BSSAP. This function is an alternative
358 * to f_init() when the high level functions of the BSC_ConnectionHandler are
359 * not needed. */
360function f_init_bssap_direct() runs on MTC_CT {
Harald Welte3ca0ce12019-04-23 17:18:48 +0200361 f_ran_adapter_init(g_bssap[0], mp_bssap_cfg[0], "MSC_Test", omit);
Philipp Maier75932982018-03-27 14:52:35 +0200362 connect(g_bssap[0].vc_SCCP:SCCP_SP_PORT, self:BSSAP_DIRECT);
Philipp Maier328d1662018-03-07 10:40:27 +0100363
364 /* Start guard timer and activate it as default */
365 Tguard_direct.start
366 activate(as_Tguard_direct());
367}
368
Harald Weltea49e36e2018-01-21 19:29:33 +0100369type function void_fn(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100370
Harald Weltea49e36e2018-01-21 19:29:33 +0100371/* FIXME: move into BSC_ConnectionHandler? */
Harald Welte9b751a62019-04-14 17:39:29 +0200372function f_init_pars(integer imsi_suffix, boolean sgsap := false, boolean gsup := true, integer ran_idx := 0,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200373 boolean ran_is_geran := true, boolean use_osmux := false, OCT4 gsup_sid := '20000101'O,
374 boolean verify_cell_id := true)
Harald Weltef9abf8d2019-04-21 13:07:17 +0200375runs on MTC_CT return BSC_ConnHdlrPars {
Harald Weltede371492018-01-27 23:44:41 +0100376 var BSC_ConnHdlrNetworkPars net_pars := {
377 kc_support := '0A'O, /* A5/1 and A5/3 enabled */
378 expect_tmsi := true,
379 expect_auth := false,
Oliver Smith1d118ff2019-07-03 10:57:35 +0200380 expect_ciph := false,
381 expect_imei := false,
382 expect_imei_early := false,
383 check_imei_result := OSMO_GSUP_IMEI_RESULT_ACK,
384 check_imei_error := false
Harald Weltede371492018-01-27 23:44:41 +0100385 };
Harald Weltea49e36e2018-01-21 19:29:33 +0100386 var BSC_ConnHdlrPars pars := {
Harald Weltef9abf8d2019-04-21 13:07:17 +0200387 sccp_addr_own := g_bssap[ran_idx].sccp_addr_own,
388 sccp_addr_peer := g_bssap[ran_idx].sccp_addr_peer,
Harald Welteedbab812018-03-18 16:02:25 +0100389 cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42)),
Harald Welte81b7f9d2018-01-24 19:06:24 +0100390 imei := f_gen_imei(imsi_suffix),
391 imsi := f_gen_imsi(imsi_suffix),
392 msisdn := f_gen_msisdn(imsi_suffix),
Harald Welte256571e2018-01-24 18:47:19 +0100393 tmsi := omit,
Harald Welte9de84792018-01-28 01:06:35 +0100394 cm1 := valueof(ts_CM1),
Harald Welte82600572018-01-21 20:54:08 +0100395 cm2 := valueof(ts_CM2_default),
Harald Welte16114282018-01-24 22:41:21 +0100396 cm3 := omit,
Harald Weltede371492018-01-27 23:44:41 +0100397 vec := omit,
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100398 net := net_pars,
Philipp Maieraeb29a82018-11-08 17:40:53 +0100399 send_early_cm := true,
400 ipa_ctrl_ip := mp_msc_ip,
401 ipa_ctrl_port := mp_msc_ctrl_port,
Philipp Maier9b690e42018-12-21 11:50:03 +0100402 ipa_ctrl_enable := true,
Philipp Maier57865482019-01-07 18:33:13 +0100403 mm_info := mp_mm_info,
Philipp Maierc09a1312019-04-09 16:05:26 +0200404 sgsap_enable := sgsap,
Harald Weltef9abf8d2019-04-21 13:07:17 +0200405 gsup_enable := gsup,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +0100406 gsup_sid := gsup_sid,
Harald Weltec1f937a2019-04-21 21:19:23 +0200407 ran_idx := ran_idx,
Harald Welte9b751a62019-04-14 17:39:29 +0200408 use_umts_aka := false,
Pau Espin Pedrola65697d2019-05-21 12:54:39 +0200409 ran_is_geran := ran_is_geran,
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200410 use_osmux := use_osmux,
411 verify_cell_id := mp_enable_cell_id_test and verify_cell_id
Harald Weltea49e36e2018-01-21 19:29:33 +0100412 };
Harald Weltee13cfb22019-04-23 16:52:02 +0200413 if (not ran_is_geran) {
414 pars.use_umts_aka := true;
415 pars.net.expect_auth := true;
416 }
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100417 return pars;
418}
419
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200420function f_start_handler_with_pars(void_fn fn, BSC_ConnHdlrPars pars, integer bssap_idx := 0) runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100421 var BSC_ConnHdlr vc_conn;
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200422 var charstring id := testcasename() & int2str(bssap_idx);
Harald Weltea49e36e2018-01-21 19:29:33 +0100423
424 vc_conn := BSC_ConnHdlr.create(id);
425 /* BSSMAP part / A interface */
Neels Hofmeyr0ac63152019-05-07 01:20:17 +0200426 connect(vc_conn:BSSAP, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:CLIENT);
427 connect(vc_conn:BSSAP_PROC, g_bssap[pars.ran_idx + bssap_idx].vc_RAN:PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100428 /* MNCC part */
429 connect(vc_conn:MNCC, vc_MNCC:MNCC_CLIENT);
430 connect(vc_conn:MNCC_PROC, vc_MNCC:MNCC_PROC);
Harald Welte4aa970c2018-01-26 10:38:09 +0100431 /* MGCP part */
432 connect(vc_conn:MGCP, vc_MGCP:MGCP_CLIENT);
433 connect(vc_conn:MGCP_PROC, vc_MGCP:MGCP_PROC);
Harald Weltea49e36e2018-01-21 19:29:33 +0100434 /* GSUP part */
Philipp Maierc09a1312019-04-09 16:05:26 +0200435 if (pars.gsup_enable == true) {
436 connect(vc_conn:GSUP, vc_GSUP:GSUP_CLIENT);
437 connect(vc_conn:GSUP_PROC, vc_GSUP:GSUP_PROC);
438 }
Harald Weltef640a012018-04-14 17:49:21 +0200439 /* SMPP part */
440 connect(vc_conn:SMPP, vc_SMPP:SMPP_CLIENT);
441 connect(vc_conn:SMPP_PROC, vc_SMPP:SMPP_PROC);
Harald Welte4263c522018-12-06 11:56:27 +0100442 /* SGs part */
Philipp Maier8e07a4a2019-02-14 18:23:28 +0100443 if (pars.sgsap_enable == true) {
Philipp Maier57865482019-01-07 18:33:13 +0100444 connect(vc_conn:SGsAP, vc_SGsAP:SGsAP_CLIENT);
445 connect(vc_conn:SGsAP_PROC, vc_SGsAP:SGsAP_PROC);
446 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100447
Harald Weltea10db902018-01-27 12:44:49 +0100448 /* We cannot use vc_conn.start(f_init_handler(fn, id, pars)); as we cannot have
449 * a stand-alone 'derefers()' call, see https://www.eclipse.org/forums/index.php/t/1091364/ */
Harald Weltea49e36e2018-01-21 19:29:33 +0100450 vc_conn.start(derefers(fn)(id, pars));
451 return vc_conn;
452}
453
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200454function f_start_handler(void_fn fn, integer imsi_suffix, integer ran_idx := 0, boolean ran_is_geran := true, boolean use_osmux := false,
455 boolean verify_cell_id := true)
Harald Welte9b751a62019-04-14 17:39:29 +0200456runs on MTC_CT return BSC_ConnHdlr {
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200457 return f_start_handler_with_pars(fn, f_init_pars(imsi_suffix, ran_idx := ran_idx, ran_is_geran := ran_is_geran, use_osmux := use_osmux, verify_cell_id := verify_cell_id));
Neels Hofmeyr9adaa702018-03-01 20:23:19 +0100458}
459
Harald Weltea49e36e2018-01-21 19:29:33 +0100460private function f_tc_lu_imsi_noauth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100461 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100462 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100463}
Harald Weltea49e36e2018-01-21 19:29:33 +0100464testcase TC_lu_imsi_noauth_tmsi() runs on MTC_CT {
465 var BSC_ConnHdlr vc_conn;
466 f_init();
467
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100468 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi), 1);
Harald Weltea49e36e2018-01-21 19:29:33 +0100469 vc_conn.done;
470}
471
472private function f_tc_lu_imsi_noauth_notmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100473 pars.net.expect_tmsi := false;
Harald Weltea10db902018-01-27 12:44:49 +0100474 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100475 f_perform_lu();
Harald Weltea49e36e2018-01-21 19:29:33 +0100476}
Harald Weltea49e36e2018-01-21 19:29:33 +0100477testcase TC_lu_imsi_noauth_notmsi() runs on MTC_CT {
478 var BSC_ConnHdlr vc_conn;
479 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100480 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
Harald Weltea49e36e2018-01-21 19:29:33 +0100481
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100482 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi), 2);
Harald Weltea49e36e2018-01-21 19:29:33 +0100483 vc_conn.done;
484}
485
486/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
Harald Weltee13cfb22019-04-23 16:52:02 +0200487friend function f_tc_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100488 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100489 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
490
491 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200492 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100493 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100494 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
495 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
496 alt {
Harald Welte5946b332018-03-18 23:32:21 +0100497 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej(int2oct(23,1)))) {
498 f_expect_clear();
499 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100500 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
501 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200502 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100503 }
504 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100505}
506testcase TC_lu_imsi_reject() runs on MTC_CT {
507 var BSC_ConnHdlr vc_conn;
508 f_init();
509
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200510 vc_conn := f_start_handler(refers(f_tc_lu_imsi_reject), 3, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100511 vc_conn.done;
512}
513
Harald Weltee13cfb22019-04-23 16:52:02 +0200514
515
Harald Weltea49e36e2018-01-21 19:29:33 +0100516/* Do LU by IMSI, timeout on GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +0200517friend function f_tc_lu_imsi_timeout_gsup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100518 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100519 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
520
521 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +0200522 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyrd076c522019-11-28 01:00:52 +0100523 f_mm_common();
Harald Weltea49e36e2018-01-21 19:29:33 +0100524 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
525 /* Normally the HLR would need to respond here, but we decide to force a timeout here */
526 alt {
527 /* FIXME: Expect specific reject cause */
Harald Welte5946b332018-03-18 23:32:21 +0100528 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
529 f_expect_clear();
530 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100531 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
532 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
Daniel Willmannafce8662018-07-06 23:11:32 +0200533 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100534 }
535 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100536}
537testcase TC_lu_imsi_timeout_gsup() runs on MTC_CT {
538 var BSC_ConnHdlr vc_conn;
539 f_init();
540
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200541 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_gsup), 4, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100542 vc_conn.done;
543}
544
Harald Weltee13cfb22019-04-23 16:52:02 +0200545
Harald Welte7b1b2812018-01-22 21:23:06 +0100546private function f_tc_lu_imsi_auth_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +0100547 pars.net.expect_auth := true;
Harald Weltea10db902018-01-27 12:44:49 +0100548 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100549 f_perform_lu();
Harald Welte7b1b2812018-01-22 21:23:06 +0100550}
551testcase TC_lu_imsi_auth_tmsi() runs on MTC_CT {
552 var BSC_ConnHdlr vc_conn;
553 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100554 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte7b1b2812018-01-22 21:23:06 +0100555
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100556 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi), 5);
Harald Welte7b1b2812018-01-22 21:23:06 +0100557 vc_conn.done;
558}
559
Harald Weltee13cfb22019-04-23 16:52:02 +0200560
561friend function f_tc_lu_imsi_auth3g_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte8a397ae2019-04-21 22:03:37 +0200562 pars.net.expect_auth := true;
563 pars.use_umts_aka := true;
564 f_init_handler(pars);
565 f_perform_lu();
566}
567testcase TC_lu_imsi_auth3g_tmsi() runs on MTC_CT {
568 var BSC_ConnHdlr vc_conn;
569 f_init();
570 f_vty_config(MSCVTY, "network", "authentication required");
571
572 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi), 1005);
573 vc_conn.done;
574}
Harald Weltea49e36e2018-01-21 19:29:33 +0100575
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100576/* Proceed with LU but never receive an TMSI Realloc from MS after LU Accept (OS#4337).
577 * TS 24.008 sec 4.3.1.5 states MSC should simply release all MM connections.
578 */
579friend function f_tc_lu_imsi_timeout_tmsi_realloc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
580
581 f_init_handler(pars);
582
583 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
584 var PDU_DTAP_MT dtap_mt;
585
586 /* tell GSUP dispatcher to send this IMSI to us */
587 f_create_gsup_expect(hex2str(g_pars.imsi));
588
589 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
590 if (g_pars.ran_is_geran) {
591 f_bssap_compl_l3(l3_lu);
592 if (g_pars.send_early_cm) {
593 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
594 }
595 } else {
596 f_ranap_initial_ue(l3_lu);
597 }
598
599 f_mm_imei_early();
600 f_mm_common();
601 f_msc_lu_hlr();
602 f_mm_imei();
603
604 alt {
605 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) -> value dtap_mt {}
606 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
607 setverdict(fail, "Expected LU ACK, but received LU REJ");
608 mtc.stop;
609 }
610 }
611
612 /* currently (due to bug OS#4337), an extra LU reject is received before
613 terminating the connection. Enabling following line makes the test
614 pass: */
615 //f_expect_lu_reject('16'O); /* Cause: congestion */
616
617 /* f_expect_lu_reject() already waits for T"-1" (X1, 5 seconds), but give some
618 extra time to avoid race conditons... */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200619 f_expect_clear(7.0, verify_vlr_cell_id := false);
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +0100620
621 setverdict(pass);
622}
623testcase TC_lu_imsi_timeout_tmsi_realloc() runs on MTC_CT {
624 var BSC_ConnHdlr vc_conn;
625 f_init();
626
627 vc_conn := f_start_handler(refers(f_tc_lu_imsi_timeout_tmsi_realloc), 5);
628 vc_conn.done;
629}
630
Harald Weltee13cfb22019-04-23 16:52:02 +0200631
Harald Weltea49e36e2018-01-21 19:29:33 +0100632/* Send CM SERVICE REQ for IMSI that has never performed LU before */
Harald Weltee13cfb22019-04-23 16:52:02 +0200633friend function f_tc_cmserv_imsi_unknown(charstring id, BSC_ConnHdlrPars pars)
Harald Weltea49e36e2018-01-21 19:29:33 +0100634runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100635 f_init_handler(pars);
Harald Weltea49e36e2018-01-21 19:29:33 +0100636
637 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welteedbab812018-03-18 16:02:25 +0100638 var BSSMAP_IE_CellIdentifier cell_id := valueof(ts_CellId_CGI('262'H, '42'H, 23, 42));
Harald Welte6ed6bf92018-01-24 21:09:15 +0100639 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltea49e36e2018-01-21 19:29:33 +0100640
641 f_create_gsup_expect(hex2str(g_pars.imsi));
642
643 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200644 f_cl3_or_initial_ue(l3_info);
Harald Welteb7817992019-05-09 13:15:39 +0200645 f_mm_auth();
Harald Weltea49e36e2018-01-21 19:29:33 +0100646
647 timer T := 10.0;
Harald Weltef6dd64d2017-11-19 12:09:51 +0100648 T.start;
649 alt {
Harald Weltea49e36e2018-01-21 19:29:33 +0100650 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
651 //[] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_ACC)) { }
Daniel Willmannafce8662018-07-06 23:11:32 +0200652 [] BSSAP.receive {
653 setverdict(fail, "Received unexpected BSSAP");
654 mtc.stop;
655 }
Harald Weltea49e36e2018-01-21 19:29:33 +0100656 [] GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi)) {
657 setverdict(fail, "Unexpected GSUP UL REQ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200658 mtc.stop;
Harald Weltea49e36e2018-01-21 19:29:33 +0100659 }
Daniel Willmannafce8662018-07-06 23:11:32 +0200660 [] T.timeout {
Neels Hofmeyrf1c3c212020-08-19 13:15:32 +0000661 setverdict(fail, "Timeout waiting for CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200662 mtc.stop;
663 }
Harald Weltef6dd64d2017-11-19 12:09:51 +0100664 }
665
Harald Welte1ddc7162018-01-27 14:25:46 +0100666 f_expect_clear();
Harald Weltef6dd64d2017-11-19 12:09:51 +0100667}
Harald Weltea49e36e2018-01-21 19:29:33 +0100668testcase TC_cmserv_imsi_unknown() runs on MTC_CT {
669 var BSC_ConnHdlr vc_conn;
670 f_init();
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200671 vc_conn := f_start_handler(refers(f_tc_cmserv_imsi_unknown), 6, verify_cell_id := false);
Harald Weltea49e36e2018-01-21 19:29:33 +0100672 vc_conn.done;
673}
674
Harald Weltee13cfb22019-04-23 16:52:02 +0200675
676friend function f_tc_lu_and_mo_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100677 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +0200678 var CallParameters cpars := valueof(t_CallParams);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +0100679 f_perform_lu();
Harald Welteb71901a2018-01-26 19:16:05 +0100680 f_mo_call(cpars);
Harald Welte2bb825f2018-01-22 11:31:18 +0100681}
682testcase TC_lu_and_mo_call() runs on MTC_CT {
683 var BSC_ConnHdlr vc_conn;
684 f_init();
685
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100686 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_call), 7);
Harald Welte071ed732018-01-23 19:53:52 +0100687 vc_conn.done;
688}
689
Pau Espin Pedrola42745c2020-01-10 18:03:28 +0100690/* Verify T(iar) triggers and releases the channel */
691friend function f_lu_and_mo_call_sccp_tiar_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
692 timer T_wait_iar := int2float(5 + 1); /* g_msc_sccp_timer_iar + Give extra time (+1 sec) */
693 f_init_handler(pars);
694 var CallParameters cpars := valueof(t_CallParams);
695 f_perform_lu();
696 f_mo_call_establish(cpars);
697
698 /* Expect the channel cleared upon T(iar) triggered: */
699 T_wait_iar.start;
700 alt {
701 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {
702 T_wait_iar.stop
703 setverdict(pass);
704 }
705 [] MGCP.receive(tr_DLCX(?)) { repeat; }
706 [] T_wait_iar.timeout {
707 setverdict(fail, "Timeout waiting for T(iar) triggered SCCP RSLD");
708 mtc.stop;
709 }
710 }
711
712 setverdict(pass);
713}
714testcase TC_lu_and_mo_call_sccp_tiar_timeout() runs on MTC_CT {
715 var BSC_ConnHdlr vc_conn;
716
717 /* Set T(iar) in MSC low enough that it will trigger before other side
718 has time to keep alive with a T(ias). Keep recommended ratio of
719 T(iar) >= T(ias)*2 */
720 g_msc_sccp_timer_ias := 2;
721 g_msc_sccp_timer_iar := 5;
722
723 f_init();
724
725 vc_conn := f_start_handler(refers(f_lu_and_mo_call_sccp_tiar_timeout), 89);
726 vc_conn.done;
727}
728
Harald Weltee13cfb22019-04-23 16:52:02 +0200729
Harald Welte071ed732018-01-23 19:53:52 +0100730/* Test LU (with authentication enabled), where HLR times out sending SAI response */
Harald Weltee13cfb22019-04-23 16:52:02 +0200731friend function f_tc_lu_auth_sai_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100732 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100733
734 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
735 var PDU_DTAP_MT dtap_mt;
736
737 /* tell GSUP dispatcher to send this IMSI to us */
738 f_create_gsup_expect(hex2str(g_pars.imsi));
739
740 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200741 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100742
743 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200744 if (pars.ran_is_geran) {
745 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
746 }
Harald Welte071ed732018-01-23 19:53:52 +0100747
748 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
749 /* The HLR would normally return an auth vector here, but we fail to do so. */
750
751 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100752 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100753}
754testcase TC_lu_auth_sai_timeout() runs on MTC_CT {
755 var BSC_ConnHdlr vc_conn;
756 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100757 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100758
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200759 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_timeout), 8, verify_cell_id := false);
Harald Welte071ed732018-01-23 19:53:52 +0100760 vc_conn.done;
761}
762
Harald Weltee13cfb22019-04-23 16:52:02 +0200763
Harald Welte071ed732018-01-23 19:53:52 +0100764/* Test LU (with authentication enabled), where HLR rejects sending SAI error */
Harald Weltee13cfb22019-04-23 16:52:02 +0200765friend function f_tc_lu_auth_sai_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100766 f_init_handler(pars);
Harald Welte071ed732018-01-23 19:53:52 +0100767
768 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
769 var PDU_DTAP_MT dtap_mt;
770
771 /* tell GSUP dispatcher to send this IMSI to us */
772 f_create_gsup_expect(hex2str(g_pars.imsi));
773
774 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200775 f_cl3_or_initial_ue(l3_lu);
Harald Welte071ed732018-01-23 19:53:52 +0100776
777 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200778 if (pars.ran_is_geran) {
779 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
780 }
Harald Welte071ed732018-01-23 19:53:52 +0100781
782 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
783 GSUP.send(ts_GSUP_SAI_ERR(g_pars.imsi, 13));
784
785 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej));
Harald Welte1ddc7162018-01-27 14:25:46 +0100786 f_expect_clear();
Harald Welte071ed732018-01-23 19:53:52 +0100787}
788testcase TC_lu_auth_sai_err() runs on MTC_CT {
789 var BSC_ConnHdlr vc_conn;
790 f_init();
Harald Welte3ca1c902018-01-24 18:51:27 +0100791 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte071ed732018-01-23 19:53:52 +0100792
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200793 vc_conn := f_start_handler(refers(f_tc_lu_auth_sai_err), 9, verify_cell_id := false);
Harald Welte2bb825f2018-01-22 11:31:18 +0100794 vc_conn.done;
795}
Harald Weltea49e36e2018-01-21 19:29:33 +0100796
Harald Weltee13cfb22019-04-23 16:52:02 +0200797
Harald Weltebc881782018-01-23 20:09:15 +0100798/* Test LU but BSC will send a clear request in the middle */
799private function f_tc_lu_clear_request(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100800 f_init_handler(pars);
Harald Weltebc881782018-01-23 20:09:15 +0100801
802 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
803 var PDU_DTAP_MT dtap_mt;
804
805 /* tell GSUP dispatcher to send this IMSI to us */
806 f_create_gsup_expect(hex2str(g_pars.imsi));
807
808 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200809 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +0200810 f_expect_common_id();
Harald Weltebc881782018-01-23 20:09:15 +0100811
812 /* Send Early Classmark, just for the fun of it */
813 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
814
815 f_sleep(1.0);
816 /* send clear request in the middle of the LU */
817 BSSAP.send(ts_BSSMAP_ClearRequest(0));
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200818 alt {
819 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { repeat; }
820 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {}
821 }
Harald Weltebc881782018-01-23 20:09:15 +0100822 BSSAP.send(ts_BSSMAP_ClearComplete);
Harald Welte89a32492018-01-27 19:07:28 +0100823 alt {
824 /* See https://osmocom.org/issues/2862 */
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200825 [] BSSAP.receive(tr_BSSMAP_ClearCommand) {
826 setverdict(fail, "Got a second Clear Command, only one expected");
Daniel Willmannafce8662018-07-06 23:11:32 +0200827 mtc.stop;
Neels Hofmeyr2b326fa2018-04-06 00:59:36 +0200828 repeat;
829 }
Harald Welte6811d102019-04-14 22:23:14 +0200830 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte89a32492018-01-27 19:07:28 +0100831 }
Harald Weltebc881782018-01-23 20:09:15 +0100832 setverdict(pass);
833}
834testcase TC_lu_clear_request() runs on MTC_CT {
835 var BSC_ConnHdlr vc_conn;
836 f_init();
837
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100838 vc_conn := f_start_handler(refers(f_tc_lu_clear_request), 10);
Harald Weltebc881782018-01-23 20:09:15 +0100839 vc_conn.done;
840}
841
Harald Welte66af9e62018-01-24 17:28:21 +0100842/* Test LU but BSC will send a clear request in the middle */
Harald Weltee13cfb22019-04-23 16:52:02 +0200843friend function f_tc_lu_disconnect(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100844 f_init_handler(pars);
Harald Welte66af9e62018-01-24 17:28:21 +0100845
846 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
847 var PDU_DTAP_MT dtap_mt;
848
849 /* tell GSUP dispatcher to send this IMSI to us */
850 f_create_gsup_expect(hex2str(g_pars.imsi));
851
852 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200853 f_cl3_or_initial_ue(l3_lu);
Harald Welte66af9e62018-01-24 17:28:21 +0100854
855 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200856 if (pars.ran_is_geran) {
857 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
858 }
Harald Welte66af9e62018-01-24 17:28:21 +0100859
860 f_sleep(1.0);
861 /* send clear request in the middle of the LU */
Harald Welte6811d102019-04-14 22:23:14 +0200862 BSSAP.send(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_REQ);
Harald Welte66af9e62018-01-24 17:28:21 +0100863 setverdict(pass);
Neels Hofmeyrbb825c92019-03-06 15:35:50 +0100864 f_sleep(1.0);
Harald Welte66af9e62018-01-24 17:28:21 +0100865}
866testcase TC_lu_disconnect() runs on MTC_CT {
867 var BSC_ConnHdlr vc_conn;
868 f_init();
869
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100870 vc_conn := f_start_handler(refers(f_tc_lu_disconnect), 11);
Harald Welte66af9e62018-01-24 17:28:21 +0100871 vc_conn.done;
872}
873
Harald Welteba7b6d92018-01-23 21:32:34 +0100874/* Test LU but with illegal mobile identity type = IMEI */
Harald Weltee13cfb22019-04-23 16:52:02 +0200875friend function f_tc_lu_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100876 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100877
Harald Welte256571e2018-01-24 18:47:19 +0100878 var PDU_ML3_MS_NW l3_lu := f_build_lu_imei(g_pars.imei)
Harald Welteba7b6d92018-01-23 21:32:34 +0100879 var PDU_DTAP_MT dtap_mt;
880
881 /* tell GSUP dispatcher to send this IMSI to us */
882 f_create_gsup_expect(hex2str(g_pars.imsi));
883
884 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200885 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100886
887 /* Send Early Classmark, just for the fun of it */
Harald Weltee13cfb22019-04-23 16:52:02 +0200888 if (pars.ran_is_geran) {
889 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
890 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100891 /* wait for LU reject, ignore any ID REQ */
892 alt {
893 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) { }
894 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req)) { repeat; }
895 }
896 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100897 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100898}
899testcase TC_lu_by_imei() runs on MTC_CT {
900 var BSC_ConnHdlr vc_conn;
901 f_init();
902
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200903 vc_conn := f_start_handler(refers(f_tc_lu_by_imei), 12, verify_cell_id := false);
Harald Welteba7b6d92018-01-23 21:32:34 +0100904 vc_conn.done;
905}
906
Harald Weltee13cfb22019-04-23 16:52:02 +0200907
Harald Welteba7b6d92018-01-23 21:32:34 +0100908/* Test LU by TMSI with unknown TMSI, expect (and answer) ID REQ. */
909private function f_tc_lu_tmsi_noauth_unknown(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200910 /* We piggyback a test for an MSC crash on overlong IMSI (OS#2864) onto this test. */
911 var hexstring overlong_imsi := '012345789ABCDEF0123456789ABCDEF'H;
Harald Weltea10db902018-01-27 12:44:49 +0100912 f_init_handler(pars);
Harald Welteba7b6d92018-01-23 21:32:34 +0100913
914 var PDU_ML3_MS_NW l3_lu := f_build_lu_tmsi('01020304'O); /* FIXME: Random */
915 var PDU_DTAP_MT dtap_mt;
916
917 /* tell GSUP dispatcher to send this IMSI to us */
918 f_create_gsup_expect(hex2str(g_pars.imsi));
919
920 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200921 f_cl3_or_initial_ue(l3_lu);
Harald Welteba7b6d92018-01-23 21:32:34 +0100922
923 /* Send Early Classmark, just for the fun of it */
924 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
925
926 /* Wait for + respond to ID REQ (IMSI) */
Oliver Smith32898452019-07-09 12:32:35 +0200927 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
Stefan Sperling04fc4bc2018-06-25 17:44:57 +0200928 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(overlong_imsi))); /* test for OS#2864 */
Harald Welteba7b6d92018-01-23 21:32:34 +0100929 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp_IMSI(g_pars.imsi)));
Harald Welte79f1e452020-08-18 22:55:02 +0200930 f_expect_common_id();
Harald Welteba7b6d92018-01-23 21:32:34 +0100931
932 /* Expect MSC to do UpdateLocation to HLR; respond to it */
933 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
934 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
935 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
936 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
937
938 alt {
Harald Welte7ec4fa82018-01-27 10:57:40 +0100939 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Acc)) {
940 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_TmsiRealloc_Cmpl));
941 }
Harald Welteba7b6d92018-01-23 21:32:34 +0100942 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
943 setverdict(fail, "Expected LU ACK, but received REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +0200944 mtc.stop;
Harald Welteba7b6d92018-01-23 21:32:34 +0100945 }
946 }
947
Philipp Maier9b690e42018-12-21 11:50:03 +0100948 /* Wait for MM-Information (if enabled) */
949 f_expect_mm_info();
950
Harald Welteba7b6d92018-01-23 21:32:34 +0100951 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100952 f_expect_clear();
Harald Welteba7b6d92018-01-23 21:32:34 +0100953}
954testcase TC_lu_by_tmsi_noauth_unknown() runs on MTC_CT {
955 var BSC_ConnHdlr vc_conn;
956 f_init();
957
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +0100958 vc_conn := f_start_handler(refers(f_tc_lu_tmsi_noauth_unknown), 13);
Harald Welteba7b6d92018-01-23 21:32:34 +0100959 vc_conn.done;
960}
961
962
Harald Welte45164da2018-01-24 12:51:27 +0100963/* Test IMSI DETACH (MI=IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200964friend function f_tc_imsi_detach_by_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100965 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100966
967 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
968
969 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200970 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100971
972 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200973 if (pars.ran_is_geran) {
974 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
975 }
Harald Welte45164da2018-01-24 12:51:27 +0100976
977 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +0100978 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +0100979}
980testcase TC_imsi_detach_by_imsi() runs on MTC_CT {
981 var BSC_ConnHdlr vc_conn;
982 f_init();
983
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +0200984 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imsi), 14, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +0100985 vc_conn.done;
986}
987
Harald Weltee13cfb22019-04-23 16:52:02 +0200988
Harald Welte45164da2018-01-24 12:51:27 +0100989/* Test IMSI DETACH (MI=TMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +0200990friend function f_tc_imsi_detach_by_tmsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +0100991 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +0100992
993 var MobileIdentityLV mi := valueof(ts_MI_TMSI_LV('01020304'O));
994
995 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +0200996 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +0100997
998 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +0200999 if (pars.ran_is_geran) {
1000 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1001 }
Harald Welte45164da2018-01-24 12:51:27 +01001002
1003 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001004 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001005}
1006testcase TC_imsi_detach_by_tmsi() runs on MTC_CT {
1007 var BSC_ConnHdlr vc_conn;
1008 f_init();
1009
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001010 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_tmsi), 15, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001011 vc_conn.done;
1012}
1013
Harald Weltee13cfb22019-04-23 16:52:02 +02001014
Harald Welte45164da2018-01-24 12:51:27 +01001015/* Test IMSI DETACH (MI=IMEI), which is illegal */
Harald Weltee13cfb22019-04-23 16:52:02 +02001016friend function f_tc_imsi_detach_by_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001017 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001018
Harald Welte256571e2018-01-24 18:47:19 +01001019 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte45164da2018-01-24 12:51:27 +01001020
1021 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001022 f_cl3_or_initial_ue(valueof(ts_ML3_MO_MM_IMSI_DET_Ind(mi)));
Harald Welte45164da2018-01-24 12:51:27 +01001023
1024 /* Send Early Classmark, just for the fun of it? */
Harald Weltee13cfb22019-04-23 16:52:02 +02001025 if (pars.ran_is_geran) {
1026 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1027 }
Harald Welte45164da2018-01-24 12:51:27 +01001028
1029 /* wait for normal teardown */
Harald Welte1ddc7162018-01-27 14:25:46 +01001030 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001031}
1032testcase TC_imsi_detach_by_imei() runs on MTC_CT {
1033 var BSC_ConnHdlr vc_conn;
1034 f_init();
1035
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001036 vc_conn := f_start_handler(refers(f_tc_imsi_detach_by_imei), 16, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001037 vc_conn.done;
1038}
1039
1040
1041/* helper function for an emergency call. caller passes in mobile identity to use */
1042private function f_emerg_call(MobileIdentityLV mi) runs on BSC_ConnHdlr {
Harald Welte0bef21e2018-02-10 09:48:23 +01001043 var CallParameters cpars := valueof(t_CallParams('112'H, 0));
1044 cpars.emergency := true;
Harald Welte45164da2018-01-24 12:51:27 +01001045
Harald Welte0bef21e2018-02-10 09:48:23 +01001046 f_mo_call(cpars);
Harald Welte45164da2018-01-24 12:51:27 +01001047}
1048
1049/* establish an emergency call by IMEI, no SIM inserted (and hence no IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001050friend function f_tc_emerg_call_imei_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001051 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001052
Harald Welte256571e2018-01-24 18:47:19 +01001053 var MobileIdentityLV mi := valueof(ts_MI_IMEI_LV(g_pars.imei));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001054 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_EMERG_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001055 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001056 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ('05'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001057 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001058}
1059testcase TC_emerg_call_imei_reject() runs on MTC_CT {
1060 var BSC_ConnHdlr vc_conn;
1061 f_init();
1062
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001063 vc_conn := f_start_handler(refers(f_tc_emerg_call_imei_reject), 17, verify_cell_id := false);
Harald Welte45164da2018-01-24 12:51:27 +01001064 vc_conn.done;
1065}
1066
Harald Weltee13cfb22019-04-23 16:52:02 +02001067
Harald Welted5b91402018-01-24 18:48:16 +01001068/* establish an emergency call by IMSI, SIM inserted (and hence IMSI) */
Harald Weltee13cfb22019-04-23 16:52:02 +02001069friend function f_tc_emerg_call_imsi(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001070 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001071 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001072 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001073 /* Then issue emergency call identified by IMSI */
1074 f_emerg_call(valueof(ts_MI_IMSI_LV(g_pars.imsi)));
1075}
1076testcase TC_emerg_call_imsi() runs on MTC_CT {
1077 var BSC_ConnHdlr vc_conn;
1078 f_init();
1079
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001080 vc_conn := f_start_handler(refers(f_tc_emerg_call_imsi), 18);
Harald Welte45164da2018-01-24 12:51:27 +01001081 vc_conn.done;
1082}
1083
Harald Weltee13cfb22019-04-23 16:52:02 +02001084
Harald Welte45164da2018-01-24 12:51:27 +01001085/* CM Service Request for VGCS -> reject */
1086private function f_tc_cm_serv_req_vgcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001087 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001088
1089 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001090 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001091
1092 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001093 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VGCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001094 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001095 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001096 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001097}
1098testcase TC_cm_serv_req_vgcs_reject() runs on MTC_CT {
1099 var BSC_ConnHdlr vc_conn;
1100 f_init();
1101
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001102 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vgcs_reject), 19);
Harald Welte45164da2018-01-24 12:51:27 +01001103 vc_conn.done;
1104}
1105
1106/* CM Service Request for VBS -> reject */
1107private function f_tc_cm_serv_req_vbs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001108 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001109
1110 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001111 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001112
1113 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001114 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_VBS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001115 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001116 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001117 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001118}
1119testcase TC_cm_serv_req_vbs_reject() runs on MTC_CT {
1120 var BSC_ConnHdlr vc_conn;
1121 f_init();
1122
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001123 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_vbs_reject), 20);
Harald Welte45164da2018-01-24 12:51:27 +01001124 vc_conn.done;
1125}
1126
1127/* CM Service Request for LCS -> reject */
1128private function f_tc_cm_serv_req_lcs_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001129 f_init_handler(pars);
Harald Welte45164da2018-01-24 12:51:27 +01001130
1131 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001132 f_perform_lu();
Harald Welte45164da2018-01-24 12:51:27 +01001133
1134 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
Harald Welte6ed6bf92018-01-24 21:09:15 +01001135 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_LCS, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001136 f_cl3_or_initial_ue(l3_info);
Harald Welte45164da2018-01-24 12:51:27 +01001137 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001138 f_expect_clear();
Harald Welte45164da2018-01-24 12:51:27 +01001139}
1140testcase TC_cm_serv_req_lcs_reject() runs on MTC_CT {
1141 var BSC_ConnHdlr vc_conn;
1142 f_init();
1143
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001144 vc_conn := f_start_handler(refers(f_tc_cm_serv_req_lcs_reject), 21);
Harald Welte45164da2018-01-24 12:51:27 +01001145 vc_conn.done;
1146}
1147
Harald Welte0195ab12018-01-24 21:50:20 +01001148/* CM Re-Establishment Request */
1149private function f_tc_cm_reest_req_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001150 f_init_handler(pars);
Harald Welte0195ab12018-01-24 21:50:20 +01001151
1152 /* First perform location update to ensure subscriber is known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001153 f_perform_lu();
Harald Welte0195ab12018-01-24 21:50:20 +01001154
1155 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1156 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_REEST_REQ(0, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001157 f_cl3_or_initial_ue(l3_info);
Harald Welte0195ab12018-01-24 21:50:20 +01001158 BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ(int2oct(32,1))));
Harald Welte1ddc7162018-01-27 14:25:46 +01001159 f_expect_clear();
Harald Welte0195ab12018-01-24 21:50:20 +01001160}
1161testcase TC_cm_reest_req_reject() runs on MTC_CT {
1162 var BSC_ConnHdlr vc_conn;
1163 f_init();
Harald Welte0195ab12018-01-24 21:50:20 +01001164
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001165 vc_conn := f_start_handler(refers(f_tc_cm_reest_req_reject), 22);
Harald Welte0195ab12018-01-24 21:50:20 +01001166 vc_conn.done;
1167}
1168
Harald Weltec638f4d2018-01-24 22:00:36 +01001169/* Test LU (with authentication enabled), with wrong response from MS */
1170private function f_tc_lu_auth_2G_fail(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001171 f_init_handler(pars);
Harald Weltec638f4d2018-01-24 22:00:36 +01001172
1173 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
1174
1175 /* tell GSUP dispatcher to send this IMSI to us */
1176 f_create_gsup_expect(hex2str(g_pars.imsi));
1177
1178 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
Harald Weltedceacc72019-04-21 20:58:35 +02001179 f_cl3_or_initial_ue(l3_lu);
Harald Weltec638f4d2018-01-24 22:00:36 +01001180
1181 /* Send Early Classmark, just for the fun of it */
1182 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1183
1184 var AuthVector vec := f_gen_auth_vec_2g();
1185 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G(vec.rand, vec.sres, vec.kc));
1186 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
1187 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
1188
1189 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_AUTH_REQ(vec.rand)));
1190 /* Send back wrong auth response */
1191 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MT_MM_AUTH_RESP_2G('00000000'O)));
1192
1193 /* Expect GSUP AUTH FAIL REP to HLR */
1194 GSUP.receive(tr_GSUP_AUTH_FAIL_IND(g_pars.imsi));
1195
1196 /* Expect LU REJECT with Cause == Illegal MS */
1197 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej('03'O)));
Harald Welte1ddc7162018-01-27 14:25:46 +01001198 f_expect_clear();
Harald Weltec638f4d2018-01-24 22:00:36 +01001199}
1200testcase TC_lu_auth_2G_fail() runs on MTC_CT {
1201 var BSC_ConnHdlr vc_conn;
1202 f_init();
1203 f_vty_config(MSCVTY, "network", "authentication required");
Harald Weltec638f4d2018-01-24 22:00:36 +01001204
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001205 vc_conn := f_start_handler(refers(f_tc_lu_auth_2G_fail), 23, verify_cell_id := false);
Harald Weltec638f4d2018-01-24 22:00:36 +01001206 vc_conn.done;
1207}
1208
Harald Weltede371492018-01-27 23:44:41 +01001209/* A5/1 + A5/3 permitted on network side, and MS capable to do it */
Harald Welte16114282018-01-24 22:41:21 +01001210private function f_tc_lu_imsi_auth_tmsi_encr_13_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltede371492018-01-27 23:44:41 +01001211 pars.net.expect_auth := true;
1212 pars.net.expect_ciph := true;
Harald Weltea10db902018-01-27 12:44:49 +01001213 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001214 f_perform_lu();
Harald Welte16114282018-01-24 22:41:21 +01001215}
1216testcase TC_lu_imsi_auth_tmsi_encr_13_13() runs on MTC_CT {
1217 var BSC_ConnHdlr vc_conn;
1218 f_init();
1219 f_vty_config(MSCVTY, "network", "authentication required");
Harald Welte16114282018-01-24 22:41:21 +01001220 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1221
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001222 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_13), 24);
Harald Welte16114282018-01-24 22:41:21 +01001223 vc_conn.done;
1224}
1225
Harald Welte1af6ea82018-01-25 18:33:15 +01001226/* Test Complete L3 without payload */
1227private function f_tc_cl3_no_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001228 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001229
1230 /* Send Complete L3 Info with empty L3 frame */
1231 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1232 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, ''O))));
1233
Harald Weltef466eb42018-01-27 14:26:54 +01001234 timer T := 5.0;
1235 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001236 alt {
Harald Welte6811d102019-04-14 22:23:14 +02001237 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001238 /* Expect LU REJECT with Cause == Illegal MS */
Harald Weltebdb3c452018-03-18 22:43:06 +01001239 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001240 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001241 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001242 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001243 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001244 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001245 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001246 }
1247 setverdict(pass);
1248}
1249testcase TC_cl3_no_payload() runs on MTC_CT {
1250 var BSC_ConnHdlr vc_conn;
1251 f_init();
1252
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001253 vc_conn := f_start_handler(refers(f_tc_cl3_no_payload), 25);
Harald Welte1af6ea82018-01-25 18:33:15 +01001254 vc_conn.done;
1255}
1256
1257/* Test Complete L3 with random payload */
1258private function f_tc_cl3_rnd_payload(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001259 f_init_handler(pars);
Harald Welte1af6ea82018-01-25 18:33:15 +01001260
Daniel Willmannaa14a382018-07-26 08:29:45 +02001261 /* length is limited by PDU_BSSAP length field which includes some
1262 * other fields beside l3info payload. So payl can only be 240 bytes
1263 * Since rnd() returns values < 1 multiply with 241
1264 */
1265 var integer len := float2int(rnd() * 241.0);
Harald Welte1af6ea82018-01-25 18:33:15 +01001266 var octetstring payl := f_rnd_octstring(len);
1267
1268 /* Send Complete L3 Info with empty L3 frame */
1269 BSSAP.send(ts_BSSAP_Conn_Req(g_pars.sccp_addr_peer, g_pars.sccp_addr_own,
1270 valueof(ts_BSSMAP_ComplL3(g_pars.cell_id, payl))));
1271
Harald Weltef466eb42018-01-27 14:26:54 +01001272 timer T := 5.0;
1273 T.start;
Harald Welte1af6ea82018-01-25 18:33:15 +01001274 alt {
1275 /* Immediate disconnect */
Harald Welte6811d102019-04-14 22:23:14 +02001276 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_DISC_IND) {}
Harald Welte1af6ea82018-01-25 18:33:15 +01001277 [] BSSAP.receive(tr_PDU_DTAP_MT(?)) { repeat; }
Harald Welte6811d102019-04-14 22:23:14 +02001278 [] BSSAP.receive(RAN_Conn_Prim:MSC_CONN_PRIM_CONF_IND) { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001279 [] as_clear_cmd_compl_disc();
Harald Weltef466eb42018-01-27 14:26:54 +01001280 [] T.timeout {
Daniel Willmann90829d62018-02-15 17:45:14 +01001281 setverdict(fail, "Timeout waiting for ClearCommand or SCCP Release");
Daniel Willmannafce8662018-07-06 23:11:32 +02001282 mtc.stop;
Harald Weltef466eb42018-01-27 14:26:54 +01001283 }
Harald Welte1af6ea82018-01-25 18:33:15 +01001284 }
1285 setverdict(pass);
1286}
1287testcase TC_cl3_rnd_payload() runs on MTC_CT {
1288 var BSC_ConnHdlr vc_conn;
1289 f_init();
1290
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001291 vc_conn := f_start_handler(refers(f_tc_cl3_rnd_payload), 26);
Harald Welte1af6ea82018-01-25 18:33:15 +01001292 vc_conn.done;
1293}
1294
Harald Welte116e4332018-01-26 22:17:48 +01001295/* Test Complete L3 with random payload */
Harald Weltee13cfb22019-04-23 16:52:02 +02001296friend function f_tc_establish_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001297 f_init_handler(pars);
Harald Welte116e4332018-01-26 22:17:48 +01001298
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001299 f_perform_lu();
Harald Welte116e4332018-01-26 22:17:48 +01001300
Harald Welteb9e86fa2018-04-09 18:18:31 +02001301 f_establish_fully();
Daniel Willmann898a7e02018-05-17 12:16:16 +02001302 f_expect_clear(10.0);
Harald Welte116e4332018-01-26 22:17:48 +01001303}
1304testcase TC_establish_and_nothing() runs on MTC_CT {
1305 var BSC_ConnHdlr vc_conn;
1306 f_init();
1307
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001308 vc_conn := f_start_handler(refers(f_tc_establish_and_nothing), 27);
Harald Welte116e4332018-01-26 22:17:48 +01001309 vc_conn.done;
1310}
1311
Harald Weltee13cfb22019-04-23 16:52:02 +02001312
Harald Welte12510c52018-01-26 22:26:24 +01001313/* Test MO Call SETUP with no response from MNCC */
Harald Weltee13cfb22019-04-23 16:52:02 +02001314friend function f_tc_mo_setup_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier109e6aa2018-10-17 10:53:32 +02001315 f_init_handler(pars, 190.0);
Harald Weltea10db902018-01-27 12:44:49 +01001316
Harald Welte12510c52018-01-26 22:26:24 +01001317 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001318 cpars.mgw_conn_2.resp := 0;
1319 cpars.stop_after_cc_setup := true;
1320
1321 f_vty_config(MSCVTY, "msc", "mncc guard-timeout 20");
Harald Welte12510c52018-01-26 22:26:24 +01001322
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001323 f_perform_lu();
Harald Welte12510c52018-01-26 22:26:24 +01001324
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001325 f_mo_call_establish(cpars);
Harald Welte12510c52018-01-26 22:26:24 +01001326
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001327 var default ccrel := activate(as_optional_cc_rel(cpars));
1328
Philipp Maier109e6aa2018-10-17 10:53:32 +02001329 f_expect_clear(185.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001330
1331 deactivate(ccrel);
1332
1333 f_sleep(1.0);
Harald Welte12510c52018-01-26 22:26:24 +01001334}
1335testcase TC_mo_setup_and_nothing() runs on MTC_CT {
1336 var BSC_ConnHdlr vc_conn;
1337 f_init();
1338
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001339 vc_conn := f_start_handler(refers(f_tc_mo_setup_and_nothing), 28);
Harald Welte12510c52018-01-26 22:26:24 +01001340 vc_conn.done;
1341}
1342
Harald Weltee13cfb22019-04-23 16:52:02 +02001343
Harald Welte3ab88002018-01-26 22:37:25 +01001344/* Test MO Call with no response to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001345friend function f_tc_mo_crcx_ran_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001346 f_init_handler(pars);
Harald Welte3ab88002018-01-26 22:37:25 +01001347 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1348 var MNCC_PDU mncc;
1349 var MgcpCommand mgcp_cmd;
1350
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001351 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001352 /* Do not respond to the second CRCX */
1353 cpars.mgw_conn_2.resp := 0;
1354 f_mo_call_establish(cpars);
Harald Welte3ab88002018-01-26 22:37:25 +01001355
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001356 var default ccrel := activate(as_optional_cc_rel(cpars));
Harald Welte3ab88002018-01-26 22:37:25 +01001357
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001358 f_expect_clear(60.0);
Harald Welte3ab88002018-01-26 22:37:25 +01001359
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001360 deactivate(ccrel);
Harald Welte3ab88002018-01-26 22:37:25 +01001361}
1362testcase TC_mo_crcx_ran_timeout() runs on MTC_CT {
1363 var BSC_ConnHdlr vc_conn;
1364 f_init();
1365
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001366 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_timeout), 29);
Harald Welte3ab88002018-01-26 22:37:25 +01001367 vc_conn.done;
1368}
1369
Harald Weltee13cfb22019-04-23 16:52:02 +02001370
Harald Welte0cc82d92018-01-26 22:52:34 +01001371/* Test MO Call with reject to RAN-side CRCX */
Harald Weltee13cfb22019-04-23 16:52:02 +02001372friend function f_tc_mo_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001373 f_init_handler(pars);
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001374
Harald Welte0cc82d92018-01-26 22:52:34 +01001375 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001376
1377 /* Respond with error for the first CRCX */
1378 cpars.mgw_conn_1.resp := -1;
Harald Welte0cc82d92018-01-26 22:52:34 +01001379
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001380 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001381 f_mo_call_establish(cpars);
Harald Welte0cc82d92018-01-26 22:52:34 +01001382
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001383 var default ccrel := activate(as_optional_cc_rel(cpars));
1384 f_expect_clear(60.0);
1385 deactivate(ccrel);
Harald Welte0cc82d92018-01-26 22:52:34 +01001386}
1387testcase TC_mo_crcx_ran_reject() runs on MTC_CT {
1388 var BSC_ConnHdlr vc_conn;
1389 f_init();
1390
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001391 vc_conn := f_start_handler(refers(f_tc_mo_crcx_ran_reject), 30);
Harald Welte0cc82d92018-01-26 22:52:34 +01001392 vc_conn.done;
1393}
1394
Harald Welte3ab88002018-01-26 22:37:25 +01001395
Harald Welte812f7a42018-01-27 00:49:18 +01001396/* helper function to start a MT call: MNCC SETUP; Paging; DChan est.; DTAP SETUP */
1397private function f_mt_call_start(inout CallParameters cpars) runs on BSC_ConnHdlr {
1398 var MNCC_PDU mncc;
1399 var MgcpCommand mgcp_cmd;
Harald Welte812f7a42018-01-27 00:49:18 +01001400
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001401 f_perform_lu();
Vadim Yanitskiyae747742020-01-10 00:23:10 +01001402 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte812f7a42018-01-27 00:49:18 +01001403
1404 /* Allocate call reference and send SETUP via MNCC to MSC */
1405 cpars.mncc_callref := f_rnd_int(2147483648);
1406 MNCC.send(ts_MNCC_SETUP_req(cpars.mncc_callref, hex2str(g_pars.msisdn),
1407 hex2str(cpars.called_party), hex2str(g_pars.imsi)));
1408
1409 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02001410 f_expect_paging();
1411
Harald Welte812f7a42018-01-27 00:49:18 +01001412 /* MS -> MSC: PAGING RESPONSE */
Harald Welteb9e86fa2018-04-09 18:18:31 +02001413 f_establish_fully(EST_TYPE_PAG_RESP);
Harald Welte812f7a42018-01-27 00:49:18 +01001414
1415 f_create_mgcp_expect(ExpectCriteria:{omit,omit,omit});
1416
1417 /* MSC->MS: SETUP */
1418 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party)));
1419}
1420
1421/* Test MT Call */
Harald Weltee13cfb22019-04-23 16:52:02 +02001422friend function f_tc_mt_crcx_ran_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltea10db902018-01-27 12:44:49 +01001423 f_init_handler(pars);
Harald Welte812f7a42018-01-27 00:49:18 +01001424 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1425 var MNCC_PDU mncc;
1426 var MgcpCommand mgcp_cmd;
1427
1428 f_mt_call_start(cpars);
1429
1430 /* MS->MSC: CALL CONFIRMED */
1431 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1432
1433 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1434
1435 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1436 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001437
1438 /* Detect if the received CRCX is a wildcarded CRCX request. If yes,
1439 * set an endpoint name that fits the pattern. If not, just use the
1440 * endpoint name from the request */
1441 if (match(mgcp_cmd.line.ep, t_MGCP_EP_wildcard)) {
1442 cpars.mgcp_ep := "rtpbridge/1@mgw";
1443 } else {
1444 cpars.mgcp_ep := mgcp_cmd.line.ep;
1445 }
1446
Harald Welte812f7a42018-01-27 00:49:18 +01001447 /* Respond to CRCX with error */
1448 var MgcpResponse mgcp_rsp := {
1449 line := {
1450 code := "542",
1451 trans_id := mgcp_cmd.line.trans_id,
1452 string := "FORCED_FAIL"
1453 },
Harald Welte812f7a42018-01-27 00:49:18 +01001454 sdp := omit
1455 }
Philipp Maierf1e02bb2018-03-15 16:30:00 +01001456 var MgcpParameter mgcp_rsp_param := {
1457 code := "Z",
1458 val := cpars.mgcp_ep
1459 };
1460 mgcp_rsp.params[0] := mgcp_rsp_param;
Harald Welte812f7a42018-01-27 00:49:18 +01001461 MGCP.send(mgcp_rsp);
1462
1463 timer T := 30.0;
1464 T.start;
1465 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001466 [] T.timeout {
1467 setverdict(fail, "Timeout waiting for channel release");
1468 mtc.stop;
1469 }
Harald Welte812f7a42018-01-27 00:49:18 +01001470 [] MNCC.receive { repeat; }
1471 [] GSUP.receive { repeat; }
1472 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1473 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1474 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1475 repeat;
1476 }
1477 [] MGCP.receive { repeat; }
Harald Welte5946b332018-03-18 23:32:21 +01001478 [] as_clear_cmd_compl_disc();
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001479 [] as_optional_cc_rel(cpars);
Harald Welte812f7a42018-01-27 00:49:18 +01001480 }
1481}
1482testcase TC_mt_crcx_ran_reject() runs on MTC_CT {
1483 var BSC_ConnHdlr vc_conn;
1484 f_init();
1485
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001486 vc_conn := f_start_handler(refers(f_tc_mt_crcx_ran_reject), 31);
Harald Welte812f7a42018-01-27 00:49:18 +01001487 vc_conn.done;
1488}
1489
1490
Harald Weltee13cfb22019-04-23 16:52:02 +02001491
Harald Welte812f7a42018-01-27 00:49:18 +01001492/* Test MT Call T310 timer */
Harald Weltee13cfb22019-04-23 16:52:02 +02001493friend function f_tc_mt_t310(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltead2952e2018-01-27 14:12:46 +01001494 f_init_handler(pars, 200.0);
Harald Welte812f7a42018-01-27 00:49:18 +01001495 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1496 var MNCC_PDU mncc;
1497 var MgcpCommand mgcp_cmd;
1498
1499 f_mt_call_start(cpars);
1500
1501 /* MS->MSC: CALL CONFIRMED */
1502 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_CALL_CONF(cpars.transaction_id)));
1503 MNCC.receive(tr_MNCC_CALL_CONF_ind(cpars.mncc_callref));
1504
1505 MGCP.receive(tr_CRCX) -> value mgcp_cmd;
1506 cpars.mgcp_call_id := f_MgcpCmd_extract_call_id(mgcp_cmd);
1507 cpars.mgcp_ep := mgcp_cmd.line.ep;
1508 /* FIXME: Respond to CRCX */
1509
1510 /* old libosmocore T310 default timeout is 180s. so let's wait 190 */
1511 timer T := 190.0;
1512 T.start;
1513 alt {
Daniel Willmannafce8662018-07-06 23:11:32 +02001514 [] T.timeout {
1515 setverdict(fail, "Timeout waiting for T310");
1516 mtc.stop;
1517 }
Harald Welte812f7a42018-01-27 00:49:18 +01001518 [] MNCC.receive(tr_MNCC_DISC_ind(cpars.mncc_callref)) {
1519 MNCC.send(ts_MNCC_REL_req(cpars.mncc_callref, valueof(ts_MNCC_cause(23))));
1520 }
1521 }
1522 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_DISC(cpars.transaction_id)));
1523 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_RELEASE(cpars.transaction_id)));
1524 /* FIXME: We're sending this with TIflag 0: allocated by sender, which is wrong */
1525 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_CC_REL_COMPL(cpars.transaction_id)));
1526
1527 alt {
Harald Welte812f7a42018-01-27 00:49:18 +01001528 [] MGCP.receive(tr_DLCX(?)) -> value mgcp_cmd {
1529 MGCP.send(ts_DLCX_ACK2(mgcp_cmd.line.trans_id));
1530 f_create_mgcp_delete_ep(cpars.mgcp_ep);
1531 repeat;
1532 }
Harald Welte5946b332018-03-18 23:32:21 +01001533 [] as_clear_cmd_compl_disc();
Harald Welte812f7a42018-01-27 00:49:18 +01001534 }
1535}
1536testcase TC_mt_t310() runs on MTC_CT {
1537 var BSC_ConnHdlr vc_conn;
1538 f_init();
1539
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001540 vc_conn := f_start_handler(refers(f_tc_mt_t310), 32);
Harald Welte812f7a42018-01-27 00:49:18 +01001541 vc_conn.done;
1542}
1543
Harald Weltee13cfb22019-04-23 16:52:02 +02001544
Harald Welte167458a2018-01-27 15:58:16 +01001545/* Perform successful LU + MO call, then GSUP LocationCancel. Subscriber must be denied CM SERV */
Harald Weltee13cfb22019-04-23 16:52:02 +02001546friend function f_tc_gsup_cancel(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte167458a2018-01-27 15:58:16 +01001547 f_init_handler(pars);
1548 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte167458a2018-01-27 15:58:16 +01001549
1550 /* Location Update to make subscriber known */
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001551 f_perform_lu();
Harald Welte167458a2018-01-27 15:58:16 +01001552
1553 /* First MO call should succeed */
1554 f_mo_call(cpars);
1555
1556 /* Cancel the subscriber in the VLR */
1557 GSUP.send(ts_GSUP_CL_REQ(g_pars.imsi, OSMO_GSUP_CANCEL_TYPE_WITHDRAW));
1558 alt {
1559 [] GSUP.receive(tr_GSUP_CL_RES(g_pars.imsi)) { }
1560 [] GSUP.receive(tr_GSUP_CL_ERR(g_pars.imsi)) {
1561 setverdict(fail, "Received GSUP Location Cancel Error");
Daniel Willmannafce8662018-07-06 23:11:32 +02001562 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001563 }
1564 }
1565
1566 /* Follow-up transactions should fail */
1567 var MobileIdentityLV mi := valueof(ts_MI_IMSI_LV(g_pars.imsi));
1568 var PDU_ML3_MS_NW l3_info := valueof(ts_CM_SERV_REQ(CM_TYPE_MO_CALL, mi));
Harald Weltedceacc72019-04-21 20:58:35 +02001569 f_cl3_or_initial_ue(l3_info);
Harald Welte167458a2018-01-27 15:58:16 +01001570 alt {
1571 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_CM_SERV_REJ)) { }
1572 [] BSSAP.receive {
1573 setverdict(fail, "Received unexpected BSSAP instead of CM SERV REJ");
Daniel Willmannafce8662018-07-06 23:11:32 +02001574 mtc.stop;
Harald Welte167458a2018-01-27 15:58:16 +01001575 }
1576 }
Neels Hofmeyr0f7429a2019-03-07 22:28:41 +01001577
1578 f_expect_clear();
Harald Welte167458a2018-01-27 15:58:16 +01001579 setverdict(pass);
1580}
1581testcase TC_gsup_cancel() runs on MTC_CT {
1582 var BSC_ConnHdlr vc_conn;
1583 f_init();
1584
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001585 vc_conn := f_start_handler(refers(f_tc_gsup_cancel), 33, verify_cell_id := false);
Harald Welte167458a2018-01-27 15:58:16 +01001586 vc_conn.done;
1587}
1588
Harald Weltee13cfb22019-04-23 16:52:02 +02001589
Harald Welte9de84792018-01-28 01:06:35 +01001590/* A5/1 only permitted on network side, and MS capable to do it */
1591private function f_tc_lu_imsi_auth_tmsi_encr_1_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1592 pars.net.expect_auth := true;
1593 pars.net.expect_ciph := true;
1594 pars.net.kc_support := '02'O; /* A5/1 only */
1595 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001596 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001597}
1598testcase TC_lu_imsi_auth_tmsi_encr_1_13() runs on MTC_CT {
1599 var BSC_ConnHdlr vc_conn;
1600 f_init();
1601 f_vty_config(MSCVTY, "network", "authentication required");
1602 f_vty_config(MSCVTY, "network", "encryption a5 1");
1603
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001604 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_1_13), 34);
Harald Welte9de84792018-01-28 01:06:35 +01001605 vc_conn.done;
1606}
1607
1608/* A5/3 only permitted on network side, and MS capable to do it */
1609private function f_tc_lu_imsi_auth_tmsi_encr_3_13(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1610 pars.net.expect_auth := true;
1611 pars.net.expect_ciph := true;
1612 pars.net.kc_support := '08'O; /* A5/3 only */
1613 f_init_handler(pars);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001614 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001615}
1616testcase TC_lu_imsi_auth_tmsi_encr_3_13() runs on MTC_CT {
1617 var BSC_ConnHdlr vc_conn;
1618 f_init();
1619 f_vty_config(MSCVTY, "network", "authentication required");
1620 f_vty_config(MSCVTY, "network", "encryption a5 3");
1621
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001622 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_13), 35);
Harald Welte9de84792018-01-28 01:06:35 +01001623 vc_conn.done;
1624}
1625
1626/* A5/3 only permitted on network side, and MS with only A5/1 support */
1627private function f_tc_lu_imsi_auth_tmsi_encr_3_1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1628 pars.net.expect_auth := true;
1629 pars.net.expect_ciph := true;
1630 pars.net.kc_support := '08'O; /* A5/3 only */
1631 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1632 f_init_handler(pars, 15.0);
1633
1634 /* cannot use f_perform_lu() as we expect a reject */
1635 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1636 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001637 f_cl3_or_initial_ue(l3_lu);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001638 if (pars.send_early_cm) {
1639 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1640 } else {
1641 pars.cm1.esind := '0'B;
1642 }
Harald Welte9de84792018-01-28 01:06:35 +01001643 f_mm_auth();
1644 alt {
Daniel Willmann52918e52018-09-20 14:39:09 +02001645 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
1646 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1647 repeat;
1648 }
Harald Welte5946b332018-03-18 23:32:21 +01001649 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1650 f_expect_clear();
1651 }
Harald Welte9de84792018-01-28 01:06:35 +01001652 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1653 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001654 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001655 }
1656 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001657 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001658 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001659 }
1660 }
1661 setverdict(pass);
1662}
1663testcase TC_lu_imsi_auth_tmsi_encr_3_1() runs on MTC_CT {
1664 var BSC_ConnHdlr vc_conn;
1665 f_init();
1666 f_vty_config(MSCVTY, "network", "authentication required");
1667 f_vty_config(MSCVTY, "network", "encryption a5 3");
1668
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001669 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 360, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001670 vc_conn.done;
1671}
1672testcase TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() runs on MTC_CT {
1673 var BSC_ConnHdlrPars pars;
1674 var BSC_ConnHdlr vc_conn;
1675 f_init();
1676 f_vty_config(MSCVTY, "network", "authentication required");
1677 f_vty_config(MSCVTY, "network", "encryption a5 3");
1678
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001679 pars := f_init_pars(361, verify_cell_id := false);
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01001680 pars.send_early_cm := false;
1681 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), pars);
Harald Welte9de84792018-01-28 01:06:35 +01001682 vc_conn.done;
1683}
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001684testcase TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() runs on MTC_CT {
1685 var BSC_ConnHdlr vc_conn;
1686 f_init();
1687 f_vty_config(MSCVTY, "network", "authentication required");
1688 f_vty_config(MSCVTY, "network", "encryption a5 3");
1689
1690 /* Make sure the MSC category is on DEBUG level to trigger the log
1691 * message that is reported in OS#2947 to trigger the segfault */
1692 f_vty_config(MSCVTY, "log stderr", "logging level msc debug");
1693
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001694 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_3_1), 362, verify_cell_id := false);
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01001695 vc_conn.done;
1696}
Harald Welte9de84792018-01-28 01:06:35 +01001697
1698/* A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1699private function f_tc_lu_imsi_auth_tmsi_encr_13_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1700 pars.net.expect_auth := true;
1701 pars.net.expect_ciph := true;
1702 pars.net.kc_support := '0A'O; /* A5/1 + A5/3 */
1703 pars.cm1.a5_1 := '1'B;
1704 pars.cm2.a5_1 := '1'B;
1705 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1706 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1707 f_init_handler(pars, 15.0);
1708
1709 /* cannot use f_perform_lu() as we expect a reject */
1710 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi);
1711 f_create_gsup_expect(hex2str(g_pars.imsi));
Harald Weltedceacc72019-04-21 20:58:35 +02001712 f_cl3_or_initial_ue(l3_lu);
Harald Welte9de84792018-01-28 01:06:35 +01001713 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
1714 f_mm_auth();
1715 alt {
Harald Welte5946b332018-03-18 23:32:21 +01001716 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
1717 f_expect_clear();
1718 }
Harald Welte9de84792018-01-28 01:06:35 +01001719 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?,?)) {
1720 setverdict(fail, "CipherModeCommand despite no A5 intersection");
Daniel Willmannafce8662018-07-06 23:11:32 +02001721 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001722 }
1723 [] BSSAP.receive {
Harald Welte458fd372018-03-21 11:26:23 +01001724 setverdict(fail, "Unknown/unexpected BSSAP received");
Daniel Willmannafce8662018-07-06 23:11:32 +02001725 mtc.stop;
Harald Welte9de84792018-01-28 01:06:35 +01001726 }
1727 }
1728 setverdict(pass);
1729}
1730testcase TC_lu_imsi_auth_tmsi_encr_13_2() runs on MTC_CT {
1731 var BSC_ConnHdlr vc_conn;
1732 f_init();
1733 f_vty_config(MSCVTY, "network", "authentication required");
1734 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
1735
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02001736 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_13_2), 37, verify_cell_id := false);
Harald Welte9de84792018-01-28 01:06:35 +01001737 vc_conn.done;
1738}
1739
1740/* A5/0 + A5/1 + A5/3 only permitted on network side, and MS with only A5/2 support */
1741private function f_tc_lu_imsi_auth_tmsi_encr_013_2(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1742 pars.net.expect_auth := true;
1743 pars.net.expect_ciph := true;
1744 pars.net.kc_support := '0B'O; /* A5/1 + A5/3 */
1745 pars.cm1.a5_1 := '1'B;
1746 pars.cm2.a5_1 := '1'B;
1747 pars.cm2.classmarkInformationType2_oct5.a5_3 := '0'B;
1748 pars.cm2.classmarkInformationType2_oct5.a5_2 := '1'B;
1749 f_init_handler(pars, 15.0);
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001750 f_perform_lu();
Harald Welte9de84792018-01-28 01:06:35 +01001751}
1752testcase TC_lu_imsi_auth_tmsi_encr_013_2() runs on MTC_CT {
1753 var BSC_ConnHdlr vc_conn;
1754 f_init();
1755 f_vty_config(MSCVTY, "network", "authentication required");
1756 f_vty_config(MSCVTY, "network", "encryption a5 0 1 3");
1757
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001758 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_encr_013_2), 38);
Harald Welte9de84792018-01-28 01:06:35 +01001759 vc_conn.done;
1760}
1761
Harald Welte33ec09b2018-02-10 15:34:46 +01001762/* LU followed by MT call (including paging) */
Neels Hofmeyr8fe8a902019-11-03 05:51:03 +01001763friend function f_tc_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Welte33ec09b2018-02-10 15:34:46 +01001764 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001765 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001766 cpars.use_osmux := pars.use_osmux;
Harald Welte33ec09b2018-02-10 15:34:46 +01001767
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001768 f_perform_lu();
Harald Welte33ec09b2018-02-10 15:34:46 +01001769 f_mt_call(cpars);
1770}
1771testcase TC_lu_and_mt_call() runs on MTC_CT {
1772 var BSC_ConnHdlr vc_conn;
1773 f_init();
1774
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001775 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39);
Harald Welte33ec09b2018-02-10 15:34:46 +01001776 vc_conn.done;
1777}
1778
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001779testcase TC_lu_and_mt_call_osmux() runs on MTC_CT {
1780 var BSC_ConnHdlr vc_conn;
1781 f_init(1, false, true, true);
Pau Espin Pedrola65697d2019-05-21 12:54:39 +02001782
1783 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call), 39, 0, true, true);
1784 vc_conn.done;
1785}
1786
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01001787/* MT call while already Paging */
1788friend function f_tc_lu_and_mt_call_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1789 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
1790 var SmsParameters spars := valueof(t_SmsPars);
1791 var OCT4 tmsi;
1792
1793 f_init_handler(pars);
1794
1795 /* Perform location update */
1796 f_perform_lu();
1797
1798 /* register an 'expect' for given IMSI (+TMSI) */
1799 if (isvalue(g_pars.tmsi)) {
1800 tmsi := g_pars.tmsi;
1801 } else {
1802 tmsi := 'FFFFFFFF'O;
1803 }
1804 f_ran_register_imsi(g_pars.imsi, tmsi);
1805
1806 log("start Paging by an SMS");
1807 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
1808
1809 /* MSC->BSC: expect PAGING from MSC */
1810 f_expect_paging();
1811
1812 log("MNCC signals MT call, before Paging Response");
1813 f_mt_call_initate(cpars);
1814 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
1815
1816 f_sleep(0.5);
1817 log("phone answers Paging, expecting both SMS and MT call to be established");
1818 f_establish_fully(EST_TYPE_PAG_RESP);
1819 spars.tp.ud := 'C8329BFD064D9B53'O;
1820 interleave {
1821 [] BSSAP.receive(f_mt_sms_deliver_pdu(spars)) {
1822 log("Got SMS-DELIVER");
1823 };
1824 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_CC_SETUP(cpars.transaction_id, *, cpars.called_party))) {
1825 log("Got CC Setup");
1826 };
1827 }
1828 setverdict(pass);
1829 log("success, tear down");
1830 var default ccrel := activate(as_optional_cc_rel(cpars));
1831 if (g_pars.ran_is_geran) {
1832 BSSAP.send(ts_BSSMAP_ClearRequest(0));
1833 } else {
1834 BSSAP.send(ts_RANAP_IuReleaseRequest(ts_RanapCause_om_intervention));
1835 }
1836 f_expect_clear();
1837 deactivate(ccrel);
1838 f_vty_sms_clear(hex2str(g_pars.imsi));
1839}
1840testcase TC_lu_and_mt_call_already_paging() runs on MTC_CT {
1841 var BSC_ConnHdlrPars pars;
1842 var BSC_ConnHdlr vc_conn;
1843 f_init();
1844 pars := f_init_pars(391);
1845 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_call_already_paging), pars);
1846 vc_conn.done;
1847}
1848
Daniel Willmann8b084372018-02-04 13:35:26 +01001849/* Test MO Call SETUP with DTMF */
1850private function f_tc_mo_setup_dtmf_dup(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1851 f_init_handler(pars);
1852 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Daniel Willmann8b084372018-02-04 13:35:26 +01001853
Neels Hofmeyrc1f105a2018-03-01 20:00:19 +01001854 f_perform_lu();
Daniel Willmann8b084372018-02-04 13:35:26 +01001855 f_mo_seq_dtmf_dup(cpars);
1856}
1857testcase TC_mo_setup_and_dtmf_dup() runs on MTC_CT {
1858 var BSC_ConnHdlr vc_conn;
1859 f_init();
1860
Neels Hofmeyre9b8eeb2018-03-01 20:29:58 +01001861 vc_conn := f_start_handler(refers(f_tc_mo_setup_dtmf_dup), 39);
Daniel Willmann8b084372018-02-04 13:35:26 +01001862 vc_conn.done;
1863}
Harald Welte9de84792018-01-28 01:06:35 +01001864
Philipp Maier328d1662018-03-07 10:40:27 +01001865testcase TC_cr_before_reset() runs on MTC_CT {
1866 timer T := 4.0;
1867 var boolean reset_ack_seen := false;
1868 f_init_bssap_direct();
1869
Harald Welte3ca0ce12019-04-23 17:18:48 +02001870 f_ran_adapter_start(g_bssap[0]);
Daniel Willmann42d1d5b2018-08-07 15:18:41 +02001871
Daniel Willmanne8018962018-08-21 14:18:00 +02001872 f_sleep(3.0);
1873
Philipp Maier328d1662018-03-07 10:40:27 +01001874 /* Make a blind connection attemt, to trigger the deadlock condition */
Philipp Maier75932982018-03-27 14:52:35 +02001875 BSSAP_DIRECT.send(ts_BSSAP_CONNECT_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, 1, omit));
Philipp Maier328d1662018-03-07 10:40:27 +01001876
1877 /* Send a BSSMAP reset */
Philipp Maier75932982018-03-27 14:52:35 +02001878 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_Reset(0)));
Philipp Maier328d1662018-03-07 10:40:27 +01001879 T.start
1880 alt {
1881 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_ResetAck)) {
1882 reset_ack_seen := true;
1883 repeat;
1884 }
1885
1886 /* Acknowledge MSC sided reset requests */
1887 [] BSSAP_DIRECT.receive(tr_BSSAP_UNITDATA_ind(?, ?, tr_BSSMAP_Reset)) {
Philipp Maier75932982018-03-27 14:52:35 +02001888 BSSAP_DIRECT.send(ts_BSSAP_UNITDATA_req(g_bssap[0].sccp_addr_peer, g_bssap[0].sccp_addr_own, ts_BSSMAP_ResetAck));
Philipp Maier328d1662018-03-07 10:40:27 +01001889 repeat;
1890 }
1891
1892 /* Ignore all other messages (e.g CR from the connection request) */
1893 [] BSSAP_DIRECT.receive { repeat }
1894
1895 /* If we got no BSSMAP RESET ACK back, then the MSC entered the
1896 * deadlock situation. The MSC is then unable to respond to any
1897 * further BSSMAP RESET or any other sort of traffic. */
1898 [reset_ack_seen == true] T.timeout { setverdict(pass) }
1899 [reset_ack_seen == false] T.timeout {
1900 setverdict(fail, "no BSSMAP RESET ACK seen!");
Daniel Willmannafce8662018-07-06 23:11:32 +02001901 mtc.stop;
Philipp Maier328d1662018-03-07 10:40:27 +01001902 }
Pau Espin Pedrol7e9178d2019-12-17 17:52:17 +01001903 }
Philipp Maier328d1662018-03-07 10:40:27 +01001904}
Harald Welte9de84792018-01-28 01:06:35 +01001905
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001906/* Test MO Call with no response to RAN-side CRCX or DTAP Release */
Harald Weltee13cfb22019-04-23 16:52:02 +02001907friend function f_tc_mo_release_timeout(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001908 f_init_handler(pars);
1909 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
1910 var MNCC_PDU mncc;
1911 var MgcpCommand mgcp_cmd;
1912
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001913 /* Do not respond to the second CRCX */
1914 cpars.mgw_conn_2.resp := 0;
1915
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001916 f_perform_lu();
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02001917 f_mo_call_establish(cpars);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001918
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001919 var default ccrel := activate(as_optional_cc_rel(cpars));
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001920
1921 f_expect_clear(60.0);
Neels Hofmeyrde76f052019-02-26 05:02:46 +01001922
1923 deactivate(ccrel);
Philipp Maier94f3f1b2018-03-15 18:54:13 +01001924}
1925testcase TC_mo_release_timeout() runs on MTC_CT {
1926 var BSC_ConnHdlr vc_conn;
1927 f_init();
1928
1929 vc_conn := f_start_handler(refers(f_tc_mo_release_timeout), 40);
1930 vc_conn.done;
1931}
1932
Harald Welte12510c52018-01-26 22:26:24 +01001933
Philipp Maier2a98a732018-03-19 16:06:12 +01001934/* LU followed by MT call (including paging) */
1935private function f_tc_lu_and_mt_call_no_dlcx_resp(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
1936 f_init_handler(pars);
Stefan Sperling26d57be2018-11-12 17:03:26 +01001937 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Philipp Maier2a98a732018-03-19 16:06:12 +01001938
1939 /* Intentionally disable the CRCX response */
1940 cpars.mgw_drop_dlcx := true;
1941
1942 /* Perform location update and call */
1943 f_perform_lu();
1944 f_mt_call(cpars);
1945}
1946testcase TC_lu_and_mt_call_no_dlcx_resp() runs on MTC_CT {
1947 var BSC_ConnHdlr vc_conn;
1948 f_init();
1949
1950 /* Perform an almost normal looking locationupdate + mt-call, but do
1951 * not respond to the DLCX at the end of the call */
1952 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_call_no_dlcx_resp), 41);
1953 vc_conn.done;
1954
1955 /* Wait a guard period until the MGCP layer in the MSC times out,
1956 * if the MSC is vulnerable to the use-after-free situation that is
1957 * fixed by I78f1b6a9149488a4ad3f120c1e190a83c07d4b89 then it should
1958 * segfault now */
1959 f_sleep(6.0);
1960
1961 /* Run the init procedures once more. If the MSC has crashed, this
1962 * this will fail */
1963 f_init();
1964}
Harald Welte45164da2018-01-24 12:51:27 +01001965
Philipp Maier75932982018-03-27 14:52:35 +02001966/* Two BSSMAP resets from two different BSCs */
1967testcase TC_reset_two() runs on MTC_CT {
1968 var BSC_ConnHdlr vc_conn;
1969 f_init(2);
1970 f_sleep(2.0);
1971 setverdict(pass);
1972}
1973
Harald Weltee13cfb22019-04-23 16:52:02 +02001974/* Two BSSMAP resets from two different BSCs plus one IuCS RANAP Reset */
1975testcase TC_reset_two_1iu() runs on MTC_CT {
1976 var BSC_ConnHdlr vc_conn;
1977 f_init(3);
1978 f_sleep(2.0);
1979 setverdict(pass);
1980}
1981
Harald Weltef640a012018-04-14 17:49:21 +02001982/***********************************************************************
1983 * SMS Testing
1984 ***********************************************************************/
1985
Harald Weltef45efeb2018-04-09 18:19:24 +02001986/* LU followed by MO SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02001987friend function f_tc_lu_and_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02001988 var SmsParameters spars := valueof(t_SmsPars);
1989
1990 f_init_handler(pars);
1991
1992 /* Perform location update and call */
1993 f_perform_lu();
1994
1995 f_establish_fully(EST_TYPE_MO_SMS);
1996
1997 //spars.exp_rp_err := 96; /* invalid mandatory information */
1998 f_mo_sms(spars);
1999
2000 f_expect_clear();
2001}
2002testcase TC_lu_and_mo_sms() runs on MTC_CT {
2003 var BSC_ConnHdlr vc_conn;
2004 f_init();
2005 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_sms), 42);
2006 vc_conn.done;
2007}
2008
Harald Weltee13cfb22019-04-23 16:52:02 +02002009
Harald Weltef45efeb2018-04-09 18:19:24 +02002010private function f_vty_sms_send(charstring imsi, charstring msisdn, charstring text)
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002011runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002012 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
2013}
2014
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002015/* Remove still pending SMS */
2016private function f_vty_sms_clear(charstring imsi)
2017runs on BSC_ConnHdlr {
2018 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " sms delete-all");
2019 f_vty_transceive(MSCVTY, "sms-queue clear");
2020}
2021
Harald Weltef45efeb2018-04-09 18:19:24 +02002022/* LU followed by MT SMS */
Harald Weltee13cfb22019-04-23 16:52:02 +02002023friend function f_tc_lu_and_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef45efeb2018-04-09 18:19:24 +02002024 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002025
2026 f_init_handler(pars);
2027
2028 /* Perform location update and call */
2029 f_perform_lu();
2030
2031 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002032 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef45efeb2018-04-09 18:19:24 +02002033
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002034 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
Harald Weltef45efeb2018-04-09 18:19:24 +02002035
2036 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002037 f_expect_paging();
2038
Harald Weltef45efeb2018-04-09 18:19:24 +02002039 /* Establish DTAP / BSSAP / SCCP connection */
2040 f_establish_fully(EST_TYPE_PAG_RESP);
2041
2042 spars.tp.ud := 'C8329BFD064D9B53'O;
2043 f_mt_sms(spars);
2044
2045 f_expect_clear();
2046}
2047testcase TC_lu_and_mt_sms() runs on MTC_CT {
2048 var BSC_ConnHdlrPars pars;
2049 var BSC_ConnHdlr vc_conn;
2050 f_init();
2051 pars := f_init_pars(43);
2052 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms), pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002053 vc_conn.done;
2054}
2055
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01002056/* SMS added while already Paging */
2057friend function f_tc_lu_and_mt_sms_already_paging(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2058 var SmsParameters spars := valueof(t_SmsPars);
2059 var OCT4 tmsi;
2060
2061 f_init_handler(pars);
2062
2063 f_perform_lu();
2064
2065 /* register an 'expect' for given IMSI (+TMSI) */
2066 if (isvalue(g_pars.tmsi)) {
2067 tmsi := g_pars.tmsi;
2068 } else {
2069 tmsi := 'FFFFFFFF'O;
2070 }
2071 f_ran_register_imsi(g_pars.imsi, tmsi);
2072
2073 log("first SMS");
2074 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2075
2076 /* MSC->BSC: expect PAGING from MSC */
2077 f_expect_paging();
2078
2079 log("second SMS");
2080 /* Now osmo-msc is in state "Paging pending", make sure that another SMS to be sent at this time just joins in
2081 * with the pending paging. Another SMS: */
2082 f_vty_sms_send(hex2str(pars.imsi), "2342", "Another SMS");
2083
2084 /* Establish DTAP / BSSAP / SCCP connection */
2085 f_establish_fully(EST_TYPE_PAG_RESP);
2086
2087 spars.tp.ud := 'C8329BFD064D9B53'O;
2088 f_mt_sms(spars);
2089
2090 spars.tp.ud := '41F79B8E2ECB41D3E614'O;
2091 f_mt_sms(spars);
2092
2093 f_expect_clear();
2094}
2095testcase TC_lu_and_mt_sms_already_paging() runs on MTC_CT {
2096 var BSC_ConnHdlrPars pars;
2097 var BSC_ConnHdlr vc_conn;
2098 f_init();
2099 pars := f_init_pars(44);
2100 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_already_paging), pars);
2101 vc_conn.done;
2102}
Harald Weltee13cfb22019-04-23 16:52:02 +02002103
Philipp Maier3983e702018-11-22 19:01:33 +01002104/* Paging for MT SMS but no response */
Harald Weltee13cfb22019-04-23 16:52:02 +02002105friend function f_tc_lu_and_mt_sms_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Philipp Maier3983e702018-11-22 19:01:33 +01002106 var SmsParameters spars := valueof(t_SmsPars);
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002107
Philipp Maier3983e702018-11-22 19:01:33 +01002108 f_init_handler(pars, 150.0);
2109
2110 /* Perform location update */
2111 f_perform_lu();
2112
2113 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002114 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Philipp Maier3983e702018-11-22 19:01:33 +01002115
Neels Hofmeyr6aaeccf2019-03-06 15:32:26 +01002116 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2117
Neels Hofmeyr16237742019-03-06 15:34:01 +01002118 /* Expect the MSC to page exactly once */
Harald Weltee13cfb22019-04-23 16:52:02 +02002119 f_expect_paging();
Philipp Maier3983e702018-11-22 19:01:33 +01002120
2121 /* Wait some time to make sure the MSC is not delivering any further
2122 * paging messages or anything else that could be unexpected. */
2123 timer T := 20.0;
2124 T.start
2125 alt {
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002126 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2127 setverdict(fail, "paging seems not to stop!");
2128 mtc.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002129 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002130 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2131 setverdict(fail, "paging seems not to stop!");
2132 mtc.stop;
Harald Weltee13cfb22019-04-23 16:52:02 +02002133 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002134 [] BSSAP.receive {
2135 setverdict(fail, "unexpected BSSAP message received");
2136 self.stop;
Philipp Maier3983e702018-11-22 19:01:33 +01002137 }
Vadim Yanitskiyda774592020-01-15 10:33:47 +07002138 [] T.timeout {
2139 setverdict(pass);
Philipp Maier3983e702018-11-22 19:01:33 +01002140 }
2141 }
2142
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01002143 f_vty_sms_clear(hex2str(g_pars.imsi));
2144
Philipp Maier3983e702018-11-22 19:01:33 +01002145 setverdict(pass);
2146}
2147testcase TC_lu_and_mt_sms_paging_and_nothing() runs on MTC_CT {
2148 var BSC_ConnHdlrPars pars;
2149 var BSC_ConnHdlr vc_conn;
2150 f_init();
Philipp Maiera99ad262019-01-22 15:35:42 +01002151 pars := f_init_pars(1843);
Philipp Maier3983e702018-11-22 19:01:33 +01002152 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_and_nothing), pars);
Philipp Maier3983e702018-11-22 19:01:33 +01002153 vc_conn.done;
2154}
2155
Alexander Couzensfc02f242019-09-12 03:43:18 +02002156/* LU followed by MT SMS with repeated paging */
2157friend function f_tc_lu_and_mt_sms_paging_repeated(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2158 var SmsParameters spars := valueof(t_SmsPars);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002159
2160 f_init_handler(pars);
2161
2162 /* Perform location update and call */
2163 f_perform_lu();
2164
2165 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002166 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Alexander Couzensfc02f242019-09-12 03:43:18 +02002167
2168 f_vty_sms_send(hex2str(pars.imsi), "2342", "Hello SMS");
2169
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002170 log("Expecting first Paging");
Alexander Couzensfc02f242019-09-12 03:43:18 +02002171 /* MSC->BSC: expect PAGING from MSC */
2172 f_expect_paging();
2173
Neels Hofmeyrc3accec2019-11-28 01:09:47 +01002174 if (g_pars.ran_is_geran) {
2175 log("GERAN: expect no further Paging");
2176 } else {
2177 log("UTRAN: expect more Paging");
2178 }
2179
2180 timer T := 5.0;
2181 T.start;
2182 alt {
2183 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
2184 setverdict(fail, "GERAN should not repeat Paging, but received a second Paging");
2185 mtc.stop;
2186 }
2187 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
2188 log("UTRAN: second Paging received, as expected");
2189 setverdict(pass);
2190 }
2191 [] T.timeout {
2192 if (g_pars.ran_is_geran) {
2193 log("GERAN: No further Paging received, as expected");
2194 setverdict(pass);
2195 } else {
2196 setverdict(fail, "UTRAN: Expected a second Paging");
2197 mtc.stop;
2198 }
2199 }
2200 }
Alexander Couzensfc02f242019-09-12 03:43:18 +02002201
2202 /* Establish DTAP / BSSAP / SCCP connection */
2203 f_establish_fully(EST_TYPE_PAG_RESP);
2204
2205 spars.tp.ud := 'C8329BFD064D9B53'O;
2206 f_mt_sms(spars);
2207
2208 f_expect_clear();
2209}
2210testcase TC_lu_and_mt_sms_paging_repeated() runs on MTC_CT {
2211 var BSC_ConnHdlrPars pars;
2212 var BSC_ConnHdlr vc_conn;
2213 f_init();
2214 pars := f_init_pars(1844);
2215 vc_conn := f_start_handler_with_pars(refers(f_tc_lu_and_mt_sms_paging_repeated), pars);
2216 vc_conn.done;
2217}
Harald Weltee13cfb22019-04-23 16:52:02 +02002218
Harald Weltef640a012018-04-14 17:49:21 +02002219/* mobile originated SMS from MS/BTS/BSC side to SMPP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002220friend function f_tc_smpp_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Harald Weltef640a012018-04-14 17:49:21 +02002221 var SmsParameters spars := valueof(t_SmsPars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002222
Harald Weltef640a012018-04-14 17:49:21 +02002223 f_init_handler(pars);
Harald Weltef45efeb2018-04-09 18:19:24 +02002224
Harald Weltef640a012018-04-14 17:49:21 +02002225 /* Perform location update so IMSI is known + registered in MSC/VLR */
2226 f_perform_lu();
Harald Weltef640a012018-04-14 17:49:21 +02002227
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002228 /* MS/UE submits a MO SMS */
2229 f_establish_fully(EST_TYPE_MO_SMS);
2230 f_mo_sms_submit(spars);
Harald Weltef640a012018-04-14 17:49:21 +02002231
2232 var SMPP_PDU smpp;
2233 var template SMPP_PDU tr_smpp := tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK);
2234 tr_smpp.body.deliver_sm := {
2235 service_type := "CMT",
2236 source_addr_ton := network_specific,
2237 source_addr_npi := isdn,
2238 source_addr := hex2str(pars.msisdn),
2239 dest_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2240 dest_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2241 destination_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2242 esm_class := '00000001'B,
2243 protocol_id := 0,
2244 priority_flag := 0,
2245 schedule_delivery_time := "",
2246 replace_if_present := 0,
2247 data_coding := '00000001'B,
2248 sm_default_msg_id := 0,
2249 sm_length := ?,
2250 short_message := spars.tp.ud,
2251 opt_pars := {
2252 {
2253 tag := user_message_reference,
2254 len := 2,
2255 opt_value := {
2256 int2_val := oct2int(spars.tp.msg_ref)
2257 }
2258 }
2259 }
2260 };
2261 alt {
2262 [] SMPP.receive(tr_smpp) -> value smpp {
2263 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_ROK, smpp.header.seq_num));
2264 }
2265 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2266 }
2267
Vadim Yanitskiy2d3f8462020-01-15 11:44:12 +07002268 /* MSC terminates the SMS transaction with RP-ACK */
2269 f_mo_sms_wait_rp_ack(spars);
2270
Harald Weltef640a012018-04-14 17:49:21 +02002271 f_expect_clear();
2272}
2273testcase TC_smpp_mo_sms() runs on MTC_CT {
2274 var BSC_ConnHdlr vc_conn;
2275 f_init();
2276 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2277 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms), 44);
2278 vc_conn.done;
2279 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2280}
2281
Vadim Yanitskiy33820762020-01-15 11:26:07 +07002282/* Test case for OS#4351: make sure that RP-ERROR from ESME is properly sent to the MS/UE */
2283friend function f_tc_smpp_mo_sms_rp_error(charstring id, BSC_ConnHdlrPars pars)
2284runs on BSC_ConnHdlr {
2285 var SmsParameters spars := valueof(t_SmsPars);
2286 var SMPP_PDU smpp_pdu;
2287 timer T := 3.0;
2288
2289 f_init_handler(pars);
2290
2291 /* Perform location update */
2292 f_perform_lu();
2293
2294 /* MS/UE submits a MO SMS */
2295 f_establish_fully(EST_TYPE_MO_SMS);
2296 f_mo_sms_submit(spars);
2297
2298 /* ESME responds with an error (Invalid Destination Address) */
2299 T.start;
2300 alt {
2301 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_deliver_sm, ESME_ROK, body := ?)) -> value smpp_pdu {
2302 SMPP.send(ts_SMPP_DELIVER_SM_resp(ESME_RINVDSTADR, smpp_pdu.header.seq_num));
2303 }
2304 [] SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK)) { repeat; }
2305 [] T.timeout {
2306 setverdict(fail, "Timeout waiting for SMPP DELIVER-SM");
2307 mtc.stop;
2308 }
2309 }
2310
2311 /* Expect RP-ERROR on BSSAP interface */
2312 spars.exp_rp_err := 1; /* FIXME: GSM411_RP_CAUSE_MO_NUM_UNASSIGNED */
2313 f_mo_sms_wait_rp_ack(spars);
2314
2315 f_expect_clear();
2316}
2317testcase TC_smpp_mo_sms_rp_error() runs on MTC_CT {
2318 var BSC_ConnHdlr vc_conn;
2319 f_init();
2320 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "default-route");
2321 vc_conn := f_start_handler(refers(f_tc_smpp_mo_sms_rp_error), 45);
2322 vc_conn.done;
2323 f_vty_config2(MSCVTY, { "smpp", "esme msc_tester"}, "no default-route");
2324}
2325
Harald Weltee13cfb22019-04-23 16:52:02 +02002326
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002327/* Test MO-SMS from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002328friend function f_tc_gsup_mo_sms(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002329runs on BSC_ConnHdlr {
2330 var SmsParameters spars := valueof(t_SmsPars);
2331 var GSUP_PDU gsup_msg_rx;
2332 var octetstring sm_tpdu;
2333
2334 f_init_handler(pars);
2335
2336 /* We need to inspect GSUP activity */
2337 f_create_gsup_expect(hex2str(g_pars.imsi));
2338
2339 /* Perform location update */
2340 f_perform_lu();
2341
2342 /* Send CM Service Request for SMS */
2343 f_establish_fully(EST_TYPE_MO_SMS);
2344
2345 /* Prepare expected SM-RP-UI (SM TPDU) */
2346 enc_TPDU_RP_DATA_MS_SGSN_fast(
2347 valueof(ts_SMS_SUBMIT(spars.tp.msg_ref,
2348 spars.tp.da, spars.tp.pid, spars.tp.dcs,
2349 spars.tp.udl, spars.tp.ud)),
2350 sm_tpdu);
2351
2352 var template GSUP_PDU mo_forwardSM := tr_GSUP_MO_FORWARD_SM_REQ(
2353 imsi := g_pars.imsi,
2354 sm_rp_mr := spars.rp.msg_ref,
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002355 /* SM-RP-DA: SMSC address */
2356 sm_rp_da := tr_GSUP_SM_RP_DA_SMSC_ADDR(t_GSUP_SM_RP_Addr(
2357 number := spars.rp.smsc_addr.rP_NumberDigits,
2358 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2359 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2360 ext := spars.rp.smsc_addr.rP_Ext)),
2361 /* SM-RP-OA: subscriber's MSISDN (filled in by MSC) */
2362 sm_rp_oa := tr_GSUP_SM_RP_OA_MSISDN(t_GSUP_SM_RP_Addr(
2363 number := g_pars.msisdn,
2364 /* NOTE: MSISDN in g_pars lacks this info, assuming defaults */
2365 npi := '0001'B, ton := '001'B, ext := '1'B)),
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002366 /* TODO: can we use decmatch here? */
2367 sm_rp_ui := sm_tpdu
2368 );
2369
2370 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2371 f_mo_sms_submit(spars);
2372 alt {
2373 [] GSUP.receive(mo_forwardSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002374 log("RX MO-forwardSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07002375 setverdict(pass);
2376 }
2377 [] GSUP.receive {
2378 log("RX unexpected GSUP message");
2379 setverdict(fail);
2380 mtc.stop;
2381 }
2382 }
2383
2384 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2385 GSUP.send(valueof(ts_GSUP_MO_FORWARD_SM_RES(
2386 imsi := g_pars.imsi,
2387 sm_rp_mr := spars.rp.msg_ref)));
2388 /* Expect RP-ACK on DTAP */
2389 f_mo_sms_wait_rp_ack(spars);
2390
2391 f_expect_clear();
2392}
2393testcase TC_gsup_mo_sms() runs on MTC_CT {
2394 var BSC_ConnHdlr vc_conn;
2395 f_init();
2396 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2397 vc_conn := f_start_handler(refers(f_tc_gsup_mo_sms), 88);
2398 vc_conn.done;
2399 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2400}
2401
Harald Weltee13cfb22019-04-23 16:52:02 +02002402
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002403/* Test MO-SMMA from MS/BTS/BSC towards HLR (via GSUP) */
Harald Weltee13cfb22019-04-23 16:52:02 +02002404friend function f_tc_gsup_mo_smma(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002405runs on BSC_ConnHdlr {
2406 var SmsParameters spars := valueof(t_SmsPars);
2407 var GSUP_PDU gsup_msg_rx;
2408
2409 f_init_handler(pars);
2410
2411 /* We need to inspect GSUP activity */
2412 f_create_gsup_expect(hex2str(g_pars.imsi));
2413
2414 /* Perform location update */
2415 f_perform_lu();
2416
2417 /* Send CM Service Request for SMS */
2418 f_establish_fully(EST_TYPE_MO_SMS);
2419
2420 var template GSUP_PDU mo_ReadyForSM := tr_GSUP_MO_READY_FOR_SM_REQ(
2421 imsi := g_pars.imsi,
2422 sm_rp_mr := spars.rp.msg_ref,
2423 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2424 );
2425
2426 /* Submit an SMS on DTAP and expect MO-forwardSM-Req on GSUP */
2427 f_mo_smma(spars);
2428 alt {
2429 [] GSUP.receive(mo_ReadyForSM) -> value gsup_msg_rx {
Vadim Yanitskiya358dd42020-01-15 10:42:47 +07002430 log("RX MO-ReadyForSM-Req: ", gsup_msg_rx);
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07002431 setverdict(pass);
2432 }
2433 [] GSUP.receive {
2434 log("RX unexpected GSUP message");
2435 setverdict(fail);
2436 mtc.stop;
2437 }
2438 }
2439
2440 /* Trigger RP-ACK by sending MO-forwardSM-Res */
2441 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2442 imsi := g_pars.imsi,
2443 sm_rp_mr := spars.rp.msg_ref)));
2444 /* Expect RP-ACK on DTAP */
2445 f_mo_sms_wait_rp_ack(spars);
2446
2447 f_expect_clear();
2448}
2449testcase TC_gsup_mo_smma() runs on MTC_CT {
2450 var BSC_ConnHdlr vc_conn;
2451 f_init();
2452 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2453 vc_conn := f_start_handler(refers(f_tc_gsup_mo_smma), 89);
2454 vc_conn.done;
2455 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2456}
2457
Harald Weltee13cfb22019-04-23 16:52:02 +02002458
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002459/* Helper for sending MT SMS over GSUP */
2460private function f_gsup_forwardSM_req(SmsParameters spars, OCT1 mms := '00'O)
2461runs on BSC_ConnHdlr {
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002462 var GSUP_SM_RP_Addr msisdn := valueof(t_GSUP_SM_RP_Addr(g_pars.msisdn));
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002463 var GSUP_SM_RP_Addr smsc := valueof(t_GSUP_SM_RP_Addr(
2464 number := spars.rp.smsc_addr.rP_NumberDigits,
2465 npi := spars.rp.smsc_addr.rP_NumberingPlanIdentification,
2466 ton := spars.rp.smsc_addr.rP_TypeOfNumber,
2467 ext := spars.rp.smsc_addr.rP_Ext));
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002468
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002469 GSUP.send(ts_GSUP_MT_FORWARD_SM_REQ(
2470 imsi := g_pars.imsi,
2471 /* NOTE: MSC should assign RP-MR itself */
2472 sm_rp_mr := 'FF'O,
Vadim Yanitskiya52347c2019-12-12 17:32:33 +09002473 sm_rp_da := valueof(ts_GSUP_SM_RP_DA_MSISDN(msisdn)),
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09002474 sm_rp_oa := valueof(ts_GSUP_SM_RP_OA_SMSC_ADDR(smsc)),
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002475 /* Encoded SMS TPDU (taken from Wireshark)
2476 * FIXME: we should encode spars somehow */
2477 sm_rp_ui := '00068021436500008111328130858200'O,
2478 sm_rp_mms := mms
2479 ));
2480}
2481
2482/* Test successful MT-SMS (RP-ACK) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002483friend function f_tc_gsup_mt_sms_ack(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002484runs on BSC_ConnHdlr {
2485 var SmsParameters spars := valueof(t_SmsPars);
2486
2487 f_init_handler(pars);
2488
2489 /* We need to inspect GSUP activity */
2490 f_create_gsup_expect(hex2str(g_pars.imsi));
2491
2492 /* Perform location update */
2493 f_perform_lu();
2494
2495 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002496 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002497
2498 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2499 imsi := g_pars.imsi,
2500 /* NOTE: MSC should assign RP-MR itself */
2501 sm_rp_mr := ?
2502 );
2503
2504 /* Submit a MT SMS on GSUP */
2505 f_gsup_forwardSM_req(spars);
2506
2507 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002508 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002509 f_establish_fully(EST_TYPE_PAG_RESP);
2510
2511 /* Wait for MT SMS on DTAP */
2512 f_mt_sms_expect(spars);
2513
2514 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2515 f_mt_sms_send_rp_ack(spars);
2516 alt {
2517 [] GSUP.receive(mt_forwardSM_res) {
2518 log("RX MT-forwardSM-Res (RP-ACK)");
2519 setverdict(pass);
2520 }
2521 [] GSUP.receive {
2522 log("RX unexpected GSUP message");
2523 setverdict(fail);
2524 mtc.stop;
2525 }
2526 }
2527
2528 f_expect_clear();
2529}
2530testcase TC_gsup_mt_sms_ack() runs on MTC_CT {
2531 var BSC_ConnHdlrPars pars;
2532 var BSC_ConnHdlr vc_conn;
2533 f_init();
2534 pars := f_init_pars(90);
2535 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2536 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_ack), pars);
2537 vc_conn.done;
2538 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2539}
2540
Harald Weltee13cfb22019-04-23 16:52:02 +02002541
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002542/* Test rejected MT-SMS (RP-ERROR) over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002543friend function f_tc_gsup_mt_sms_err(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002544runs on BSC_ConnHdlr {
2545 var SmsParameters spars := valueof(t_SmsPars);
2546 var OCT1 sm_rp_cause := '78'O; /* dummy RP-Cause value */
2547
2548 f_init_handler(pars);
2549
2550 /* We need to inspect GSUP activity */
2551 f_create_gsup_expect(hex2str(g_pars.imsi));
2552
2553 /* Perform location update */
2554 f_perform_lu();
2555
2556 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002557 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002558
2559 var template GSUP_PDU mt_forwardSM_err := tr_GSUP_MT_FORWARD_SM_ERR(
2560 imsi := g_pars.imsi,
2561 /* NOTE: MSC should assign RP-MR itself */
2562 sm_rp_mr := ?,
2563 sm_rp_cause := sm_rp_cause
2564 );
2565
2566 /* Submit a MT SMS on GSUP */
2567 f_gsup_forwardSM_req(spars);
2568
2569 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002570 f_expect_paging();
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07002571 f_establish_fully(EST_TYPE_PAG_RESP);
2572
2573 /* Wait for MT SMS on DTAP */
2574 f_mt_sms_expect(spars);
2575
2576 /* Send RP-ERROR and expect MT-forwardSM-Err on GSUP */
2577 f_mt_sms_send_rp_error(spars, oct2int(sm_rp_cause));
2578 alt {
2579 [] GSUP.receive(mt_forwardSM_err) {
2580 log("RX MT-forwardSM-Err (RP-ERROR)");
2581 setverdict(pass);
2582 mtc.stop;
2583 }
2584 [] GSUP.receive {
2585 log("RX unexpected GSUP message");
2586 setverdict(fail);
2587 mtc.stop;
2588 }
2589 }
2590
2591 f_expect_clear();
2592}
2593testcase TC_gsup_mt_sms_err() runs on MTC_CT {
2594 var BSC_ConnHdlrPars pars;
2595 var BSC_ConnHdlr vc_conn;
2596 f_init();
2597 pars := f_init_pars(91);
2598 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2599 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_err), pars);
2600 vc_conn.done;
2601 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2602}
2603
Harald Weltee13cfb22019-04-23 16:52:02 +02002604
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002605/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002606friend function f_tc_gsup_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002607runs on BSC_ConnHdlr {
2608 var SmsParameters spars1 := valueof(t_SmsPars); /* 1st SMS */
2609 var SmsParameters spars2 := valueof(t_SmsPars); /* 2nd SMS */
2610
2611 f_init_handler(pars);
2612
2613 /* We need to inspect GSUP activity */
2614 f_create_gsup_expect(hex2str(g_pars.imsi));
2615
2616 /* Perform location update */
2617 f_perform_lu();
2618
2619 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002620 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002621
2622 /* Submit the 1st MT SMS on GSUP */
2623 log("TX MT-forwardSM-Req for the 1st SMS");
2624 f_gsup_forwardSM_req(spars1);
2625
2626 /* Expect Paging Request and Establish DTAP / BSSAP / SCCP connection */
Harald Weltee035e3e2019-04-21 17:32:05 +02002627 f_expect_paging();
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07002628 f_establish_fully(EST_TYPE_PAG_RESP);
2629
2630 /* Wait for 1st MT SMS on DTAP */
2631 f_mt_sms_expect(spars1);
2632 log("RX the 1st SMS on DTAP, DTAP TID is ", spars1.tid,
2633 ", SM-RP-MR is ", spars1.rp.msg_ref);
2634
2635 /* Submit the 2nd MT SMS on GSUP */
2636 log("TX MT-forwardSM-Req for the 2nd SMS");
2637 f_gsup_forwardSM_req(spars2);
2638
2639 /* Wait for 2nd MT SMS on DTAP */
2640 f_mt_sms_expect(spars2);
2641 log("RX the 2nd SMS on DTAP, DTAP TID is ", spars2.tid,
2642 ", SM-RP-MR is ", spars2.rp.msg_ref);
2643
2644 /* Both transaction IDs shall be different */
2645 if (spars1.tid == spars2.tid) {
2646 log("Both DTAP transaction IDs shall be different");
2647 setverdict(fail);
2648 }
2649
2650 /* Both SM-RP-MR values shall be different */
2651 if (spars1.rp.msg_ref == spars2.rp.msg_ref) {
2652 log("Both SM-RP-MR values shall be different");
2653 setverdict(fail);
2654 }
2655
2656 /* Both SM-RP-MR values shall be assigned */
2657 if (spars1.rp.msg_ref == 'FF'O) {
2658 log("Unassigned SM-RP-MR value for the 1st SMS");
2659 setverdict(fail);
2660 }
2661 if (spars2.rp.msg_ref == 'FF'O) {
2662 log("Unassigned SM-RP-MR value for the 2nd SMS");
2663 setverdict(fail);
2664 }
2665
2666 /* Send the 1st RP-ACK and expect MT-forwardSM-Res on GSUP */
2667 f_mt_sms_send_rp_ack(spars1);
2668 alt {
2669 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2670 imsi := g_pars.imsi,
2671 sm_rp_mr := spars1.rp.msg_ref
2672 )) {
2673 log("RX MT-forwardSM-Res (RP-ACK)");
2674 setverdict(pass);
2675 }
2676 [] GSUP.receive {
2677 log("RX unexpected GSUP message");
2678 setverdict(fail);
2679 mtc.stop;
2680 }
2681 }
2682
2683 /* Send the 2nd RP-ACK and expect MT-forwardSM-Res on GSUP */
2684 f_mt_sms_send_rp_ack(spars2);
2685 alt {
2686 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2687 imsi := g_pars.imsi,
2688 sm_rp_mr := spars2.rp.msg_ref
2689 )) {
2690 log("RX MT-forwardSM-Res (RP-ACK)");
2691 setverdict(pass);
2692 }
2693 [] GSUP.receive {
2694 log("RX unexpected GSUP message");
2695 setverdict(fail);
2696 mtc.stop;
2697 }
2698 }
2699
2700 f_expect_clear();
2701}
2702testcase TC_gsup_mt_sms_rp_mr() runs on MTC_CT {
2703 var BSC_ConnHdlrPars pars;
2704 var BSC_ConnHdlr vc_conn;
2705 f_init();
2706 pars := f_init_pars(92);
2707 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2708 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_sms_rp_mr), pars);
2709 vc_conn.done;
2710 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2711}
2712
Harald Weltee13cfb22019-04-23 16:52:02 +02002713
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002714/* Test SM-RP-MR assignment for MT-SMS over GSUP */
Harald Weltee13cfb22019-04-23 16:52:02 +02002715friend function f_tc_gsup_mo_mt_sms_rp_mr(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002716runs on BSC_ConnHdlr {
2717 var SmsParameters spars_mo := valueof(t_SmsPars); /* MO SMMA */
2718 var SmsParameters spars_mt := valueof(t_SmsPars); /* MT SMS */
2719
2720 f_init_handler(pars);
2721
2722 /* We need to inspect GSUP activity */
2723 f_create_gsup_expect(hex2str(g_pars.imsi));
2724
2725 /* Perform location update */
2726 f_perform_lu();
2727
2728 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002729 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07002730
2731 /* Send CM Service Request for MO SMMA */
2732 f_establish_fully(EST_TYPE_MO_SMS);
2733
2734 /* Submit MO SMMA on DTAP */
2735 log("Submit MO SMMA on DTAP, SM-RP-MR is '00'O");
2736 spars_mo.rp.msg_ref := '00'O;
2737 f_mo_smma(spars_mo);
2738
2739 /* Expect MO-forwardSM-Req for MO SMMA on GSUP */
2740 alt {
2741 [] GSUP.receive(tr_GSUP_MO_READY_FOR_SM_REQ(
2742 imsi := g_pars.imsi,
2743 sm_rp_mr := spars_mo.rp.msg_ref,
2744 sm_alert_rsn := GSUP_SM_ALERT_RSN_TYPE_MEM_AVAIL
2745 )) {
2746 log("RX MO-ReadyForSM-Req, SM-RP-MR is '00'O");
2747 setverdict(pass);
2748 }
2749 [] GSUP.receive {
2750 log("RX unexpected GSUP message");
2751 setverdict(fail);
2752 mtc.stop;
2753 }
2754 }
2755
2756 /* Submit MT SMS on GSUP */
2757 log("TX MT-forwardSM-Req for the MT SMS");
2758 f_gsup_forwardSM_req(spars_mt);
2759
2760 /* Wait for MT SMS on DTAP */
2761 f_mt_sms_expect(spars_mt);
2762 log("RX MT SMS on DTAP, DTAP TID is ", spars_mt.tid,
2763 ", SM-RP-MR is ", spars_mt.rp.msg_ref);
2764
2765 /* Both SM-RP-MR values shall be different */
2766 if (spars_mo.rp.msg_ref == spars_mt.rp.msg_ref) {
2767 log("Both SM-RP-MR values shall be different");
2768 setverdict(fail);
2769 }
2770
2771 /* SM-RP-MR value for MT SMS shall be assigned */
2772 if (spars_mt.rp.msg_ref == 'FF'O) {
2773 log("Unassigned SM-RP-MR value for the MT SMS");
2774 setverdict(fail);
2775 }
2776
2777 /* Trigger RP-ACK for MO SMMA by sending MO-forwardSM-Res */
2778 GSUP.send(valueof(ts_GSUP_MO_READY_FOR_SM_RES(
2779 imsi := g_pars.imsi,
2780 sm_rp_mr := spars_mo.rp.msg_ref)));
2781 /* Expect RP-ACK for MO SMMA on DTAP */
2782 f_mo_sms_wait_rp_ack(spars_mo);
2783
2784 /* Send RP-ACK for MT SMS and expect MT-forwardSM-Res on GSUP */
2785 f_mt_sms_send_rp_ack(spars_mt);
2786 alt {
2787 [] GSUP.receive(tr_GSUP_MT_FORWARD_SM_RES(
2788 imsi := g_pars.imsi,
2789 sm_rp_mr := spars_mt.rp.msg_ref
2790 )) {
2791 log("RX MT-forwardSM-Res (RP-ACK)");
2792 setverdict(pass);
2793 }
2794 [] GSUP.receive {
2795 log("RX unexpected GSUP message");
2796 setverdict(fail);
2797 mtc.stop;
2798 }
2799 }
2800
2801 f_expect_clear();
2802}
2803testcase TC_gsup_mo_mt_sms_rp_mr() runs on MTC_CT {
2804 var BSC_ConnHdlrPars pars;
2805 var BSC_ConnHdlr vc_conn;
2806 f_init();
2807 pars := f_init_pars(93);
2808 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2809 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mo_mt_sms_rp_mr), pars);
2810 vc_conn.done;
2811 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2812}
2813
Harald Weltee13cfb22019-04-23 16:52:02 +02002814
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002815/* Test multi-part MT-SMS over GSUP */
2816private function f_tc_gsup_mt_multi_part_sms(charstring id, BSC_ConnHdlrPars pars)
2817runs on BSC_ConnHdlr {
2818 var SmsParameters spars := valueof(t_SmsPars);
2819
2820 f_init_handler(pars);
2821
2822 /* We need to inspect GSUP activity */
2823 f_create_gsup_expect(hex2str(g_pars.imsi));
2824
2825 /* Perform location update */
2826 f_perform_lu();
2827
2828 /* Register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002829 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002830
2831 var template GSUP_PDU mt_forwardSM_res := tr_GSUP_MT_FORWARD_SM_RES(
2832 imsi := g_pars.imsi,
2833 /* NOTE: MSC should assign RP-MR itself */
2834 sm_rp_mr := ?
2835 );
2836
2837 /* Send 4 messages (NOTE: SM-RP-UI remains unchanged) */
2838 for (var integer i := 3; i >= 0; i := i-1) {
2839 /* Submit a MT SMS on GSUP (MMS is decremented) */
2840 f_gsup_forwardSM_req(spars, int2oct(i, 1));
2841
2842 /* Expect Paging Request and Establish connection */
2843 if (i == 3) { /* ... only once! */
Harald Weltee13cfb22019-04-23 16:52:02 +02002844 f_expect_paging();
Vadim Yanitskiy1cd11a02018-12-03 02:43:35 +07002845 f_establish_fully(EST_TYPE_PAG_RESP);
2846 }
2847
2848 /* Wait for MT SMS on DTAP */
2849 f_mt_sms_expect(spars);
2850
2851 /* Send RP-ACK and expect MT-forwardSM-Res on GSUP */
2852 f_mt_sms_send_rp_ack(spars);
2853 alt {
2854 [] GSUP.receive(mt_forwardSM_res) {
2855 log("RX MT-forwardSM-Res (RP-ACK)");
2856 setverdict(pass);
2857 }
2858 [] GSUP.receive {
2859 log("RX unexpected GSUP message");
2860 setverdict(fail);
2861 mtc.stop;
2862 }
2863 }
2864
2865 /* Keep some 'distance' between transmissions */
2866 f_sleep(1.5);
2867 }
2868
2869 f_expect_clear();
2870}
2871testcase TC_gsup_mt_multi_part_sms() runs on MTC_CT {
2872 var BSC_ConnHdlrPars pars;
2873 var BSC_ConnHdlr vc_conn;
2874 f_init();
2875 pars := f_init_pars(91);
2876 f_vty_config(MSCVTY, "msc", "sms-over-gsup");
2877 vc_conn := f_start_handler_with_pars(refers(f_tc_gsup_mt_multi_part_sms), pars);
2878 vc_conn.done;
2879 f_vty_config(MSCVTY, "msc", "no sms-over-gsup");
2880}
2881
Harald Weltef640a012018-04-14 17:49:21 +02002882/* convert GSM L3 TON to SMPP_TON enum */
2883function f_sm_ton_from_gsm(BIT3 ton) return SMPP_TON {
2884 select (ton) {
2885 case ('000'B) { return unknown; }
2886 case ('001'B) { return international; }
2887 case ('010'B) { return national; }
2888 case ('011'B) { return network_specific; }
2889 case ('100'B) { return subscriber_number; }
2890 case ('101'B) { return alphanumeric; }
2891 case ('110'B) { return abbreviated; }
2892 }
2893 setverdict(fail, "Unknown TON ", ton);
Daniel Willmannafce8662018-07-06 23:11:32 +02002894 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002895}
2896/* convert GSM L3 NPI to SMPP_NPI enum */
2897function f_sm_npi_from_gsm(BIT4 npi) return SMPP_NPI {
2898 select (npi) {
2899 case ('0000'B) { return unknown; }
2900 case ('0001'B) { return isdn; }
2901 case ('0011'B) { return data; }
2902 case ('0100'B) { return telex; }
2903 case ('0110'B) { return land_mobile; }
2904 case ('1000'B) { return national; }
2905 case ('1001'B) { return private_; }
2906 case ('1010'B) { return ermes; }
2907 }
2908 setverdict(fail, "Unknown NPI ", npi);
Daniel Willmannafce8662018-07-06 23:11:32 +02002909 mtc.stop;
Harald Weltef640a012018-04-14 17:49:21 +02002910}
2911
2912/* build a SMPP_SM from SmsParameters */
2913function f_mt_sm_from_spars(SmsParameters spars)
2914runs on BSC_ConnHdlr return SMPP_SM {
2915 var SMPP_SM sm := {
2916 service_type := "CMT",
2917 source_addr_ton := f_sm_ton_from_gsm(spars.tp.da.tP_DA_NoPad.tP_TypeOfNumber),
2918 source_addr_npi := f_sm_npi_from_gsm(spars.tp.da.tP_DA_NoPad.tP_NumberingPlanID),
2919 source_addr := hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue),
2920 dest_addr_ton := international,
2921 dest_addr_npi := isdn,
2922 destination_addr := hex2str(g_pars.msisdn),
2923 esm_class := '00000001'B,
2924 protocol_id := 0,
2925 priority_flag := 0,
2926 schedule_delivery_time := "",
2927 validity_period := "",
2928 registered_delivery := '00000000'B,
2929 replace_if_present := 0,
2930 data_coding := '00000001'B,
2931 sm_default_msg_id := 0,
2932 sm_length := spars.tp.udl,
2933 short_message := spars.tp.ud,
2934 opt_pars := {}
2935 };
2936 return sm;
2937}
2938
2939/* helper function to encode SMS from 'spars', send it via SMPP to MSC; receive it on MS side */
2940private function f_smpp_mt_sms(SmsParameters spars, boolean trans_mode) runs on BSC_ConnHdlr {
2941 var SMPP_SM sm := f_mt_sm_from_spars(spars);
2942 if (trans_mode) {
2943 sm.esm_class := '00000010'B;
2944 }
2945
2946 /* actually cause MSC to send a SMS via SUBMIT-SM from SMPP side */
2947 SMPP.send(ts_SMPP_SUBMIT_SM(sm));
2948 if (not match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2949 /* if we're not in SMPP transaction mode, we expect the SMPP-level ACK
2950 * before we expect the SMS delivery on the BSC/radio side */
2951 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2952 }
2953
2954 /* MSC->BSC: expect PAGING from MSC */
Harald Weltee035e3e2019-04-21 17:32:05 +02002955 f_expect_paging();
Harald Weltef640a012018-04-14 17:49:21 +02002956 /* Establish DTAP / BSSAP / SCCP connection */
2957 f_establish_fully(EST_TYPE_PAG_RESP);
2958 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2959
2960 f_mt_sms(spars);
2961
2962 if (match(sm.esm_class, tr_ESM_CLASS_TRANSACTION)) {
2963 SMPP.receive(tr_SMPP(c_SMPP_command_id_submit_sm_resp, ESME_ROK));
2964 }
2965 f_expect_clear();
2966}
2967
2968/* mobile terminated SMS, from SMPP to BSC/BTS/MS */
2969private function f_tc_smpp_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
2970 f_init_handler(pars);
2971
2972 /* Perform location update so IMSI is known + registered in MSC/VLR */
2973 f_perform_lu();
2974 SMPP.receive(tr_SMPP(c_SMPP_command_id_alert_notification, ESME_ROK));
2975
2976 /* register an 'expect' for given IMSI (+TMSI) */
Vadim Yanitskiyae747742020-01-10 00:23:10 +01002977 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Weltef640a012018-04-14 17:49:21 +02002978
2979 var SmsParameters spars := valueof(t_SmsPars);
2980 /* TODO: test with more intelligent user data; test different coding schemes */
2981 spars.tp.ud := '00'O;
2982 spars.tp.udl := 1;
2983
2984 /* first test the non-transaction store+forward mode */
2985 f_smpp_mt_sms(spars, false);
2986
2987 /* then test the transaction mode */
2988 f_smpp_mt_sms(spars, true);
2989}
2990testcase TC_smpp_mt_sms() runs on MTC_CT {
2991 var BSC_ConnHdlr vc_conn;
2992 f_init();
2993 vc_conn := f_start_handler(refers(f_tc_smpp_mt_sms), 45);
2994 vc_conn.done;
2995}
2996
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07002997/***********************************************************************
2998 * USSD Testing
2999 ***********************************************************************/
3000
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003001private altstep as_unexp_gsup_or_bssap_msg()
3002runs on BSC_ConnHdlr {
3003 [] GSUP.receive {
3004 setverdict(fail, "Unknown/unexpected GSUP received");
3005 self.stop;
3006 }
3007 [] BSSAP.receive {
3008 setverdict(fail, "Unknown/unexpected BSSAP message received");
3009 self.stop;
3010 }
3011}
3012
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003013private function f_expect_gsup_msg(template GSUP_PDU msg,
3014 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003015runs on BSC_ConnHdlr return GSUP_PDU {
3016 var GSUP_PDU gsup_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003017 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003018
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003019 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003020 alt {
3021 [] GSUP.receive(msg) -> value gsup_msg_complete {
3022 setverdict(pass);
3023 }
3024 /* We don't expect anything else */
3025 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003026 [] T.timeout {
3027 setverdict(fail, "Timeout waiting for GSUP message: ", msg);
3028 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003029 }
3030
3031 return gsup_msg_complete;
3032}
3033
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003034private function f_expect_mt_dtap_msg(template PDU_ML3_NW_MS msg,
3035 float T_val := 2.0)
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003036runs on BSC_ConnHdlr return PDU_ML3_NW_MS {
3037 var PDU_DTAP_MT bssap_msg_complete;
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003038 timer T := T_val;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003039
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003040 T.start;
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003041 alt {
3042 [] BSSAP.receive(tr_PDU_DTAP_MT(msg)) -> value bssap_msg_complete {
3043 setverdict(pass);
3044 }
3045 /* We don't expect anything else */
3046 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003047 [] T.timeout {
3048 setverdict(fail, "Timeout waiting for BSSAP message: ", msg);
3049 }
Vadim Yanitskiyce8cc372018-06-21 01:46:33 +07003050 }
3051
3052 return bssap_msg_complete.dtap;
3053}
3054
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003055/* LU followed by MO USSD request */
Harald Weltee13cfb22019-04-23 16:52:02 +02003056friend function f_tc_lu_and_mo_ussd_single_request(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003057runs on BSC_ConnHdlr {
3058 f_init_handler(pars);
3059
3060 /* Perform location update */
3061 f_perform_lu();
3062
3063 /* Send CM Service Request for SS/USSD */
3064 f_establish_fully(EST_TYPE_SS_ACT);
3065
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003066 /* We need to inspect GSUP activity */
3067 f_create_gsup_expect(hex2str(g_pars.imsi));
3068
3069 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3070 invoke_id := 5, /* Phone may not start from 0 or 1 */
3071 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3072 ussd_string := "*#100#"
3073 );
3074
3075 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3076 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
3077 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3078 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3079 )
3080
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003081 /* Compose a new SS/REGISTER message with request */
3082 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3083 tid := 1, /* We just need a single transaction */
3084 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003085 facility := valueof(facility_req)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003086 );
3087
3088 /* Compose SS/RELEASE_COMPLETE template with expected response */
3089 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3090 tid := 1, /* Response should arrive within the same transaction */
3091 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003092 facility := valueof(facility_rsp)
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003093 );
3094
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003095 /* Compose expected MSC -> HLR message */
3096 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3097 imsi := g_pars.imsi,
3098 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3099 ss := valueof(facility_req)
3100 );
3101
3102 /* To be used for sending response with correct session ID */
3103 var GSUP_PDU gsup_req_complete;
3104
3105 /* Request own number */
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003106 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003107 /* Expect GSUP message containing the SS payload */
3108 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3109
3110 /* Compose the response from HLR using received session ID */
3111 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3112 imsi := g_pars.imsi,
3113 sid := gsup_req_complete.ies[1].val.session_id,
3114 state := OSMO_GSUP_SESSION_STATE_END,
3115 ss := valueof(facility_rsp)
3116 );
3117
3118 /* Finally, HLR terminates the session */
3119 GSUP.send(gsup_rsp);
3120 /* Expect RELEASE_COMPLETE message with the response */
3121 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003122
3123 f_expect_clear();
3124}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003125testcase TC_lu_and_mo_ussd_single_request() runs on MTC_CT {
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003126 var BSC_ConnHdlr vc_conn;
3127 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003128 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 46);
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07003129 vc_conn.done;
3130}
3131
Harald Weltee13cfb22019-04-23 16:52:02 +02003132
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003133/* LU followed by MT USSD notification */
Harald Weltee13cfb22019-04-23 16:52:02 +02003134friend function f_tc_lu_and_mt_ussd_notification(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003135runs on BSC_ConnHdlr {
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003136 timer T := 5.0;
3137
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003138 f_init_handler(pars);
3139
3140 /* Perform location update */
3141 f_perform_lu();
3142
Harald Welte6811d102019-04-14 22:23:14 +02003143 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003144
3145 /* We need to inspect GSUP activity */
3146 f_create_gsup_expect(hex2str(g_pars.imsi));
3147
3148 /* Facility IE with network-originated USSD notification */
3149 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3150 op_code := SS_OP_CODE_USS_NOTIFY,
3151 ussd_string := "Mahlzeit!"
3152 );
3153
3154 /* Facility IE with acknowledgment to the USSD notification */
3155 var template OCTN facility_rsp := enc_SS_FacilityInformation(
3156 /* In case of USSD notification, Return Result is empty */
3157 valueof(ts_SS_USSD_FACILITY_RETURN_RESULT_EMPTY())
3158 );
3159
3160 /* Compose a new MT SS/REGISTER message with USSD notification */
3161 var template PDU_ML3_NW_MS ussd_ntf := tr_ML3_MT_SS_REGISTER(
3162 tid := 0, /* FIXME: most likely, it should be 0 */
3163 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3164 facility := valueof(facility_req)
3165 );
3166
3167 /* Compose HLR -> MSC GSUP message */
3168 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3169 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003170 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003171 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3172 ss := valueof(facility_req)
3173 );
3174
3175 /* Send it to MSC and expect Paging Request */
3176 GSUP.send(gsup_req);
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003177 T.start;
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003178 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02003179 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3180 setverdict(pass);
3181 }
Harald Welte62113fc2019-05-09 13:04:02 +02003182 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003183 setverdict(pass);
3184 }
3185 /* We don't expect anything else */
3186 [] as_unexp_gsup_or_bssap_msg();
Vadim Yanitskiyd1e1ce52019-06-15 03:40:59 +07003187 [] T.timeout {
3188 setverdict(fail, "Timeout waiting for Paging Request");
3189 }
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003190 }
3191
3192 /* Send Paging Response and expect USSD notification */
3193 f_establish_fully(EST_TYPE_PAG_RESP);
3194 /* Expect MT REGISTER message with USSD notification */
3195 f_expect_mt_dtap_msg(ussd_ntf);
3196
3197 /* Compose a new MO SS/FACILITY message with empty response */
3198 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3199 tid := 0, /* FIXME: it shall match the request tid */
3200 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3201 facility := valueof(facility_rsp)
3202 );
3203
3204 /* Compose expected MSC -> HLR GSUP message */
3205 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3206 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003207 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003208 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3209 ss := valueof(facility_rsp)
3210 );
3211
3212 /* MS sends response to the notification */
3213 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3214 /* Expect GSUP message containing the SS payload */
3215 f_expect_gsup_msg(gsup_rsp);
3216
3217 /* Compose expected MT SS/RELEASE COMPLETE message */
3218 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3219 tid := 0, /* FIXME: it shall match the request tid */
3220 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3221 facility := omit
3222 );
3223
3224 /* Compose MSC -> HLR GSUP message */
3225 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3226 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003227 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003228 state := OSMO_GSUP_SESSION_STATE_END
3229 );
3230
3231 /* Finally, HLR terminates the session */
3232 GSUP.send(gsup_term)
3233 /* Expect MT RELEASE COMPLETE without Facility IE */
3234 f_expect_mt_dtap_msg(ussd_term);
3235
3236 f_expect_clear();
3237}
3238testcase TC_lu_and_mt_ussd_notification() runs on MTC_CT {
3239 var BSC_ConnHdlr vc_conn;
3240 f_init();
3241 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_notification), 47);
3242 vc_conn.done;
3243}
3244
Harald Weltee13cfb22019-04-23 16:52:02 +02003245
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003246/* LU followed by MT call and MO USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003247friend function f_tc_lu_and_mo_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003248runs on BSC_ConnHdlr {
3249 f_init_handler(pars);
3250
3251 /* Call parameters taken from f_tc_lu_and_mt_call */
3252 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003253
3254 /* Perform location update */
3255 f_perform_lu();
3256
3257 /* Establish a MT call */
3258 f_mt_call_establish(cpars);
3259
3260 /* Hold the call for some time */
3261 f_sleep(1.0);
3262
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003263 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3264 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3265 ussd_string := "*#100#"
3266 );
3267
3268 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3269 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3270 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
3271 )
3272
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003273 /* Compose a new SS/REGISTER message with request */
3274 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
3275 tid := 1, /* We just need a single transaction */
3276 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003277 facility := valueof(facility_req)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003278 );
3279
3280 /* Compose SS/RELEASE_COMPLETE template with expected response */
3281 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
3282 tid := 1, /* Response should arrive within the same transaction */
3283 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003284 facility := valueof(facility_rsp)
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003285 );
3286
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003287 /* Compose expected MSC -> HLR message */
3288 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
3289 imsi := g_pars.imsi,
3290 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3291 ss := valueof(facility_req)
3292 );
3293
3294 /* To be used for sending response with correct session ID */
3295 var GSUP_PDU gsup_req_complete;
3296
3297 /* Request own number */
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003298 BSSAP.send(ts_PDU_DTAP_MO(ussd_req));
Vadim Yanitskiy747689e2018-06-19 00:14:28 +07003299 /* Expect GSUP message containing the SS payload */
3300 gsup_req_complete := f_expect_gsup_msg(gsup_req);
3301
3302 /* Compose the response from HLR using received session ID */
3303 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
3304 imsi := g_pars.imsi,
3305 sid := gsup_req_complete.ies[1].val.session_id,
3306 state := OSMO_GSUP_SESSION_STATE_END,
3307 ss := valueof(facility_rsp)
3308 );
3309
3310 /* Finally, HLR terminates the session */
3311 GSUP.send(gsup_rsp);
3312 /* Expect RELEASE_COMPLETE message with the response */
3313 f_expect_mt_dtap_msg(ussd_rsp);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003314
3315 /* Hold the call for some time */
3316 f_sleep(1.0);
3317
3318 /* Release the call (does Clear Complete itself) */
3319 f_call_hangup(cpars, true);
3320}
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003321testcase TC_lu_and_mo_ussd_during_mt_call() runs on MTC_CT {
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003322 var BSC_ConnHdlr vc_conn;
3323 f_init();
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07003324 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_during_mt_call), 48);
Vadim Yanitskiy0aaf48d2018-06-06 07:02:47 +07003325 vc_conn.done;
3326}
3327
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003328/* BSSMAP Clear Request in the middle of a call, see OS#3062 */
Harald Weltee13cfb22019-04-23 16:52:02 +02003329friend function f_tc_mo_cc_bssmap_clear(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003330 f_init_handler(pars);
3331 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003332 cpars.ran_clear_when_alerting := true;
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003333
3334 f_perform_lu();
3335
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003336 var default ccrel := activate(as_optional_cc_rel(cpars));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02003337 f_mo_call_establish(cpars);
3338 f_expect_clear()
Neels Hofmeyrde76f052019-02-26 05:02:46 +01003339 deactivate(ccrel);
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02003340
3341 f_sleep(1.0);
3342}
3343testcase TC_mo_cc_bssmap_clear() runs on MTC_CT {
3344 var BSC_ConnHdlr vc_conn;
3345 f_init();
3346
3347 vc_conn := f_start_handler(refers(f_tc_mo_cc_bssmap_clear), 43);
3348 vc_conn.done;
3349}
3350
Harald Weltee13cfb22019-04-23 16:52:02 +02003351
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003352/* LU followed by MT call and MT USSD request during this call */
Harald Weltee13cfb22019-04-23 16:52:02 +02003353friend function f_tc_lu_and_mt_ussd_during_mt_call(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003354runs on BSC_ConnHdlr {
3355 f_init_handler(pars);
3356
3357 /* Call parameters taken from f_tc_lu_and_mt_call */
3358 var CallParameters cpars := valueof(t_CallParams('123456'H, 0));
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003359
3360 /* Perform location update */
3361 f_perform_lu();
3362
3363 /* Establish a MT call */
3364 f_mt_call_establish(cpars);
3365
3366 /* Hold the call for some time */
3367 f_sleep(1.0);
3368
3369 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
3370 op_code := SS_OP_CODE_USS_REQUEST,
3371 ussd_string := "Please type anything..."
3372 );
3373
3374 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
3375 op_code := SS_OP_CODE_USS_REQUEST,
3376 ussd_string := "Nope."
3377 )
3378
3379 /* Compose MT SS/REGISTER message with network-originated request */
3380 var template (value) PDU_ML3_NW_MS ussd_req := ts_ML3_MT_SS_REGISTER(
3381 tid := 0, /* FIXME: most likely, it should be 0 */
3382 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3383 facility := valueof(facility_req)
3384 );
3385
3386 /* Compose HLR -> MSC GSUP message */
3387 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3388 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003389 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003390 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3391 ss := valueof(facility_req)
3392 );
3393
3394 /* Send it to MSC */
3395 GSUP.send(gsup_req);
3396 /* Expect MT REGISTER message with USSD request */
3397 f_expect_mt_dtap_msg(ussd_req);
3398
3399 /* Compose a new MO SS/FACILITY message with response */
3400 var template (value) PDU_ML3_MS_NW ussd_rsp := ts_ML3_MO_SS_FACILITY(
3401 tid := 0, /* FIXME: it shall match the request tid */
3402 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3403 facility := valueof(facility_rsp)
3404 );
3405
3406 /* Compose expected MSC -> HLR GSUP message */
3407 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_REQ(
3408 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003409 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003410 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3411 ss := valueof(facility_rsp)
3412 );
3413
3414 /* MS sends response */
3415 BSSAP.send(ts_PDU_DTAP_MO(ussd_rsp));
3416 f_expect_gsup_msg(gsup_rsp);
3417
3418 /* Compose expected MT SS/RELEASE COMPLETE message */
3419 var template PDU_ML3_NW_MS ussd_term := tr_ML3_MT_SS_RELEASE_COMPLETE(
3420 tid := 0, /* FIXME: it shall match the request tid */
3421 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3422 facility := omit
3423 );
3424
3425 /* Compose MSC -> HLR GSUP message */
3426 var template GSUP_PDU gsup_term := ts_GSUP_PROC_SS_REQ(
3427 imsi := g_pars.imsi,
Vadim Yanitskiy2dd96612020-01-07 21:48:29 +01003428 sid := g_pars.gsup_sid,
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07003429 state := OSMO_GSUP_SESSION_STATE_END
3430 );
3431
3432 /* Finally, HLR terminates the session */
3433 GSUP.send(gsup_term);
3434 /* Expect MT RELEASE COMPLETE without Facility IE */
3435 f_expect_mt_dtap_msg(ussd_term);
3436
3437 /* Hold the call for some time */
3438 f_sleep(1.0);
3439
3440 /* Release the call (does Clear Complete itself) */
3441 f_call_hangup(cpars, true);
3442}
3443testcase TC_lu_and_mt_ussd_during_mt_call() runs on MTC_CT {
3444 var BSC_ConnHdlr vc_conn;
3445 f_init();
3446 vc_conn := f_start_handler(refers(f_tc_lu_and_mt_ussd_during_mt_call), 49);
3447 vc_conn.done;
3448}
3449
Harald Weltee13cfb22019-04-23 16:52:02 +02003450
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003451/* LU followed by MO USSD request and MO Release during transaction */
Harald Weltee13cfb22019-04-23 16:52:02 +02003452friend function f_tc_lu_and_mo_ussd_mo_release(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07003453runs on BSC_ConnHdlr {
3454 f_init_handler(pars);
3455
3456 /* Perform location update */
3457 f_perform_lu();
3458
3459 /* Send CM Service Request for SS/USSD */
3460 f_establish_fully(EST_TYPE_SS_ACT);
3461
3462 /* We need to inspect GSUP activity */
3463 f_create_gsup_expect(hex2str(g_pars.imsi));
3464
3465 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3466 invoke_id := 1, /* Initial request */
3467 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3468 ussd_string := "*6766*266#"
3469 );
3470
3471 var template OCTN facility_net_req := f_USSD_FACILITY_IE_INVOKE(
3472 invoke_id := 2, /* Counter request */
3473 op_code := SS_OP_CODE_USS_REQUEST,
3474 ussd_string := "Password?!?"
3475 )
3476
3477 /* Compose MO SS/REGISTER message with request */
3478 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3479 tid := 1, /* We just need a single transaction */
3480 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3481 facility := valueof(facility_ms_req)
3482 );
3483
3484 /* Compose expected MSC -> HLR message */
3485 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3486 imsi := g_pars.imsi,
3487 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3488 ss := valueof(facility_ms_req)
3489 );
3490
3491 /* To be used for sending response with correct session ID */
3492 var GSUP_PDU gsup_ms_req_complete;
3493
3494 /* Initiate a new transaction */
3495 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3496 /* Expect GSUP request with original Facility IE */
3497 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3498
3499 /* Compose the response from HLR using received session ID */
3500 var template (value) GSUP_PDU gsup_net_req := ts_GSUP_PROC_SS_REQ(
3501 imsi := g_pars.imsi,
3502 sid := gsup_ms_req_complete.ies[1].val.session_id,
3503 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3504 ss := valueof(facility_net_req)
3505 );
3506
3507 /* Compose expected MT SS/FACILITY template with counter request */
3508 var template PDU_ML3_NW_MS ussd_net_req := tr_ML3_MT_SS_FACILITY(
3509 tid := 1, /* Response should arrive within the same transaction */
3510 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3511 facility := valueof(facility_net_req)
3512 );
3513
3514 /* Send response over GSUP */
3515 GSUP.send(gsup_net_req);
3516 /* Expect MT SS/FACILITY message with counter request */
3517 f_expect_mt_dtap_msg(ussd_net_req);
3518
3519 /* Compose MO SS/RELEASE COMPLETE */
3520 var template (value) PDU_ML3_MS_NW ussd_abort := ts_ML3_MO_SS_RELEASE_COMPLETE(
3521 tid := 1, /* Response should arrive within the same transaction */
3522 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3523 facility := omit
3524 /* TODO: cause? */
3525 );
3526
3527 /* Compose expected HLR -> MSC abort message */
3528 var template GSUP_PDU gsup_abort := tr_GSUP_PROC_SS_REQ(
3529 imsi := g_pars.imsi,
3530 sid := gsup_ms_req_complete.ies[1].val.session_id,
3531 state := OSMO_GSUP_SESSION_STATE_END
3532 );
3533
3534 /* Abort transaction */
3535 BSSAP.send(ts_PDU_DTAP_MO(ussd_abort));
3536 /* Expect GSUP message indicating abort */
3537 f_expect_gsup_msg(gsup_abort);
3538
3539 f_expect_clear();
3540}
3541testcase TC_lu_and_mo_ussd_mo_release() runs on MTC_CT {
3542 var BSC_ConnHdlr vc_conn;
3543 f_init();
3544 vc_conn := f_start_handler(refers(f_tc_lu_and_mo_ussd_mo_release), 50);
3545 vc_conn.done;
3546}
3547
Harald Weltee13cfb22019-04-23 16:52:02 +02003548
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003549/* LU followed by MO USSD request and MT Release due to timeout */
Harald Weltee13cfb22019-04-23 16:52:02 +02003550friend function f_tc_lu_and_ss_session_timeout(charstring id, BSC_ConnHdlrPars pars)
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003551runs on BSC_ConnHdlr {
3552 f_init_handler(pars);
3553
3554 /* Perform location update */
3555 f_perform_lu();
3556
3557 /* Send CM Service Request for SS/USSD */
3558 f_establish_fully(EST_TYPE_SS_ACT);
3559
3560 /* We need to inspect GSUP activity */
3561 f_create_gsup_expect(hex2str(g_pars.imsi));
3562
3563 var template OCTN facility_ms_req := f_USSD_FACILITY_IE_INVOKE(
3564 invoke_id := 1,
3565 op_code := SS_OP_CODE_PROCESS_USS_REQ,
3566 ussd_string := "#release_me");
3567
3568 /* Compose MO SS/REGISTER message with request */
3569 var template (value) PDU_ML3_MS_NW ussd_ms_req := ts_ML3_MO_SS_REGISTER(
3570 tid := 1, /* An arbitrary transaction identifier */
3571 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3572 facility := valueof(facility_ms_req));
3573
3574 /* Compose expected MSC -> HLR message */
3575 var template GSUP_PDU gsup_ms_req := tr_GSUP_PROC_SS_REQ(
3576 imsi := g_pars.imsi,
3577 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3578 ss := valueof(facility_ms_req));
3579
3580 /* To be used for sending response with correct session ID */
3581 var GSUP_PDU gsup_ms_req_complete;
3582
3583 /* Initiate a new SS transaction */
3584 BSSAP.send(ts_PDU_DTAP_MO(ussd_ms_req));
3585 /* Expect GSUP request with original Facility IE */
3586 gsup_ms_req_complete := f_expect_gsup_msg(gsup_ms_req);
3587
3588 /* Don't respond, wait for timeout */
3589 f_sleep(3.0);
3590
3591 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3592 tid := 1, /* Should match the request's tid */
3593 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3594 cause := *, /* TODO: expect some specific value */
3595 facility := omit);
3596
3597 var template GSUP_PDU gsup_rel := tr_GSUP_PROC_SS_ERR(
3598 imsi := g_pars.imsi,
3599 sid := gsup_ms_req_complete.ies[1].val.session_id,
3600 state := OSMO_GSUP_SESSION_STATE_END,
3601 cause := ?); /* TODO: expect some specific value */
3602
3603 /* Expect release on both interfaces */
3604 interleave {
3605 [] BSSAP.receive(tr_PDU_DTAP_MT(dtap_rel)) { };
3606 [] GSUP.receive(gsup_rel) { };
3607 }
3608
3609 f_expect_clear();
3610 setverdict(pass);
3611}
3612testcase TC_lu_and_ss_session_timeout() runs on MTC_CT {
3613 var BSC_ConnHdlr vc_conn;
3614 f_init();
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003615 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 3");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003616 vc_conn := f_start_handler(refers(f_tc_lu_and_ss_session_timeout), 51);
3617 vc_conn.done;
Vadim Yanitskiy36d28dd2018-12-03 02:45:45 +07003618 f_vty_config(MSCVTY, "msc", "ncss guard-timeout 0");
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07003619}
3620
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003621/* MT (network-originated) USSD for unknown subscriber */
3622friend function f_tc_mt_ussd_for_unknown_subscr(charstring id, BSC_ConnHdlrPars pars)
3623runs on BSC_ConnHdlr {
3624 var hexstring imsi := '000000000000000'H; /* Some unknown IMSI */
3625 var OCT4 sid := '20000222'O;
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003626
3627 f_init_handler(pars);
3628 f_ran_register_imsi(imsi, 'FFFFFFFF'O);
3629 f_create_gsup_expect(hex2str(imsi));
3630
3631 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3632 imsi := imsi,
3633 sid := sid,
3634 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3635 ss := f_rnd_octstring(23)
3636 );
3637
3638 /* Error with cause GMM_CAUSE_IMSI_UNKNOWN */
3639 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3640 imsi := imsi,
3641 sid := sid,
3642 state := OSMO_GSUP_SESSION_STATE_END,
3643 cause := 2 /* FIXME: introduce an enumerated type! */
3644 );
3645
3646 /* Initiate a MT USSD notification */
3647 GSUP.send(gsup_req);
3648
3649 /* Expect GSUP PROC_SS_ERROR message */
Vadim Yanitskiy851798c2019-06-15 14:22:28 +07003650 f_expect_gsup_msg(gsup_rsp);
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07003651}
3652testcase TC_mt_ussd_for_unknown_subscr() runs on MTC_CT {
3653 var BSC_ConnHdlr vc_conn;
3654 f_init();
3655 vc_conn := f_start_handler(refers(f_tc_mt_ussd_for_unknown_subscr), 0);
3656 vc_conn.done;
3657}
3658
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003659/* MO (mobile-originated) SS/USSD for unknown transaction */
3660friend function f_tc_mo_ussd_for_unknown_trans(charstring id, BSC_ConnHdlrPars pars)
3661runs on BSC_ConnHdlr {
3662 f_init_handler(pars);
3663
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003664 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07003665 f_create_gsup_expect(hex2str(g_pars.imsi));
3666
3667 /* Perform location update */
3668 f_perform_lu();
3669
3670 /* Send CM Service Request for SS/USSD */
3671 f_establish_fully(EST_TYPE_SS_ACT);
3672
3673 /* GSM 04.80 FACILITY message for a non-existing transaction */
3674 var template (value) PDU_ML3_MS_NW mo_ss_fac := ts_ML3_MO_SS_FACILITY(
3675 tid := 1, /* An arbitrary transaction identifier */
3676 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3677 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3678 );
3679
3680 /* GSM 04.80 RELEASE COMPLETE message for a non-existing transaction */
3681 var template (value) PDU_ML3_MS_NW mo_ss_rel := ts_ML3_MO_SS_RELEASE_COMPLETE(
3682 tid := 1, /* An arbitrary transaction identifier */
3683 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3684 facility := f_rnd_octstring(23) /* We don't care about the Facility IE */
3685 );
3686
3687 /* Expected response from the network */
3688 var template PDU_ML3_NW_MS mt_ss_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3689 tid := 1, /* Same as in the FACILITY message */
3690 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
3691 facility := omit
3692 );
3693
3694 /* Send GSM 04.80 FACILITY for non-existing transaction */
3695 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_fac));
3696
3697 /* Expect GSM 04.80 RELEASE COMPLETE message */
3698 f_expect_mt_dtap_msg(mt_ss_rel);
3699 f_expect_clear();
3700
3701 /* Send another CM Service Request for SS/USSD */
3702 f_establish_fully(EST_TYPE_SS_ACT);
3703
3704 /* Send GSM 04.80 RELEASE COMPLETE for non-existing transaction */
3705 BSSAP.send(ts_PDU_DTAP_MO(mo_ss_rel));
3706
3707 /* Expect GSM 04.80 RELEASE COMPLETE message */
3708 f_expect_mt_dtap_msg(mt_ss_rel);
3709 f_expect_clear();
3710}
3711testcase TC_mo_ussd_for_unknown_trans() runs on MTC_CT {
3712 var BSC_ConnHdlr vc_conn;
3713 f_init();
3714 vc_conn := f_start_handler(refers(f_tc_mo_ussd_for_unknown_trans), 111);
3715 vc_conn.done;
3716}
3717
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003718/* MT (network-originated) USSD for unknown session */
3719friend function f_tc_proc_ss_for_unknown_session(charstring id, BSC_ConnHdlrPars pars)
3720runs on BSC_ConnHdlr {
3721 var OCT4 sid := '20000333'O;
3722
3723 f_init_handler(pars);
3724
3725 /* Perform location update */
3726 f_perform_lu();
3727
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003728 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07003729 f_create_gsup_expect(hex2str(g_pars.imsi));
3730
3731 /* Request referencing a non-existing SS session */
3732 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3733 imsi := g_pars.imsi,
3734 sid := sid,
3735 state := OSMO_GSUP_SESSION_STATE_CONTINUE,
3736 ss := f_rnd_octstring(23)
3737 );
3738
3739 /* Error with some cause value */
3740 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3741 imsi := g_pars.imsi,
3742 sid := sid,
3743 state := OSMO_GSUP_SESSION_STATE_END,
3744 cause := ? /* FIXME: introduce an enumerated type! */
3745 );
3746
3747 /* Initiate a MT USSD notification */
3748 GSUP.send(gsup_req);
3749
3750 /* Expect GSUP PROC_SS_ERROR message */
3751 f_expect_gsup_msg(gsup_rsp);
3752}
3753testcase TC_proc_ss_for_unknown_session() runs on MTC_CT {
3754 var BSC_ConnHdlr vc_conn;
3755 f_init();
3756 vc_conn := f_start_handler(refers(f_tc_proc_ss_for_unknown_session), 110);
3757 vc_conn.done;
3758}
3759
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003760/* MT (network-originated) USSD and no response to Paging Request */
3761friend function f_tc_proc_ss_paging_fail(charstring id, BSC_ConnHdlrPars pars)
3762runs on BSC_ConnHdlr {
3763 timer TP := 2.0; /* Paging timer */
3764
3765 f_init_handler(pars);
3766
3767 /* Perform location update */
3768 f_perform_lu();
3769
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003770 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003771 f_create_gsup_expect(hex2str(g_pars.imsi));
3772
3773 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3774 imsi := g_pars.imsi,
3775 sid := '20000444'O,
3776 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3777 ss := f_rnd_octstring(23)
3778 );
3779
3780 /* Error with some cause value */
3781 var template GSUP_PDU gsup_rsp := tr_GSUP_PROC_SS_ERR(
3782 imsi := g_pars.imsi,
3783 sid := '20000444'O,
3784 state := OSMO_GSUP_SESSION_STATE_END,
3785 cause := ? /* FIXME: introduce an enumerated type! */
3786 );
3787
3788 /* Initiate a MT USSD notification */
3789 GSUP.send(gsup_req);
3790
3791 /* Send it to MSC and expect Paging Request */
3792 TP.start;
3793 alt {
3794 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3795 setverdict(pass);
3796 }
3797 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
3798 setverdict(pass);
3799 }
3800 /* We don't expect anything else */
3801 [] as_unexp_gsup_or_bssap_msg();
3802 [] TP.timeout {
3803 setverdict(fail, "Timeout waiting for Paging Request");
3804 }
3805 }
3806
Vadim Yanitskiyd24b5252019-10-02 00:04:51 +07003807 /* Wait up to 20 seconds for GSUP PROC_SS_ERROR message.
3808 * OsmoMSC waits for Paging Response 10 seconds by default. */
3809 f_expect_gsup_msg(gsup_rsp, T_val := 20.0);
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07003810}
3811testcase TC_proc_ss_paging_fail() runs on MTC_CT {
3812 var BSC_ConnHdlr vc_conn;
3813 f_init();
3814 vc_conn := f_start_handler(refers(f_tc_proc_ss_paging_fail), 101);
3815 vc_conn.done;
3816}
3817
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07003818/* MT (network-originated) USSD followed by immediate abort */
3819friend function f_tc_proc_ss_abort(charstring id, BSC_ConnHdlrPars pars)
3820runs on BSC_ConnHdlr {
3821 var octetstring facility := f_rnd_octstring(23);
3822 var OCT4 sid := '20000555'O;
3823 timer TP := 2.0;
3824
3825 f_init_handler(pars);
3826
3827 /* Perform location update */
3828 f_perform_lu();
3829
Vadim Yanitskiy70d15bf2020-01-09 22:51:01 +01003830 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07003831 f_create_gsup_expect(hex2str(g_pars.imsi));
3832
3833 /* PROC_SS_REQ initiates a mobile-originated SS/USSD session */
3834 var template (value) GSUP_PDU gsup_req := ts_GSUP_PROC_SS_REQ(
3835 imsi := g_pars.imsi, sid := sid,
3836 state := OSMO_GSUP_SESSION_STATE_BEGIN,
3837 ss := facility
3838 );
3839
3840 /* On the MS side, we expect GSM 04.80 REGISTER message */
3841 var template PDU_ML3_NW_MS dtap_reg := tr_ML3_MT_SS_REGISTER(
3842 tid := 0, /* Most likely, it should be 0 */
3843 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3844 facility := facility
3845 );
3846
3847 /* PROC_SS_ERR with SESSION_STATE_END terminates the SS/USSD session */
3848 var template (value) GSUP_PDU gsup_abort := ts_GSUP_PROC_SS_ERR(
3849 imsi := g_pars.imsi, sid := sid,
3850 state := OSMO_GSUP_SESSION_STATE_END,
3851 cause := 0 /* FIXME: introduce an enumerated type! */
3852 );
3853
3854 /* On the MS side, we expect GSM 04.80 REGISTER message */
3855 var template PDU_ML3_NW_MS dtap_rel := tr_ML3_MT_SS_RELEASE_COMPLETE(
3856 tid := 0, /* Most likely, it should be 0 */
3857 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
3858 cause := *, /* FIXME: expect some specific cause value */
3859 facility := omit
3860 );
3861
3862 /* Initiate a MT USSD with random payload */
3863 GSUP.send(gsup_req);
3864
3865 /* Expect Paging Request */
3866 TP.start;
3867 alt {
3868 [pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)) {
3869 setverdict(pass);
3870 }
3871 [not pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
3872 setverdict(pass);
3873 }
3874 /* We don't expect anything else */
3875 [] as_unexp_gsup_or_bssap_msg();
3876 [] TP.timeout {
3877 setverdict(fail, "Timeout waiting for Paging Request");
3878 }
3879 }
3880
3881 /* Send Paging Response and establish connection */
3882 f_establish_fully(EST_TYPE_PAG_RESP);
3883 /* Expect MT REGISTER message with random facility */
3884 f_expect_mt_dtap_msg(dtap_reg);
3885
3886 /* HLR/EUSE decides to abort the session even
3887 * before getting any response from the MS */
3888 /* Initiate a MT USSD with random payload */
3889 GSUP.send(gsup_abort);
3890
3891 /* Expect RELEASE COMPLETE on ths MS side */
3892 f_expect_mt_dtap_msg(dtap_rel);
3893
3894 f_expect_clear();
3895}
3896testcase TC_proc_ss_abort() runs on MTC_CT {
3897 var BSC_ConnHdlr vc_conn;
3898 f_init();
3899 vc_conn := f_start_handler(refers(f_tc_proc_ss_abort), 102);
3900 vc_conn.done;
3901}
3902
Harald Weltee13cfb22019-04-23 16:52:02 +02003903
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01003904/* Verify multiple concurrent MO SS/USSD transactions
3905 * (one subscriber - one transaction) */
3906testcase TC_multi_lu_and_mo_ussd() runs on MTC_CT {
3907 var BSC_ConnHdlr vc_conn[16];
3908 var integer i;
3909
3910 f_init();
3911
3912 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3913 vc_conn[i] := f_start_handler(refers(f_tc_lu_and_mo_ussd_single_request), 210 + i);
3914 }
3915
3916 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3917 vc_conn[i].done;
3918 }
3919}
3920
3921/* Verify multiple concurrent MT SS/USSD transactions
3922 * (one subscriber - one transaction) */
3923testcase TC_multi_lu_and_mt_ussd() runs on MTC_CT {
3924 var BSC_ConnHdlr vc_conn[16];
3925 var integer i;
3926 var OCT4 sid;
3927
3928 f_init();
3929
3930 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3931 sid := '200001'O & int2oct(i, 1); /* All transactions must use different session ID */
3932 vc_conn[i] := f_start_handler_with_pars(refers(f_tc_lu_and_mt_ussd_notification),
3933 f_init_pars(226 + i, gsup_sid := sid));
3934 }
3935
3936 for (i := 0; i < sizeof(vc_conn); i := i + 1) {
3937 vc_conn[i].done;
3938 }
3939}
3940
3941
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003942/* A5/1 only permitted on network side; attempt an invalid CIPHER MODE COMPLETE with A5/3 which MSC should reject. */
3943private function f_tc_cipher_complete_with_invalid_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
3944 pars.net.expect_auth := true;
3945 pars.net.expect_ciph := true;
3946 pars.net.kc_support := '02'O; /* A5/1 only */
3947 f_init_handler(pars);
3948
3949 g_pars.vec := f_gen_auth_vec_2g();
3950
3951 /* Can't use f_perform_lu() directly. Code below is based on it. */
3952
3953 /* tell GSUP dispatcher to send this IMSI to us */
3954 f_create_gsup_expect(hex2str(g_pars.imsi));
3955
3956 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
3957 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
Harald Weltedceacc72019-04-21 20:58:35 +02003958 f_cl3_or_initial_ue(l3_lu);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003959
3960 f_mm_auth();
3961
3962 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
3963 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
3964 alt {
3965 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
3966 BSSAP.send(ts_BSSMAP_CipherModeCompl(int2oct(4 /* "accept" A5/3 */, 1)));
3967 }
3968 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
3969 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
3970 mtc.stop;
3971 }
3972 [] BSSAP.receive {
3973 setverdict(fail, "Unknown/unexpected BSSAP received");
3974 mtc.stop;
3975 }
3976 }
Harald Welte79f1e452020-08-18 22:55:02 +02003977 f_expect_common_id();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003978
3979 /* Expect LU reject from MSC. */
3980 alt {
3981 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
3982 setverdict(pass);
3983 }
3984 [] BSSAP.receive {
3985 setverdict(fail, "Unknown/unexpected BSSAP received");
3986 mtc.stop;
3987 }
3988 }
Stefan Sperlingc620b352018-12-18 17:23:36 +01003989 f_expect_clear();
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003990}
3991
3992testcase TC_cipher_complete_with_invalid_cipher() runs on MTC_CT {
3993 var BSC_ConnHdlr vc_conn;
3994 f_init();
3995 f_vty_config(MSCVTY, "network", "encryption a5 1");
3996
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02003997 vc_conn := f_start_handler(refers(f_tc_cipher_complete_with_invalid_cipher), 52, verify_cell_id := false);
Stefan Sperling89eb1f32018-12-17 15:06:20 +01003998 vc_conn.done;
3999}
4000
Harald Welteb2284bd2019-05-10 11:30:43 +02004001/* Location Update with invalid (non-matching) MCC/MNC reported on BSSMAP level from BSC */
4002friend function f_tc_lu_with_invalid_mcc_mnc(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4003 f_init_handler(pars);
4004
4005 /* tell GSUP dispatcher to send this IMSI to us */
4006 f_create_gsup_expect(hex2str(g_pars.imsi));
4007
4008 /* modify the cell ID which will be used to construct the COMPLELTE L3 or InitialUE */
4009 g_pars.cell_id := valueof(ts_CellId_CGI('333'H, '22'H, 23, 42));
4010
4011 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4012 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4013 f_cl3_or_initial_ue(l3_lu);
Harald Welte79f1e452020-08-18 22:55:02 +02004014 f_expect_common_id();
Harald Welteb2284bd2019-05-10 11:30:43 +02004015
4016 /* Expect LU reject from MSC. */
4017 alt {
4018 [] BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_LU_Rej)) {
4019 setverdict(pass);
4020 }
4021 [] BSSAP.receive {
4022 setverdict(fail, "Unknown/unexpected BSSAP received");
4023 mtc.stop;
4024 }
4025 }
4026 f_expect_clear();
4027}
4028testcase TC_lu_with_invalid_mcc_mnc() runs on MTC_CT {
4029 var BSC_ConnHdlr vc_conn;
4030 f_init();
4031 vc_conn := f_start_handler(refers(f_tc_lu_with_invalid_mcc_mnc), 54);
4032 vc_conn.done;
4033}
4034
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004035private function f_tc_cipher_complete_without_alg(charstring id, BSC_ConnHdlrPars pars, octetstring kc_support) runs on BSC_ConnHdlr {
4036 pars.net.expect_auth := true;
4037 pars.net.expect_ciph := true;
4038 pars.net.kc_support := kc_support;
4039 f_init_handler(pars);
4040
4041 g_pars.vec := f_gen_auth_vec_2g();
4042
4043 /* Can't use f_perform_lu() directly. Code below is based on it. */
4044
4045 /* tell GSUP dispatcher to send this IMSI to us */
4046 f_create_gsup_expect(hex2str(g_pars.imsi));
4047
4048 /* Send BSSAP_Conn_Req with COMPL L3 INFO to MSC */
4049 var PDU_ML3_MS_NW l3_lu := f_build_lu_imsi(g_pars.imsi)
4050 f_cl3_or_initial_ue(l3_lu);
4051
4052 f_mm_auth();
4053
4054 var OCT1 a5_net := f_alg_mask_from_cm(g_pars.cm2);
4055 var OCT1 a5_intersect := g_pars.net.kc_support and4b a5_net;
4056 alt {
4057 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(a5_intersect, g_pars.vec.kc)) {
4058 BSSAP.send(ts_BSSMAP_CipherModeComplAlg(omit));
4059 }
4060 [] BSSAP.receive(tr_BSSMAP_ClassmarkReq) {
4061 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
4062 repeat;
4063 }
4064 [] BSSAP.receive(tr_BSSMAP_CipherModeCmd(?, g_pars.vec.kc)) {
4065 setverdict(fail, "Wrong ciphering algorithm mask in CiphModCmd");
4066 mtc.stop;
4067 }
4068 [] BSSAP.receive {
4069 setverdict(fail, "Unknown/unexpected BSSAP received");
4070 mtc.stop;
4071 }
4072 }
Harald Welte79f1e452020-08-18 22:55:02 +02004073 f_expect_common_id();
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01004074
4075 /* TODO: Verify MSC is using the best cipher available! How? */
4076
4077 f_msc_lu_hlr();
4078 f_accept_reject_lu();
4079 f_expect_clear();
4080 setverdict(pass);
4081}
4082
4083/* A5/1 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4084private function f_tc_cipher_complete_1_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4085 f_tc_cipher_complete_without_alg(id, pars, '02'O /* A5/1 only */);
4086}
4087
4088/* A5/3 only permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4089private function f_tc_cipher_complete_3_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4090 f_tc_cipher_complete_without_alg(id, pars, '08'O /* A5/3 only */);
4091}
4092
4093/* A5/1 + A5/3 permitted on network side; attempt CIPHER MODE COMPLETE without specifying the accepted algorithm. */
4094private function f_tc_cipher_complete_13_without_cipher(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4095 f_tc_cipher_complete_without_alg(id, pars, '0A'O /* A5/1 and A5/3 enabled */);
4096}
4097
4098testcase TC_cipher_complete_1_without_cipher() runs on MTC_CT {
4099 var BSC_ConnHdlr vc_conn;
4100 f_init();
4101 f_vty_config(MSCVTY, "network", "encryption a5 1");
4102
4103 vc_conn := f_start_handler(refers(f_tc_cipher_complete_1_without_cipher), 53);
4104 vc_conn.done;
4105}
4106
4107testcase TC_cipher_complete_3_without_cipher() runs on MTC_CT {
4108 var BSC_ConnHdlr vc_conn;
4109 f_init();
4110 f_vty_config(MSCVTY, "network", "encryption a5 3");
4111
4112 vc_conn := f_start_handler(refers(f_tc_cipher_complete_3_without_cipher), 54);
4113 vc_conn.done;
4114}
4115
4116testcase TC_cipher_complete_13_without_cipher() runs on MTC_CT {
4117 var BSC_ConnHdlr vc_conn;
4118 f_init();
4119 f_vty_config(MSCVTY, "network", "encryption a5 1 3");
4120
4121 vc_conn := f_start_handler(refers(f_tc_cipher_complete_13_without_cipher), 55);
4122 vc_conn.done;
4123}
Harald Welteb2284bd2019-05-10 11:30:43 +02004124
Harald Weltef640a012018-04-14 17:49:21 +02004125/* TODO (SMS):
4126 * different user data lengths
4127 * SMPP transaction mode with unsuccessful delivery
4128 * queued MT-SMS with no paging response + later delivery
4129 * different data coding schemes
4130 * multi-part SMS
4131 * user-data headers
4132 * TP-PID for SMS to SIM
4133 * behavior if SMS memory is full + RP-SMMA
4134 * delivery reports
4135 * SMPP osmocom extensions
4136 * more-messages-to-send
4137 * SMS during ongoing call (SACCH/SAPI3)
4138 */
4139
4140/* TODO (General):
Harald Welteba7b6d92018-01-23 21:32:34 +01004141 * continue to send repeated MO signalling messages to keep channel open: does MSC tmeout?
4142 * malformed messages (missing IE, invalid message type): properly rejected?
4143 * MT call while LU or is ongoing: Do we use existing lchan or page while lchan active?
4144 * 3G/2G auth permutations
4145 * encryption algorithms vs. classmark vs. vty config
Harald Welteba7b6d92018-01-23 21:32:34 +01004146 * send new transaction after/during clear (like SMS, ...)
Harald Welte45164da2018-01-24 12:51:27 +01004147 * too long L3 INFO in DTAP
4148 * too long / padded BSSAP
4149 * too long / short TLV values
Harald Welteba7b6d92018-01-23 21:32:34 +01004150 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01004151
Harald Weltee13cfb22019-04-23 16:52:02 +02004152/***********************************************************************
4153 * SGsAP Testing
4154 ***********************************************************************/
4155
Philipp Maier948747b2019-04-02 15:22:33 +02004156/* Check if a subscriber exists in the VLR */
4157private function f_ctrl_subscr_in_vlr(charstring imsi_or_msisdn) runs on BSC_ConnHdlr return boolean {
4158
4159 var CtrlValue active_subsribers;
4160 var integer rc;
4161 active_subsribers := f_ctrl_get(IPA_CTRL, "subscriber-list-active-v1");
4162
4163 rc := f_strstr(active_subsribers, imsi_or_msisdn);
4164 if (rc < 0) {
4165 return false;
4166 }
4167
4168 return true;
4169}
4170
Harald Welte4263c522018-12-06 11:56:27 +01004171/* Perform a location updatye at the A-Interface and run some checks to confirm
4172 * that everything is back to normal. */
4173private function f_sgsap_bssmap_screening() runs on BSC_ConnHdlr {
4174 var SmsParameters spars := valueof(t_SmsPars);
4175
4176 /* Perform a location update, the SGs association is expected to fall
4177 * back to NULL */
4178 f_perform_lu();
4179 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4180
4181 /* Trigger a paging request and expect the paging on BSSMAP, this is
4182 * to make sure that pagings are sent throught the A-Interface again
4183 * and not throught the SGs interface.*/
Harald Welte6811d102019-04-14 22:23:14 +02004184 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
Harald Welte4263c522018-12-06 11:56:27 +01004185 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4186
4187 alt {
Harald Weltee13cfb22019-04-23 16:52:02 +02004188 [g_pars.ran_is_geran] BSSAP.receive(tr_BSSMAP_Paging(g_pars.imsi)); {
4189 setverdict(pass);
4190 }
Harald Welte62113fc2019-05-09 13:04:02 +02004191 [not g_pars.ran_is_geran] BSSAP.receive(tr_RANAP_Paging(cs_domain, imsi_hex2oct(g_pars.imsi))) {
Harald Welte4263c522018-12-06 11:56:27 +01004192 setverdict(pass);
4193 }
4194 [] SGsAP.receive {
4195 setverdict(fail, "Received unexpected message on SGs");
4196 }
4197 }
4198
4199 /* Send an SMS to make sure that also payload messages are routed
4200 * throught the A-Interface again */
4201 f_establish_fully(EST_TYPE_MO_SMS);
4202 f_mo_sms(spars);
4203 f_expect_clear();
4204}
4205
4206private function f_tc_sgsap_reset(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4207 var charstring vlr_name;
4208 f_init_handler(pars);
4209
4210 vlr_name := f_sgsap_reset_mme(mp_mme_name);
4211 log("VLR name: ", vlr_name);
4212 setverdict(pass);
Neels Hofmeyrc0b520d2019-03-06 15:35:50 +01004213 f_sleep(1.0);
Harald Welte4263c522018-12-06 11:56:27 +01004214}
4215
4216testcase TC_sgsap_reset() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004217 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004218 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004219 f_init(1, true);
4220 pars := f_init_pars(11810, true);
4221 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_reset), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004222 vc_conn.done;
4223}
4224
4225/* like f_mm_auth() but for SGs */
4226function f_mm_auth_sgs() runs on BSC_ConnHdlr {
4227 if (g_pars.net.expect_auth) {
4228 g_pars.vec := f_gen_auth_vec_3g();
4229 var GSUP_IE auth_tuple := valueof(ts_GSUP_IE_AuthTuple2G3G(g_pars.vec.rand,
4230 g_pars.vec.sres,
4231 g_pars.vec.kc,
4232 g_pars.vec.ik,
4233 g_pars.vec.ck,
4234 g_pars.vec.autn,
4235 g_pars.vec.res));
4236 GSUP.receive(tr_GSUP_SAI_REQ(g_pars.imsi));
4237 GSUP.send(ts_GSUP_SAI_RES(g_pars.imsi, auth_tuple));
4238 SGsAP.receive(tr_ML3_MT_MM_AUTH_REQ_3G(g_pars.vec.rand, g_pars.vec.autn));
4239 SGsAP.send(ts_ML3_MT_MM_AUTH_RESP_3G(g_pars.vec.sres, g_pars.vec.res));
4240 }
4241}
4242
4243/* like f_perform_lu(), but on SGs rather than BSSAP */
4244function f_sgs_perform_lu() runs on BSC_ConnHdlr {
4245 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4246 var PDU_SGsAP lur;
4247 var PDU_SGsAP lua;
4248 var PDU_SGsAP mm_info;
4249 var octetstring mm_info_dtap;
4250
4251 /* tell GSUP dispatcher to send this IMSI to us */
4252 f_create_gsup_expect(hex2str(g_pars.imsi));
4253
4254 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4255 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4256 /* Old LAI, if MS sends it */
4257 /* TMSI status, if MS has no valid TMSI */
4258 /* IMEISV, if it supports "automatic device detection" */
4259 /* TAI, if available in MME */
4260 /* E-CGI, if available in MME */
4261 SGsAP.send(lur);
4262
4263 /* FIXME: is this really done over SGs? The Ue is already authenticated
4264 * via the MME ... */
4265 f_mm_auth_sgs();
4266
4267 /* Expect MSC to perform LU with HLR */
4268 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4269 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4270 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4271 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4272
4273 alt {
4274 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) -> value lua {
4275 if (isvalue(lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets)) {
4276 g_pars.tmsi :=lua.sGsAP_LOCATION_UPDATE_ACCEPT.newTMSIorIMSI.iD.iD.tmsi_ptmsi.octets
4277 SGsAP.send(ts_SGsAP_TMSI_REALL_CMPL(g_pars.imsi));
4278 }
4279 setverdict(pass);
4280 }
4281 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4282 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4283 }
4284 [] SGsAP.receive {
4285 setverdict(fail, "Received unexpected message on SGs");
4286 }
4287 }
4288
4289 /* Check MM information */
4290 if (mp_mm_info == true) {
4291 SGsAP.receive(tr_SGsAP_MM_INFO_REQ(g_pars.imsi, ?)) -> value mm_info;
4292 mm_info_dtap := '0532'O & mm_info.sGsAP_MM_INFORMATION_REQUEST.mM_Information.information;
4293 if (not match(dec_PDU_ML3_NW_MS(mm_info_dtap), tr_ML3_MT_MM_Info)) {
4294 setverdict(fail, "Unexpected MM Information");
4295 }
4296 }
4297
4298 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4299}
4300
4301private function f_tc_sgsap_lu(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4302 f_init_handler(pars);
4303 f_sgs_perform_lu();
4304 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4305
4306 f_sgsap_bssmap_screening();
4307
4308 setverdict(pass);
4309}
4310testcase TC_sgsap_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004311 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004312 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004313 f_init(1, true);
4314 pars := f_init_pars(11811, true);
4315 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004316 vc_conn.done;
4317}
4318
4319/* Do LU by IMSI, refuse it on GSUP and expect LU REJ back to MS */
4320private function f_tc_sgsap_lu_imsi_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4321 f_init_handler(pars);
4322 var PDU_SGsAP lur;
4323
4324 f_create_gsup_expect(hex2str(g_pars.imsi));
4325 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4326 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4327 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4328 SGsAP.send(lur);
4329
4330 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4331 GSUP.send(ts_GSUP_UL_ERR(g_pars.imsi, 23));
4332 alt {
4333 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4334 setverdict(pass);
4335 }
4336 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4337 setverdict(fail, "Expecting LU REJ, but got ACCEPT");
4338 mtc.stop;
4339 }
4340 [] SGsAP.receive {
4341 setverdict(fail, "Received unexpected message on SGs");
4342 }
4343 }
4344
4345 f_sgsap_bssmap_screening();
4346
4347 setverdict(pass);
4348}
4349testcase TC_sgsap_lu_imsi_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004350 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004351 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004352 f_init(1, true);
4353 pars := f_init_pars(11812, true);
Harald Welte4263c522018-12-06 11:56:27 +01004354
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004355 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_imsi_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004356 vc_conn.done;
4357}
4358
4359/* Do LU by IMSI, but then remain silent so that Ts6-1 times out */
4360private function f_tc_sgsap_lu_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4361 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4362 var PDU_SGsAP lur;
4363
4364 f_init_handler(pars);
4365
4366 /* tell GSUP dispatcher to send this IMSI to us */
4367 f_create_gsup_expect(hex2str(g_pars.imsi));
4368
4369 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
4370 ts_SGsAP_LAI('901'H, '70'H, 2342)));
4371 /* Old LAI, if MS sends it */
4372 /* TMSI status, if MS has no valid TMSI */
4373 /* IMEISV, if it supports "automatic device detection" */
4374 /* TAI, if available in MME */
4375 /* E-CGI, if available in MME */
4376 SGsAP.send(lur);
4377
4378 /* FIXME: is this really done over SGs? The Ue is already authenticated
4379 * via the MME ... */
4380 f_mm_auth_sgs();
4381
4382 /* Expect MSC to perform LU with HLR */
4383 GSUP.receive(tr_GSUP_UL_REQ(g_pars.imsi));
4384 GSUP.send(ts_GSUP_ISD_REQ(g_pars.imsi, g_pars.msisdn));
4385 GSUP.receive(tr_GSUP_ISD_RES(g_pars.imsi));
4386 GSUP.send(ts_GSUP_UL_RES(g_pars.imsi));
4387
4388 alt {
4389 [] SGsAP.receive(tr_SGsAP_LU_ACCEPT(g_pars.imsi, ?)) {
4390 setverdict(pass);
4391 }
4392 [] SGsAP.receive(tr_SGsAP_LU_REJECT(g_pars.imsi, ?, ?)) {
4393 setverdict(fail, "Received LU-REJECT instead of ACCEPT");
4394 }
4395 [] SGsAP.receive {
4396 setverdict(fail, "Received unexpected message on SGs");
4397 }
4398 }
4399
4400 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4401
4402 /* Wait until the VLR has abort the TMSI reallocation procedure */
4403 f_sleep(45.0);
4404
4405 /* The outcome does not change the SGs state, see also 5.2.3.4 */
4406 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4407
4408 f_sgsap_bssmap_screening();
4409
4410 setverdict(pass);
4411}
4412testcase TC_sgsap_lu_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004413 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004414 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004415 f_init(1, true);
4416 pars := f_init_pars(11813, true);
Harald Welte4263c522018-12-06 11:56:27 +01004417
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004418 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004419 vc_conn.done;
4420}
4421
4422private function f_tc_sgsap_expl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4423runs on BSC_ConnHdlr {
4424 f_init_handler(pars);
4425 f_sgs_perform_lu();
4426 f_sleep(3.0);
4427
4428 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4429 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, UE_initiated));
4430 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4431 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4432
4433 f_sgsap_bssmap_screening();
4434
4435 setverdict(pass);
4436}
4437testcase TC_sgsap_expl_imsi_det_eps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004438 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004439 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004440 f_init(1, true);
4441 pars := f_init_pars(11814, true);
4442 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_eps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004443 vc_conn.done;
4444}
4445
Philipp Maierfc19f172019-03-21 11:17:54 +01004446private function f_tc_sgsap_impl_imsi_det_eps(charstring id, BSC_ConnHdlrPars pars)
4447runs on BSC_ConnHdlr {
4448 f_init_handler(pars);
4449 f_sgs_perform_lu();
4450 f_sleep(3.0);
4451
4452 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4453 SGsAP.send(ts_SGsAP_EPS_DETACH_IND(g_pars.imsi, mme_name, network_initiated));
4454 SGsAP.receive(tr_SGsAP_EPS_DETACH_ACK(g_pars.imsi));
4455 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4456
4457 f_sgsap_bssmap_screening();
4458
4459 setverdict(pass);
4460}
4461testcase TC_sgsap_impl_imsi_det_eps() runs on MTC_CT {
4462 var BSC_ConnHdlrPars pars;
4463 var BSC_ConnHdlr vc_conn;
4464 f_init(1, true);
4465 pars := f_init_pars(11814, true);
4466 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_eps), pars);
4467 vc_conn.done;
4468}
4469
Harald Welte4263c522018-12-06 11:56:27 +01004470private function f_tc_sgsap_expl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4471runs on BSC_ConnHdlr {
4472 f_init_handler(pars);
4473 f_sgs_perform_lu();
4474 f_sleep(3.0);
4475
4476 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4477 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, combined_UE_initiated));
4478 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
Philipp Maierd08e7e72019-04-02 15:27:10 +02004479
4480 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4481 setverdict(fail, "subscriber not removed from VLR");
4482 }
Harald Welte4263c522018-12-06 11:56:27 +01004483
4484 f_sgsap_bssmap_screening();
4485
4486 setverdict(pass);
4487}
4488testcase TC_sgsap_expl_imsi_det_noneps() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004489 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004490 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004491 f_init(1, true);
4492 pars := f_init_pars(11815, true);
4493 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_expl_imsi_det_noneps), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004494 vc_conn.done;
4495}
4496
Philipp Maier5d812702019-03-21 10:51:26 +01004497private function f_tc_sgsap_impl_imsi_det_noneps(charstring id, BSC_ConnHdlrPars pars)
4498runs on BSC_ConnHdlr {
4499 f_init_handler(pars);
4500 f_sgs_perform_lu();
4501 f_sleep(3.0);
4502
4503 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
4504 SGsAP.send(ts_SGsAP_IMSI_DETACH_IND(g_pars.imsi, mme_name, implicit_network_initiated));
4505 SGsAP.receive(tr_SGsAP_IMSI_DETACH_ACK(g_pars.imsi));
4506
4507 if (f_ctrl_subscr_in_vlr(hex2str(g_pars.imsi))) {
4508 setverdict(fail, "subscriber not removed from VLR");
4509 }
4510
4511 f_sgsap_bssmap_screening();
4512
4513 setverdict(pass);
4514}
4515testcase TC_sgsap_impl_imsi_det_noneps() runs on MTC_CT {
4516 var BSC_ConnHdlrPars pars;
4517 var BSC_ConnHdlr vc_conn;
4518 f_init(1, true);
4519 pars := f_init_pars(11815, true);
4520 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_impl_imsi_det_noneps), pars);
4521 vc_conn.done;
4522}
4523
Harald Welte4263c522018-12-06 11:56:27 +01004524/* Trigger a paging request via VTY and send a paging reject in response */
4525private function f_tc_sgsap_paging_rej(charstring id, BSC_ConnHdlrPars pars)
4526runs on BSC_ConnHdlr {
4527 f_init_handler(pars);
4528 f_sgs_perform_lu();
4529 f_sleep(1.0);
4530
4531 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4532 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4533 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4534 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4535
4536 /* Initiate paging via VTY */
4537 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4538 alt {
4539 [] SGsAP.receive(exp_resp) {
4540 setverdict(pass);
4541 }
4542 [] SGsAP.receive {
4543 setverdict(fail, "Received unexpected message on SGs");
4544 }
4545 }
4546
4547 /* Now reject the paging */
4548 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
4549
4550 /* Wait for the states inside the MSC to settle and check the state
4551 * of the SGs Association */
4552 f_sleep(1.0);
4553 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4554
4555 /* FIXME: At the moment we send an IMSI_unknown as cause code, which is fine,
4556 * but we also need to cover tha case where the cause code indicates an
4557 * "IMSI detached for EPS services". In those cases the VLR is expected to
4558 * try paging on tha A/Iu interface. This will be another testcase similar to
4559 * this one, but extended with checks for the presence of the A/Iu paging
4560 * messages. */
4561
4562 f_sgsap_bssmap_screening();
4563
4564 setverdict(pass);
4565}
4566testcase TC_sgsap_paging_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004567 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004568 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004569 f_init(1, true);
4570 pars := f_init_pars(11816, true);
4571 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004572 vc_conn.done;
4573}
4574
4575/* Trigger a paging request via VTY and send a paging reject that indicates
4576 * that the subscriber intentionally rejected the call. */
4577private function f_tc_sgsap_paging_subscr_rej(charstring id, BSC_ConnHdlrPars pars)
4578runs on BSC_ConnHdlr {
4579 f_init_handler(pars);
4580 f_sgs_perform_lu();
4581 f_sleep(1.0);
4582
4583 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4584 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4585 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4586 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4587
4588 /* Initiate paging via VTY */
4589 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4590 alt {
4591 [] SGsAP.receive(exp_resp) {
4592 setverdict(pass);
4593 }
4594 [] SGsAP.receive {
4595 setverdict(fail, "Received unexpected message on SGs");
4596 }
4597 }
4598
4599 /* Now reject the paging */
4600 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4601
4602 /* Wait for the states inside the MSC to settle and check the state
4603 * of the SGs Association */
4604 f_sleep(1.0);
4605 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4606
4607 /* FIXME: The VLR is supposed to trigger an User Determined User Busy (UDUB) as specified
4608 * in 3GPP TS 24.082, this is not yet implemented in the MSC or in this tests, we need
4609 * to check back how this works and how it can be tested */
4610
4611 f_sgsap_bssmap_screening();
4612
4613 setverdict(pass);
4614}
4615testcase TC_sgsap_paging_subscr_rej() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004616 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004617 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004618 f_init(1, true);
4619 pars := f_init_pars(11817, true);
4620 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_subscr_rej), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004621 vc_conn.done;
4622}
4623
4624/* Trigger a paging request via VTY and send an UE unreacable messge in response */
4625private function f_tc_sgsap_paging_ue_unr(charstring id, BSC_ConnHdlrPars pars)
4626runs on BSC_ConnHdlr {
4627 f_init_handler(pars);
4628 f_sgs_perform_lu();
4629 f_sleep(1.0);
4630
4631 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4632 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
4633 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4634 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4635
4636 /* Initiate paging via VTY */
4637 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4638 alt {
4639 [] SGsAP.receive(exp_resp) {
4640 setverdict(pass);
4641 }
4642 [] SGsAP.receive {
4643 setverdict(fail, "Received unexpected message on SGs");
4644 }
4645 }
4646
4647 /* Now pretend that the UE is unreachable */
4648 SGsAP.send(ts_SGsAP_UE_UNREACHABLE(g_pars.imsi, UE_unreachable));
4649
4650 /* Wait for the states inside the MSC to settle and check the state
4651 * of the SGs Association. */
4652 f_sleep(1.0);
4653 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4654
4655 f_sgsap_bssmap_screening();
4656
4657 setverdict(pass);
4658}
4659testcase TC_sgsap_paging_ue_unr() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004660 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004661 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004662 f_init(1, true);
4663 pars := f_init_pars(11818, true);
4664 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_ue_unr), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004665 vc_conn.done;
4666}
4667
4668/* Trigger a paging request via VTY but don't respond to it */
4669private function f_tc_sgsap_paging_and_nothing(charstring id, BSC_ConnHdlrPars pars)
4670runs on BSC_ConnHdlr {
4671 f_init_handler(pars);
4672 f_sgs_perform_lu();
4673 f_sleep(1.0);
4674
4675 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4676 var template PDU_SGsAP exp_resp := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, CS_call_indicator, omit);
Philipp Maier34218102019-09-24 09:15:49 +02004677 var template PDU_SGsAP exp_serv_abrt := ts_SGsAP_SERVICE_ABORT_REQ(g_pars.imsi);
Harald Welte4263c522018-12-06 11:56:27 +01004678 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
4679 exp_resp.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
4680
4681 /* Initiate paging via VTY */
4682 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4683 alt {
4684 [] SGsAP.receive(exp_resp) {
4685 setverdict(pass);
4686 }
4687 [] SGsAP.receive {
4688 setverdict(fail, "Received unexpected message on SGs");
4689 }
4690 }
4691
Philipp Maier34218102019-09-24 09:15:49 +02004692 /* While we are doing nothing, expect an SGsAP-SERVICE-ABORT-REQUEST
4693 * after some time */
4694 timer T := 10.0;
4695 T.start
4696 alt {
4697 [] SGsAP.receive(exp_serv_abrt)
4698 {
4699 setverdict(pass);
4700 }
4701 [] SGsAP.receive {
4702 setverdict(fail, "unexpected SGsAP message received");
4703 self.stop;
4704 }
4705 [] T.timeout {
4706 setverdict(fail, "MSC did not send SGsAP-SERVICE-ABORT-REQUEST");
4707 self.stop;
4708 }
4709 }
4710
4711 /* The SGs association must remain unchanged. */
Harald Welte4263c522018-12-06 11:56:27 +01004712 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4713
4714 f_sgsap_bssmap_screening();
4715
4716 setverdict(pass);
4717}
4718testcase TC_sgsap_paging_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004719 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004720 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004721 f_init(1, true);
4722 pars := f_init_pars(11819, true);
4723 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004724 vc_conn.done;
4725}
4726
4727/* Trigger a paging request via VTY and slip in an LU */
4728private function f_tc_sgsap_paging_and_lu(charstring id, BSC_ConnHdlrPars pars)
4729runs on BSC_ConnHdlr {
4730 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4731 f_init_handler(pars);
4732
4733 /* First we prepar the situation, where the SGs association is in state
4734 * NULL and the confirmed by radio contact indicator is set to false
4735 * as well. This can be archived by performing an SGs LU and then
4736 * resetting the VLR */
4737 f_sgs_perform_lu();
4738 f_sgsap_reset_mme(mp_mme_name);
4739 f_sleep(1.0);
4740 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4741
4742 /* Perform a paging, expect the paging messages on the SGs interface */
4743 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
4744 alt {
4745 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4746 setverdict(pass);
4747 }
4748 [] SGsAP.receive {
4749 setverdict(fail, "Received unexpected message on SGs");
4750 }
4751 }
4752
4753 /* Perform the LU as normal */
4754 f_sgs_perform_lu();
4755 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4756
4757 /* Expect a new paging request right after the LU */
4758 alt {
4759 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
4760 setverdict(pass);
4761 }
4762 [] SGsAP.receive {
4763 setverdict(fail, "Received unexpected message on SGs");
4764 }
4765 }
4766
4767 /* Test is done now, lets round everything up by rejecting the paging
4768 * cleanly. */
4769 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, user_rejected_mobile_terminating_CS_fallback_call));
4770 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4771
4772 f_sgsap_bssmap_screening();
4773
4774 setverdict(pass);
4775}
4776testcase TC_sgsap_paging_and_lu() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004777 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004778 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004779 f_init(1, true);
4780 pars := f_init_pars(11820, true);
4781 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_paging_and_lu), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004782 vc_conn.done;
4783}
4784
4785/* Send unexpected unit-data through the SGs interface */
4786private function f_tc_sgsap_unexp_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4787 f_init_handler(pars);
4788 f_sleep(1.0);
4789
4790 /* This simulates what happens when a subscriber without SGs
4791 * association gets unitdata via the SGs interface. */
4792
4793 /* Make sure the subscriber exists and the SGs association
4794 * is in NULL state */
4795 f_perform_lu();
4796 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
4797
4798 /* Send some random unit data, the MSC/VLR should send a release
4799 * immediately. */
4800 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4801 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_detached_for_EPS_nonEPS_services));
4802
4803 f_sgsap_bssmap_screening();
4804
4805 setverdict(pass);
4806}
4807testcase TC_sgsap_unexp_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004808 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004809 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004810 f_init(1, true);
4811 pars := f_init_pars(11821, true);
4812 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unexp_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004813 vc_conn.done;
4814}
4815
4816/* Send unsolicited unit-data through the SGs interface */
4817private function f_tc_sgsap_unsol_ud(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4818 f_init_handler(pars);
4819 f_sleep(1.0);
4820
4821 /* This simulates what happens when the MME attempts to send unitdata
4822 * to a subscriber that is completely unknown to the VLR */
4823
4824 /* Send some random unit data, the MSC/VLR should send a release
4825 * immediately. */
4826 SGsAP.send(ts_SGsAP_UL_UD(pars.imsi,'1234'O));
4827 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, IMSI_unknown));
4828
4829 f_sgsap_bssmap_screening();
4830
4831 setverdict(pass);
4832}
4833testcase TC_sgsap_unsol_ud() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004834 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004835 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004836 f_init(1, true);
4837 pars := f_init_pars(11822, true);
4838 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_unsol_ud), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004839 vc_conn.done;
4840}
4841
4842private altstep as_other_sms_sgs() runs on BSC_ConnHdlr {
4843 /* FIXME: Match an actual payload (second questionmark), the type is
4844 * octetstring, how do we use a tr_PDU_DTAP_MT here? */
4845 [] SGsAP.receive(tr_SGsAP_DL_UD(?,?)) {
4846 setverdict(fail, "Unexpected SMS related PDU from MSC");
4847 mtc.stop;
4848 }
4849}
4850
4851/* receive a MT-SMS delivered from the MSC/SMSC over an already existing SGsAP connection */
4852function f_mt_sms_sgs(inout SmsParameters spars)
4853runs on BSC_ConnHdlr {
4854 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4855 var template (value) RPDU_MS_SGSN rp_mo;
4856 var template (value) PDU_ML3_MS_NW l3_mo;
4857
4858 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4859 var template RPDU_SGSN_MS rp_mt;
4860 var template PDU_ML3_NW_MS l3_mt;
4861
4862 var PDU_ML3_NW_MS sgsap_l3_mt;
4863
4864 var default d := activate(as_other_sms_sgs());
4865
4866 /* Expect CP-DATA(RP-DATA(SMS-DELIVER)) */
4867 tp_mt := tr_SMS_DELIVER(?, spars.tp.ud, spars.tp.pid, spars.tp.dcs, ?);
Vadim Yanitskiy04dd5f72019-12-13 15:45:44 +09004868 rp_mt := tr_RP_DATA_MT(?, spars.rp.smsc_addr, omit, tp_mt);
Harald Welte4263c522018-12-06 11:56:27 +01004869 l3_mt := tr_ML3_MT_SMS(?, c_TIF_ORIG, tr_CP_DATA_MT(rp_mt));
4870
4871 SGsAP.receive(l3_mt) -> value sgsap_l3_mt;
4872
4873 /* Extract relevant identifiers */
4874 spars.tid := bit2int(sgsap_l3_mt.tiOrSkip.transactionId.tio);
4875 spars.rp.msg_ref := sgsap_l3_mt.msgs.sms.cP_DATA.cP_User_Data.cP_RPDU.rP_DATA_SGSN_MS.rP_MessageReference;
4876
4877 /* send CP-ACK for CP-DATA just received */
4878 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_ACK_MO);
4879
4880 SGsAP.send(l3_mo);
4881
4882 /* send RP-ACK for RP-DATA */
4883 rp_mo := ts_RP_ACK_MO(spars.rp.msg_ref);
4884 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_REPL, ts_CP_DATA_MO(rp_mo));
4885
4886 SGsAP.send(l3_mo);
4887
4888 /* expect CP-ACK for CP-DATA(RP-ACK) just sent */
4889 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_ORIG, tr_CP_ACK_MT);
4890
4891 SGsAP.receive(l3_mt);
4892
4893 deactivate(d);
4894
4895 setverdict(pass);
4896}
4897
4898/* submit a MO-SMS to MSC/SMSC over an already existing SGsAP connection */
4899function f_mo_sms_sgs(inout SmsParameters spars)
4900runs on BSC_ConnHdlr {
4901 var template (value) TPDU_RP_DATA_MS_SGSN tp_mo;
4902 var template (value) RPDU_MS_SGSN rp_mo;
4903 var template (value) PDU_ML3_MS_NW l3_mo;
4904
4905 var template TPDU_RP_DATA_SGSN_MS tp_mt;
4906 var template RPDU_SGSN_MS rp_mt;
4907 var template PDU_ML3_NW_MS l3_mt;
4908
4909 var default d := activate(as_other_sms_sgs());
4910
4911 /* just in case this is routed to SMPP.. */
4912 f_create_smpp_expect(hex2str(spars.tp.da.tP_DA_NoPad.tP_DAValue));
4913
4914 tp_mo := ts_SMS_SUBMIT(spars.tp.msg_ref, spars.tp.da, spars.tp.pid, spars.tp.dcs,
4915 spars.tp.udl, spars.tp.ud);
Vadim Yanitskiy437b5a62019-12-15 14:13:39 +09004916 rp_mo := ts_RP_DATA_MO(spars.rp.msg_ref, omit, spars.rp.smsc_addr, tp_mo);
Harald Welte4263c522018-12-06 11:56:27 +01004917 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_DATA_MO(rp_mo));
4918
4919 SGsAP.send(l3_mo);
4920
4921 /* receive CP-ACK for CP-DATA above */
4922 SGsAP.receive(tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_ACK_MT));
4923
4924 if (ispresent(spars.exp_rp_err)) {
4925 /* expect an RP-ERROR message from MSC with given cause */
4926 rp_mt := tr_RP_ERROR_MT(spars.rp.msg_ref, spars.exp_rp_err);
4927 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4928 SGsAP.receive(l3_mt);
4929 /* send CP-ACK for CP-DATA just received */
4930 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4931 SGsAP.send(l3_mo);
4932 } else {
4933 /* expect RP-ACK for RP-DATA */
4934 rp_mt := tr_RP_ACK_MT(spars.rp.msg_ref);
4935 l3_mt := tr_ML3_MT_SMS(spars.tid, c_TIF_REPL, tr_CP_DATA_MT(rp_mt));
4936 SGsAP.receive(l3_mt);
4937 /* send CP-ACO for CP-DATA just received */
4938 l3_mo := ts_ML3_MO_SMS(spars.tid, c_TIF_ORIG, ts_CP_ACK_MO);
4939 SGsAP.send(l3_mo);
4940 }
4941
4942 deactivate(d);
4943
4944 setverdict(pass);
4945}
4946
4947private function f_vty_sms_send_conn_hdlr(charstring imsi, charstring msisdn, charstring text)
4948runs on BSC_ConnHdlr {
4949 f_vty_transceive(MSCVTY, "subscriber imsi "&imsi&" sms sender msisdn "&msisdn&" send "&text);
4950}
4951
4952/* Send a MT SMS via SGs interface */
4953private function f_tc_sgsap_mt_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4954 f_init_handler(pars);
4955 f_sgs_perform_lu();
4956 f_sleep(1.0);
4957 var SmsParameters spars := valueof(t_SmsPars);
4958 spars.tp.ud := 'C8329BFD064D9B53'O;
4959
4960 /* Trigger SMS via VTY */
4961 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
4962 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
4963
4964 /* Expect a paging request and respond accordingly with a service request */
4965 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, SMS_indicator, omit));
4966 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, SMS_indicator, EMM_CONNECTED));
4967
4968 /* Connection is now live, receive the MT-SMS */
4969 f_mt_sms_sgs(spars);
4970
4971 /* Expect a concluding release from the MSC */
4972 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
4973
4974 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
4975 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
4976
4977 f_sgsap_bssmap_screening();
4978
4979 setverdict(pass);
4980}
4981testcase TC_sgsap_mt_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004982 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01004983 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01004984 f_init(1, true);
4985 pars := f_init_pars(11823, true);
4986 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01004987 vc_conn.done;
4988}
4989
4990/* Send a MO SMS via SGs interface */
4991private function f_tc_sgsap_mo_sms(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
4992 f_init_handler(pars);
4993 f_sgs_perform_lu();
4994 f_sleep(1.0);
4995 var SmsParameters spars := valueof(t_SmsPars);
4996 spars.tp.ud := 'C8329BFD064D9B53'O;
4997
4998 /* Send the MO-SMS */
4999 f_mo_sms_sgs(spars);
5000
5001 /* Expect a concluding release from the MSC/VLR */
5002 SGsAP.receive(tr_SGsAP_RELEASE_REQ(pars.imsi, omit));
5003
5004 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5005 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5006
5007 setverdict(pass);
5008
5009 f_sgsap_bssmap_screening()
5010}
5011testcase TC_sgsap_mo_sms() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005012 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005013 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005014 f_init(1, true);
5015 pars := f_init_pars(11824, true);
5016 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mo_sms), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005017 vc_conn.done;
5018}
5019
5020/* Trigger sending of an MT sms via VTY but never respond to anything */
5021private function f_tc_sgsap_mt_sms_and_nothing(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5022 f_init_handler(pars, 170.0);
5023 f_sgs_perform_lu();
5024 f_sleep(1.0);
5025
5026 var SmsParameters spars := valueof(t_SmsPars);
5027 spars.tp.ud := 'C8329BFD064D9B53'O;
5028 var integer page_count := 0;
5029 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5030 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5031 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5032 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5033
5034 /* Trigger SMS via VTY */
5035 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5036
Neels Hofmeyr16237742019-03-06 15:34:01 +01005037 /* Expect the MSC/VLR to page exactly once */
5038 SGsAP.receive(exp_pag_req);
Harald Welte4263c522018-12-06 11:56:27 +01005039
5040 /* Wait some time to make sure the MSC is not delivering any further
5041 * paging messages or anything else that could be unexpected. */
5042 timer T := 20.0;
5043 T.start
5044 alt {
5045 [] SGsAP.receive(exp_pag_req)
5046 {
5047 setverdict(fail, "paging seems not to stop!");
5048 mtc.stop;
5049 }
5050 [] SGsAP.receive {
5051 setverdict(fail, "unexpected SGsAP message received");
5052 self.stop;
5053 }
5054 [] T.timeout {
5055 setverdict(pass);
5056 }
5057 }
5058
5059 /* Even on a failed paging the SGs Association should stay intact */
5060 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5061
Philipp Maier26bdb8c2019-09-24 09:21:12 +02005062 /* Make sure that the SMS we just inserted is cleared and the
5063 * subscriber is expired. This is necessary because otherwise the MSC
5064 * might re-try the SMS delivery and disturb the following tests. */
Harald Welte4263c522018-12-06 11:56:27 +01005065
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005066 f_vty_sms_clear(hex2str(g_pars.imsi));
5067
Harald Welte4263c522018-12-06 11:56:27 +01005068 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " expire");
5069
5070 setverdict(pass);
Neels Hofmeyrb0f82342019-03-06 15:36:51 +01005071
5072 f_sgsap_bssmap_screening();
Harald Welte4263c522018-12-06 11:56:27 +01005073}
5074testcase TC_sgsap_mt_sms_and_nothing() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005075 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005076 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005077 f_init(1, true);
5078 pars := f_init_pars(11825, true);
5079 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_nothing), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005080 vc_conn.done;
5081}
5082
5083/* Trigger sending of an MT sms via VTY but reject the paging immediately */
5084private function f_tc_sgsap_mt_sms_and_reject(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5085 f_init_handler(pars, 150.0);
5086 f_sgs_perform_lu();
5087 f_sleep(1.0);
5088
5089 var SmsParameters spars := valueof(t_SmsPars);
5090 spars.tp.ud := 'C8329BFD064D9B53'O;
5091 var integer page_count := 0;
5092 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5093 var template PDU_SGsAP exp_pag_req := tr_SGsAP_PAGING_REQ(g_pars.imsi, vlr_name, SMS_indicator, omit);
5094 var template LocationAreaId exp_lai := ts_SGsAP_IE_Lai(valueof(ts_SGsAP_LAI('901'H, '70'H, 2342)));
5095 exp_pag_req.sGsAP_PAGING_REQUEST.locationAreaId := exp_lai;
5096
5097 /* Trigger SMS via VTY */
5098 f_vty_sms_send_conn_hdlr(hex2str(pars.imsi), "2342", "Hello SMS");
5099
5100 /* Expect a paging request and reject it immediately */
5101 SGsAP.receive(exp_pag_req);
5102 SGsAP.send(ts_SGsAP_PAGING_REJ(g_pars.imsi, IMSI_unknown));
5103
5104 /* The MSC/VLR should no longer try to page once the paging has been
5105 * rejected. Wait some time and check if there are no unexpected
5106 * messages on the SGs interface. */
5107 timer T := 20.0;
5108 T.start
5109 alt {
5110 [] SGsAP.receive(exp_pag_req)
5111 {
5112 setverdict(fail, "paging seems not to stop!");
5113 mtc.stop;
5114 }
5115 [] SGsAP.receive {
5116 setverdict(fail, "unexpected SGsAP message received");
5117 self.stop;
5118 }
5119 [] T.timeout {
5120 setverdict(pass);
5121 }
5122 }
5123
Neels Hofmeyr8256ed22019-03-06 15:34:01 +01005124 f_vty_sms_clear(hex2str(g_pars.imsi));
5125
Harald Welte4263c522018-12-06 11:56:27 +01005126 /* A rejected paging with IMSI_unknown (see above) should always send
5127 * the SGs association to NULL. */
5128 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-NULL");
5129
5130 f_sgsap_bssmap_screening();
5131
Harald Welte4263c522018-12-06 11:56:27 +01005132 setverdict(pass);
5133}
5134testcase TC_sgsap_mt_sms_and_reject() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005135 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005136 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005137 f_init(1, true);
5138 pars := f_init_pars(11826, true);
5139 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_mt_sms_and_reject), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005140 vc_conn.done;
5141}
5142
5143/* Perform an MT CSDB call including LU */
5144private function f_mt_lu_and_csfb_call(charstring id, BSC_ConnHdlrPars pars, boolean bssmap_lu) runs on BSC_ConnHdlr {
5145 f_init_handler(pars);
5146
5147 /* Be sure that the BSSMAP reset is done before we begin. */
5148 f_sleep(2.0);
5149
5150 /* Testcase variation: See what happens when we do a regular BSSMAP
5151 * LU first (this should not hurt in any way!) */
5152 if (bssmap_lu) {
5153 f_perform_lu();
5154 }
5155
5156 f_sgs_perform_lu();
5157 f_sleep(1.0);
5158
5159 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5160 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Harald Welte4263c522018-12-06 11:56:27 +01005161
5162 /* Initiate a call via MNCC interface */
5163 f_mt_call_initate(cpars);
5164
5165 /* Expect a paging request and respond accordingly with a service request */
5166 SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit));
5167 SGsAP.send(ts_SGsAP_SERVICE_REQ(pars.imsi, CS_call_indicator, EMM_CONNECTED));
5168
5169 /* Complete the call, hold it for some time and then tear it down */
5170 f_mt_call_complete(cpars);
5171 f_sleep(3.0);
Harald Welte4c422b72019-02-17 16:27:10 +01005172 f_call_hangup(cpars, true, is_csfb := true);
Harald Welte4263c522018-12-06 11:56:27 +01005173
5174 /* Make sure that subscriber is still present and the SGs association is in tact (ref-counting) */
5175 f_ctrl_get_exp(IPA_CTRL, "fsm.SGs-UE.id.imsi:" & hex2str(g_pars.imsi) & ".state", "SGs-ASSOCIATED");
5176
Harald Welte4263c522018-12-06 11:56:27 +01005177 /* Test for successful return by triggering a paging, when the paging
5178 * request is received via SGs, we can be sure that the MSC/VLR has
5179 * recognized that the UE is now back on 4G */
5180 f_sleep(1.0);
5181 f_vty_transceive(MSCVTY, "subscriber imsi " & hex2str(g_pars.imsi) & " paging");
5182 alt {
5183 [] SGsAP.receive(tr_SGsAP_PAGING_REQ(pars.imsi, vlr_name, CS_call_indicator, omit)) {
5184 setverdict(pass);
5185 }
5186 [] SGsAP.receive {
5187 setverdict(fail, "Received unexpected message on SGs");
5188 }
5189 }
5190
5191 f_sgsap_bssmap_screening();
5192
5193 setverdict(pass);
5194}
5195
5196/* Perform a regular BSSAP LU first, do a SGSAP LU and then make a CSFB call */
5197private function f_tc_bssap_lu_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5198 f_mt_lu_and_csfb_call(id, pars, true);
5199}
5200testcase TC_bssap_lu_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005201 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005202 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005203 f_init(1, true);
5204 pars := f_init_pars(118139, true);
Harald Welte4263c522018-12-06 11:56:27 +01005205
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005206 vc_conn := f_start_handler_with_pars(refers(f_tc_bssap_lu_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005207 vc_conn.done;
5208}
5209
Harald Welte4263c522018-12-06 11:56:27 +01005210/* Perform a SGSAP LU and then make a CSFB call */
5211private function f_tc_sgsap_lu_and_mt_call(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5212 f_mt_lu_and_csfb_call(id, pars, false);
5213}
5214testcase TC_sgsap_lu_and_mt_call() runs on MTC_CT {
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005215 var BSC_ConnHdlrPars pars;
Harald Welte4263c522018-12-06 11:56:27 +01005216 var BSC_ConnHdlr vc_conn;
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005217 f_init(1, true);
5218 pars := f_init_pars(11827, true);
Harald Welte4263c522018-12-06 11:56:27 +01005219
Philipp Maier8e07a4a2019-02-14 18:23:28 +01005220 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_lu_and_mt_call), pars);
Harald Welte4263c522018-12-06 11:56:27 +01005221 vc_conn.done;
5222}
5223
Philipp Maier628c0052019-04-09 17:36:57 +02005224/* Simulate an HLR/VLR failure */
5225private function f_tc_sgsap_vlr_failure(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5226 var octetstring mme_name := f_enc_dns_hostname(mp_mme_name);
5227 var octetstring vlr_name := f_enc_dns_hostname(mp_vlr_name);
5228
5229 var PDU_SGsAP lur;
5230
5231 f_init_handler(pars);
5232
5233 /* Attempt location update (which is expected to fail) */
5234 lur := valueof(ts_SGsAP_LU_REQ(g_pars.imsi, mme_name, IMSI_attach,
5235 ts_SGsAP_LAI('901'H, '70'H, 2342)));
5236 SGsAP.send(lur);
5237
5238 /* Respond to SGsAP-RESET-INDICATION from VLR */
5239 alt {
5240 [] SGsAP.receive(tr_SGsAP_RESET_IND_VLR(vlr_name)); {
5241 SGsAP.send(valueof(ts_SGsAP_RESET_ACK_MME(mme_name)));
5242 setverdict(pass);
5243 }
5244 [] SGsAP.receive {
5245 setverdict(fail, "Received unexpected message on SGs");
5246 }
5247 }
5248
5249 f_sleep(1.0);
5250 setverdict(pass);
5251}
5252testcase TC_sgsap_vlr_failure() runs on MTC_CT {
5253 var BSC_ConnHdlrPars pars;
5254 var BSC_ConnHdlr vc_conn;
5255 f_init(1, true, false);
5256 pars := f_init_pars(11811, true, false);
5257 vc_conn := f_start_handler_with_pars(refers(f_tc_sgsap_vlr_failure), pars);
5258 vc_conn.done;
5259}
5260
Harald Welte4263c522018-12-06 11:56:27 +01005261/* SGs TODO:
5262 * LU attempt for IMSI without NAM_PS in HLR
5263 * LU attempt with AUTH FAIL due to invalid RES/SRES
5264 * LU attempt with no response from HLR (VLR should timeout + LU REJ)
5265 * LU attempt with new TMSI but without TMSI REALL CMPL baco to VLR
5266 * implicit IMSI detach from EPS
5267 * implicit IMSI detach from non-EPS
5268 * MM INFO
5269 *
5270 */
Harald Weltef6dd64d2017-11-19 12:09:51 +01005271
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005272private function f_tc_ho_inter_bsc_unknown_cell(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5273 f_init_handler(pars);
5274 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005275
5276 f_perform_lu();
5277 f_mo_call_establish(cpars);
5278
5279 f_sleep(1.0);
5280
5281 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5282 var BssmapCause cause := enum2int(cause_val);
5283
5284 var template BSSMAP_FIELD_CellIdentificationList cil;
5285 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 999) } };
5286
5287 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5288 BSSAP.receive(tr_BSSMAP_HandoverRequiredReject);
5289
5290 f_call_hangup(cpars, true);
5291}
5292testcase TC_ho_inter_bsc_unknown_cell() runs on MTC_CT {
5293 var BSC_ConnHdlr vc_conn;
5294 f_init();
5295
5296 vc_conn := f_start_handler(refers(f_tc_ho_inter_bsc_unknown_cell), 53);
5297 vc_conn.done;
5298}
5299
5300private altstep as_mgcp_ack_all_mdcx(CallParameters cpars) runs on BSC_ConnHdlr {
5301 var MgcpCommand mgcp_cmd;
5302 [] MGCP.receive(tr_MDCX) -> value mgcp_cmd {
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005303 var SDP_Message sdp := valueof(ts_SDP(cpars.mgw_conn_2.mgw_rtp_ip, cpars.mgw_conn_2.mgw_rtp_ip,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005304 hex2str(cpars.mgcp_call_id), "42",
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005305 cpars.mgw_conn_2.mgw_rtp_port,
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005306 { int2str(cpars.rtp_payload_type) },
5307 { valueof(ts_SDP_rtpmap(cpars.rtp_payload_type,
5308 cpars.rtp_sdp_format)),
5309 valueof(ts_SDP_ptime(20)) }));
Neels Hofmeyr3c89a6b2019-10-15 16:54:37 +02005310 MGCP.send(ts_MDCX_ACK(mgcp_cmd.line.trans_id, cpars.mgw_conn_2.mgcp_connection_id, sdp));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005311 repeat;
5312 }
5313}
5314
5315private function f_tc_ho_inter_bsc0(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5316 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005317
5318 f_init_handler(pars);
5319
5320 f_vty_transceive(MSCVTY, "configure terminal");
5321 f_vty_transceive(MSCVTY, "msc");
5322 f_vty_transceive(MSCVTY, "neighbor a cgi 262 42 23 42 ran-pc 0.24.1");
5323 f_vty_transceive(MSCVTY, "neighbor a lac 5 ran-pc 0.24.2");
5324 f_vty_transceive(MSCVTY, "exit");
5325 f_vty_transceive(MSCVTY, "exit");
5326
5327 f_perform_lu();
5328 f_mo_call_establish(cpars);
5329
5330 f_sleep(1.0);
5331
5332 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5333
5334 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5335 var BssmapCause cause := enum2int(cause_val);
5336
5337 var template BSSMAP_FIELD_CellIdentificationList cil;
5338 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('023'H, '42'H, 5) } };
5339
5340 /* old BSS sends Handover Required */
5341 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5342
5343 /* Now the action goes on in f_tc_ho_inter_bsc1() */
5344
5345 /* MSC forwards the RR Handover Command to old BSS */
5346 var PDU_BSSAP ho_command;
5347 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5348
5349 log("GOT HandoverCommand", ho_command);
5350
5351 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5352
5353 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5354 f_expect_clear();
5355
5356 log("FIRST inter-BSC Handover done");
5357
5358
5359 /* ------------------------ */
5360
5361 /* Ok, that went well, now the other BSC is handovering back here --
5362 * from now on this here is the new BSS. */
5363 f_create_bssmap_exp_handoverRequest(193);
5364
5365 var PDU_BSSAP ho_request;
5366 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5367
5368 /* new BSS composes a RR Handover Command */
5369 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5370 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5371 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5372 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5373 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5374
5375 /* Now f_tc_ho_inter_bsc1() expects HandoverCommand */
5376
5377 f_sleep(0.5);
5378
5379 /* Notify that the MS is now over here */
5380
5381 BSSAP.send(ts_BSSMAP_HandoverDetect);
5382 f_sleep(0.1);
5383 BSSAP.send(ts_BSSMAP_HandoverComplete);
5384
5385 f_sleep(3.0);
5386
5387 deactivate(ack_mdcx);
5388
5389 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5390
5391 /* blatant cheating */
5392 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5393 last_n_sd[0] := 3;
5394 f_bssmap_continue_after_n_sd(last_n_sd);
5395
5396 f_call_hangup(cpars, true);
5397 f_sleep(1.0);
5398 deactivate(ccrel);
5399
5400 setverdict(pass);
5401}
5402private function f_tc_ho_inter_bsc1(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5403 f_init_handler(pars);
5404 f_create_bssmap_exp_handoverRequest(194);
5405
5406 var PDU_BSSAP ho_request;
5407 BSSAP.receive(tr_BSSMAP_HandoverRequest) -> value ho_request;
5408
5409 /* new BSS composes a RR Handover Command */
5410 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5411 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5412 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5413 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5414 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5415
5416 /* Now f_tc_ho_inter_bsc0() expects HandoverCommand */
5417
5418 f_sleep(0.5);
5419
5420 /* Notify that the MS is now over here */
5421
5422 BSSAP.send(ts_BSSMAP_HandoverDetect);
5423 f_sleep(0.1);
5424 BSSAP.send(ts_BSSMAP_HandoverComplete);
5425
5426 f_sleep(3.0);
5427
5428 /* Now I'd like to f_call_hangup() but we don't know any cpars here. So
5429 * ... handover back to the first BSC :P */
5430
5431 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5432 var BssmapCause cause := enum2int(cause_val);
5433
5434 var template BSSMAP_FIELD_CellIdentificationList cil;
5435 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('262'H, '42'H, 23) } };
5436
5437 /* old BSS sends Handover Required */
5438 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5439
5440 /* Now the action goes on in f_tc_ho_inter_bsc0() */
5441
5442 /* MSC forwards the RR Handover Command to old BSS */
5443 var PDU_BSSAP ho_command;
5444 BSSAP.receive(tr_BSSMAP_HandoverCommand) -> value ho_command;
5445
5446 log("GOT HandoverCommand", ho_command);
5447
5448 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5449
5450 /* f_tc_ho_inter_bsc1() completes Handover, then expecting a Clear here. */
5451 f_expect_clear();
5452 setverdict(pass);
5453}
5454testcase TC_ho_inter_bsc() runs on MTC_CT {
5455 var BSC_ConnHdlr vc_conn0;
5456 var BSC_ConnHdlr vc_conn1;
5457 f_init(2);
5458
5459 var BSC_ConnHdlrPars pars0 := f_init_pars(53);
5460 var BSC_ConnHdlrPars pars1 := f_init_pars(53);
5461
5462 vc_conn0 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc0), pars0, 0);
5463 vc_conn1 := f_start_handler_with_pars(refers(f_tc_ho_inter_bsc1), pars1, 1);
5464 vc_conn0.done;
5465 vc_conn1.done;
5466}
5467
5468function f_ML3_patch_seq_nr_MS_NW(in uint2_t seq_nr, inout octetstring enc_l3) {
5469 log("MS_NW patching N(SD)=", seq_nr, " into dtap ", enc_l3);
5470 enc_l3[2] := (enc_l3[2] and4b '3f'O) or4b bit2oct(int2bit(seq_nr, 8) << 6);
5471 log("MS_NW patched enc_l3: ", enc_l3);
5472}
5473
5474private function f_tc_ho_inter_msc_out(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5475 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005476 var hexstring ho_number := f_gen_msisdn(99999);
5477
5478 f_init_handler(pars);
5479
5480 f_create_mncc_expect(hex2str(ho_number));
5481
5482 f_vty_transceive(MSCVTY, "configure terminal");
5483 f_vty_transceive(MSCVTY, "msc");
5484 f_vty_transceive(MSCVTY, "neighbor a cgi 017 017 1 1 msc-ipa-name msc-017-017-1");
5485 f_vty_transceive(MSCVTY, "exit");
5486 f_vty_transceive(MSCVTY, "exit");
5487
5488 f_perform_lu();
5489 f_mo_call_establish(cpars);
5490
5491 f_sleep(1.0);
5492
5493 var default ack_mdcx := activate(as_mgcp_ack_all_mdcx(cpars));
5494
5495 var myBSSMAP_Cause cause_val := GSM0808_CAUSE_BETTER_CELL;
5496 var BssmapCause cause := enum2int(cause_val);
5497
5498 var template BSSMAP_FIELD_CellIdentificationList cil;
5499 cil := { cIl_LAI := { ts_BSSMAP_CI_LAI('017'H, '017'H, 1) } };
5500
5501 /* old BSS sends Handover Required */
5502 BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5503
5504 /* The target cell 017-017 LAC 1 is configured to be a remote MSC of name "msc-017-017-1".
5505 * This MSC tries to reach the other MSC via GSUP. */
5506
5507 var octetstring remote_msc_name := '6D73632D3031372D3031372D3100'O; /* "msc-017-017-1\0" as octetstring */
5508 var GSUP_PDU prep_ho_req;
5509 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_HANDOVER_REQUEST,
5510 pars.imsi, destination_name := remote_msc_name)) -> value prep_ho_req;
5511
5512 var GSUP_IeValue source_name_ie;
5513 f_gsup_find_ie(prep_ho_req, OSMO_GSUP_SOURCE_NAME_IE, source_name_ie);
5514 var octetstring local_msc_name := source_name_ie.source_name;
5515
5516 /* Remote MSC has figured out its BSC and signals success */
5517 var PDU_ML3_NW_MS rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5518 var octetstring rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5519 var PDU_BSSAP ho_req_ack := valueof(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5520 aoIPTransportLayer := omit,
5521 speechCodec := ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5522 GSUP.send(ts_GSUP_E_PrepareHandoverResult(
5523 pars.imsi,
5524 ho_number,
5525 remote_msc_name, local_msc_name,
5526 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006, enc_PDU_BSSAP(ho_req_ack)))));
5527
5528 /* MSC forwards the RR Handover Command to old BSS */
5529 BSSAP.receive(tr_BSSMAP_HandoverCommand);
5530
5531 /* The MS shows up at remote new BSS */
5532
5533 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5534 pars.imsi, remote_msc_name, local_msc_name,
5535 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5536 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverDetect))))));
5537 BSSAP.receive(tr_BSSMAP_HandoverSucceeded);
5538 f_sleep(0.1);
5539
5540 /* Save the MS sequence counters for use on the other connection */
5541 var N_Sd_Array last_n_sd := f_bssmap_last_n_sd();
5542
5543 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_SEND_END_SIGNAL_REQUEST,
5544 pars.imsi, remote_msc_name, local_msc_name,
5545 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5546 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverComplete))))));
5547
5548 /* The local BSS conn clears, all communication goes via remote MSC now */
5549 f_expect_clear();
5550
5551 /**********************************/
5552 /* Play through some signalling across the inter-MSC link.
5553 * This is a copy of f_tc_lu_and_mo_ussd_single_request() translated into GSUP AN-APDUs. */
5554
5555 if (false) {
5556 var template OCTN facility_req := f_USSD_FACILITY_IE_INVOKE(
5557 invoke_id := 5, /* Phone may not start from 0 or 1 */
5558 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5559 ussd_string := "*#100#"
5560 );
5561
5562 var template OCTN facility_rsp := f_USSD_FACILITY_IE_RETURN_RESULT(
5563 invoke_id := 5, /* InvokeID shall be the same for both REQ and RSP */
5564 op_code := SS_OP_CODE_PROCESS_USS_REQ,
5565 ussd_string := "Your extension is " & hex2str(g_pars.msisdn) & "\r"
5566 )
5567
5568 /* Compose a new SS/REGISTER message with request */
5569 var template (value) PDU_ML3_MS_NW ussd_req := ts_ML3_MO_SS_REGISTER(
5570 tid := 1, /* We just need a single transaction */
5571 ti_flag := c_TIF_ORIG, /* Sent from the side that originates the TI */
5572 facility := valueof(facility_req)
5573 );
5574 var PDU_ML3_MS_NW ussd_req_v := valueof(ussd_req);
5575
5576 /* Compose SS/RELEASE_COMPLETE template with expected response */
5577 var template PDU_ML3_NW_MS ussd_rsp := tr_ML3_MT_SS_RELEASE_COMPLETE(
5578 tid := 1, /* Response should arrive within the same transaction */
5579 ti_flag := c_TIF_REPL, /* Sent to the side that originates the TI */
5580 facility := valueof(facility_rsp)
5581 );
5582
5583 /* Compose expected MSC -> HLR message */
5584 var template GSUP_PDU gsup_req := tr_GSUP_PROC_SS_REQ(
5585 imsi := g_pars.imsi,
5586 state := OSMO_GSUP_SESSION_STATE_BEGIN,
5587 ss := valueof(facility_req)
5588 );
5589
5590 /* To be used for sending response with correct session ID */
5591 var GSUP_PDU gsup_req_complete;
5592
5593 /* Request own number */
5594 /* From remote MSC instead of BSSAP directly */
5595 /* Patch the correct N_SD value into the message. */
5596 var octetstring l3_enc := enc_PDU_ML3_MS_NW(ussd_req_v);
5597 var RAN_Emulation.ConnectionData cd;
5598 f_ML3_patch_seq_nr_MS_NW(f_next_n_sd(last_n_sd, f_ML3_n_sd_idx(ussd_req_v)), l3_enc);
5599 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PROCESS_ACCESS_SIGNALLING_REQUEST,
5600 pars.imsi, remote_msc_name, local_msc_name,
5601 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5602 enc_PDU_BSSAP(valueof(ts_BSSAP_DTAP(l3_enc)))
5603 ))
5604 ));
5605
5606 /* Expect GSUP message containing the SS payload */
5607 gsup_req_complete := f_expect_gsup_msg(gsup_req);
5608
5609 /* Compose the response from HLR using received session ID */
5610 var template GSUP_PDU gsup_rsp := ts_GSUP_PROC_SS_REQ(
5611 imsi := g_pars.imsi,
5612 sid := gsup_req_complete.ies[1].val.session_id,
5613 state := OSMO_GSUP_SESSION_STATE_END,
5614 ss := valueof(facility_rsp)
5615 );
5616
5617 /* Finally, HLR terminates the session */
5618 GSUP.send(gsup_rsp);
5619
5620 /* The USSD response goes out to remote MSC, on GSUP E instead of BSSAP */
5621 var GSUP_PDU gsup_ussd_rsp;
5622 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5623 pars.imsi, destination_name := remote_msc_name)) -> value gsup_ussd_rsp;
5624
5625 var GSUP_IeValue an_apdu;
5626 if (not f_gsup_find_ie(gsup_ussd_rsp, OSMO_GSUP_AN_APDU_IE, an_apdu)) {
5627 setverdict(fail, "No AN-APDU in received GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5628 mtc.stop;
5629 }
5630 var PDU_BSSAP bssap_dtap_mt := dec_PDU_BSSAP(an_apdu.an_apdu.pdu);
5631 var PDU_ML3_NW_MS dtap_mt := dec_PDU_ML3_NW_MS(bssap_dtap_mt.pdu.dtap);
5632 log("Expecting", ussd_rsp);
5633 log("Got", dtap_mt);
5634 if (not match(dtap_mt, ussd_rsp)) {
5635 setverdict(fail, "Unexpected GSUP message. Expected USSD response in DTAP, got", gsup_ussd_rsp);
5636 mtc.stop;
5637 }
5638 }
5639 /**********************************/
5640
5641
5642 /* inter-MSC handover back to the first MSC */
5643 f_create_bssmap_exp_handoverRequest(193);
5644 cil := { cIl_CGI := { ts_BSSMAP_CI_CGI('262'H, '42'H, 23, 42) } };
5645
5646 /* old BSS sends Handover Required, via inter-MSC E link: like
5647 * BSSAP.send(ts_BSSMAP_HandoverRequired(cause, cil));
5648 * but via GSUP */
5649 GSUP.send(ts_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_REQUEST,
5650 pars.imsi, remote_msc_name, local_msc_name,
5651 valueof(t_GSUP_AN_APDU(OSMO_GSUP_AN_PROTO_48006,
5652 enc_PDU_BSSAP(valueof(ts_BSSMAP_HandoverRequired(cause, cil)))
5653 ))
5654 ));
5655
5656 /* MSC asks local BSS to prepare Handover to it */
5657 BSSAP.receive(tr_BSSMAP_HandoverRequest);
5658
5659 /* Make sure the new BSSAP conn continues with the correct N_SD sequence numbers */
5660 f_bssmap_continue_after_n_sd(last_n_sd);
5661
5662 /* new BSS composes a RR Handover Command */
5663 rr_ho_cmd := valueof(ts_RR_HandoverCommand);
5664 rr_ho_cmd_enc := enc_PDU_ML3_NW_MS(rr_ho_cmd);
5665 var BSSMAP_IE_AoIP_TransportLayerAddress tla := valueof(ts_BSSMAP_IE_AoIP_TLA4('01020304'O, 2342));
5666 BSSAP.send(ts_BSSMAP_HandoverRequestAcknowledge(rr_ho_cmd_enc, lengthof(rr_ho_cmd_enc),
5667 tla, ts_BSSMAP_IE_SpeechCodec({ts_CodecFR})));
5668
5669 /* HandoverCommand goes out via remote MSC-I */
5670 var GSUP_PDU prep_subsq_ho_res;
5671 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_PREPARE_SUBSEQUENT_HANDOVER_RESULT,
5672 pars.imsi, destination_name := remote_msc_name)) -> value prep_subsq_ho_res;
5673
5674 /* MS shows up at the local BSS */
5675 BSSAP.send(ts_BSSMAP_HandoverDetect);
5676 f_sleep(0.1);
5677 BSSAP.send(ts_BSSMAP_HandoverComplete);
5678
5679 /* Handover Succeeded message */
5680 GSUP.receive(tr_GSUP_E_AN_APDU(OSMO_GSUP_MSGT_E_FORWARD_ACCESS_SIGNALLING_REQUEST,
5681 pars.imsi, destination_name := remote_msc_name));
5682
5683 /* MS has handovered to here, Clear Command goes out via remote MSC-I -- in form of a GSUP Close. */
5684 GSUP.receive(tr_GSUP_E_NO_PDU(OSMO_GSUP_MSGT_E_CLOSE,
5685 pars.imsi, destination_name := remote_msc_name));
5686
5687 /* Handover ends successfully. Call goes on for a little longer and then we hang up. */
5688
5689 f_sleep(1.0);
5690 deactivate(ack_mdcx);
5691
5692 /* FIXME: the inter-MSC call has put a number of MNCC messages in the queue, which above code should expect and
5693 * clear out. The f_call_hangup() expects an MNCC_REL_IND, so, for the time being, just clear the MNCC messages
5694 * before starting the call hangup. Instead of this, the individual messages should be tested for above. */
5695 MNCC.clear;
5696
5697 var default ccrel := activate(as_optional_cc_rel(cpars, true));
5698 f_call_hangup(cpars, true);
5699 f_sleep(1.0);
5700 deactivate(ccrel);
5701
5702 setverdict(pass);
5703}
5704testcase TC_ho_inter_msc_out() runs on MTC_CT {
5705 var BSC_ConnHdlr vc_conn;
5706 f_init(1);
5707
5708 var BSC_ConnHdlrPars pars := f_init_pars(54);
5709
5710 vc_conn := f_start_handler_with_pars(refers(f_tc_ho_inter_msc_out), pars, 0);
5711 vc_conn.done;
5712}
5713
Oliver Smith1d118ff2019-07-03 10:57:35 +02005714private function f_tc_lu_imsi_auth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5715 pars.net.expect_auth := true;
5716 pars.net.expect_imei := true;
5717 f_init_handler(pars);
5718 f_perform_lu();
5719}
5720testcase TC_lu_imsi_auth_tmsi_check_imei() runs on MTC_CT {
5721 var BSC_ConnHdlr vc_conn;
5722 f_init();
5723 f_vty_config(MSCVTY, "network", "authentication required");
5724 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5725
5726 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei), 5);
5727 vc_conn.done;
5728}
5729
5730private function f_tc_lu_imsi_auth3g_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5731 pars.net.expect_auth := true;
5732 pars.use_umts_aka := true;
5733 pars.net.expect_imei := true;
5734 f_init_handler(pars);
5735 f_perform_lu();
5736}
5737testcase TC_lu_imsi_auth3g_tmsi_check_imei() runs on MTC_CT {
5738 var BSC_ConnHdlr vc_conn;
5739 f_init();
5740 f_vty_config(MSCVTY, "network", "authentication required");
5741 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5742
5743 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei), 5);
5744 vc_conn.done;
5745}
5746
5747private function f_tc_lu_imsi_noauth_tmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5748 pars.net.expect_imei := true;
5749 f_init_handler(pars);
5750 f_perform_lu();
5751}
5752testcase TC_lu_imsi_noauth_tmsi_check_imei() runs on MTC_CT {
5753 var BSC_ConnHdlr vc_conn;
5754 f_init();
5755 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5756
5757 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei), 5);
5758 vc_conn.done;
5759}
5760
5761private function f_tc_lu_imsi_noauth_notmsi_check_imei(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5762 pars.net.expect_tmsi := false;
5763 pars.net.expect_imei := true;
5764 f_init_handler(pars);
5765 f_perform_lu();
5766}
5767testcase TC_lu_imsi_noauth_notmsi_check_imei() runs on MTC_CT {
5768 var BSC_ConnHdlr vc_conn;
5769 f_init();
5770 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
5771 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5772
5773 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei), 5);
5774 vc_conn.done;
5775}
5776
5777private function f_tc_lu_imsi_auth_tmsi_check_imei_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5778 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005779
5780 pars.net.expect_auth := true;
5781 pars.net.expect_imei := true;
5782 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
5783 f_init_handler(pars);
5784
5785 /* Cannot use f_perform_lu() as we expect a reject */
5786 l3_lu := f_build_lu_imsi(g_pars.imsi)
5787 f_create_gsup_expect(hex2str(g_pars.imsi));
5788 f_bssap_compl_l3(l3_lu);
5789 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5790
5791 f_mm_common();
5792 f_msc_lu_hlr();
5793 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005794 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005795 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005796}
5797testcase TC_lu_imsi_auth_tmsi_check_imei_nack() runs on MTC_CT {
5798 var BSC_ConnHdlr vc_conn;
5799 f_init();
5800 f_vty_config(MSCVTY, "network", "authentication required");
5801 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5802
5803 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_nack), 5);
5804 vc_conn.done;
5805}
5806
5807private function f_tc_lu_imsi_auth_tmsi_check_imei_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5808 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005809
5810 pars.net.expect_auth := true;
5811 pars.net.expect_imei := true;
5812 pars.net.check_imei_error := true;
5813 f_init_handler(pars);
5814
5815 /* Cannot use f_perform_lu() as we expect a reject */
5816 l3_lu := f_build_lu_imsi(g_pars.imsi)
5817 f_create_gsup_expect(hex2str(g_pars.imsi));
5818 f_bssap_compl_l3(l3_lu);
5819 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5820
5821 f_mm_common();
5822 f_msc_lu_hlr();
5823 f_mm_imei();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005824 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005825 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005826}
5827testcase TC_lu_imsi_auth_tmsi_check_imei_err() runs on MTC_CT {
5828 var BSC_ConnHdlr vc_conn;
5829 f_init();
5830 f_vty_config(MSCVTY, "network", "authentication required");
5831 f_vty_config(MSCVTY, "msc", "check-imei-rqd 1");
5832
5833 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_err), 5);
5834 vc_conn.done;
5835}
5836
5837private function f_tc_lu_imsi_auth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5838 pars.net.expect_auth := true;
5839 pars.net.expect_imei_early := true;
5840 f_init_handler(pars);
5841 f_perform_lu();
5842}
5843testcase TC_lu_imsi_auth_tmsi_check_imei_early() runs on MTC_CT {
5844 var BSC_ConnHdlr vc_conn;
5845 f_init();
5846 f_vty_config(MSCVTY, "network", "authentication required");
5847 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5848
5849 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early), 5);
5850 vc_conn.done;
5851}
5852
5853private function f_tc_lu_imsi_auth3g_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5854 pars.net.expect_auth := true;
5855 pars.use_umts_aka := true;
5856 pars.net.expect_imei_early := true;
5857 f_init_handler(pars);
5858 f_perform_lu();
5859}
5860testcase TC_lu_imsi_auth3g_tmsi_check_imei_early() runs on MTC_CT {
5861 var BSC_ConnHdlr vc_conn;
5862 f_init();
5863 f_vty_config(MSCVTY, "network", "authentication required");
5864 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5865
5866 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth3g_tmsi_check_imei_early), 5);
5867 vc_conn.done;
5868}
5869
5870private function f_tc_lu_imsi_noauth_tmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5871 pars.net.expect_imei_early := true;
5872 f_init_handler(pars);
5873 f_perform_lu();
5874}
5875testcase TC_lu_imsi_noauth_tmsi_check_imei_early() runs on MTC_CT {
5876 var BSC_ConnHdlr vc_conn;
5877 f_init();
5878 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5879
5880 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_tmsi_check_imei_early), 5);
5881 vc_conn.done;
5882}
5883
5884private function f_tc_lu_imsi_noauth_notmsi_check_imei_early(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5885 pars.net.expect_tmsi := false;
5886 pars.net.expect_imei_early := true;
5887 f_init_handler(pars);
5888 f_perform_lu();
5889}
5890testcase TC_lu_imsi_noauth_notmsi_check_imei_early() runs on MTC_CT {
5891 var BSC_ConnHdlr vc_conn;
5892 f_init();
5893 f_vty_config(MSCVTY, "msc", "no assign-tmsi");
5894 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5895
5896 vc_conn := f_start_handler(refers(f_tc_lu_imsi_noauth_notmsi_check_imei_early), 5);
5897 vc_conn.done;
5898}
5899
5900private function f_tc_lu_imsi_auth_tmsi_check_imei_early_nack(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5901 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005902
5903 pars.net.expect_auth := true;
5904 pars.net.expect_imei_early := true;
5905 pars.net.check_imei_result := OSMO_GSUP_IMEI_RESULT_NACK;
5906 f_init_handler(pars);
5907
5908 /* Cannot use f_perform_lu() as we expect a reject */
5909 l3_lu := f_build_lu_imsi(g_pars.imsi)
5910 f_create_gsup_expect(hex2str(g_pars.imsi));
5911 f_bssap_compl_l3(l3_lu);
5912 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5913
5914 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005915 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005916 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005917}
5918testcase TC_lu_imsi_auth_tmsi_check_imei_early_nack() runs on MTC_CT {
5919 var BSC_ConnHdlr vc_conn;
5920 f_init();
5921 f_vty_config(MSCVTY, "network", "authentication required");
5922 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5923
5924 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_nack), 5);
5925 vc_conn.done;
5926}
5927
5928private function f_tc_lu_imsi_auth_tmsi_check_imei_early_err(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5929 var PDU_ML3_MS_NW l3_lu;
Oliver Smith1d118ff2019-07-03 10:57:35 +02005930
5931 pars.net.expect_auth := true;
5932 pars.net.expect_imei_early := true;
5933 pars.net.check_imei_error := true;
5934 f_init_handler(pars);
5935
5936 /* Cannot use f_perform_lu() as we expect a reject */
5937 l3_lu := f_build_lu_imsi(g_pars.imsi)
5938 f_create_gsup_expect(hex2str(g_pars.imsi));
5939 f_bssap_compl_l3(l3_lu);
5940 BSSAP.send(ts_BSSMAP_ClassmarkUpd(g_pars.cm2, g_pars.cm3));
5941
5942 f_mm_imei_early();
Oliver Smith91bfa1c2019-07-19 15:01:15 +02005943 f_expect_lu_reject();
Oliver Smith690d60f2019-07-23 13:09:08 +02005944 f_expect_clear();
Oliver Smith1d118ff2019-07-03 10:57:35 +02005945}
5946testcase TC_lu_imsi_auth_tmsi_check_imei_early_err() runs on MTC_CT {
5947 var BSC_ConnHdlr vc_conn;
5948 f_init();
5949 f_vty_config(MSCVTY, "network", "authentication required");
5950 f_vty_config(MSCVTY, "msc", "check-imei-rqd early");
5951
5952 vc_conn := f_start_handler(refers(f_tc_lu_imsi_auth_tmsi_check_imei_early_err), 5);
5953 vc_conn.done;
5954}
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02005955
Neels Hofmeyr8df69622019-11-02 19:16:03 +01005956friend function f_tc_invalid_mgcp_crash(charstring id, BSC_ConnHdlrPars pars) runs on BSC_ConnHdlr {
5957 f_init_handler(pars);
5958 var CallParameters cpars := valueof(t_CallParams('12345'H, 0));
5959
5960 /* Set invalid IP address so that osmo-msc discards the rtp_stream and MGCP endpoint FSM instances in the middle
5961 * of successful MGCP response dispatch. If things aren't safeguarded, the on_success() in osmo_mgcpc_ep_fsm
5962 * will cause a use-after-free after that event dispatch. */
5963 cpars.mgw_conn_1.mgw_rtp_ip := "0.0.0.0";
5964 cpars.mgw_conn_2.mgw_rtp_ip := "0.0.0.0";
5965 cpars.rtp_sdp_format := "FOO/8000";
5966 cpars.expect_release := true;
5967
5968 f_perform_lu();
5969 f_mo_call_establish(cpars);
5970}
5971testcase TC_invalid_mgcp_crash() runs on MTC_CT {
5972 var BSC_ConnHdlr vc_conn;
5973 f_init();
5974
5975 vc_conn := f_start_handler(refers(f_tc_invalid_mgcp_crash), 7);
5976 vc_conn.done;
5977}
5978
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01005979friend function f_tc_mm_id_resp_no_identity(charstring id, BSC_ConnHdlrPars pars)
5980runs on BSC_ConnHdlr {
5981 pars.tmsi := 'FFFFFFFF'O;
5982 f_init_handler(pars);
5983
5984 f_create_gsup_expect(hex2str(g_pars.imsi));
5985
5986 /* Initiate Location Updating using an unknown TMSI */
5987 f_bssap_compl_l3(f_build_lu_tmsi(pars.tmsi));
5988
5989 /* Expect an Identity Request, send response with no identity */
5990 BSSAP.receive(tr_PDU_DTAP_MT(tr_ML3_MT_MM_ID_Req(CM_ID_TYPE_IMSI)));
5991 BSSAP.send(ts_PDU_DTAP_MO(ts_ML3_MO_MM_ID_Rsp({
5992 lengthIndicator := 1,
5993 mobileIdentityV := {
5994 typeOfIdentity := '000'B,
5995 oddEvenInd_identity := {
5996 no_identity := {
5997 oddevenIndicator := '0'B,
5998 fillerDigits := '00000'H
5999 }
6000 }
6001 }
6002 })));
6003
6004 f_expect_lu_reject();
6005 f_expect_clear();
6006}
6007testcase TC_mm_id_resp_no_identity() runs on MTC_CT {
6008 var BSC_ConnHdlr vc_conn;
6009
6010 f_init();
6011
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006012 vc_conn := f_start_handler(refers(f_tc_mm_id_resp_no_identity), 7, verify_cell_id := false);
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006013 vc_conn.done;
6014}
6015
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006016/* Verify the case when T3212 expires during Paging procedure, just before the receipt
6017 * of Paging Response. This used to provoke a NULL-pointer dereference in old versions
6018 * of OsmoMSC, but apparently the bug has been fixed, and we're safe now. */
6019friend function f_tc_lu_and_expire_while_paging(charstring id, BSC_ConnHdlrPars pars)
6020runs on BSC_ConnHdlr {
6021 var charstring imsi := hex2str(pars.imsi);
6022
6023 f_init_handler(pars);
6024
6025 /* Perform location update */
6026 f_perform_lu();
6027
6028 f_ran_register_imsi(g_pars.imsi, g_pars.tmsi);
6029 f_create_gsup_expect(hex2str(g_pars.imsi));
6030
6031 /* Initiate paging procedure from the VTY */
6032 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " paging");
6033 f_expect_paging();
6034
6035 /* Emulate T3212 expiration during paging (we don't want to wait, right?) */
6036 f_vty_transceive(MSCVTY, "subscriber imsi " & imsi & " expire");
6037
6038 /* MS sends PAGING RESPONSE, *old* OsmoMSC crashes here... */
6039 f_establish_fully(EST_TYPE_PAG_RESP);
6040
6041 /* The recent OsmoMSC keeps subscriber in its VLR unless the Paging is completed.
6042 * In this case we do not send anything and just wait for a Clear Command. */
Neels Hofmeyr4e18ccc2020-06-24 19:08:17 +02006043 f_expect_clear(verify_vlr_cell_id := false);
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006044}
6045testcase TC_lu_and_expire_while_paging() runs on MTC_CT {
6046 var BSC_ConnHdlr vc_conn;
6047
6048 f_init();
6049
6050 vc_conn := f_start_handler(refers(f_tc_lu_and_expire_while_paging), 7);
6051 vc_conn.done;
6052}
6053
Harald Weltef6dd64d2017-11-19 12:09:51 +01006054control {
Philipp Maier328d1662018-03-07 10:40:27 +01006055 execute( TC_cr_before_reset() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006056 execute( TC_lu_imsi_noauth_tmsi() );
Harald Welted2328a22018-01-27 14:27:16 +01006057 execute( TC_lu_imsi_noauth_notmsi() );
Harald Weltea49e36e2018-01-21 19:29:33 +01006058 execute( TC_lu_imsi_reject() );
6059 execute( TC_lu_imsi_timeout_gsup() );
Harald Welted2328a22018-01-27 14:27:16 +01006060 execute( TC_lu_imsi_auth_tmsi() );
Harald Welte8a397ae2019-04-21 22:03:37 +02006061 execute( TC_lu_imsi_auth3g_tmsi() );
Pau Espin Pedrold3d54a92019-12-17 17:02:54 +01006062 execute( TC_lu_imsi_timeout_tmsi_realloc() );
Harald Welted2328a22018-01-27 14:27:16 +01006063 execute( TC_cmserv_imsi_unknown() );
Harald Welte2bb825f2018-01-22 11:31:18 +01006064 execute( TC_lu_and_mo_call() );
Pau Espin Pedrola42745c2020-01-10 18:03:28 +01006065 execute( TC_lu_and_mo_call_sccp_tiar_timeout() );
Harald Welte071ed732018-01-23 19:53:52 +01006066 execute( TC_lu_auth_sai_timeout() );
6067 execute( TC_lu_auth_sai_err() );
Harald Weltee1a2f3c2018-01-24 17:28:48 +01006068 execute( TC_lu_clear_request() );
6069 execute( TC_lu_disconnect() );
6070 execute( TC_lu_by_imei() );
6071 execute( TC_lu_by_tmsi_noauth_unknown() );
6072 execute( TC_imsi_detach_by_imsi() );
6073 execute( TC_imsi_detach_by_tmsi() );
6074 execute( TC_imsi_detach_by_imei() );
6075 execute( TC_emerg_call_imei_reject() );
6076 execute( TC_emerg_call_imsi() );
6077 execute( TC_cm_serv_req_vgcs_reject() );
6078 execute( TC_cm_serv_req_vbs_reject() );
6079 execute( TC_cm_serv_req_lcs_reject() );
Harald Welte0195ab12018-01-24 21:50:20 +01006080 execute( TC_cm_reest_req_reject() );
Harald Welte1af6ea82018-01-25 18:33:15 +01006081 execute( TC_lu_auth_2G_fail() );
6082 execute( TC_lu_imsi_auth_tmsi_encr_13_13() );
6083 execute( TC_cl3_no_payload() );
6084 execute( TC_cl3_rnd_payload() );
Harald Welte1852a842018-01-26 22:53:36 +01006085 execute( TC_establish_and_nothing() );
6086 execute( TC_mo_setup_and_nothing() );
6087 execute( TC_mo_crcx_ran_timeout() );
6088 execute( TC_mo_crcx_ran_reject() );
Harald Welted2328a22018-01-27 14:27:16 +01006089 execute( TC_mt_crcx_ran_reject() );
Daniel Willmann8b084372018-02-04 13:35:26 +01006090 execute( TC_mo_setup_and_dtmf_dup() );
Harald Welteaa54cf82018-01-30 08:15:32 +01006091 //execute( TC_mt_t310() );
Harald Welte167458a2018-01-27 15:58:16 +01006092 execute( TC_gsup_cancel() );
Harald Welte9de84792018-01-28 01:06:35 +01006093 execute( TC_lu_imsi_auth_tmsi_encr_1_13() );
6094 execute( TC_lu_imsi_auth_tmsi_encr_3_13() );
6095 execute( TC_lu_imsi_auth_tmsi_encr_3_1() );
Neels Hofmeyr29b8da02018-03-01 18:09:45 +01006096 execute( TC_lu_imsi_auth_tmsi_encr_3_1_no_cm() );
Harald Welte9de84792018-01-28 01:06:35 +01006097 execute( TC_lu_imsi_auth_tmsi_encr_13_2() );
6098 execute( TC_lu_imsi_auth_tmsi_encr_013_2() );
Philipp Maier94f3f1b2018-03-15 18:54:13 +01006099 execute( TC_mo_release_timeout() );
Philipp Maier2a98a732018-03-19 16:06:12 +01006100 execute( TC_lu_and_mt_call_no_dlcx_resp() );
Philipp Maier75932982018-03-27 14:52:35 +02006101 execute( TC_reset_two() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006102
6103 execute( TC_lu_and_mt_call() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006104 execute( TC_lu_and_mt_call_already_paging() );
Harald Welte33ec09b2018-02-10 15:34:46 +01006105
Harald Weltef45efeb2018-04-09 18:19:24 +02006106 execute( TC_lu_and_mo_sms() );
6107 execute( TC_lu_and_mt_sms() );
Neels Hofmeyrb58d9742019-11-27 18:44:54 +01006108 execute( TC_lu_and_mt_sms_already_paging() );
Philipp Maier3983e702018-11-22 19:01:33 +01006109 execute( TC_lu_and_mt_sms_paging_and_nothing() );
Alexander Couzensfc02f242019-09-12 03:43:18 +02006110 execute( TC_lu_and_mt_sms_paging_repeated() );
Harald Weltef640a012018-04-14 17:49:21 +02006111 execute( TC_smpp_mo_sms() );
Vadim Yanitskiy33820762020-01-15 11:26:07 +07006112 execute( TC_smpp_mo_sms_rp_error() );
Harald Weltef640a012018-04-14 17:49:21 +02006113 execute( TC_smpp_mt_sms() );
Harald Weltef45efeb2018-04-09 18:19:24 +02006114
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006115 execute( TC_gsup_mo_sms() );
Vadim Yanitskiy9cc019a2018-11-15 02:06:07 +07006116 execute( TC_gsup_mo_smma() );
Vadim Yanitskiyd7b37ab2018-11-24 03:40:20 +07006117 execute( TC_gsup_mt_sms_ack() );
6118 execute( TC_gsup_mt_sms_err() );
Vadim Yanitskiybe1ff4b2019-01-18 15:04:13 +07006119 execute( TC_gsup_mt_sms_rp_mr() );
Vadim Yanitskiy5ac49cc2019-01-24 16:57:31 +07006120 execute( TC_gsup_mo_mt_sms_rp_mr() );
Vadim Yanitskiya2a8a112019-07-08 20:04:32 +07006121 execute( TC_gsup_mt_multi_part_sms() );
Vadim Yanitskiy103d09f2018-11-12 02:50:23 +07006122
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006123 execute( TC_lu_and_mo_ussd_single_request() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006124 execute( TC_lu_and_mt_ussd_notification() );
Vadim Yanitskiy2a978b92018-06-19 17:51:20 +07006125 execute( TC_lu_and_mo_ussd_during_mt_call() );
Vadim Yanitskiy13e4a272018-06-19 18:24:31 +07006126 execute( TC_lu_and_mt_ussd_during_mt_call() );
Vadim Yanitskiy2daf52d2018-06-21 04:19:58 +07006127 execute( TC_lu_and_mo_ussd_mo_release() );
Vadim Yanitskiy0e392dd2018-11-29 00:47:54 +07006128 execute( TC_lu_and_ss_session_timeout() );
Vadim Yanitskiy7d1f9182018-05-28 16:21:42 +07006129
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006130 execute( TC_mt_ussd_for_unknown_subscr() );
Vadim Yanitskiyc3c07d42019-06-17 23:00:44 +07006131 execute( TC_mo_ussd_for_unknown_trans() );
Vadim Yanitskiyd612d282019-06-15 14:46:03 +07006132 execute( TC_proc_ss_for_unknown_session() );
Vadim Yanitskiye5f4ed92019-06-16 02:36:33 +07006133 execute( TC_proc_ss_paging_fail() );
Vadim Yanitskiy29ba8d62019-06-16 15:19:41 +07006134 execute( TC_proc_ss_abort() );
Vadim Yanitskiy0e6c9f52019-06-15 01:01:28 +07006135
Vadim Yanitskiy1c9754d2020-01-07 21:56:55 +01006136 execute( TC_multi_lu_and_mo_ussd() );
6137 execute( TC_multi_lu_and_mt_ussd() );
6138
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006139 execute( TC_cipher_complete_with_invalid_cipher() );
Stefan Sperlinga2d59c62018-12-18 16:32:44 +01006140 execute( TC_cipher_complete_1_without_cipher() );
6141 execute( TC_cipher_complete_3_without_cipher() );
6142 execute( TC_cipher_complete_13_without_cipher() );
Harald Welteb2284bd2019-05-10 11:30:43 +02006143 execute( TC_lu_with_invalid_mcc_mnc() );
Stefan Sperling89eb1f32018-12-17 15:06:20 +01006144
Harald Welte4263c522018-12-06 11:56:27 +01006145 execute( TC_sgsap_reset() );
6146 execute( TC_sgsap_lu() );
6147 execute( TC_sgsap_lu_imsi_reject() );
6148 execute( TC_sgsap_lu_and_nothing() );
6149 execute( TC_sgsap_expl_imsi_det_eps() );
Philipp Maierfc19f172019-03-21 11:17:54 +01006150 execute( TC_sgsap_impl_imsi_det_eps() );
Harald Welte4263c522018-12-06 11:56:27 +01006151 execute( TC_sgsap_expl_imsi_det_noneps() );
Philipp Maier5d812702019-03-21 10:51:26 +01006152 execute( TC_sgsap_impl_imsi_det_noneps() );
Harald Welte4263c522018-12-06 11:56:27 +01006153 execute( TC_sgsap_paging_rej() );
6154 execute( TC_sgsap_paging_subscr_rej() );
6155 execute( TC_sgsap_paging_ue_unr() );
6156 execute( TC_sgsap_paging_and_nothing() );
6157 execute( TC_sgsap_paging_and_lu() );
6158 execute( TC_sgsap_mt_sms() );
6159 execute( TC_sgsap_mo_sms() );
6160 execute( TC_sgsap_mt_sms_and_nothing() );
6161 execute( TC_sgsap_mt_sms_and_reject() );
6162 execute( TC_sgsap_unexp_ud() );
6163 execute( TC_sgsap_unsol_ud() );
6164 execute( TC_bssap_lu_sgsap_lu_and_mt_call() );
6165 execute( TC_sgsap_lu_and_mt_call() );
Philipp Maier628c0052019-04-09 17:36:57 +02006166 execute( TC_sgsap_vlr_failure() );
Harald Welte4263c522018-12-06 11:56:27 +01006167
Neels Hofmeyr0ac63152019-05-07 01:20:17 +02006168 execute( TC_ho_inter_bsc_unknown_cell() );
6169 execute( TC_ho_inter_bsc() );
6170
6171 execute( TC_ho_inter_msc_out() );
6172
Oliver Smith1d118ff2019-07-03 10:57:35 +02006173 execute( TC_lu_imsi_auth_tmsi_check_imei() );
6174 execute( TC_lu_imsi_auth3g_tmsi_check_imei() );
6175 execute( TC_lu_imsi_noauth_tmsi_check_imei() );
6176 execute( TC_lu_imsi_noauth_notmsi_check_imei() );
6177 execute( TC_lu_imsi_auth_tmsi_check_imei_nack() );
6178 execute( TC_lu_imsi_auth_tmsi_check_imei_err() );
6179 execute( TC_lu_imsi_auth_tmsi_check_imei_early() );
6180 execute( TC_lu_imsi_auth3g_tmsi_check_imei_early() );
6181 execute( TC_lu_imsi_noauth_tmsi_check_imei_early() );
6182 execute( TC_lu_imsi_noauth_notmsi_check_imei_early() );
6183 execute( TC_lu_imsi_auth_tmsi_check_imei_early_nack() );
6184 execute( TC_lu_imsi_auth_tmsi_check_imei_early_err() );
6185
Neels Hofmeyr1b3c6e32018-03-01 17:52:21 +01006186 /* Run this last: at the time of writing this test crashes the MSC */
6187 execute( TC_lu_imsi_auth_tmsi_encr_3_1_log_msc_debug() );
Neels Hofmeyr692c9ee2018-04-10 02:07:13 +02006188 execute( TC_mo_cc_bssmap_clear() );
Pau Espin Pedrol690d6592019-05-31 17:56:32 +02006189 if (mp_enable_osmux_test) {
6190 execute( TC_lu_and_mt_call_osmux() );
6191 }
Neels Hofmeyr8df69622019-11-02 19:16:03 +01006192 execute( TC_invalid_mgcp_crash() );
Vadim Yanitskiyeddebaa2019-12-28 17:45:34 +01006193 execute( TC_mm_id_resp_no_identity() );
Vadim Yanitskiy25219062020-01-21 01:41:33 +07006194 execute( TC_lu_and_expire_while_paging() );
Harald Weltef6dd64d2017-11-19 12:09:51 +01006195}
6196
6197
6198}