net: align the EPSLOCI dummy with the corrected trace study (v2.7.2)
The UICC_NAA.md C3/C3a recipes were re-checked against the corpus: the EPSLOCI dummy tail is FF*13 + `FF FE` + status - the TAC is always FFFE (never FF) and the status byte is 01 (not updated), not FF; the old `<FF*16>` reading was a misparse of that tail. The rejection form (status 02) is the C3a spec model: the only observed rejection trace never writes 6FE3 at all. - build_epsloci_dummy(status=ST_NOT_UPDATED, keep_plmn=None): corrected tail; keep_plmn selects the NMR style that preserves the last visited TAI PLMN (the guest style wipes GUTI and TAI PLMN) - both are observed - write_dummy_locations(): drop the all-FF special case (service loss now ends `FF FE 01`) and thread keep_plmn through - tests: exact guest/NMR/rejection vectors, 18-byte length, runner assertions for service_lost and roaming_denied; netstate fixture updated - UICC_NAA.md C3a tail `<FF*15> 02` corrected to `<FF*13> FF FE 02`; the PWA help/param text no longer claims the EPSLOCI dummy keeps the PLMN; SW cache simple-v205
This commit is contained in:
+1
-1
@@ -483,7 +483,7 @@
|
||||
<ul class="list-disc list-inside text-sm space-y-1 mb-3">
|
||||
<li><strong>Cold boot</strong> — invalidate EPSNSC (KSI 07, key wiped) and dummy the location files.</li>
|
||||
<li><strong>EPS attach / 2G attach</strong> — store a real EPS NAS context (KSI, KASME, NAS counts, algorithm) and write real LOCI/PSLOCI/EPSLOCI (2G also writes real Kc/KcGPRS).</li>
|
||||
<li><strong>Service lost / Limited service / Roaming denied</strong> — send the Location status event (only when the card subscribed to it), invalidate EPSNSC (optionally keeping the old KASME), dummy the location files (PLMN kept, LAC <code class="font-mono text-sm">FFFE</code>, status <code class="font-mono text-sm">01</code>) and invalidate Kc. <strong>Roaming denied</strong> emulates a permanent “PLMN not allowed” rejection (NAS cause #11): the location files carry status <code class="font-mono text-sm">010</code> (EPSLOCI wiped to <code class="font-mono text-sm">0B F6</code> + status), the denied VPLMN is appended to <strong>EF.FPLMN</strong> with the shift-list semantics of TS 31.102 §4.2.16 (never the home PLMN) and the key context is dropped.</li>
|
||||
<li><strong>Service lost / Limited service / Roaming denied</strong> — send the Location status event (only when the card subscribed to it), invalidate EPSNSC (optionally keeping the old KASME), dummy the location files (the LOCI/PSLOCI keep the PLMN, LAC <code class="font-mono text-sm">FFFE</code>, status <code class="font-mono text-sm">01</code>; EPSLOCI is wiped to <code class="font-mono text-sm">0B F6</code> + FF×13 + <code class="font-mono text-sm">FF FE 01</code>) and invalidate Kc. <strong>Roaming denied</strong> emulates a permanent “PLMN not allowed” rejection (NAS cause #11): the location files carry status <code class="font-mono text-sm">010</code> (EPSLOCI <code class="font-mono text-sm">0B F6</code> + FF×13 + <code class="font-mono text-sm">FF FE 02</code>), the denied VPLMN is appended to <strong>EF.FPLMN</strong> with the shift-list semantics of TS 31.102 §4.2.16 (never the home PLMN) and the key context is dropped.</li>
|
||||
<li><strong>Churn</strong> — replay real → invalid EPSNSC records back-to-back (count and delay configurable).</li>
|
||||
<li><strong>SMS received</strong> — bump the EF.SMSstatus counter (read-modify-write) and optionally rewrite the location files.</li>
|
||||
<li><strong>CB reconfig</strong> — write the CBMI/CBMIR message-ID lists or clear them (all FF).</li>
|
||||
|
||||
Reference in New Issue
Block a user