bss.c 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606
  1. /*
  2. * BSS table
  3. * Copyright (c) 2009-2010, Jouni Malinen <j@w1.fi>
  4. *
  5. * This program is free software; you can redistribute it and/or modify
  6. * it under the terms of the GNU General Public License version 2 as
  7. * published by the Free Software Foundation.
  8. *
  9. * Alternatively, this software may be distributed under the terms of BSD
  10. * license.
  11. *
  12. * See README and COPYING for more details.
  13. */
  14. #include "utils/includes.h"
  15. #include "utils/common.h"
  16. #include "utils/eloop.h"
  17. #include "common/ieee802_11_defs.h"
  18. #include "drivers/driver.h"
  19. #include "wpa_supplicant_i.h"
  20. #include "config.h"
  21. #include "notify.h"
  22. #include "scan.h"
  23. #include "bss.h"
  24. /**
  25. * WPA_BSS_EXPIRATION_PERIOD - Period of expiration run in seconds
  26. */
  27. #define WPA_BSS_EXPIRATION_PERIOD 10
  28. /**
  29. * WPA_BSS_EXPIRATION_AGE - BSS entry age after which it can be expired
  30. *
  31. * This value control the time in seconds after which a BSS entry gets removed
  32. * if it has not been updated or is not in use.
  33. */
  34. #define WPA_BSS_EXPIRATION_AGE 180
  35. /**
  36. * WPA_BSS_EXPIRATION_SCAN_COUNT - Expire BSS after number of scans
  37. *
  38. * If the BSS entry has not been seen in this many scans, it will be removed.
  39. * Value 1 means that the entry is removed after the first scan without the
  40. * BSSID being seen. Larger values can be used to avoid BSS entries
  41. * disappearing if they are not visible in every scan (e.g., low signal quality
  42. * or interference).
  43. */
  44. #define WPA_BSS_EXPIRATION_SCAN_COUNT 2
  45. #define WPA_BSS_FREQ_CHANGED_FLAG BIT(0)
  46. #define WPA_BSS_SIGNAL_CHANGED_FLAG BIT(1)
  47. #define WPA_BSS_PRIVACY_CHANGED_FLAG BIT(2)
  48. #define WPA_BSS_MODE_CHANGED_FLAG BIT(3)
  49. #define WPA_BSS_WPAIE_CHANGED_FLAG BIT(4)
  50. #define WPA_BSS_RSNIE_CHANGED_FLAG BIT(5)
  51. #define WPA_BSS_WPS_CHANGED_FLAG BIT(6)
  52. #define WPA_BSS_RATES_CHANGED_FLAG BIT(7)
  53. #define WPA_BSS_IES_CHANGED_FLAG BIT(8)
  54. static void wpa_bss_remove(struct wpa_supplicant *wpa_s, struct wpa_bss *bss)
  55. {
  56. dl_list_del(&bss->list);
  57. dl_list_del(&bss->list_id);
  58. wpa_s->num_bss--;
  59. wpa_printf(MSG_DEBUG, "BSS: Remove id %u BSSID " MACSTR " SSID '%s'",
  60. bss->id, MAC2STR(bss->bssid),
  61. wpa_ssid_txt(bss->ssid, bss->ssid_len));
  62. wpas_notify_bss_removed(wpa_s, bss->bssid, bss->id);
  63. os_free(bss);
  64. }
  65. struct wpa_bss * wpa_bss_get(struct wpa_supplicant *wpa_s, const u8 *bssid,
  66. const u8 *ssid, size_t ssid_len)
  67. {
  68. struct wpa_bss *bss;
  69. dl_list_for_each(bss, &wpa_s->bss, struct wpa_bss, list) {
  70. if (os_memcmp(bss->bssid, bssid, ETH_ALEN) == 0 &&
  71. bss->ssid_len == ssid_len &&
  72. os_memcmp(bss->ssid, ssid, ssid_len) == 0)
  73. return bss;
  74. }
  75. return NULL;
  76. }
  77. static void wpa_bss_copy_res(struct wpa_bss *dst, struct wpa_scan_res *src)
  78. {
  79. os_time_t usec;
  80. dst->flags = src->flags;
  81. os_memcpy(dst->bssid, src->bssid, ETH_ALEN);
  82. dst->freq = src->freq;
  83. dst->beacon_int = src->beacon_int;
  84. dst->caps = src->caps;
  85. dst->qual = src->qual;
  86. dst->noise = src->noise;
  87. dst->level = src->level;
  88. dst->tsf = src->tsf;
  89. os_get_time(&dst->last_update);
  90. dst->last_update.sec -= src->age / 1000;
  91. usec = (src->age % 1000) * 1000;
  92. if (dst->last_update.usec < usec) {
  93. dst->last_update.sec--;
  94. dst->last_update.usec += 1000000;
  95. }
  96. dst->last_update.usec -= usec;
  97. }
  98. static void wpa_bss_add(struct wpa_supplicant *wpa_s,
  99. const u8 *ssid, size_t ssid_len,
  100. struct wpa_scan_res *res)
  101. {
  102. struct wpa_bss *bss;
  103. bss = os_zalloc(sizeof(*bss) + res->ie_len + res->beacon_ie_len);
  104. if (bss == NULL)
  105. return;
  106. bss->id = wpa_s->bss_next_id++;
  107. bss->last_update_idx = wpa_s->bss_update_idx;
  108. wpa_bss_copy_res(bss, res);
  109. os_memcpy(bss->ssid, ssid, ssid_len);
  110. bss->ssid_len = ssid_len;
  111. bss->ie_len = res->ie_len;
  112. bss->beacon_ie_len = res->beacon_ie_len;
  113. os_memcpy(bss + 1, res + 1, res->ie_len + res->beacon_ie_len);
  114. dl_list_add_tail(&wpa_s->bss, &bss->list);
  115. dl_list_add_tail(&wpa_s->bss_id, &bss->list_id);
  116. wpa_s->num_bss++;
  117. wpa_printf(MSG_DEBUG, "BSS: Add new id %u BSSID " MACSTR " SSID '%s'",
  118. bss->id, MAC2STR(bss->bssid), wpa_ssid_txt(ssid, ssid_len));
  119. wpas_notify_bss_added(wpa_s, bss->bssid, bss->id);
  120. if (wpa_s->num_bss > wpa_s->conf->bss_max_count) {
  121. /* Remove the oldest entry */
  122. wpa_bss_remove(wpa_s, dl_list_first(&wpa_s->bss,
  123. struct wpa_bss, list));
  124. }
  125. }
  126. static int are_ies_equal(const struct wpa_bss *old,
  127. const struct wpa_scan_res *new, u32 ie)
  128. {
  129. const u8 *old_ie, *new_ie;
  130. struct wpabuf *old_ie_buff = NULL;
  131. struct wpabuf *new_ie_buff = NULL;
  132. int new_ie_len, old_ie_len, ret, is_multi;
  133. switch (ie) {
  134. case WPA_IE_VENDOR_TYPE:
  135. old_ie = wpa_bss_get_vendor_ie(old, ie);
  136. new_ie = wpa_scan_get_vendor_ie(new, ie);
  137. is_multi = 0;
  138. break;
  139. case WPS_IE_VENDOR_TYPE:
  140. old_ie_buff = wpa_bss_get_vendor_ie_multi(old, ie);
  141. new_ie_buff = wpa_scan_get_vendor_ie_multi(new, ie);
  142. is_multi = 1;
  143. break;
  144. case WLAN_EID_RSN:
  145. case WLAN_EID_SUPP_RATES:
  146. case WLAN_EID_EXT_SUPP_RATES:
  147. old_ie = wpa_bss_get_ie(old, ie);
  148. new_ie = wpa_scan_get_ie(new, ie);
  149. is_multi = 0;
  150. break;
  151. default:
  152. wpa_printf(MSG_DEBUG, "bss: %s: cannot compare IEs", __func__);
  153. return 0;
  154. }
  155. if (is_multi) {
  156. /* in case of multiple IEs stored in buffer */
  157. old_ie = old_ie_buff ? wpabuf_head_u8(old_ie_buff) : NULL;
  158. new_ie = new_ie_buff ? wpabuf_head_u8(new_ie_buff) : NULL;
  159. old_ie_len = old_ie_buff ? wpabuf_len(old_ie_buff) : 0;
  160. new_ie_len = new_ie_buff ? wpabuf_len(new_ie_buff) : 0;
  161. } else {
  162. /* in case of single IE */
  163. old_ie_len = old_ie ? old_ie[1] + 2 : 0;
  164. new_ie_len = new_ie ? new_ie[1] + 2 : 0;
  165. }
  166. ret = (old_ie_len == new_ie_len &&
  167. os_memcmp(old_ie, new_ie, old_ie_len) == 0);
  168. wpabuf_free(old_ie_buff);
  169. wpabuf_free(new_ie_buff);
  170. return ret;
  171. }
  172. static u32 wpa_bss_compare_res(const struct wpa_bss *old,
  173. const struct wpa_scan_res *new)
  174. {
  175. u32 changes = 0;
  176. int caps_diff = old->caps ^ new->caps;
  177. if (old->freq != new->freq)
  178. changes |= WPA_BSS_FREQ_CHANGED_FLAG;
  179. if (old->level != new->level)
  180. changes |= WPA_BSS_SIGNAL_CHANGED_FLAG;
  181. if (caps_diff & IEEE80211_CAP_PRIVACY)
  182. changes |= WPA_BSS_PRIVACY_CHANGED_FLAG;
  183. if (caps_diff & IEEE80211_CAP_IBSS)
  184. changes |= WPA_BSS_MODE_CHANGED_FLAG;
  185. if (old->ie_len == new->ie_len &&
  186. os_memcmp(old + 1, new + 1, old->ie_len) == 0)
  187. return changes;
  188. changes |= WPA_BSS_IES_CHANGED_FLAG;
  189. if (!are_ies_equal(old, new, WPA_IE_VENDOR_TYPE))
  190. changes |= WPA_BSS_WPAIE_CHANGED_FLAG;
  191. if (!are_ies_equal(old, new, WLAN_EID_RSN))
  192. changes |= WPA_BSS_RSNIE_CHANGED_FLAG;
  193. if (!are_ies_equal(old, new, WPS_IE_VENDOR_TYPE))
  194. changes |= WPA_BSS_WPS_CHANGED_FLAG;
  195. if (!are_ies_equal(old, new, WLAN_EID_SUPP_RATES) ||
  196. !are_ies_equal(old, new, WLAN_EID_EXT_SUPP_RATES))
  197. changes |= WPA_BSS_RATES_CHANGED_FLAG;
  198. return changes;
  199. }
  200. static void notify_bss_changes(struct wpa_supplicant *wpa_s, u32 changes,
  201. const struct wpa_bss *bss)
  202. {
  203. if (changes & WPA_BSS_FREQ_CHANGED_FLAG)
  204. wpas_notify_bss_freq_changed(wpa_s, bss->id);
  205. if (changes & WPA_BSS_SIGNAL_CHANGED_FLAG)
  206. wpas_notify_bss_signal_changed(wpa_s, bss->id);
  207. if (changes & WPA_BSS_PRIVACY_CHANGED_FLAG)
  208. wpas_notify_bss_privacy_changed(wpa_s, bss->id);
  209. if (changes & WPA_BSS_MODE_CHANGED_FLAG)
  210. wpas_notify_bss_mode_changed(wpa_s, bss->id);
  211. if (changes & WPA_BSS_WPAIE_CHANGED_FLAG)
  212. wpas_notify_bss_wpaie_changed(wpa_s, bss->id);
  213. if (changes & WPA_BSS_RSNIE_CHANGED_FLAG)
  214. wpas_notify_bss_rsnie_changed(wpa_s, bss->id);
  215. if (changes & WPA_BSS_WPS_CHANGED_FLAG)
  216. wpas_notify_bss_wps_changed(wpa_s, bss->id);
  217. if (changes & WPA_BSS_IES_CHANGED_FLAG)
  218. wpas_notify_bss_ies_changed(wpa_s, bss->id);
  219. if (changes & WPA_BSS_RATES_CHANGED_FLAG)
  220. wpas_notify_bss_rates_changed(wpa_s, bss->id);
  221. }
  222. static void wpa_bss_update(struct wpa_supplicant *wpa_s, struct wpa_bss *bss,
  223. struct wpa_scan_res *res)
  224. {
  225. u32 changes;
  226. changes = wpa_bss_compare_res(bss, res);
  227. bss->scan_miss_count = 0;
  228. bss->last_update_idx = wpa_s->bss_update_idx;
  229. wpa_bss_copy_res(bss, res);
  230. /* Move the entry to the end of the list */
  231. dl_list_del(&bss->list);
  232. if (bss->ie_len + bss->beacon_ie_len >=
  233. res->ie_len + res->beacon_ie_len) {
  234. os_memcpy(bss + 1, res + 1, res->ie_len + res->beacon_ie_len);
  235. bss->ie_len = res->ie_len;
  236. bss->beacon_ie_len = res->beacon_ie_len;
  237. } else {
  238. struct wpa_bss *nbss;
  239. struct dl_list *prev = bss->list_id.prev;
  240. dl_list_del(&bss->list_id);
  241. nbss = os_realloc(bss, sizeof(*bss) + res->ie_len +
  242. res->beacon_ie_len);
  243. if (nbss) {
  244. bss = nbss;
  245. os_memcpy(bss + 1, res + 1,
  246. res->ie_len + res->beacon_ie_len);
  247. bss->ie_len = res->ie_len;
  248. bss->beacon_ie_len = res->beacon_ie_len;
  249. }
  250. dl_list_add(prev, &bss->list_id);
  251. }
  252. dl_list_add_tail(&wpa_s->bss, &bss->list);
  253. notify_bss_changes(wpa_s, changes, bss);
  254. }
  255. static int wpa_bss_in_use(struct wpa_supplicant *wpa_s, struct wpa_bss *bss)
  256. {
  257. return bss == wpa_s->current_bss ||
  258. os_memcmp(bss->bssid, wpa_s->bssid, ETH_ALEN) == 0 ||
  259. os_memcmp(bss->bssid, wpa_s->pending_bssid, ETH_ALEN) == 0;
  260. }
  261. void wpa_bss_update_start(struct wpa_supplicant *wpa_s)
  262. {
  263. wpa_s->bss_update_idx++;
  264. wpa_printf(MSG_DEBUG, "BSS: Start scan result update %u",
  265. wpa_s->bss_update_idx);
  266. }
  267. void wpa_bss_update_scan_res(struct wpa_supplicant *wpa_s,
  268. struct wpa_scan_res *res)
  269. {
  270. const u8 *ssid;
  271. struct wpa_bss *bss;
  272. ssid = wpa_scan_get_ie(res, WLAN_EID_SSID);
  273. if (ssid == NULL) {
  274. wpa_printf(MSG_DEBUG, "BSS: No SSID IE included for " MACSTR,
  275. MAC2STR(res->bssid));
  276. return;
  277. }
  278. if (ssid[1] > 32) {
  279. wpa_printf(MSG_DEBUG, "BSS: Too long SSID IE included for "
  280. MACSTR, MAC2STR(res->bssid));
  281. return;
  282. }
  283. /* TODO: add option for ignoring BSSes we are not interested in
  284. * (to save memory) */
  285. bss = wpa_bss_get(wpa_s, res->bssid, ssid + 2, ssid[1]);
  286. if (bss == NULL)
  287. wpa_bss_add(wpa_s, ssid + 2, ssid[1], res);
  288. else
  289. wpa_bss_update(wpa_s, bss, res);
  290. }
  291. static int wpa_bss_included_in_scan(const struct wpa_bss *bss,
  292. const struct scan_info *info)
  293. {
  294. int found;
  295. size_t i;
  296. if (info == NULL)
  297. return 1;
  298. if (info->num_freqs) {
  299. found = 0;
  300. for (i = 0; i < info->num_freqs; i++) {
  301. if (bss->freq == info->freqs[i]) {
  302. found = 1;
  303. break;
  304. }
  305. }
  306. if (!found)
  307. return 0;
  308. }
  309. if (info->num_ssids) {
  310. found = 0;
  311. for (i = 0; i < info->num_ssids; i++) {
  312. const struct wpa_driver_scan_ssid *s = &info->ssids[i];
  313. if ((s->ssid == NULL || s->ssid_len == 0) ||
  314. (s->ssid_len == bss->ssid_len &&
  315. os_memcmp(s->ssid, bss->ssid, bss->ssid_len) ==
  316. 0)) {
  317. found = 1;
  318. break;
  319. }
  320. }
  321. if (!found)
  322. return 0;
  323. }
  324. return 1;
  325. }
  326. void wpa_bss_update_end(struct wpa_supplicant *wpa_s, struct scan_info *info,
  327. int new_scan)
  328. {
  329. struct wpa_bss *bss, *n;
  330. if (!new_scan)
  331. return; /* do not expire entries without new scan */
  332. dl_list_for_each_safe(bss, n, &wpa_s->bss, struct wpa_bss, list) {
  333. if (wpa_bss_in_use(wpa_s, bss))
  334. continue;
  335. if (!wpa_bss_included_in_scan(bss, info))
  336. continue; /* expire only BSSes that were scanned */
  337. if (bss->last_update_idx < wpa_s->bss_update_idx)
  338. bss->scan_miss_count++;
  339. if (bss->scan_miss_count >= WPA_BSS_EXPIRATION_SCAN_COUNT) {
  340. wpa_printf(MSG_DEBUG, "BSS: Expire BSS %u due to no "
  341. "match in scan", bss->id);
  342. wpa_bss_remove(wpa_s, bss);
  343. }
  344. }
  345. }
  346. static void wpa_bss_timeout(void *eloop_ctx, void *timeout_ctx)
  347. {
  348. struct wpa_supplicant *wpa_s = eloop_ctx;
  349. struct wpa_bss *bss, *n;
  350. struct os_time t;
  351. if (dl_list_empty(&wpa_s->bss))
  352. return;
  353. os_get_time(&t);
  354. t.sec -= WPA_BSS_EXPIRATION_AGE;
  355. dl_list_for_each_safe(bss, n, &wpa_s->bss, struct wpa_bss, list) {
  356. if (wpa_bss_in_use(wpa_s, bss))
  357. continue;
  358. if (os_time_before(&bss->last_update, &t)) {
  359. wpa_printf(MSG_DEBUG, "BSS: Expire BSS %u due to age",
  360. bss->id);
  361. wpa_bss_remove(wpa_s, bss);
  362. } else
  363. break;
  364. }
  365. eloop_register_timeout(WPA_BSS_EXPIRATION_PERIOD, 0,
  366. wpa_bss_timeout, wpa_s, NULL);
  367. }
  368. int wpa_bss_init(struct wpa_supplicant *wpa_s)
  369. {
  370. dl_list_init(&wpa_s->bss);
  371. dl_list_init(&wpa_s->bss_id);
  372. eloop_register_timeout(WPA_BSS_EXPIRATION_PERIOD, 0,
  373. wpa_bss_timeout, wpa_s, NULL);
  374. return 0;
  375. }
  376. void wpa_bss_deinit(struct wpa_supplicant *wpa_s)
  377. {
  378. struct wpa_bss *bss, *n;
  379. eloop_cancel_timeout(wpa_bss_timeout, wpa_s, NULL);
  380. if (wpa_s->bss.next == NULL)
  381. return; /* BSS table not yet initialized */
  382. dl_list_for_each_safe(bss, n, &wpa_s->bss, struct wpa_bss, list)
  383. wpa_bss_remove(wpa_s, bss);
  384. }
  385. struct wpa_bss * wpa_bss_get_bssid(struct wpa_supplicant *wpa_s,
  386. const u8 *bssid)
  387. {
  388. struct wpa_bss *bss;
  389. dl_list_for_each(bss, &wpa_s->bss, struct wpa_bss, list) {
  390. if (os_memcmp(bss->bssid, bssid, ETH_ALEN) == 0)
  391. return bss;
  392. }
  393. return NULL;
  394. }
  395. struct wpa_bss * wpa_bss_get_id(struct wpa_supplicant *wpa_s, unsigned int id)
  396. {
  397. struct wpa_bss *bss;
  398. dl_list_for_each(bss, &wpa_s->bss, struct wpa_bss, list) {
  399. if (bss->id == id)
  400. return bss;
  401. }
  402. return NULL;
  403. }
  404. const u8 * wpa_bss_get_ie(const struct wpa_bss *bss, u8 ie)
  405. {
  406. const u8 *end, *pos;
  407. pos = (const u8 *) (bss + 1);
  408. end = pos + bss->ie_len;
  409. while (pos + 1 < end) {
  410. if (pos + 2 + pos[1] > end)
  411. break;
  412. if (pos[0] == ie)
  413. return pos;
  414. pos += 2 + pos[1];
  415. }
  416. return NULL;
  417. }
  418. const u8 * wpa_bss_get_vendor_ie(const struct wpa_bss *bss, u32 vendor_type)
  419. {
  420. const u8 *end, *pos;
  421. pos = (const u8 *) (bss + 1);
  422. end = pos + bss->ie_len;
  423. while (pos + 1 < end) {
  424. if (pos + 2 + pos[1] > end)
  425. break;
  426. if (pos[0] == WLAN_EID_VENDOR_SPECIFIC && pos[1] >= 4 &&
  427. vendor_type == WPA_GET_BE32(&pos[2]))
  428. return pos;
  429. pos += 2 + pos[1];
  430. }
  431. return NULL;
  432. }
  433. struct wpabuf * wpa_bss_get_vendor_ie_multi(const struct wpa_bss *bss,
  434. u32 vendor_type)
  435. {
  436. struct wpabuf *buf;
  437. const u8 *end, *pos;
  438. buf = wpabuf_alloc(bss->ie_len);
  439. if (buf == NULL)
  440. return NULL;
  441. pos = (const u8 *) (bss + 1);
  442. end = pos + bss->ie_len;
  443. while (pos + 1 < end) {
  444. if (pos + 2 + pos[1] > end)
  445. break;
  446. if (pos[0] == WLAN_EID_VENDOR_SPECIFIC && pos[1] >= 4 &&
  447. vendor_type == WPA_GET_BE32(&pos[2]))
  448. wpabuf_put_data(buf, pos + 2 + 4, pos[1] - 4);
  449. pos += 2 + pos[1];
  450. }
  451. if (wpabuf_len(buf) == 0) {
  452. wpabuf_free(buf);
  453. buf = NULL;
  454. }
  455. return buf;
  456. }
  457. int wpa_bss_get_max_rate(const struct wpa_bss *bss)
  458. {
  459. int rate = 0;
  460. const u8 *ie;
  461. int i;
  462. ie = wpa_bss_get_ie(bss, WLAN_EID_SUPP_RATES);
  463. for (i = 0; ie && i < ie[1]; i++) {
  464. if ((ie[i + 2] & 0x7f) > rate)
  465. rate = ie[i + 2] & 0x7f;
  466. }
  467. ie = wpa_bss_get_ie(bss, WLAN_EID_EXT_SUPP_RATES);
  468. for (i = 0; ie && i < ie[1]; i++) {
  469. if ((ie[i + 2] & 0x7f) > rate)
  470. rate = ie[i + 2] & 0x7f;
  471. }
  472. return rate;
  473. }
  474. int wpa_bss_get_bit_rates(const struct wpa_bss *bss, u8 **rates)
  475. {
  476. const u8 *ie, *ie2;
  477. int i, j;
  478. unsigned int len;
  479. u8 *r;
  480. ie = wpa_bss_get_ie(bss, WLAN_EID_SUPP_RATES);
  481. ie2 = wpa_bss_get_ie(bss, WLAN_EID_EXT_SUPP_RATES);
  482. len = (ie ? ie[1] : 0) + (ie2 ? ie2[1] : 0);
  483. r = os_malloc(len);
  484. if (!r)
  485. return -1;
  486. for (i = 0; ie && i < ie[1]; i++)
  487. r[i] = ie[i + 2] & 0x7f;
  488. for (j = 0; ie2 && j < ie2[1]; j++)
  489. r[i + j] = ie2[j + 2] & 0x7f;
  490. *rates = r;
  491. return len;
  492. }