Don't send a for ServerKeyExchange for kDHr and kDHd
[openssl.git] / Configure
1 :
2 eval 'exec perl -S $0 ${1+"$@"}'
3     if $running_under_some_shell;
4 ##
5 ##  Configure -- OpenSSL source tree configuration script
6 ##  If editing this file, run this command before committing
7 ##      make -f Makefile.org TABLE
8 ##
9
10 require 5.000;
11 use strict;
12 use File::Basename;
13 use File::Spec::Functions;
14
15 # see INSTALL for instructions.
16
17 my $usage="Usage: Configure [no-<cipher> ...] [enable-<cipher> ...] [experimental-<cipher> ...] [-Dxxx] [-lxxx] [-Lxxx] [-fxxx] [-Kxxx] [no-hw-xxx|no-hw] [[no-]threads] [[no-]shared] [[no-]zlib|zlib-dynamic] [no-asm] [no-dso] [no-krb5] [sctp] [386] [--prefix=DIR] [--openssldir=OPENSSLDIR] [--with-xxx[=vvv]] [--test-sanity] [--config=FILE] os/compiler[:flags]\n";
18
19 # Options:
20 #
21 # --config      add the given configuration file, which will be read after
22 #               any "Configurations*" files that are found in the same
23 #               directory as this script.
24 # --openssldir  install OpenSSL in OPENSSLDIR (Default: DIR/ssl if the
25 #               --prefix option is given; /usr/local/ssl otherwise)
26 # --prefix      prefix for the OpenSSL include, lib and bin directories
27 #               (Default: the OPENSSLDIR directory)
28 #
29 # --install_prefix  Additional prefix for package builders (empty by
30 #               default).  This needn't be set in advance, you can
31 #               just as well use "make INSTALL_PREFIX=/whatever install".
32 #
33 # --with-krb5-dir  Declare where Kerberos 5 lives.  The libraries are expected
34 #               to live in the subdirectory lib/ and the header files in
35 #               include/.  A value is required.
36 # --with-krb5-lib  Declare where the Kerberos 5 libraries live.  A value is
37 #               required.
38 #               (Default: KRB5_DIR/lib)
39 # --with-krb5-include  Declare where the Kerberos 5 header files live.  A
40 #               value is required.
41 #               (Default: KRB5_DIR/include)
42 # --with-krb5-flavor  Declare what flavor of Kerberos 5 is used.  Currently
43 #               supported values are "MIT" and "Heimdal".  A value is required.
44 #
45 # --test-sanity Make a number of sanity checks on the data in this file.
46 #               This is a debugging tool for OpenSSL developers.
47 #
48 # --cross-compile-prefix Add specified prefix to binutils components.
49 #
50 # no-hw-xxx     do not compile support for specific crypto hardware.
51 #               Generic OpenSSL-style methods relating to this support
52 #               are always compiled but return NULL if the hardware
53 #               support isn't compiled.
54 # no-hw         do not compile support for any crypto hardware.
55 # [no-]threads  [don't] try to create a library that is suitable for
56 #               multithreaded applications (default is "threads" if we
57 #               know how to do it)
58 # [no-]shared   [don't] try to create shared libraries when supported.
59 # no-asm        do not use assembler
60 # no-dso        do not compile in any native shared-library methods. This
61 #               will ensure that all methods just return NULL.
62 # no-krb5       do not compile in any KRB5 library or code.
63 # [no-]zlib     [don't] compile support for zlib compression.
64 # zlib-dynamic  Like "zlib", but the zlib library is expected to be a shared
65 #               library and will be loaded in run-time by the OpenSSL library.
66 # sctp          include SCTP support
67 # 386           generate 80386 code
68 # no-sse2       disables IA-32 SSE2 code, above option implies no-sse2
69 # no-<cipher>   build without specified algorithm (rsa, idea, rc5, ...)
70 # -<xxx> +<xxx> compiler options are passed through
71 #
72 # DEBUG_SAFESTACK use type-safe stacks to enforce type-safety on stack items
73 #               provided to stack calls. Generates unique stack functions for
74 #               each possible stack type.
75 # DES_PTR       use pointer lookup vs arrays in the DES in crypto/des/des_locl.h
76 # DES_RISC1     use different DES_ENCRYPT macro that helps reduce register
77 #               dependancies but needs to more registers, good for RISC CPU's
78 # DES_RISC2     A different RISC variant.
79 # DES_UNROLL    unroll the inner DES loop, sometimes helps, somtimes hinders.
80 # DES_INT       use 'int' instead of 'long' for DES_LONG in crypto/des/des.h
81 #               This is used on the DEC Alpha where long is 8 bytes
82 #               and int is 4
83 # BN_LLONG      use the type 'long long' in crypto/bn/bn.h
84 # MD2_CHAR      use 'char' instead of 'int' for MD2_INT in crypto/md2/md2.h
85 # MD2_LONG      use 'long' instead of 'int' for MD2_INT in crypto/md2/md2.h
86 # IDEA_SHORT    use 'short' instead of 'int' for IDEA_INT in crypto/idea/idea.h
87 # IDEA_LONG     use 'long' instead of 'int' for IDEA_INT in crypto/idea/idea.h
88 # RC2_SHORT     use 'short' instead of 'int' for RC2_INT in crypto/rc2/rc2.h
89 # RC2_LONG      use 'long' instead of 'int' for RC2_INT in crypto/rc2/rc2.h
90 # RC4_CHAR      use 'char' instead of 'int' for RC4_INT in crypto/rc4/rc4.h
91 # RC4_LONG      use 'long' instead of 'int' for RC4_INT in crypto/rc4/rc4.h
92 # RC4_INDEX     define RC4_INDEX in crypto/rc4/rc4_locl.h.  This turns on
93 #               array lookups instead of pointer use.
94 # RC4_CHUNK     enables code that handles data aligned at long (natural CPU
95 #               word) boundary.
96 # RC4_CHUNK_LL  enables code that handles data aligned at long long boundary
97 #               (intended for 64-bit CPUs running 32-bit OS).
98 # BF_PTR        use 'pointer arithmatic' for Blowfish (unsafe on Alpha).
99 # BF_PTR2       intel specific version (generic version is more efficient).
100 #
101 # Following are set automatically by this script
102 #
103 # MD5_ASM       use some extra md5 assember,
104 # SHA1_ASM      use some extra sha1 assember, must define L_ENDIAN for x86
105 # RMD160_ASM    use some extra ripemd160 assember,
106 # SHA256_ASM    sha256_block is implemented in assembler
107 # SHA512_ASM    sha512_block is implemented in assembler
108 # AES_ASM       ASE_[en|de]crypt is implemented in assembler
109
110 # Minimum warning options... any contributions to OpenSSL should at least get
111 # past these.
112
113 my $gcc_devteam_warn = "-Wall -pedantic -DPEDANTIC -Wno-long-long -Wsign-compare -Wmissing-prototypes -Wshadow -Wformat -Werror -DCRYPTO_MDEBUG_ALL -DCRYPTO_MDEBUG_ABORT -DREF_CHECK -DDEBUG_UNUSED";
114
115 my $clang_disabled_warnings = "-Wno-language-extension-token -Wno-extended-offsetof -Wno-padded -Wno-shorten-64-to-32 -Wno-format-nonliteral -Wno-missing-noreturn -Wno-unused-parameter -Wno-sign-conversion -Wno-unreachable-code -Wno-conversion -Wno-documentation -Wno-missing-variable-declarations -Wno-cast-align -Wno-incompatible-pointer-types-discards-qualifiers -Wno-missing-variable-declarations -Wno-missing-field-initializers -Wno-unused-macros -Wno-disabled-macro-expansion -Wno-conditional-uninitialized -Wno-switch-enum";
116
117 my $strict_warnings = 0;
118
119 my $x86_gcc_des="DES_PTR DES_RISC1 DES_UNROLL";
120
121 # MD2_CHAR slags pentium pros
122 my $x86_gcc_opts="RC4_INDEX MD2_INT";
123
124 # MODIFY THESE PARAMETERS IF YOU ARE GOING TO USE THE 'util/speed.sh SCRIPT
125 # Don't worry about these normally
126
127 my $tcc="cc";
128 my $tflags="-fast -Xa";
129 my $tbn_mul="";
130 my $tlib="-lnsl -lsocket";
131 #$bits1="SIXTEEN_BIT ";
132 #$bits2="THIRTY_TWO_BIT ";
133 my $bits1="THIRTY_TWO_BIT ";
134 my $bits2="SIXTY_FOUR_BIT ";
135
136 my $x86_asm="x86cpuid.o:bn-586.o co-586.o x86-mont.o x86-gf2m.o:ecp_nistz256.o ecp_nistz256-x86.o:des-586.o crypt586.o:aes-586.o vpaes-x86.o aesni-x86.o:bf-586.o:md5-586.o:sha1-586.o sha256-586.o sha512-586.o:cast-586.o:rc4-586.o:rmd-586.o:rc5-586.o:wp_block.o wp-mmx.o:cmll-x86.o:ghash-x86.o:e_padlock-x86.o";
137 my $x86_asm_nocast=$x86_asm;$x86_asm_nocast=~s/cast\-586\.o//;
138
139 my $x86_elf_asm="$x86_asm:elf";
140 my $android_x86_elf_asm="$x86_asm:android";
141
142 my $x86_64_asm="x86_64cpuid.o:x86_64-gcc.o x86_64-mont.o x86_64-mont5.o x86_64-gf2m.o rsaz_exp.o rsaz-x86_64.o rsaz-avx2.o:ecp_nistz256.o ecp_nistz256-x86_64.o::aes-x86_64.o vpaes-x86_64.o bsaes-x86_64.o aesni-x86_64.o aesni-sha1-x86_64.o aesni-sha256-x86_64.o aesni-mb-x86_64.o::md5-x86_64.o:sha1-x86_64.o sha256-x86_64.o sha512-x86_64.o sha1-mb-x86_64.o sha256-mb-x86_64.o::rc4-x86_64.o rc4-md5-x86_64.o:::wp-x86_64.o:cmll-x86_64.o cmll_misc.o:ghash-x86_64.o aesni-gcm-x86_64.o:e_padlock-x86_64.o";
143 my $win_x86_64_asm=$x86_asm;$win_x86_64_asm=~s/x86_64-gcc\.o/bn_asm.o/;
144 my $ia64_asm="ia64cpuid.o:bn-ia64.o ia64-mont.o:::aes_core.o aes_cbc.o aes-ia64.o::md5-ia64.o:sha1-ia64.o sha256-ia64.o sha512-ia64.o::rc4-ia64.o rc4_skey.o:::::ghash-ia64.o::void";
145 my $sparcv9_asm="sparcv9cap.o sparccpuid.o:bn-sparcv9.o sparcv9-mont.o sparcv9a-mont.o vis3-mont.o sparct4-mont.o sparcv9-gf2m.o::des_enc-sparc.o fcrypt_b.o dest4-sparcv9.o:aes_core.o aes_cbc.o aes-sparcv9.o aest4-sparcv9.o::md5-sparcv9.o:sha1-sparcv9.o sha256-sparcv9.o sha512-sparcv9.o::::::camellia.o cmll_misc.o cmll_cbc.o cmllt4-sparcv9.o:ghash-sparcv9.o::void";
146 my $sparcv8_asm=":sparcv8.o::des_enc-sparc.o fcrypt_b.o:::::::::::::void";
147 my $alpha_asm="alphacpuid.o:bn_asm.o alpha-mont.o::::::sha1-alpha.o:::::::ghash-alpha.o::void";
148 my $mips64_asm=":bn-mips.o mips-mont.o:::aes_cbc.o aes-mips.o:::sha1-mips.o sha256-mips.o sha512-mips.o::::::::";
149 my $mips32_asm=$mips64_asm; $mips32_asm =~ s/\s*sha512\-mips\.o//;
150 my $s390x_asm="s390xcap.o s390xcpuid.o:bn-s390x.o s390x-mont.o s390x-gf2m.o:::aes-s390x.o aes-ctr.o aes-xts.o:::sha1-s390x.o sha256-s390x.o sha512-s390x.o::rc4-s390x.o:::::ghash-s390x.o:";
151 my $s390x_32_asm=$s390x_asm;$s390x_32_asm=~s/bn\-s390x\.o/bn_asm.o/;
152 my $armv4_asm="armcap.o armv4cpuid.o:bn_asm.o armv4-mont.o armv4-gf2m.o:ecp_nistz256.o ecp_nistz256-armv4.o::aes_cbc.o aes-armv4.o bsaes-armv7.o aesv8-armx.o:::sha1-armv4-large.o sha256-armv4.o sha512-armv4.o:::::::ghash-armv4.o ghashv8-armx.o::void";
153 my $aarch64_asm="armcap.o arm64cpuid.o mem_clr.o::::aes_core.o aes_cbc.o aesv8-armx.o:::sha1-armv8.o sha256-armv8.o sha512-armv8.o:::::::ghashv8-armx.o:";
154 my $parisc11_asm="pariscid.o:bn_asm.o parisc-mont.o:::aes_core.o aes_cbc.o aes-parisc.o:::sha1-parisc.o sha256-parisc.o sha512-parisc.o::rc4-parisc.o:::::ghash-parisc.o::32";
155 my $parisc20_64_asm="pariscid.o:pa-risc2W.o parisc-mont.o:::aes_core.o aes_cbc.o aes-parisc.o:::sha1-parisc.o sha256-parisc.o sha512-parisc.o::rc4-parisc.o:::::ghash-parisc.o::64";
156 my $parisc20_32_asm=$parisc20_64_asm;$parisc20_32_asm=~s/2W\./2\./;$parisc20_32_asm=~s/:64/:32/;
157 my $ppc64_asm="ppccpuid.o ppccap.o:bn-ppc.o ppc-mont.o ppc64-mont.o:::aes_core.o aes_cbc.o aes-ppc.o vpaes-ppc.o aesp8-ppc.o:::sha1-ppc.o sha256-ppc.o sha512-ppc.o sha256p8-ppc.o sha512p8-ppc.o:::::::ghashp8-ppc.o:";
158 my $ppc32_asm=$ppc64_asm;
159
160 # As for $BSDthreads. Idea is to maintain "collective" set of flags,
161 # which would cover all BSD flavors. -pthread applies to them all,
162 # but is treated differently. OpenBSD expands is as -D_POSIX_THREAD
163 # -lc_r, which is sufficient. FreeBSD 4.x expands it as -lc_r,
164 # which has to be accompanied by explicit -D_THREAD_SAFE and
165 # sometimes -D_REENTRANT. FreeBSD 5.x expands it as -lc_r, which
166 # seems to be sufficient?
167 my $BSDthreads="-pthread -D_THREAD_SAFE -D_REENTRANT";
168
169 # table of known configurations, read in from files
170 #
171 # The content of each entry can take one of two forms:
172 #
173 # - old style config-string, colon seperated fields with exactly the
174 #   following structure.:
175 #
176 #       $cc : $cflags : $unistd : $thread_cflag : $sys_id : $lflags : $bn_ops : $cpuid_obj : $bn_obj : $ec_obj : $des_obj : $aes_obj : $bf_obj : $md5_obj : $sha1_obj : $cast_obj : $rc4_obj : $rmd160_obj : $rc5_obj : $wp_obj : $cmll_obj : $modes_obj : $engines_obj : $perlasm_scheme : $dso_scheme : $shared_target : $shared_cflag : $shared_ldflag : $shared_extension : $ranlib : $arflags : $multilib
177 #
178 #   We use the stringtohash function - defined below - to combine with the
179 #   fields and form a proper hash table from the string.
180 #
181 # - direct transfer of old style config string to hash table, using the names
182 #   of the fields as keys:
183 #
184 #       {
185 #         cc => $cc,
186 #         cflags => $cflags,
187 #         unistd => $unistd,
188 #         thread_cflag => $thread_cflag,
189 #         sys_id => $sys_id,
190 #         lflags => $lflags,
191 #         bn_ops => $bn_ops,
192 #         cpuid_obj => $cpuid_obj,
193 #         bn_obj => $bn_obj,
194 #         ec_obj => $ec_obj,
195 #         des_obj => $des_obj,
196 #         aes_obj => $aes_obj,
197 #         bf_obj => $bf_obj,
198 #         md5_obj => $md5_obj,
199 #         sha1_obj => $sha1_obj,
200 #         cast_obj => $cast_obj,
201 #         rc4_obj => $rc4_obj,
202 #         rmd160_obj => $rmd160_obj,
203 #         rc5_obj => $rc5_obj,
204 #         wp_obj => $wp_obj,
205 #         cmll_obj => $cmll_obj,
206 #         modes_obj => $modes_obj,
207 #         engines_obj => $engines_obj,
208 #         perlasm_scheme => $perlasm_scheme,
209 #         dso_scheme => $dso_scheme,
210 #         shared_target => $shared_target,
211 #         shared_cflag => $shared_cflag,
212 #         shared_ldflag => $shared_ldflag,
213 #         shared_extension => $shared_extension,
214 #         ranlib => $ranlib,
215 #         arflags => $arflags,
216 #         multilib => $multilib
217 #       }
218 #
219 # - new style config hash table, which has additional attributes for debug
220 #   and non-debug flags to be added to the common flags, for cflags and lflags:
221 #
222 #       {
223 #         cc => $cc,
224 #         cflags => $cflags,
225 #         debug_cflags => $debug_cflags,
226 #         release_cflags => $release_cflags,
227 #         unistd => $unistd,
228 #         thread_cflag => $thread_cflag,
229 #         sys_id => $sys_id,
230 #         lflags => $lflags,
231 #         debug_lflags => $debug_lflags,
232 #         release_lflags => $release_lflags,
233 #         bn_ops => $bn_ops,
234 #         cpuid_obj => $cpuid_obj,
235 #         bn_obj => $bn_obj,
236 #         ec_obj => $ec_obj,
237 #         des_obj => $des_obj,
238 #         aes_obj => $aes_obj,
239 #         bf_obj => $bf_obj,
240 #         md5_obj => $md5_obj,
241 #         sha1_obj => $sha1_obj,
242 #         cast_obj => $cast_obj,
243 #         rc4_obj => $rc4_obj,
244 #         rmd160_obj => $rmd160_obj,
245 #         rc5_obj => $rc5_obj,
246 #         wp_obj => $wp_obj,
247 #         cmll_obj => $cmll_obj,
248 #         modes_obj => $modes_obj,
249 #         engines_obj => $engines_obj,
250 #         dso_scheme => $dso_scheme,
251 #         shared_target => $shared_target,
252 #         shared_cflag => $shared_cflag,
253 #         shared_ldflag => $shared_ldflag,
254 #         shared_extension => $shared_extension,
255 #         ranlib => $ranlib,
256 #         arflags => $arflags,
257 #         multilib => $multilib
258 #       }
259 #
260 # The configuration reader will do what it can to translate everything into
261 # new style config hash tables, including merging $target and debug-$target
262 # if they are similar enough.
263 #
264 # The configuration hashes can refer to templates in two different manners:
265 #
266 # - as part of the hash, one can have a key called 'inherit_from' that
267 #   indicate what other configuration hashes to inherit data from.
268 #   These are resolved recursively.
269 #
270 #   Inheritance works as a set of default values that can be overriden
271 #   by corresponding attribute values in the inheriting configuration.
272 #
273 #   If several configurations are given in the 'inherit_from' array, the
274 #   values of same attribute are concatenated with space separation.
275 #   With this, it's possible to have several smaller templates for
276 #   different configuration aspects that can be combined into a complete
277 #   configuration.
278 #
279 #   Example:
280 #
281 #       "foo" => {
282 #               template => 1,
283 #               haha => "haha",
284 #               hoho => "ho"
285 #       },
286 #       "bar" => {
287 #               template => 1,
288 #               hoho => "ho",
289 #               hehe => "hehe"
290 #       },
291 #       "laughter" => {
292 #               inherit_from => [ "foo", "bar" ],
293 #       }
294 #
295 #       The entry for "foo" will become as follows after processing:
296 #
297 #       "laughter" => {
298 #               haha => "haha",
299 #               hoho => "ho ho",
300 #               hehe => "hehe"
301 #       }
302 #
303 #   Note 1: any entry from the table can be used as a template.
304 #   Note 2: pure templates have the attribute 'template => 1' and cannot
305 #           be used as targets.
306 #
307 # - instead of a string, one can have a code block of the form
308 #   'sub { /* your code here */ }', where the arguments are the list of
309 #   inherited values for that key.  In fact, the concatenation of strings
310 #   is really done by using 'sub { join(" ",@_) }' on the list of inherited
311 #   values.
312 #
313 #   Example:
314 #
315 #       "foo" => {
316 #               template => 1,
317 #               haha => "ha ha",
318 #               hoho => "ho",
319 #               ignored => "This should not appear in the end result",
320 #       },
321 #       "bar" => {
322 #               template => 1,
323 #               haha => "ah",
324 #               hoho => "haho",
325 #               hehe => "hehe"
326 #       },
327 #       "laughter" => {
328 #               inherit_from => [ "foo", "bar" ],
329 #               hehe => sub { join(" ",(@_,"!!!")) },
330 #               ignored => "",
331 #       }
332 #
333 #       The entry for "foo" will become as follows after processing:
334 #
335 #       "laughter" => {
336 #               haha => "ha ha ah",
337 #               hoho => "ho haho",
338 #               hehe => "hehe !!!",
339 #               ignored => ""
340 #       }
341 #
342
343 my %table=(
344
345     # All these templates are merely a translation of the corresponding
346     # variables further up.
347     #
348     # Note: as long as someone might use old style configuration strings,
349     # or we bother supporting that, those variables need to stay
350
351     x86_asm => {
352         template        => 1,
353         cpuid_obj       => "x86cpuid.o",
354         bn_obj          => "bn-586.o co-586.o x86-mont.o x86-gf2m.o",
355         ec_obj          => "ecp_nistz256.o ecp_nistz256-x86.o",
356         des_obj         => "des-586.o crypt586.o",
357         aes_obj         => "aes-586.o vpaes-x86.o aesni-x86.o",
358         bf_obj          => "bf-586.o",
359         md5_obj         => "md5-586.o",
360         sha1_obj        => "sha1-586.o sha256-586.o sha512-586.o",
361         rc4_obj         => "rc4-586.o",
362         rmd160_obj      => "rmd-586.o",
363         rc5_obj         => "rc5-586.o",
364         wp_obj          => "wp_block.o wp-mmx.o",
365         cmll_obj        => "cmll-x86.o",
366         modes_obj       => "ghash-x86.o",
367         engines_obj     => "e_padlock-x86.o"
368     },
369     x86_elf_asm => {
370         template        => 1,
371         inherit_from    => [ "x86_asm" ],
372         perlasm_scheme  => "elf"
373     },
374     x86_64_asm => {
375         template        => 1,
376         cpuid_obj       => "x86_64cpuid.o",
377         bn_obj          => "x86_64-gcc.o x86_64-mont.o x86_64-mont5.o x86_64-gf2m.o rsaz_exp.o rsaz-x86_64.o rsaz-avx2.o",
378         ec_obj          => "ecp_nistz256.o ecp_nistz256-x86_64.o",
379         aes_obj         => "aes-x86_64.o vpaes-x86_64.o bsaes-x86_64.o aesni-x86_64.o aesni-sha1-x86_64.o aesni-sha256-x86_64.o aesni-mb-x86_64.o",
380         md5_obj         => "md5-x86_64.o",
381         sha1_obj        => "sha1-x86_64.o sha256-x86_64.o sha512-x86_64.o sha1-mb-x86_64.o sha256-mb-x86_64.o",
382         rc4_obj         => "rc4-x86_64.o rc4-md5-x86_64.o",
383         wp_obj          => "wp-x86_64.o",
384         cmll_obj        => "cmll-x86_64.o cmll_misc.o",
385         modes_obj       => "ghash-x86_64.o aesni-gcm-x86_64.o",
386         engines_obj     => "e_padlock-x86_64.o"
387     },
388     ia64_asm => {
389         template        => 1,
390         cpuid_obj       => "ia64cpuid.o",
391         bn_obj          => "bn-ia64.o ia64-mont.o",
392         aes_obj         => "aes_core.o aes_cbc.o aes-ia64.o",
393         md5_obj         => "md5-ia64.o",
394         sha1_obj        => "sha1-ia64.o sha256-ia64.o sha512-ia64.o",
395         rc4_obj         => "rc4-ia64.o rc4_skey.o",
396         modes_obj       => "ghash-ia64.o",
397         perlasm_scheme  => "void"
398     },
399     sparcv9_asm => {
400         template        => 1,
401         cpuid_obj       => "sparcv9cap.o sparccpuid.o",
402         bn_obj          => "bn-sparcv9.o sparcv9-mont.o sparcv9a-mont.o vis3-mont.o sparct4-mont.o sparcv9-gf2m.o",
403         des_obj         => "des_enc-sparc.o fcrypt_b.o dest4-sparcv9.o",
404         aes_obj         => "aes_core.o aes_cbc.o aes-sparcv9.o aest4-sparcv9.o",
405         md5_obj         => "md5-sparcv9.o",
406         sha1_obj        => "sha1-sparcv9.o sha256-sparcv9.o sha512-sparcv9.o",
407         cmll_obj        => "camellia.o cmll_misc.o cmll_cbc.o cmllt4-sparcv9.o",
408         modes_obj       => "ghash-sparcv9.o",
409         perlasm_scheme  => "void"
410     },
411     sparcv8_asm => {
412         template        => 1,
413         cpuid_obj       => "",
414         bn_obj          => "sparcv8.o",
415         des_obj         => "des_enc-sparc.o fcrypt_b.o",
416         perlasm_scheme  => "void"
417     },
418     alpha_asm => {
419         template        => 1,
420         cpuid_obj       => "alphacpuid.o",
421         bn_obj          => "bn_asm.o alpha-mont.o",
422         sha1_obj        => "sha1-alpha.o",
423         modes_obj       => "ghash-alpha.o",
424         perlasm_scheme  => "void"
425     },
426     mips32_asm => {
427         template        => 1,
428         bn_obj          => "bn-mips.o mips-mont.o",
429         aes_obj         => "aes_cbc.o aes-mips.o",
430         sha1_obj        => "sha1-mips.o sha256-mips.o",
431     },
432     mips64_asm => {
433         inherit_from    => [ "mips32_asm" ],
434         template        => 1,
435         sha1_obj        => sub { join(" ", @_, "sha512-mips.o") }
436     },
437     s390x_asm => {
438         template        => 1,
439         cpuid_obj       => "s390xcap.o s390xcpuid.o",
440         bn_obj          => "bn-s390x.o s390x-mont.o s390x-gf2m.o",
441         aes_obj         => "aes-s390x.o aes-ctr.o aes-xts.o",
442         sha1_obj        => "sha1-s390x.o sha256-s390x.o sha512-s390x.o",
443         rc4_obj         => "rc4-s390x.o",
444         modes_obj       => "ghash-s390x.o",
445     },
446     armv4_asm => {
447         template        => 1,
448         cpuid_obj       => "armcap.o armv4cpuid.o",
449         bn_obj          => "bn_asm.o armv4-mont.o armv4-gf2m.o",
450         ec_obj          => "ecp_nistz256.o ecp_nistz256-armv4.o",
451         aes_obj         => "aes_cbc.o aes-armv4.o bsaes-armv7.o aesv8-armx.o",
452         sha1_obj        => "sha1-armv4-large.o sha256-armv4.o sha512-armv4.o",
453         modes_obj       => "ghash-armv4.o ghashv8-armx.o",
454         perlasm_scheme  => "void"
455     },
456     aarch64_asm => {
457         template        => 1,
458         cpuid_obj       => "armcap.o arm64cpuid.o mem_clr.o",
459         aes_obj         => "aes_core.o aes_cbc.o aesv8-armx.o",
460         sha1_obj        => "sha1-armv8.o sha256-armv8.o sha512-armv8.o",
461         modes_obj       => "ghashv8-armx.o",
462     },
463     parisc11_asm => {
464         template        => 1,
465         cpuid_obj       => "pariscid.o",
466         bn_obj          => "bn_asm.o parisc-mont.o",
467         aes_obj         => "aes_core.o aes_cbc.o aes-parisc.o",
468         sha1_obj        => "sha1-parisc.o sha256-parisc.o sha512-parisc.o",
469         rc4_obj         => "rc4-parisc.o",
470         modes_obj       => "ghash-parisc.o",
471         perlasm_scheme  => "32"
472     },
473     parisc20_64_asm => {
474         template        => 1,
475         inherit_from    => [ "parisc11_asm" ],
476         bn_obj          => sub { my $r=join(" ",@_); $r=~s/bn_asm/pa-risc2W/; $r; },
477         perlasm_scheme  => "64",
478     },
479     ppc64_asm => {
480         template        => 1,
481         cpuid_obj       => "ppccpuid.o ppccap.o",
482         bn_obj          => "bn-ppc.o ppc-mont.o ppc64-mont.o",
483         aes_obj         => "aes_core.o aes_cbc.o aes-ppc.o vpaes-ppc.o aesp8-ppc.o",
484         sha1_obj        => "sha1-ppc.o sha256-ppc.o sha512-ppc.o sha256p8-ppc.o sha512p8-ppc.o",
485         modes_obj       => "ghashp8-ppc.o",
486     },
487     ppc32_asm => {
488         inherit_from    => [ "ppc64_asm" ],
489         template        => 1
490     },
491 );
492
493 {   my $no_asm_templates=0;
494     foreach (@ARGV) { $no_asm_templates=1 if (/^\-?no\-asm$/); }
495     sub asm { $no_asm_templates?():@_; }
496 }
497
498
499 sub stringtohash {
500     my $in = shift @_;
501     if (ref($in) eq "HASH") {
502         return $in;
503     }
504     my @stringsequence = (
505         "cc",
506         "cflags",
507         "unistd",
508         "thread_cflag",
509         "sys_id",
510         "lflags",
511         "bn_ops",
512         "cpuid_obj",
513         "bn_obj",
514         "ec_obj",
515         "des_obj",
516         "aes_obj",
517         "bf_obj",
518         "md5_obj",
519         "sha1_obj",
520         "cast_obj",
521         "rc4_obj",
522         "rmd160_obj",
523         "rc5_obj",
524         "wp_obj",
525         "cmll_obj",
526         "modes_obj",
527         "engines_obj",
528         "perlasm_scheme",
529         "dso_scheme",
530         "shared_target",
531         "shared_cflag",
532         "shared_ldflag",
533         "shared_extension",
534         "ranlib",
535         "arflags",
536         "multilib",
537         );
538
539     # return a ref to a hash, that's what the outer braces are for.
540     return { map { shift @stringsequence => $_ } split /:/, $in };
541 };
542
543 # Read configuration target stanzas from a file, so that people can have
544 # local files with their own definitions
545 sub read_config {
546         my $fname = shift;
547         open(CONFFILE, "< $fname")
548                 or die "Can't open configuration file '$fname'!\n";
549         my $x = $/;
550         undef $/;
551         my $content = <CONFFILE>;
552         $/ = $x;
553         close(CONFFILE);
554         my %targets = ();
555         eval $content;
556
557         # Make sure we have debug- targets first
558         my @keys =
559             sort {
560                 my $a_nd = $a =~ m/^debug-/ ? $' :$a;
561                 my $b_nd = $b =~ m/^debug-/ ? $' :$b;
562                 my $res = 0;
563
564                 if (($a_nd == $a) == ($b_nd == $b)) {
565                     # they are both debug- or not, compare them as they are
566                     $res = $a cmp $b;
567                 } elsif ($a_nd != $a) {
568                     # $a is debug-, make it lesser
569                     $res = -1;
570                 } else {
571                     # $b is debug-, make $a greater
572                     $res = 1;
573                 }
574                 $res;
575             } keys %targets;
576
577         foreach (@keys) {
578             if (ref($targets{$_}) ne "HASH") {
579                 # Value is assumed to be a string.  Split it up to
580                 # become a hash table of parameters.  Also, try to
581                 # merge debug- variants with the non-debug target.
582
583                 # Start with converting the value from a string to a
584                 # standardised hash of fields.  Using $tohash is safe,
585                 # if the input is already a hash ref, it's just returned
586                 # back.
587                 $targets{$_} = stringtohash($targets{$_});
588
589                 # If the current target is a debug target, there might
590                 # be a corresponding non-debug target that we can merge
591                 # with.  If it isn't a debug- target, we've already done
592                 # as much merging as we can and do not need to bother
593                 # with that any more.
594                 if ($_ =~ m/^debug-/) {
595                     my $debugkey = $_;
596                     my $nondebugkey = $';
597                     my $debug = $targets{$debugkey};
598                     my $nondebug;
599
600                     if ($targets{$nondebugkey}) {
601                         $nondebug = stringtohash($targets{$nondebugkey});
602                     }
603
604                     if ($nondebug) {
605                         # There's both a debug and non-debug variant of
606                         # this target, so we should try to merge them
607                         # together.
608
609                         # First, check that the non-debug variant isn't
610                         # already built up with all it should have.
611                         if ($nondebug->{debug_cflags}
612                             || $nondebug->{release_cflags}
613                             || $nondebug->{debug_lflags}
614                             || $nondebug->{release_lflags}) {
615                             warn "there's a debug target $debugkey to be merged with a target $nondebugkey, but the latter seems to already have both nodebug and debug information.  This requires human intervention.  Skipping $debugkey...";
616                             next;
617                         }
618
619                         # Now, check similarity.
620                         # For keys they have in common, support that
621                         # cflags and lflags can differ, otherwise they
622                         # must have exactly the same values for them
623                         # to be merged into one.
624                         my $similarenough = 1;
625                         for (keys %{$debug}) {
626                             if ($nondebug->{$_} ne $debug->{$_}
627                                 && $_ !~ m/^[cl]flags$/) {
628                                 $similarenough = 0;
629                                 last;
630                             }
631                         }
632
633                         if ($similarenough) {
634                             # Here's where the magic happens, split the
635                             # options in the debug and non-debug variants
636                             # cflags and ldflags into three strings each,
637                             # one with common flags, one with extra debug
638                             # flags and one with extra non-debug flags.
639
640                             # The result ends up in %h_nondebug, which
641                             # becomes the merged variant when we're done.
642                             # for each of cflags and lflags, they are
643                             # replaced with cflags, debug_cflags,
644                             # release_cflags and similar for lflags.
645                             #
646                             # The purpose is that 'cflags' should be
647                             # used together with 'debug_cflags' or
648                             # 'release_cflags' depending on what the
649                             # user asks for.
650                             foreach (("cflags", "lflags")) {
651                                 my @list_d = split /\s+/, $debug->{$_};
652                                 my @list_nd = split /\s+/, $nondebug->{$_};
653                                 my %presence = (); # bitmap
654                                                    # 1: present in @list_d
655                                                    # 2: present in @list_nd
656                                                    # 3: present in both
657                                 map { $presence{$_} += 1; } @list_d;
658                                 map { $presence{$_} += 2; } @list_nd;
659
660                                 delete $nondebug->{$_};
661                                 # Note: we build from the original lists to
662                                 # preserve order, it might be important
663                                 $nondebug->{"debug-".$_} =
664                                     join(" ",
665                                          grep { $presence{$_} == 1 } @list_d);
666                                 $nondebug->{"nodebug-".$_} =
667                                     join(" ",
668                                          grep { $presence{$_} == 2 } @list_nd);
669                                 $nondebug->{$_} =
670                                     join(" ",
671                                          grep { $presence{$_} == 3 } @list_d);
672                             }
673
674                             $targets{$nondebugkey} = $nondebug;
675                             delete $targets{$debugkey};
676                         }
677                     }
678                 }
679             }
680         }
681
682         %table = (%table, %targets);
683
684         # Local function to resolve inheritance
685         my $resolve_inheritance;
686         $resolve_inheritance =
687             sub {
688                 my $target = shift;
689                 my @breadcrumbs = @_;
690
691                 if (grep { $_ eq $target } @breadcrumbs) {
692                     die "inherit_from loop!  target backtrace:\n  "
693                         ,$target,"\n  ",join("\n  ", @breadcrumbs),"\n";
694                 }
695
696                 # Recurse through all inheritances.  They will be resolved on
697                 # the fly, so when this operation is done, they will all just
698                 # be a bunch of attributes with string values.
699                 # What we get here, though, are keys with references to lists
700                 # of the combined values of them all.  We will deal with lists
701                 # after this stage is done.
702                 my %combined_inheritance = ();
703                 if ($table{$target}->{inherit_from}) {
704                     foreach (@{$table{$target}->{inherit_from}}) {
705                         my %inherited_config =
706                             $resolve_inheritance->($_, $target, @breadcrumbs);
707
708                         # 'template' is a marker that's considered private to
709                         # the config that had it.
710                         delete $inherited_config{template};
711
712                         map {
713                             if (!$combined_inheritance{$_}) {
714                                 $combined_inheritance{$_} = [];
715                             }
716                             push @{$combined_inheritance{$_}}, $inherited_config{$_};
717                         } keys %inherited_config;
718                     }
719                 }
720
721                 # We won't need inherit_from in this target any more, since
722                 # we've resolved all the inheritances that lead to this
723                 delete $table{$target}->{inherit_from};
724
725                 # Now is the time to deal with those lists.  Here's the place
726                 # to decide what shall be done with those lists, all based on
727                 # the values of the target we're currently dealing with.
728                 # - If a value is a coderef, it will be executed with the list
729                 #   of inherited values as arguments.
730                 # - If the corresponding key doesn't have a value at all or is
731                 #   the emoty string, the inherited value list will be run
732                 #   through the default combiner (below), and the result
733                 #   becomes this target's value.
734                 # - Otherwise, this target's value is assumed to be a string
735                 #   that will simply override the inherited list of values.
736                 my $default_combiner = sub { join(' ',@_) };
737
738                 my %all_keys =
739                     map { $_ => 1 } (keys %combined_inheritance,
740                                      keys %{$table{$target}});
741                 foreach (sort keys %all_keys) {
742
743                     # Current target doesn't have a value for the current key?
744                     # Assign it the default combiner, the rest of this loop
745                     # body will handle it just like any other coderef.
746                     if (!exists $table{$target}->{$_}) {
747                         $table{$target}->{$_} = $default_combiner;
748                     }
749
750                     my $valuetype = ref($table{$target}->{$_});
751                     if ($valuetype eq "CODE") {
752                         # CODE reference, execute it with the inherited values
753                         # as arguments.
754                         $table{$target}->{$_} =
755                             $table{$target}->{$_}->(@{$combined_inheritance{$_}});
756                     } elsif ($valuetype eq "") {
757                         # Scalar, just leave it as is.
758                     } else {
759                         # Some other type of reference that we don't handle.
760                         # Better to abort at this point.
761                         die "cannot handle reference type $valuetype,"
762                             ," found in target $target -> $_\n";
763                     }
764                 }
765
766                 # Finally done, return the result.
767                 %{$table{$target}};
768         };
769
770         # Go through all new targets and resolve inheritance and template
771         # references.
772         foreach (keys %targets) {
773             # We're ignoring the returned values here, they are only valuable
774             # to the inner recursion of this function.
775             $resolve_inheritance->($_);
776         }
777 }
778
779 my ($vol, $dir, $dummy) = File::Spec->splitpath($0);
780 my $pattern = File::Spec->catpath($vol, $dir, "Configurations/*.conf");
781 foreach (sort glob($pattern) ) {
782     &read_config($_);
783 }
784
785 my @MK1MF_Builds=qw(VC-WIN64I VC-WIN64A
786                     debug-VC-WIN64I debug-VC-WIN64A
787                     VC-NT VC-CE VC-WIN32 debug-VC-WIN32
788                     BC-32
789                     netware-clib netware-clib-bsdsock
790                     netware-libc netware-libc-bsdsock);
791
792 my $prefix="";
793 my $libdir="";
794 my $openssldir="";
795 my $exe_ext="";
796 my $install_prefix= "$ENV{'INSTALL_PREFIX'}";
797 my $cross_compile_prefix="";
798 my $fipslibdir="/usr/local/ssl/fips-2.0/lib/";
799 my $nofipscanistercheck=0;
800 my $baseaddr="0xFB00000";
801 my $no_threads=0;
802 my $threads=0;
803 my $no_shared=0; # but "no-shared" is default
804 my $zlib=1;      # but "no-zlib" is default
805 my $no_krb5=0;   # but "no-krb5" is implied unless "--with-krb5-..." is used
806 my $no_rfc3779=1; # but "no-rfc3779" is default
807 my $no_asm=0;
808 my $no_dso=0;
809 my $no_gmp=0;
810 my @skip=();
811 my $Makefile="Makefile";
812 my $des_locl="crypto/des/des_locl.h";
813 my $des ="crypto/des/des.h";
814 my $bn  ="crypto/bn/bn.h";
815 my $md2 ="crypto/md2/md2.h";
816 my $rc4 ="crypto/rc4/rc4.h";
817 my $rc4_locl="crypto/rc4/rc4_locl.h";
818 my $idea        ="crypto/idea/idea.h";
819 my $rc2 ="crypto/rc2/rc2.h";
820 my $bf  ="crypto/bf/bf_locl.h";
821 my $bn_asm      ="bn_asm.o";
822 my $des_enc="des_enc.o fcrypt_b.o";
823 my $aes_enc="aes_core.o aes_cbc.o";
824 my $bf_enc      ="bf_enc.o";
825 my $cast_enc="c_enc.o";
826 my $rc4_enc="rc4_enc.o rc4_skey.o";
827 my $rc5_enc="rc5_enc.o";
828 my $cmll_enc="camellia.o cmll_misc.o cmll_cbc.o";
829 my $processor="";
830 my $default_ranlib;
831 my $perl;
832 my $fips=0;
833
834 # All of the following is disabled by default (RC5 was enabled before 0.9.8):
835
836 my %disabled = ( # "what"         => "comment" [or special keyword "experimental"]
837                  "deprecated" => "default",
838                  "ec_nistp_64_gcc_128" => "default",
839                  "gmp"            => "default",
840                  "jpake"          => "experimental",
841                  "md2"            => "default",
842                  "rc5"            => "default",
843                  "rfc3779"        => "default",
844                  "sctp"       => "default",
845                  "shared"         => "default",
846                  "ssl-trace"      => "default",
847                  "store"          => "experimental",
848                  "unit-test"      => "default",
849                  "zlib"           => "default",
850                  "zlib-dynamic"   => "default"
851                );
852 my @experimental = ();
853
854 # This is what $depflags will look like with the above defaults
855 # (we need this to see if we should advise the user to run "make depend"):
856 my $default_depflags = " -DOPENSSL_NO_DEPRECATED -DOPENSSL_NO_EC_NISTP_64_GCC_128 -DOPENSSL_NO_GMP -DOPENSSL_NO_JPAKE -DOPENSSL_NO_MD2 -DOPENSSL_NO_RC5 -DOPENSSL_NO_RFC3779 -DOPENSSL_NO_SCTP -DOPENSSL_NO_SSL_TRACE -DOPENSSL_NO_STORE -DOPENSSL_NO_UNIT_TEST";
857
858 # Explicit "no-..." options will be collected in %disabled along with the defaults.
859 # To remove something from %disabled, use "enable-foo" (unless it's experimental).
860 # For symmetry, "disable-foo" is a synonym for "no-foo".
861
862 # For features called "experimental" here, a more explicit "experimental-foo" is needed to enable.
863 # We will collect such requests in @experimental.
864 # To avoid accidental use of experimental features, applications will have to use -DOPENSSL_EXPERIMENTAL_FOO.
865
866
867 my $no_sse2=0;
868
869 &usage if ($#ARGV < 0);
870
871 my $flags;
872 my $depflags;
873 my $openssl_experimental_defines;
874 my $openssl_algorithm_defines;
875 my $openssl_thread_defines;
876 my $openssl_sys_defines="";
877 my $openssl_other_defines;
878 my $libs;
879 my $libkrb5="";
880 my $target;
881 my $options;
882 my $symlink;
883 my $make_depend=0;
884 my %withargs=();
885 my $build_prefix = "release_";
886
887 my @argvcopy=@ARGV;
888 my $argvstring="";
889 my $argv_unprocessed=1;
890
891 while($argv_unprocessed)
892         {
893         $flags="";
894         $depflags="";
895         $openssl_experimental_defines="";
896         $openssl_algorithm_defines="";
897         $openssl_thread_defines="";
898         $openssl_sys_defines="";
899         $openssl_other_defines="";
900         $libs="";
901         $target="";
902         $options="";
903         $symlink=1;
904
905         $argv_unprocessed=0;
906         $argvstring=join(' ',@argvcopy);
907
908 PROCESS_ARGS:
909         foreach (@argvcopy)
910                 {
911                 s /^-no-/no-/; # some people just can't read the instructions
912
913                 # rewrite some options in "enable-..." form
914                 s /^-?-?shared$/enable-shared/;
915                 s /^sctp$/enable-sctp/;
916                 s /^threads$/enable-threads/;
917                 s /^zlib$/enable-zlib/;
918                 s /^zlib-dynamic$/enable-zlib-dynamic/;
919
920                 if (/^no-(.+)$/ || /^disable-(.+)$/)
921                         {
922                         if (!($disabled{$1} eq "experimental"))
923                                 {
924                                 if ($1 eq "ssl")
925                                         {
926                                         $disabled{"ssl3"} = "option(ssl)";
927                                         }
928                                 elsif ($1 eq "tls")
929                                         {
930                                         $disabled{"tls1"} = "option(tls)"
931                                         }
932                                 elsif ($1 eq "ssl3-method")
933                                         {
934                                         $disabled{"ssl3-method"} = "option(ssl)";
935                                         $disabled{"ssl3"} = "option(ssl)";
936                                         }
937                                 else
938                                         {
939                                         $disabled{$1} = "option";
940                                         }
941                                 }
942                         }
943                 elsif (/^enable-(.+)$/ || /^experimental-(.+)$/)
944                         {
945                         my $algo = $1;
946                         if ($disabled{$algo} eq "experimental")
947                                 {
948                                 die "You are requesting an experimental feature; please say 'experimental-$algo' if you are sure\n"
949                                         unless (/^experimental-/);
950                                 push @experimental, $algo;
951                                 }
952                         delete $disabled{$algo};
953
954                         $threads = 1 if ($algo eq "threads");
955                         }
956                 elsif (/^--test-sanity$/)
957                         {
958                         exit(&test_sanity());
959                         }
960                 elsif (/^--strict-warnings$/)
961                         {
962                         $strict_warnings = 1;
963                         }
964                 elsif (/^--debug$/)
965                         {
966                         $build_prefix = "debug_";
967                         }
968                 elsif (/^--release$/)
969                         {
970                         $build_prefix = "release_";
971                         }
972                 elsif (/^reconfigure/ || /^reconf/)
973                         {
974                         if (open(IN,"<$Makefile"))
975                                 {
976                                 while (<IN>)
977                                         {
978                                         chomp;
979                                         if (/^CONFIGURE_ARGS=(.*)/)
980                                                 {
981                                                 $argvstring=$1;
982                                                 @argvcopy=split(' ',$argvstring);
983                                                 die "Incorrect data to reconfigure, please do a normal configuration\n"
984                                                         if (grep(/^reconf/,@argvcopy));
985                                                 print "Reconfiguring with: $argvstring\n";
986                                                 $argv_unprocessed=1;
987                                                 close(IN);
988                                                 last PROCESS_ARGS;
989                                                 }
990                                         }
991                                 close(IN);
992                                 }
993                         die "Insufficient data to reconfigure, please do a normal configuration\n";
994                         }
995                 elsif (/^386$/)
996                         { $processor=386; }
997                 elsif (/^fips$/)
998                         {
999                         $fips=1;
1000                         }
1001                 elsif (/^rsaref$/)
1002                         {
1003                         # No RSAref support any more since it's not needed.
1004                         # The check for the option is there so scripts aren't
1005                         # broken
1006                         }
1007                 elsif (/^nofipscanistercheck$/)
1008                         {
1009                         $fips = 1;
1010                         $nofipscanistercheck = 1;
1011                         }
1012                 elsif (/^[-+]/)
1013                         {
1014                         if (/^--prefix=(.*)$/)
1015                                 {
1016                                 $prefix=$1;
1017                                 }
1018                         elsif (/^--libdir=(.*)$/)
1019                                 {
1020                                 $libdir=$1;
1021                                 }
1022                         elsif (/^--openssldir=(.*)$/)
1023                                 {
1024                                 $openssldir=$1;
1025                                 }
1026                         elsif (/^--install.prefix=(.*)$/)
1027                                 {
1028                                 $install_prefix=$1;
1029                                 }
1030                         elsif (/^--with-krb5-(dir|lib|include|flavor)=(.*)$/)
1031                                 {
1032                                 $withargs{"krb5-".$1}=$2;
1033                                 }
1034                         elsif (/^--with-zlib-lib=(.*)$/)
1035                                 {
1036                                 $withargs{"zlib-lib"}=$1;
1037                                 }
1038                         elsif (/^--with-zlib-include=(.*)$/)
1039                                 {
1040                                 $withargs{"zlib-include"}="-I$1";
1041                                 }
1042                         elsif (/^--with-fipslibdir=(.*)$/)
1043                                 {
1044                                 $fipslibdir="$1/";
1045                                 }
1046                         elsif (/^--with-baseaddr=(.*)$/)
1047                                 {
1048                                 $baseaddr="$1";
1049                                 }
1050                         elsif (/^--cross-compile-prefix=(.*)$/)
1051                                 {
1052                                 $cross_compile_prefix=$1;
1053                                 }
1054                         elsif (/^--config=(.*)$/)
1055                                 {
1056                                 read_config $1;
1057                                 }
1058                         elsif (/^-[lL](.*)$/ or /^-Wl,/)
1059                                 {
1060                                 $libs.=$_." ";
1061                                 }
1062                         else    # common if (/^[-+]/), just pass down...
1063                                 {
1064                                 $_ =~ s/%([0-9a-f]{1,2})/chr(hex($1))/gei;
1065                                 $flags.=$_." ";
1066                                 }
1067                         }
1068                 elsif ($_ =~ /^([^:]+):(.+)$/)
1069                         {
1070                         eval "\$table{\$1} = \"$2\""; # allow $xxx constructs in the string
1071                         $target=$1;
1072                         }
1073                 else
1074                         {
1075                         die "target already defined - $target (offending arg: $_)\n" if ($target ne "");
1076                         $target=$_;
1077                         }
1078
1079                 unless ($_ eq $target || /^no-/ || /^disable-/)
1080                         {
1081                         # "no-..." follows later after implied disactivations
1082                         # have been derived.  (Don't take this too seroiusly,
1083                         # we really only write OPTIONS to the Makefile out of
1084                         # nostalgia.)
1085
1086                         if ($options eq "")
1087                                 { $options = $_; }
1088                         else
1089                                 { $options .= " ".$_; }
1090                         }
1091                 }
1092         }
1093
1094
1095
1096 if ($processor eq "386")
1097         {
1098         $disabled{"sse2"} = "forced";
1099         }
1100
1101 if (!defined($withargs{"krb5-flavor"}) || $withargs{"krb5-flavor"} eq "")
1102         {
1103         $disabled{"krb5"} = "krb5-flavor not specified";
1104         }
1105
1106 if (!defined($disabled{"zlib-dynamic"}))
1107         {
1108         # "zlib-dynamic" was specifically enabled, so enable "zlib"
1109         delete $disabled{"zlib"};
1110         }
1111
1112 if (defined($disabled{"rijndael"}))
1113         {
1114         $disabled{"aes"} = "forced";
1115         }
1116 if (defined($disabled{"des"}))
1117         {
1118         $disabled{"mdc2"} = "forced";
1119         }
1120 if (defined($disabled{"ec"}))
1121         {
1122         $disabled{"ecdsa"} = "forced";
1123         $disabled{"ecdh"} = "forced";
1124         }
1125
1126 # SSL 3.0 and TLS requires MD5 and SHA and either RSA or DSA+DH
1127 if (defined($disabled{"md5"}) || defined($disabled{"sha"})
1128     || (defined($disabled{"rsa"})
1129         && (defined($disabled{"dsa"}) || defined($disabled{"dh"}))))
1130         {
1131         $disabled{"ssl3"} = "forced";
1132         $disabled{"tls1"} = "forced";
1133         }
1134
1135 if (defined($disabled{"tls1"}))
1136         {
1137         $disabled{"tlsext"} = "forced";
1138         }
1139
1140 if (defined($disabled{"ec"}) || defined($disabled{"dsa"})
1141     || defined($disabled{"dh"}))
1142         {
1143         $disabled{"gost"} = "forced";
1144         }
1145
1146 # SRP and HEARTBEATS require TLSEXT
1147 if (defined($disabled{"tlsext"}))
1148         {
1149         $disabled{"srp"} = "forced";
1150         $disabled{"heartbeats"} = "forced";
1151         }
1152
1153 if ($target eq "TABLE") {
1154         foreach $target (sort keys %table) {
1155                 print_table_entry($target, "TABLE");
1156         }
1157         exit 0;
1158 }
1159
1160 if ($target eq "LIST") {
1161         foreach (sort keys %table) {
1162                 print;
1163                 print "\n";
1164         }
1165         exit 0;
1166 }
1167
1168 if ($target eq "HASH") {
1169         print "%table = (\n";
1170         foreach (sort keys %table) {
1171                 print_table_entry($_, "HASH");
1172         }
1173         exit 0;
1174 }
1175
1176 if ($target =~ m/^CygWin32(-.*)$/) {
1177         $target = "Cygwin".$1;
1178 }
1179
1180 print "Configuring for $target\n";
1181
1182 # Support for legacy targets having a name starting with 'debug-'
1183 my ($d, $t) = $target =~ m/^(debug-)?(.*)$/;
1184 if ($d) {
1185     $build_prefix = "debug_";
1186
1187     # If we do not find debug-foo in the table, the target is set to foo,
1188     # but only if the foo target has a noon-empty debug_cflags or debug_lflags
1189     # attribute.
1190     if (!$table{$target} && ($table{$t}->{debug_cflags}
1191                              || $table{$t}->{debug_lflags})) {
1192         $target = $t;
1193     }
1194 }
1195
1196 &usage if (!defined($table{$target})
1197            || $table{$target}->{template}
1198            || ($build_prefix eq "debug_"
1199                && $target !~ /^debug-/
1200                && !($table{$target}->{debug_cflags}
1201                     || $table{$target}->{debug_lflags})));
1202
1203 if ($fips)
1204         {
1205         delete $disabled{"shared"} if ($disabled{"shared"} eq "default");
1206         }
1207
1208 foreach (sort (keys %disabled))
1209         {
1210         $options .= " no-$_";
1211
1212         printf "    no-%-12s %-10s", $_, "[$disabled{$_}]";
1213
1214         if (/^dso$/)
1215                 { $no_dso = 1; }
1216         elsif (/^threads$/)
1217                 { $no_threads = 1; }
1218         elsif (/^shared$/)
1219                 { $no_shared = 1; }
1220         elsif (/^zlib$/)
1221                 { $zlib = 0; }
1222         elsif (/^static-engine$/)
1223                 { }
1224         elsif (/^zlib-dynamic$/)
1225                 { }
1226         elsif (/^symlinks$/)
1227                 { $symlink = 0; }
1228         elsif (/^sse2$/)
1229                 { $no_sse2 = 1; }
1230         else
1231                 {
1232                 my ($ALGO, $algo);
1233                 ($ALGO = $algo = $_) =~ tr/[\-a-z]/[_A-Z]/;
1234
1235                 if (/^asm$/ || /^err$/ || /^hw$/ || /^hw-/)
1236                         {
1237                         $openssl_other_defines .= "#define OPENSSL_NO_$ALGO\n";
1238                         print " OPENSSL_NO_$ALGO";
1239
1240                         if (/^err$/)    { $flags .= "-DOPENSSL_NO_ERR "; }
1241                         elsif (/^asm$/) { $no_asm = 1; }
1242                         }
1243                 else
1244                         {
1245                         ($ALGO,$algo) = ("RMD160","rmd160") if ($algo eq "ripemd");
1246
1247                         $openssl_algorithm_defines .= "#define OPENSSL_NO_$ALGO\n";
1248                         print " OPENSSL_NO_$ALGO";
1249
1250                         if (/^krb5$/)
1251                                 { $no_krb5 = 1; }
1252                         else
1253                                 {
1254                                 push @skip, $algo;
1255                                 # fix-up crypto/directory name(s)
1256                                 $skip[$#skip]="whrlpool" if $algo eq "whirlpool";
1257                                 $skip[$#skip]="ripemd" if $algo eq "rmd160";
1258
1259                                 print " (skip dir)";
1260
1261                                 $depflags .= " -DOPENSSL_NO_$ALGO";
1262                                 }
1263                         }
1264                 }
1265
1266         print "\n";
1267         }
1268
1269 my $exp_cflags = "";
1270
1271 foreach (sort @experimental)
1272         {
1273         my $ALGO;
1274         ($ALGO = $_) =~ tr/[a-z]/[A-Z]/;
1275
1276         # opensslconf.h will set OPENSSL_NO_... unless OPENSSL_EXPERIMENTAL_... is defined
1277         $openssl_experimental_defines .= "#define OPENSSL_NO_$ALGO\n";
1278         $exp_cflags .= " -DOPENSSL_EXPERIMENTAL_$ALGO";
1279         }
1280
1281 my $IsMK1MF=scalar grep /^$target$/,@MK1MF_Builds;
1282
1283 $exe_ext=".exe" if ($target eq "Cygwin" || $target eq "DJGPP" || $target =~ /^mingw/);
1284 $exe_ext=".nlm" if ($target =~ /netware/);
1285 $exe_ext=".pm"  if ($target =~ /vos/);
1286 $openssldir="/usr/local/ssl" if ($openssldir eq "" and $prefix eq "");
1287 $prefix=$openssldir if $prefix eq "";
1288
1289 $default_ranlib= &which("ranlib") or $default_ranlib="true";
1290 $perl=$ENV{'PERL'} or $perl=&which("perl5") or $perl=&which("perl")
1291   or $perl="perl";
1292 my $make = $ENV{'MAKE'} || "make";
1293
1294 $cross_compile_prefix=$ENV{'CROSS_COMPILE'} if $cross_compile_prefix eq "";
1295
1296 chop $openssldir if $openssldir =~ /\/$/;
1297 chop $prefix if $prefix =~ /.\/$/;
1298
1299 $openssldir=$prefix . "/ssl" if $openssldir eq "";
1300 $openssldir=$prefix . "/" . $openssldir if $openssldir !~ /(^\/|^[a-zA-Z]:[\\\/])/;
1301
1302
1303 print "IsMK1MF=$IsMK1MF\n";
1304
1305 # Allow environment CC to override compiler...
1306 my $cc = $ENV{CC} || $table{$target}->{cc};
1307
1308 # For cflags and lflags, add the debug_ or release_ attributes
1309 # Do it in such a way that no spurious space is appended (hence the grep).
1310 my $cflags = join(" ",
1311                   grep { $_ } ($table{$target}->{cflags},
1312                                $table{$target}->{$build_prefix."cflags"}));
1313 my $lflags = join(" ",
1314                   grep { $_ } ($table{$target}->{lflags},
1315                                $table{$target}->{$build_prefix."lflags"}));
1316
1317 my $unistd = $table{$target}->{unistd};
1318 my $thread_cflag = $table{$target}->{thread_cflag};
1319 my $sys_id = $table{$target}->{sys_id};
1320 my $bn_ops = $table{$target}->{bn_ops};
1321 my $cpuid_obj = $table{$target}->{cpuid_obj};
1322 my $bn_obj = $table{$target}->{bn_obj};
1323 my $ec_obj = $table{$target}->{ec_obj};
1324 my $des_obj = $table{$target}->{des_obj};
1325 my $aes_obj = $table{$target}->{aes_obj};
1326 my $bf_obj = $table{$target}->{bf_obj};
1327 my $md5_obj = $table{$target}->{md5_obj};
1328 my $sha1_obj = $table{$target}->{sha1_obj};
1329 my $cast_obj = $table{$target}->{cast_obj};
1330 my $rc4_obj = $table{$target}->{rc4_obj};
1331 my $rmd160_obj = $table{$target}->{rmd160_obj};
1332 my $rc5_obj = $table{$target}->{rc5_obj};
1333 my $wp_obj = $table{$target}->{wp_obj};
1334 my $cmll_obj = $table{$target}->{cmll_obj};
1335 my $modes_obj = $table{$target}->{modes_obj};
1336 my $engines_obj = $table{$target}->{engines_obj};
1337 my $perlasm_scheme = $table{$target}->{perlasm_scheme};
1338 my $dso_scheme = $table{$target}->{dso_scheme};
1339 my $shared_target = $table{$target}->{shared_target};
1340 my $shared_cflag = $table{$target}->{shared_cflag};
1341 my $shared_ldflag = $table{$target}->{shared_ldflag};
1342 my $shared_extension = $table{$target}->{shared_extension};
1343 my $ranlib = $ENV{'RANLIB'} || $table{$target}->{ranlib};
1344 my $ar = $ENV{'AR'} || "ar";
1345 my $arflags = $table{$target}->{arflags};
1346 my $multilib = $table{$target}->{multilib};
1347
1348 # if $prefix/lib$multilib is not an existing directory, then
1349 # assume that it's not searched by linker automatically, in
1350 # which case adding $multilib suffix causes more grief than
1351 # we're ready to tolerate, so don't...
1352 $multilib="" if !-d "$prefix/lib$multilib";
1353
1354 $libdir="lib$multilib" if $libdir eq "";
1355
1356 $cflags = "$cflags$exp_cflags";
1357
1358 # '%' in $lflags is used to split flags to "pre-" and post-flags
1359 my ($prelflags,$postlflags)=split('%',$lflags);
1360 if (defined($postlflags))       { $lflags=$postlflags;  }
1361 else                            { $lflags=$prelflags; undef $prelflags; }
1362
1363 if ($target =~ /^mingw/ && `$cc --target-help 2>&1` !~ m/\-mno\-cygwin/m)
1364         {
1365         $cflags =~ s/\-mno\-cygwin\s*//;
1366         $shared_ldflag =~ s/\-mno\-cygwin\s*//;
1367         }
1368
1369 if ($target =~ /linux.*\-mips/ && !$no_asm && $flags !~ /\-m(ips|arch=)/) {
1370         # minimally required architecture flags for assembly modules
1371         $cflags="-mips2 $cflags" if ($target =~ /mips32/);
1372         $cflags="-mips3 $cflags" if ($target =~ /mips64/);
1373 }
1374
1375 my $no_shared_warn=0;
1376 my $no_user_cflags=0;
1377
1378 if ($flags ne "")       { $cflags="$flags$cflags"; }
1379 else                    { $no_user_cflags=1;       }
1380
1381 # Kerberos settings.  The flavor must be provided from outside, either through
1382 # the script "config" or manually.
1383 if (!$no_krb5)
1384         {
1385         my ($lresolv, $lpath, $lext);
1386         if ($withargs{"krb5-flavor"} =~ /^[Hh]eimdal$/)
1387                 {
1388                 die "Sorry, Heimdal is currently not supported\n";
1389                 }
1390         ##### HACK to force use of Heimdal.
1391         ##### WARNING: Since we don't really have adequate support for Heimdal,
1392         #####          using this will break the build.  You'll have to make
1393         #####          changes to the source, and if you do, please send
1394         #####          patches to openssl-dev@openssl.org
1395         if ($withargs{"krb5-flavor"} =~ /^force-[Hh]eimdal$/)
1396                 {
1397                 warn "Heimdal isn't really supported.  Your build WILL break\n";
1398                 warn "If you fix the problems, please send a patch to openssl-dev\@openssl.org\n";
1399                 $withargs{"krb5-dir"} = "/usr/heimdal"
1400                         if $withargs{"krb5-dir"} eq "";
1401                 $withargs{"krb5-lib"} = "-L".$withargs{"krb5-dir"}.
1402                         "/lib -lgssapi -lkrb5 -lcom_err"
1403                         if $withargs{"krb5-lib"} eq "" && !$IsMK1MF;
1404                 $cflags="-DKRB5_HEIMDAL $cflags";
1405                 }
1406         if ($withargs{"krb5-flavor"} =~ /^[Mm][Ii][Tt]/)
1407                 {
1408                 $withargs{"krb5-dir"} = "/usr/kerberos"
1409                         if $withargs{"krb5-dir"} eq "";
1410                 $withargs{"krb5-lib"} = "-L".$withargs{"krb5-dir"}.
1411                         "/lib -lgssapi_krb5 -lkrb5 -lcom_err -lk5crypto"
1412                         if $withargs{"krb5-lib"} eq "" && !$IsMK1MF;
1413                 $cflags="-DKRB5_MIT $cflags";
1414                 $withargs{"krb5-flavor"} =~ s/^[Mm][Ii][Tt][._-]*//;
1415                 if ($withargs{"krb5-flavor"} =~ /^1[._-]*[01]/)
1416                         {
1417                         $cflags="-DKRB5_MIT_OLD11 $cflags";
1418                         }
1419                 }
1420         LRESOLV:
1421         foreach $lpath ("/lib", "/usr/lib")
1422                 {
1423                 foreach $lext ("a", "so")
1424                         {
1425                         $lresolv = "$lpath/libresolv.$lext";
1426                         last LRESOLV    if (-r "$lresolv");
1427                         $lresolv = "";
1428                         }
1429                 }
1430         $withargs{"krb5-lib"} .= " -lresolv"
1431                 if ("$lresolv" ne "");
1432         $withargs{"krb5-include"} = "-I".$withargs{"krb5-dir"}."/include"
1433                 if $withargs{"krb5-include"} eq "" &&
1434                    $withargs{"krb5-dir"} ne "";
1435         }
1436
1437 # The DSO code currently always implements all functions so that no
1438 # applications will have to worry about that from a compilation point
1439 # of view. However, the "method"s may return zero unless that platform
1440 # has support compiled in for them. Currently each method is enabled
1441 # by a define "DSO_<name>" ... we translate the "dso_scheme" config
1442 # string entry into using the following logic;
1443 my $dso_cflags;
1444 if (!$no_dso && $dso_scheme ne "")
1445         {
1446         $dso_scheme =~ tr/[a-z]/[A-Z]/;
1447         if ($dso_scheme eq "DLFCN")
1448                 {
1449                 $dso_cflags = "-DDSO_DLFCN -DHAVE_DLFCN_H";
1450                 }
1451         elsif ($dso_scheme eq "DLFCN_NO_H")
1452                 {
1453                 $dso_cflags = "-DDSO_DLFCN";
1454                 }
1455         else
1456                 {
1457                 $dso_cflags = "-DDSO_$dso_scheme";
1458                 }
1459         $cflags = "$dso_cflags $cflags";
1460         }
1461
1462 my $thread_cflags;
1463 my $thread_defines;
1464 if ($thread_cflag ne "(unknown)" && !$no_threads)
1465         {
1466         # If we know how to do it, support threads by default.
1467         $threads = 1;
1468         }
1469 if ($thread_cflag eq "(unknown)" && $threads)
1470         {
1471         # If the user asked for "threads", [s]he is also expected to
1472         # provide any system-dependent compiler options that are
1473         # necessary.
1474         if ($no_user_cflags)
1475                 {
1476                 print "You asked for multi-threading support, but didn't\n";
1477                 print "provide any system-specific compiler options\n";
1478                 exit(1);
1479                 }
1480         $thread_cflags="-DOPENSSL_THREADS $cflags" ;
1481         $thread_defines .= "#define OPENSSL_THREADS\n";
1482         }
1483 else
1484         {
1485         $thread_cflags="-DOPENSSL_THREADS $thread_cflag $cflags";
1486         $thread_defines .= "#define OPENSSL_THREADS\n";
1487 #       my $def;
1488 #       foreach $def (split ' ',$thread_cflag)
1489 #               {
1490 #               if ($def =~ s/^-D// && $def !~ /^_/)
1491 #                       {
1492 #                       $thread_defines .= "#define $def\n";
1493 #                       }
1494 #               }
1495         }
1496
1497 $lflags="$libs$lflags" if ($libs ne "");
1498
1499 if ($no_asm)
1500         {
1501         $cpuid_obj=$bn_obj=$ec_obj=
1502         $des_obj=$aes_obj=$bf_obj=$cast_obj=$rc4_obj=$rc5_obj=$cmll_obj=
1503         $modes_obj=$sha1_obj=$md5_obj=$rmd160_obj=$wp_obj=$engines_obj="";
1504         $cflags=~s/\-D[BL]_ENDIAN//             if ($fips);
1505         $thread_cflags=~s/\-D[BL]_ENDIAN//      if ($fips);
1506         }
1507 elsif (defined($disabled{ec2m}))
1508         {
1509         $bn_obj =~ s/\w+-gf2m.o//;
1510         }
1511
1512 if (!$no_shared)
1513         {
1514         $cast_obj="";   # CAST assembler is not PIC
1515         }
1516
1517 if ($threads)
1518         {
1519         $cflags=$thread_cflags;
1520         $openssl_thread_defines .= $thread_defines;
1521         }
1522
1523 if ($zlib)
1524         {
1525         $cflags = "-DZLIB $cflags";
1526         if (defined($disabled{"zlib-dynamic"}))
1527                 {
1528                 if (defined($withargs{"zlib-lib"}))
1529                         {
1530                         $lflags = "$lflags -L" . $withargs{"zlib-lib"} . " -lz";
1531                         }
1532                 else
1533                         {
1534                         $lflags = "$lflags -lz";
1535                         }
1536                 }
1537         else
1538                 {
1539                 $cflags = "-DZLIB_SHARED $cflags";
1540                 }
1541         }
1542
1543 #Build the library with OPENSSL_USE_DEPRECATED if deprecation is not disabled
1544 if(!defined($disabled{"deprecated"}))
1545         {
1546         $cflags = "-DOPENSSL_USE_DEPRECATED $cflags";
1547         }
1548
1549 # You will find shlib_mark1 and shlib_mark2 explained in Makefile.org
1550 my $shared_mark = "";
1551 if ($shared_target eq "")
1552         {
1553         $no_shared_warn = 1 if !$no_shared && !$fips;
1554         $no_shared = 1;
1555         }
1556 if (!$no_shared)
1557         {
1558         if ($shared_cflag ne "")
1559                 {
1560                 $cflags = "$shared_cflag -DOPENSSL_PIC $cflags";
1561                 }
1562         }
1563
1564 if (!$IsMK1MF)
1565         {
1566         # add {no-}static-engine to options to allow mkdef.pl to work without extra arguments
1567         if ($no_shared)
1568                 {
1569                 $openssl_other_defines.="#define OPENSSL_NO_DYNAMIC_ENGINE\n";
1570                 $options.=" static-engine";
1571                 }
1572         else
1573                 {
1574                 $openssl_other_defines.="#define OPENSSL_NO_STATIC_ENGINE\n";
1575                 $options.=" no-static-engine";
1576                 }
1577         }
1578
1579 $cpuid_obj.=" uplink.o uplink-x86.o" if ($cflags =~ /\-DOPENSSL_USE_APPLINK/);
1580
1581 #
1582 # Platform fix-ups
1583 #
1584 if ($target =~ /\-icc$/)        # Intel C compiler
1585         {
1586         my $iccver=0;
1587         if (open(FD,"$cc -V 2>&1 |"))
1588                 {
1589                 while(<FD>) { $iccver=$1 if (/Version ([0-9]+)\./); }
1590                 close(FD);
1591                 }
1592         if ($iccver>=8)
1593                 {
1594                 $cflags=~s/\-KPIC/-fPIC/;
1595                 # Eliminate unnecessary dependency from libirc.a. This is
1596                 # essential for shared library support, as otherwise
1597                 # apps/openssl can end up in endless loop upon startup...
1598                 $cflags.=" -Dmemcpy=__builtin_memcpy -Dmemset=__builtin_memset";
1599                 }
1600         if ($iccver>=9)
1601                 {
1602                 $lflags.=" -i-static";
1603                 $lflags=~s/\-no_cpprt/-no-cpprt/;
1604                 }
1605         if ($iccver>=10)
1606                 {
1607                 $lflags=~s/\-i\-static/-static-intel/;
1608                 }
1609         if ($iccver>=11)
1610                 {
1611                 $cflags.=" -no-intel-extensions";       # disable Cilk
1612                 $lflags=~s/\-no\-cpprt/-no-cxxlib/;
1613                 }
1614         }
1615
1616 # Unlike other OSes (like Solaris, Linux, Tru64, IRIX) BSD run-time
1617 # linkers (tested OpenBSD, NetBSD and FreeBSD) "demand" RPATH set on
1618 # .so objects. Apparently application RPATH is not global and does
1619 # not apply to .so linked with other .so. Problem manifests itself
1620 # when libssl.so fails to load libcrypto.so. One can argue that we
1621 # should engrave this into Makefile.shared rules or into BSD-* config
1622 # lines above. Meanwhile let's try to be cautious and pass -rpath to
1623 # linker only when --prefix is not /usr.
1624 if ($target =~ /^BSD\-/)
1625         {
1626         $shared_ldflag.=" -Wl,-rpath,\$(LIBRPATH)" if ($prefix !~ m|^/usr[/]*$|);
1627         }
1628
1629 if ($sys_id ne "")
1630         {
1631         #$cflags="-DOPENSSL_SYS_$sys_id $cflags";
1632         $openssl_sys_defines="#define OPENSSL_SYS_$sys_id\n";
1633         }
1634
1635 if ($ranlib eq "")
1636         {
1637         $ranlib = $default_ranlib;
1638         }
1639
1640 #my ($bn1)=split(/\s+/,$bn_obj);
1641 #$bn1 = "" unless defined $bn1;
1642 #$bn1=$bn_asm unless ($bn1 =~ /\.o$/);
1643 #$bn_obj="$bn1";
1644
1645 $cpuid_obj="" if ($processor eq "386");
1646
1647 $bn_obj = $bn_asm unless $bn_obj ne "";
1648 # bn-586 is the only one implementing bn_*_part_words
1649 $cflags.=" -DOPENSSL_BN_ASM_PART_WORDS" if ($bn_obj =~ /bn-586/);
1650 $cflags.=" -DOPENSSL_IA32_SSE2" if (!$no_sse2 && $bn_obj =~ /86/);
1651
1652 $cflags.=" -DOPENSSL_BN_ASM_MONT" if ($bn_obj =~ /-mont/);
1653 $cflags.=" -DOPENSSL_BN_ASM_MONT5" if ($bn_obj =~ /-mont5/);
1654 $cflags.=" -DOPENSSL_BN_ASM_GF2m" if ($bn_obj =~ /-gf2m/);
1655
1656 if ($fips)
1657         {
1658         $openssl_other_defines.="#define OPENSSL_FIPS\n";
1659         }
1660
1661 $cpuid_obj="mem_clr.o"  unless ($cpuid_obj =~ /\.o$/);
1662 $des_obj=$des_enc       unless ($des_obj =~ /\.o$/);
1663 $bf_obj=$bf_enc         unless ($bf_obj =~ /\.o$/);
1664 $cast_obj=$cast_enc     unless ($cast_obj =~ /\.o$/);
1665 $rc4_obj=$rc4_enc       unless ($rc4_obj =~ /\.o$/);
1666 $rc5_obj=$rc5_enc       unless ($rc5_obj =~ /\.o$/);
1667 if ($sha1_obj =~ /\.o$/)
1668         {
1669 #       $sha1_obj=$sha1_enc;
1670         $cflags.=" -DSHA1_ASM"   if ($sha1_obj =~ /sx86/ || $sha1_obj =~ /sha1/);
1671         $cflags.=" -DSHA256_ASM" if ($sha1_obj =~ /sha256/);
1672         $cflags.=" -DSHA512_ASM" if ($sha1_obj =~ /sha512/);
1673         if ($sha1_obj =~ /sse2/)
1674             {   if ($no_sse2)
1675                 {   $sha1_obj =~ s/\S*sse2\S+//;        }
1676                 elsif ($cflags !~ /OPENSSL_IA32_SSE2/)
1677                 {   $cflags.=" -DOPENSSL_IA32_SSE2";    }
1678             }
1679         }
1680 if ($md5_obj =~ /\.o$/)
1681         {
1682 #       $md5_obj=$md5_enc;
1683         $cflags.=" -DMD5_ASM";
1684         }
1685 if ($rmd160_obj =~ /\.o$/)
1686         {
1687 #       $rmd160_obj=$rmd160_enc;
1688         $cflags.=" -DRMD160_ASM";
1689         }
1690 if ($aes_obj =~ /\.o$/)
1691         {
1692         $cflags.=" -DAES_ASM" if ($aes_obj =~ m/\baes\-/);;
1693         # aes-ctr.o is not a real file, only indication that assembler
1694         # module implements AES_ctr32_encrypt...
1695         $cflags.=" -DAES_CTR_ASM" if ($aes_obj =~ s/\s*aes\-ctr\.o//);
1696         # aes-xts.o indicates presence of AES_xts_[en|de]crypt...
1697         $cflags.=" -DAES_XTS_ASM" if ($aes_obj =~ s/\s*aes\-xts\.o//);
1698         $aes_obj =~ s/\s*(vpaes|aesni)\-x86\.o//g if ($no_sse2);
1699         $cflags.=" -DVPAES_ASM" if ($aes_obj =~ m/vpaes/);
1700         $cflags.=" -DBSAES_ASM" if ($aes_obj =~ m/bsaes/);
1701         }
1702 else    {
1703         $aes_obj=$aes_enc;
1704         }
1705 $wp_obj="" if ($wp_obj =~ /mmx/ && $processor eq "386");
1706 if ($wp_obj =~ /\.o$/ && !$disabled{"whirlpool"})
1707         {
1708         $cflags.=" -DWHIRLPOOL_ASM";
1709         }
1710 else    {
1711         $wp_obj="wp_block.o";
1712         }
1713 $cmll_obj=$cmll_enc     unless ($cmll_obj =~ /.o$/);
1714 if ($modes_obj =~ /ghash\-/)
1715         {
1716         $cflags.=" -DGHASH_ASM";
1717         }
1718 if ($ec_obj =~ /ecp_nistz256/)
1719         {
1720         $cflags.=" -DECP_NISTZ256_ASM";
1721         }
1722
1723 # "Stringify" the C flags string.  This permits it to be made part of a string
1724 # and works as well on command lines.
1725 $cflags =~ s/([\\\"])/\\\1/g;
1726
1727 my $version = "unknown";
1728 my $version_num = "unknown";
1729 my $major = "unknown";
1730 my $minor = "unknown";
1731 my $shlib_version_number = "unknown";
1732 my $shlib_version_history = "unknown";
1733 my $shlib_major = "unknown";
1734 my $shlib_minor = "unknown";
1735
1736 open(IN,'<crypto/opensslv.h') || die "unable to read opensslv.h:$!\n";
1737 while (<IN>)
1738         {
1739         $version=$1 if /OPENSSL.VERSION.TEXT.*OpenSSL (\S+) /;
1740         $version_num=$1 if /OPENSSL.VERSION.NUMBER.*0x(\S+)/;
1741         $shlib_version_number=$1 if /SHLIB_VERSION_NUMBER *"([^"]+)"/;
1742         $shlib_version_history=$1 if /SHLIB_VERSION_HISTORY *"([^"]*)"/;
1743         }
1744 close(IN);
1745 if ($shlib_version_history ne "") { $shlib_version_history .= ":"; }
1746
1747 if ($version =~ /(^[0-9]*)\.([0-9\.]*)/)
1748         {
1749         $major=$1;
1750         $minor=$2;
1751         }
1752
1753 if ($shlib_version_number =~ /(^[0-9]*)\.([0-9\.]*)/)
1754         {
1755         $shlib_major=$1;
1756         $shlib_minor=$2;
1757         }
1758
1759 if ($strict_warnings)
1760         {
1761         my $wopt;
1762         die "ERROR --strict-warnings requires gcc or clang" unless ($cc =~ /gcc$/ or $cc =~ /clang$/);
1763         foreach $wopt (split /\s+/, $gcc_devteam_warn)
1764                 {
1765                 $cflags .= " $wopt" unless ($cflags =~ /$wopt/)
1766                 }
1767         }
1768
1769 open(IN,"<Makefile.org") || die "unable to read Makefile.org:$!\n";
1770 unlink("$Makefile.new") || die "unable to remove old $Makefile.new:$!\n" if -e "$Makefile.new";
1771 open(OUT,">$Makefile.new") || die "unable to create $Makefile.new:$!\n";
1772 print OUT "### Generated automatically from Makefile.org by Configure.\n\n";
1773 my $sdirs=0;
1774
1775 while (<IN>)
1776         {
1777         chomp;
1778         $sdirs = 1 if /^SDIRS=/;
1779         if ($sdirs) {
1780                 my $dir;
1781                 foreach $dir (@skip) {
1782                         s/(\s)$dir /$1/;
1783                         s/\s$dir$//;
1784                         }
1785                 }
1786         $sdirs = 0 unless /\\$/;
1787         s/fips // if (/^DIRS=/ && !$fips);
1788         s/engines // if (/^DIRS=/ && $disabled{"engine"});
1789         s/ccgost// if (/^ENGDIRS=/ && $disabled{"gost"});
1790         s/^VERSION=.*/VERSION=$version/;
1791         s/^MAJOR=.*/MAJOR=$major/;
1792         s/^MINOR=.*/MINOR=$minor/;
1793         s/^SHLIB_VERSION_NUMBER=.*/SHLIB_VERSION_NUMBER=$shlib_version_number/;
1794         s/^SHLIB_VERSION_HISTORY=.*/SHLIB_VERSION_HISTORY=$shlib_version_history/;
1795         s/^SHLIB_MAJOR=.*/SHLIB_MAJOR=$shlib_major/;
1796         s/^SHLIB_MINOR=.*/SHLIB_MINOR=$shlib_minor/;
1797         s/^SHLIB_EXT=.*/SHLIB_EXT=$shared_extension/;
1798         s/^INSTALLTOP=.*$/INSTALLTOP=$prefix/;
1799         s/^MULTILIB=.*$/MULTILIB=$multilib/;
1800         s/^OPENSSLDIR=.*$/OPENSSLDIR=$openssldir/;
1801         s/^LIBDIR=.*$/LIBDIR=$libdir/;
1802         s/^INSTALL_PREFIX=.*$/INSTALL_PREFIX=$install_prefix/;
1803         s/^PLATFORM=.*$/PLATFORM=$target/;
1804         s/^OPTIONS=.*$/OPTIONS=$options/;
1805         s/^CONFIGURE_ARGS=.*$/CONFIGURE_ARGS=$argvstring/;
1806         if ($cross_compile_prefix)
1807                 {
1808                 s/^CC=.*$/CROSS_COMPILE= $cross_compile_prefix\nCC= \$\(CROSS_COMPILE\)$cc/;
1809                 s/^AR=\s*/AR= \$\(CROSS_COMPILE\)/;
1810                 s/^NM=\s*/NM= \$\(CROSS_COMPILE\)/;
1811                 s/^RANLIB=\s*/RANLIB= \$\(CROSS_COMPILE\)/;
1812                 s/^MAKEDEPPROG=.*$/MAKEDEPPROG= \$\(CROSS_COMPILE\)$cc/ if $cc eq "gcc";
1813                 }
1814         else    {
1815                 s/^CC=.*$/CC= $cc/;
1816                 s/^AR=\s*ar/AR= $ar/;
1817                 s/^RANLIB=.*/RANLIB= $ranlib/;
1818                 s/^MAKEDEPPROG=.*$/MAKEDEPPROG= $cc/ if $cc eq "gcc" || ($cc eq 'cc' && $target =~ /darwin/);
1819                 }
1820         s/^CFLAG=.*$/CFLAG= $cflags/;
1821         s/^DEPFLAG=.*$/DEPFLAG=$depflags/;
1822         s/^PEX_LIBS=.*$/PEX_LIBS= $prelflags/;
1823         s/^EX_LIBS=.*$/EX_LIBS= $lflags/;
1824         s/^EXE_EXT=.*$/EXE_EXT= $exe_ext/;
1825         s/^CPUID_OBJ=.*$/CPUID_OBJ= $cpuid_obj/;
1826         s/^BN_ASM=.*$/BN_ASM= $bn_obj/;
1827         s/^EC_ASM=.*$/EC_ASM= $ec_obj/;
1828         s/^DES_ENC=.*$/DES_ENC= $des_obj/;
1829         s/^AES_ENC=.*$/AES_ENC= $aes_obj/;
1830         s/^BF_ENC=.*$/BF_ENC= $bf_obj/;
1831         s/^CAST_ENC=.*$/CAST_ENC= $cast_obj/;
1832         s/^RC4_ENC=.*$/RC4_ENC= $rc4_obj/;
1833         s/^RC5_ENC=.*$/RC5_ENC= $rc5_obj/;
1834         s/^MD5_ASM_OBJ=.*$/MD5_ASM_OBJ= $md5_obj/;
1835         s/^SHA1_ASM_OBJ=.*$/SHA1_ASM_OBJ= $sha1_obj/;
1836         s/^RMD160_ASM_OBJ=.*$/RMD160_ASM_OBJ= $rmd160_obj/;
1837         s/^WP_ASM_OBJ=.*$/WP_ASM_OBJ= $wp_obj/;
1838         s/^CMLL_ENC=.*$/CMLL_ENC= $cmll_obj/;
1839         s/^MODES_ASM_OBJ.=*$/MODES_ASM_OBJ= $modes_obj/;
1840         s/^ENGINES_ASM_OBJ.=*$/ENGINES_ASM_OBJ= $engines_obj/;
1841         s/^PERLASM_SCHEME=.*$/PERLASM_SCHEME= $perlasm_scheme/;
1842         s/^PROCESSOR=.*/PROCESSOR= $processor/;
1843         s/^ARFLAGS=.*/ARFLAGS= $arflags/;
1844         s/^PERL=.*/PERL= $perl/;
1845         s/^KRB5_INCLUDES=.*/KRB5_INCLUDES=$withargs{"krb5-include"}/;
1846         s/^LIBKRB5=.*/LIBKRB5=$withargs{"krb5-lib"}/;
1847         s/^LIBZLIB=.*/LIBZLIB=$withargs{"zlib-lib"}/;
1848         s/^ZLIB_INCLUDE=.*/ZLIB_INCLUDE=$withargs{"zlib-include"}/;
1849         s/^FIPSLIBDIR=.*/FIPSLIBDIR=$fipslibdir/;
1850         s/^FIPSCANLIB=.*/FIPSCANLIB=libcrypto/ if $fips;
1851         s/^SHARED_FIPS=.*/SHARED_FIPS=/;
1852         s/^SHLIBDIRS=.*/SHLIBDIRS= crypto ssl/;
1853         s/^BASEADDR=.*/BASEADDR=$baseaddr/;
1854         s/^SHLIB_TARGET=.*/SHLIB_TARGET=$shared_target/;
1855         s/^SHLIB_MARK=.*/SHLIB_MARK=$shared_mark/;
1856         s/^SHARED_LIBS=.*/SHARED_LIBS=\$(SHARED_CRYPTO) \$(SHARED_SSL)/ if (!$no_shared);
1857         if ($shared_extension ne "" && $shared_extension =~ /^\.s([ol])\.[^\.]*$/)
1858                 {
1859                 my $sotmp = $1;
1860                 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.s$sotmp/;
1861                 }
1862         elsif ($shared_extension ne "" && $shared_extension =~ /^\.[^\.]*\.dylib$/)
1863                 {
1864                 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.dylib/;
1865                 }
1866         elsif ($shared_extension ne "" && $shared_extension =~ /^\.s([ol])\.[^\.]*\.[^\.]*$/)
1867                 {
1868                 my $sotmp = $1;
1869                 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.s$sotmp.\$(SHLIB_MAJOR) .s$sotmp/;
1870                 }
1871         elsif ($shared_extension ne "" && $shared_extension =~ /^\.[^\.]*\.[^\.]*\.dylib$/)
1872                 {
1873                 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.\$(SHLIB_MAJOR).dylib .dylib/;
1874                 }
1875         s/^SHARED_LDFLAGS=.*/SHARED_LDFLAGS=$shared_ldflag/;
1876         print OUT $_."\n";
1877         }
1878 close(IN);
1879 close(OUT);
1880 rename($Makefile,"$Makefile.bak") || die "unable to rename $Makefile\n" if -e $Makefile;
1881 rename("$Makefile.new",$Makefile) || die "unable to rename $Makefile.new\n";
1882
1883 print "CC            =$cc\n";
1884 print "CFLAG         =$cflags\n";
1885 print "EX_LIBS       =$lflags\n";
1886 print "CPUID_OBJ     =$cpuid_obj\n";
1887 print "BN_ASM        =$bn_obj\n";
1888 print "EC_ASM        =$ec_obj\n";
1889 print "DES_ENC       =$des_obj\n";
1890 print "AES_ENC       =$aes_obj\n";
1891 print "BF_ENC        =$bf_obj\n";
1892 print "CAST_ENC      =$cast_obj\n";
1893 print "RC4_ENC       =$rc4_obj\n";
1894 print "RC5_ENC       =$rc5_obj\n";
1895 print "MD5_OBJ_ASM   =$md5_obj\n";
1896 print "SHA1_OBJ_ASM  =$sha1_obj\n";
1897 print "RMD160_OBJ_ASM=$rmd160_obj\n";
1898 print "CMLL_ENC      =$cmll_obj\n";
1899 print "MODES_OBJ     =$modes_obj\n";
1900 print "ENGINES_OBJ   =$engines_obj\n";
1901 print "PROCESSOR     =$processor\n";
1902 print "RANLIB        =$ranlib\n";
1903 print "ARFLAGS       =$arflags\n";
1904 print "PERL          =$perl\n";
1905 print "KRB5_INCLUDES =",$withargs{"krb5-include"},"\n"
1906         if $withargs{"krb5-include"} ne "";
1907
1908 my $des_ptr=0;
1909 my $des_risc1=0;
1910 my $des_risc2=0;
1911 my $des_unroll=0;
1912 my $bn_ll=0;
1913 my $def_int=2;
1914 my $rc4_int=$def_int;
1915 my $md2_int=$def_int;
1916 my $idea_int=$def_int;
1917 my $rc2_int=$def_int;
1918 my $rc4_idx=0;
1919 my $rc4_chunk=0;
1920 my $bf_ptr=0;
1921 my @type=("char","short","int","long");
1922 my ($b64l,$b64,$b32,$b16,$b8)=(0,0,1,0,0);
1923 my $export_var_as_fn=0;
1924
1925 my $des_int;
1926
1927 foreach (sort split(/\s+/,$bn_ops))
1928         {
1929         $des_ptr=1 if /DES_PTR/;
1930         $des_risc1=1 if /DES_RISC1/;
1931         $des_risc2=1 if /DES_RISC2/;
1932         $des_unroll=1 if /DES_UNROLL/;
1933         $des_int=1 if /DES_INT/;
1934         $bn_ll=1 if /BN_LLONG/;
1935         $rc4_int=0 if /RC4_CHAR/;
1936         $rc4_int=3 if /RC4_LONG/;
1937         $rc4_idx=1 if /RC4_INDEX/;
1938         $rc4_chunk=1 if /RC4_CHUNK/;
1939         $rc4_chunk=2 if /RC4_CHUNK_LL/;
1940         $md2_int=0 if /MD2_CHAR/;
1941         $md2_int=3 if /MD2_LONG/;
1942         $idea_int=1 if /IDEA_SHORT/;
1943         $idea_int=3 if /IDEA_LONG/;
1944         $rc2_int=1 if /RC2_SHORT/;
1945         $rc2_int=3 if /RC2_LONG/;
1946         $bf_ptr=1 if $_ eq "BF_PTR";
1947         $bf_ptr=2 if $_ eq "BF_PTR2";
1948         ($b64l,$b64,$b32,$b16,$b8)=(0,1,0,0,0) if /SIXTY_FOUR_BIT/;
1949         ($b64l,$b64,$b32,$b16,$b8)=(1,0,0,0,0) if /SIXTY_FOUR_BIT_LONG/;
1950         ($b64l,$b64,$b32,$b16,$b8)=(0,0,1,0,0) if /THIRTY_TWO_BIT/;
1951         ($b64l,$b64,$b32,$b16,$b8)=(0,0,0,1,0) if /SIXTEEN_BIT/;
1952         ($b64l,$b64,$b32,$b16,$b8)=(0,0,0,0,1) if /EIGHT_BIT/;
1953         $export_var_as_fn=1 if /EXPORT_VAR_AS_FN/;
1954         }
1955
1956 open(IN,'<crypto/opensslconf.h.in') || die "unable to read crypto/opensslconf.h.in:$!\n";
1957 unlink("crypto/opensslconf.h.new") || die "unable to remove old crypto/opensslconf.h.new:$!\n" if -e "crypto/opensslconf.h.new";
1958 open(OUT,'>crypto/opensslconf.h.new') || die "unable to create crypto/opensslconf.h.new:$!\n";
1959 print OUT "/* opensslconf.h */\n";
1960 print OUT "/* WARNING: Generated automatically from opensslconf.h.in by Configure. */\n\n";
1961
1962 print OUT "#ifdef  __cplusplus\n";
1963 print OUT "extern \"C\" {\n";
1964 print OUT "#endif\n";
1965 print OUT "/* OpenSSL was configured with the following options: */\n";
1966 my $openssl_algorithm_defines_trans = $openssl_algorithm_defines;
1967 $openssl_experimental_defines =~ s/^\s*#\s*define\s+OPENSSL_NO_(.*)/#ifndef OPENSSL_EXPERIMENTAL_$1\n# ifndef OPENSSL_NO_$1\n#  define OPENSSL_NO_$1\n# endif\n#endif/mg;
1968 $openssl_algorithm_defines_trans =~ s/^\s*#\s*define\s+OPENSSL_(.*)/# if defined(OPENSSL_$1) \&\& !defined($1)\n#  define $1\n# endif/mg;
1969 $openssl_algorithm_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
1970 $openssl_algorithm_defines = "   /* no ciphers excluded */\n" if $openssl_algorithm_defines eq "";
1971 $openssl_thread_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
1972 $openssl_sys_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
1973 $openssl_other_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
1974 print OUT $openssl_sys_defines;
1975 print OUT "#ifndef OPENSSL_DOING_MAKEDEPEND\n\n";
1976 print OUT $openssl_experimental_defines;
1977 print OUT "\n";
1978 print OUT $openssl_algorithm_defines;
1979 print OUT "\n#endif /* OPENSSL_DOING_MAKEDEPEND */\n\n";
1980 print OUT $openssl_thread_defines;
1981 print OUT $openssl_other_defines,"\n";
1982
1983 print OUT "/* The OPENSSL_NO_* macros are also defined as NO_* if the application\n";
1984 print OUT "   asks for it.  This is a transient feature that is provided for those\n";
1985 print OUT "   who haven't had the time to do the appropriate changes in their\n";
1986 print OUT "   applications.  */\n";
1987 print OUT "#ifdef OPENSSL_ALGORITHM_DEFINES\n";
1988 print OUT $openssl_algorithm_defines_trans;
1989 print OUT "#endif\n\n";
1990
1991 print OUT "#define OPENSSL_CPUID_OBJ\n\n" if ($cpuid_obj ne "mem_clr.o");
1992
1993 while (<IN>)
1994         {
1995         if      (/^#define\s+OPENSSLDIR/)
1996                 {
1997                 my $foo = $openssldir;
1998                 $foo =~ s/\\/\\\\/g;
1999                 print OUT "#define OPENSSLDIR \"$foo\"\n";
2000                 }
2001         elsif   (/^#define\s+ENGINESDIR/)
2002                 {
2003                 my $foo = "$prefix/$libdir/engines";
2004                 $foo =~ s/\\/\\\\/g;
2005                 print OUT "#define ENGINESDIR \"$foo\"\n";
2006                 }
2007         elsif   (/^#((define)|(undef))\s+OPENSSL_EXPORT_VAR_AS_FUNCTION/)
2008                 { printf OUT "#undef OPENSSL_EXPORT_VAR_AS_FUNCTION\n"
2009                         if $export_var_as_fn;
2010                   printf OUT "#%s OPENSSL_EXPORT_VAR_AS_FUNCTION\n",
2011                         ($export_var_as_fn)?"define":"undef"; }
2012         elsif   (/^#define\s+OPENSSL_UNISTD/)
2013                 {
2014                 $unistd = "<unistd.h>" if $unistd eq "";
2015                 print OUT "#define OPENSSL_UNISTD $unistd\n";
2016                 }
2017         elsif   (/^#((define)|(undef))\s+SIXTY_FOUR_BIT_LONG/)
2018                 { printf OUT "#%s SIXTY_FOUR_BIT_LONG\n",($b64l)?"define":"undef"; }
2019         elsif   (/^#((define)|(undef))\s+SIXTY_FOUR_BIT/)
2020                 { printf OUT "#%s SIXTY_FOUR_BIT\n",($b64)?"define":"undef"; }
2021         elsif   (/^#((define)|(undef))\s+THIRTY_TWO_BIT/)
2022                 { printf OUT "#%s THIRTY_TWO_BIT\n",($b32)?"define":"undef"; }
2023         elsif   (/^#((define)|(undef))\s+SIXTEEN_BIT/)
2024                 { printf OUT "#%s SIXTEEN_BIT\n",($b16)?"define":"undef"; }
2025         elsif   (/^#((define)|(undef))\s+EIGHT_BIT/)
2026                 { printf OUT "#%s EIGHT_BIT\n",($b8)?"define":"undef"; }
2027         elsif   (/^#((define)|(undef))\s+BN_LLONG\s*$/)
2028                 { printf OUT "#%s BN_LLONG\n",($bn_ll)?"define":"undef"; }
2029         elsif   (/^\#define\s+DES_LONG\s+.*/)
2030                 { printf OUT "#define DES_LONG unsigned %s\n",
2031                         ($des_int)?'int':'long'; }
2032         elsif   (/^\#(define|undef)\s+DES_PTR/)
2033                 { printf OUT "#%s DES_PTR\n",($des_ptr)?'define':'undef'; }
2034         elsif   (/^\#(define|undef)\s+DES_RISC1/)
2035                 { printf OUT "#%s DES_RISC1\n",($des_risc1)?'define':'undef'; }
2036         elsif   (/^\#(define|undef)\s+DES_RISC2/)
2037                 { printf OUT "#%s DES_RISC2\n",($des_risc2)?'define':'undef'; }
2038         elsif   (/^\#(define|undef)\s+DES_UNROLL/)
2039                 { printf OUT "#%s DES_UNROLL\n",($des_unroll)?'define':'undef'; }
2040         elsif   (/^#define\s+RC4_INT\s/)
2041                 { printf OUT "#define RC4_INT unsigned %s\n",$type[$rc4_int]; }
2042         elsif   (/^#undef\s+RC4_CHUNK/)
2043                 {
2044                 printf OUT "#undef RC4_CHUNK\n" if $rc4_chunk==0;
2045                 printf OUT "#define RC4_CHUNK unsigned long\n" if $rc4_chunk==1;
2046                 printf OUT "#define RC4_CHUNK unsigned long long\n" if $rc4_chunk==2;
2047                 }
2048         elsif   (/^#((define)|(undef))\s+RC4_INDEX/)
2049                 { printf OUT "#%s RC4_INDEX\n",($rc4_idx)?"define":"undef"; }
2050         elsif (/^#(define|undef)\s+I386_ONLY/)
2051                 { printf OUT "#%s I386_ONLY\n", ($processor eq "386")?
2052                         "define":"undef"; }
2053         elsif   (/^#define\s+MD2_INT\s/)
2054                 { printf OUT "#define MD2_INT unsigned %s\n",$type[$md2_int]; }
2055         elsif   (/^#define\s+IDEA_INT\s/)
2056                 {printf OUT "#define IDEA_INT unsigned %s\n",$type[$idea_int];}
2057         elsif   (/^#define\s+RC2_INT\s/)
2058                 {printf OUT "#define RC2_INT unsigned %s\n",$type[$rc2_int];}
2059         elsif (/^#(define|undef)\s+BF_PTR/)
2060                 {
2061                 printf OUT "#undef BF_PTR\n" if $bf_ptr == 0;
2062                 printf OUT "#define BF_PTR\n" if $bf_ptr == 1;
2063                 printf OUT "#define BF_PTR2\n" if $bf_ptr == 2;
2064                 }
2065         else
2066                 { print OUT $_; }
2067         }
2068 close(IN);
2069 print OUT "#ifdef  __cplusplus\n";
2070 print OUT "}\n";
2071 print OUT "#endif\n";
2072 close(OUT);
2073 rename("crypto/opensslconf.h","crypto/opensslconf.h.bak") || die "unable to rename crypto/opensslconf.h\n" if -e "crypto/opensslconf.h";
2074 rename("crypto/opensslconf.h.new","crypto/opensslconf.h") || die "unable to rename crypto/opensslconf.h.new\n";
2075
2076
2077 # Fix the date
2078
2079 print "SIXTY_FOUR_BIT_LONG mode\n" if $b64l;
2080 print "SIXTY_FOUR_BIT mode\n" if $b64;
2081 print "THIRTY_TWO_BIT mode\n" if $b32;
2082 print "SIXTEEN_BIT mode\n" if $b16;
2083 print "EIGHT_BIT mode\n" if $b8;
2084 print "DES_PTR used\n" if $des_ptr;
2085 print "DES_RISC1 used\n" if $des_risc1;
2086 print "DES_RISC2 used\n" if $des_risc2;
2087 print "DES_UNROLL used\n" if $des_unroll;
2088 print "DES_INT used\n" if $des_int;
2089 print "BN_LLONG mode\n" if $bn_ll;
2090 print "RC4 uses u$type[$rc4_int]\n" if $rc4_int != $def_int;
2091 print "RC4_INDEX mode\n" if $rc4_idx;
2092 print "RC4_CHUNK is undefined\n" if $rc4_chunk==0;
2093 print "RC4_CHUNK is unsigned long\n" if $rc4_chunk==1;
2094 print "RC4_CHUNK is unsigned long long\n" if $rc4_chunk==2;
2095 print "MD2 uses u$type[$md2_int]\n" if $md2_int != $def_int;
2096 print "IDEA uses u$type[$idea_int]\n" if $idea_int != $def_int;
2097 print "RC2 uses u$type[$rc2_int]\n" if $rc2_int != $def_int;
2098 print "BF_PTR used\n" if $bf_ptr == 1;
2099 print "BF_PTR2 used\n" if $bf_ptr == 2;
2100
2101 if($IsMK1MF) {
2102         open (OUT,">crypto/buildinf.h") || die "Can't open buildinf.h";
2103         printf OUT <<EOF;
2104 #ifndef MK1MF_BUILD
2105   /* auto-generated by Configure for crypto/cversion.c:
2106    * for Unix builds, crypto/Makefile.ssl generates functional definitions;
2107    * Windows builds (and other mk1mf builds) compile cversion.c with
2108    * -DMK1MF_BUILD and use definitions added to this file by util/mk1mf.pl. */
2109   #error "Windows builds (PLATFORM=$target) use mk1mf.pl-created Makefiles"
2110 #endif
2111 EOF
2112         close(OUT);
2113 } else {
2114         my $make_command = "$make PERL=\'$perl\'";
2115         my $make_targets = "";
2116         $make_targets .= " links" if $symlink;
2117         $make_targets .= " depend" if $depflags ne $default_depflags && $make_depend;
2118         $make_targets .= " gentests" if $symlink;
2119         (system $make_command.$make_targets) == 0 or die "make $make_targets failed"
2120                 if $make_targets ne "";
2121         if ( $perl =~ m@^/@) {
2122             &dofile("tools/c_rehash",$perl,'^#!/', '#!%s','^my \$dir;$', 'my $dir = "' . $openssldir . '";', '^my \$prefix;$', 'my $prefix = "' . $prefix . '";');
2123             &dofile("apps/CA.pl",$perl,'^#!/', '#!%s');
2124         } else {
2125             # No path for Perl known ...
2126             &dofile("tools/c_rehash",'/usr/local/bin/perl','^#!/', '#!%s','^my \$dir;$', 'my $dir = "' . $openssldir . '";',  '^my \$prefix;$', 'my $prefix = "' . $prefix . '";');
2127             &dofile("apps/CA.pl",'/usr/local/bin/perl','^#!/', '#!%s');
2128         }
2129         if ($depflags ne $default_depflags && !$make_depend) {
2130                 print <<EOF;
2131
2132 Since you've disabled or enabled at least one algorithm, you need to do
2133 the following before building:
2134
2135         make depend
2136 EOF
2137         }
2138 }
2139
2140 # create the ms/version32.rc file if needed
2141 if ($IsMK1MF && ($target !~ /^netware/)) {
2142         my ($v1, $v2, $v3, $v4);
2143         if ($version_num =~ /(^[0-9a-f]{1})([0-9a-f]{2})([0-9a-f]{2})([0-9a-f]{2})/i) {
2144                 $v1=hex $1;
2145                 $v2=hex $2;
2146                 $v3=hex $3;
2147                 $v4=hex $4;
2148         }
2149         open (OUT,">ms/version32.rc") || die "Can't open ms/version32.rc";
2150         print OUT <<EOF;
2151 #include <winver.h>
2152
2153 LANGUAGE 0x09,0x01
2154
2155 1 VERSIONINFO
2156   FILEVERSION $v1,$v2,$v3,$v4
2157   PRODUCTVERSION $v1,$v2,$v3,$v4
2158   FILEFLAGSMASK 0x3fL
2159 #ifdef _DEBUG
2160   FILEFLAGS 0x01L
2161 #else
2162   FILEFLAGS 0x00L
2163 #endif
2164   FILEOS VOS__WINDOWS32
2165   FILETYPE VFT_DLL
2166   FILESUBTYPE 0x0L
2167 BEGIN
2168     BLOCK "StringFileInfo"
2169     BEGIN
2170         BLOCK "040904b0"
2171         BEGIN
2172             // Required:
2173             VALUE "CompanyName", "The OpenSSL Project, http://www.openssl.org/\\0"
2174             VALUE "FileDescription", "OpenSSL Shared Library\\0"
2175             VALUE "FileVersion", "$version\\0"
2176 #if defined(CRYPTO)
2177             VALUE "InternalName", "libeay32\\0"
2178             VALUE "OriginalFilename", "libeay32.dll\\0"
2179 #elif defined(SSL)
2180             VALUE "InternalName", "ssleay32\\0"
2181             VALUE "OriginalFilename", "ssleay32.dll\\0"
2182 #endif
2183             VALUE "ProductName", "The OpenSSL Toolkit\\0"
2184             VALUE "ProductVersion", "$version\\0"
2185             // Optional:
2186             //VALUE "Comments", "\\0"
2187             VALUE "LegalCopyright", "Copyright Â© 1998-2005 The OpenSSL Project. Copyright Â© 1995-1998 Eric A. Young, Tim J. Hudson. All rights reserved.\\0"
2188             //VALUE "LegalTrademarks", "\\0"
2189             //VALUE "PrivateBuild", "\\0"
2190             //VALUE "SpecialBuild", "\\0"
2191         END
2192     END
2193     BLOCK "VarFileInfo"
2194     BEGIN
2195         VALUE "Translation", 0x409, 0x4b0
2196     END
2197 END
2198 EOF
2199         close(OUT);
2200   }
2201
2202 print <<EOF;
2203
2204 Configured for $target.
2205 EOF
2206
2207 print <<\EOF if (!$no_threads && !$threads);
2208
2209 The library could not be configured for supporting multi-threaded
2210 applications as the compiler options required on this system are not known.
2211 See file INSTALL for details if you need multi-threading.
2212 EOF
2213
2214 print <<\EOF if ($no_shared_warn);
2215
2216 You gave the option 'shared'.  Normally, that would give you shared libraries.
2217 Unfortunately, the OpenSSL configuration doesn't include shared library support
2218 for this platform yet, so it will pretend you gave the option 'no-shared'.  If
2219 you can inform the developpers (openssl-dev\@openssl.org) how to support shared
2220 libraries on this platform, they will at least look at it and try their best
2221 (but please first make sure you have tried with a current version of OpenSSL).
2222 EOF
2223
2224 exit(0);
2225
2226 sub usage
2227         {
2228         print STDERR $usage;
2229         print STDERR "\npick os/compiler from:\n";
2230         my $j=0;
2231         my $i;
2232         my $k=0;
2233         foreach $i (sort keys %table)
2234                 {
2235                 next if $i =~ /^debug/;
2236                 $k += length($i) + 1;
2237                 if ($k > 78)
2238                         {
2239                         print STDERR "\n";
2240                         $k=length($i);
2241                         }
2242                 print STDERR $i . " ";
2243                 }
2244         foreach $i (sort keys %table)
2245                 {
2246                 next if $i !~ /^debug/;
2247                 $k += length($i) + 1;
2248                 if ($k > 78)
2249                         {
2250                         print STDERR "\n";
2251                         $k=length($i);
2252                         }
2253                 print STDERR $i . " ";
2254                 }
2255         print STDERR "\n\nNOTE: If in doubt, on Unix-ish systems use './config'.\n";
2256         exit(1);
2257         }
2258
2259 sub which
2260         {
2261         my($name)=@_;
2262         my $path;
2263         foreach $path (split /:/, $ENV{PATH})
2264                 {
2265                 if (-f "$path/$name$exe_ext" and -x _)
2266                         {
2267                         return "$path/$name$exe_ext" unless ($name eq "perl" and
2268                          system("$path/$name$exe_ext -e " . '\'exit($]<5.0);\''));
2269                         }
2270                 }
2271         }
2272
2273 sub dofile
2274         {
2275         my $f; my $p; my %m; my @a; my $k; my $ff;
2276         ($f,$p,%m)=@_;
2277
2278         open(IN,"<$f.in") || open(IN,"<$f") || die "unable to open $f:$!\n";
2279         @a=<IN>;
2280         close(IN);
2281         foreach $k (keys %m)
2282                 {
2283                 grep(/$k/ && ($_=sprintf($m{$k}."\n",$p)),@a);
2284                 }
2285         open(OUT,">$f.new") || die "unable to open $f.new:$!\n";
2286         print OUT @a;
2287         close(OUT);
2288         rename($f,"$f.bak") || die "unable to rename $f\n" if -e $f;
2289         rename("$f.new",$f) || die "unable to rename $f.new\n";
2290         }
2291
2292 sub print_table_entry
2293         {
2294         my $target = shift;
2295         my $type = shift;
2296
2297         # Don't print the templates
2298         return if $table{$target}->{template};
2299
2300         if ($type eq "TABLE") {
2301             print <<EOF
2302
2303 *** $target
2304 \$cc           = $table{$target}->{cc}
2305 \$cflags       = $table{$target}->{cflags}
2306 \$debug_cflags   = $table{$target}->{debug_cflags}
2307 \$release_cflags = $table{$target}->{release_cflags}
2308 \$unistd       = $table{$target}->{unistd}
2309 \$thread_cflag = $table{$target}->{thread_cflag}
2310 \$sys_id       = $table{$target}->{sys_id}
2311 \$lflags       = $table{$target}->{lflags}
2312 \$debug_lflags   = $table{$target}->{debug_lflags}
2313 \$release_lflags = $table{$target}->{release_lflags}
2314 \$bn_ops       = $table{$target}->{bn_ops}
2315 \$cpuid_obj    = $table{$target}->{cpuid_obj}
2316 \$bn_obj       = $table{$target}->{bn_obj}
2317 \$ec_obj       = $table{$target}->{ec_obj}
2318 \$des_obj      = $table{$target}->{des_obj}
2319 \$aes_obj      = $table{$target}->{aes_obj}
2320 \$bf_obj       = $table{$target}->{bf_obj}
2321 \$md5_obj      = $table{$target}->{md5_obj}
2322 \$sha1_obj     = $table{$target}->{sha1_obj}
2323 \$cast_obj     = $table{$target}->{cast_obj}
2324 \$rc4_obj      = $table{$target}->{rc4_obj}
2325 \$rmd160_obj   = $table{$target}->{rmd160_obj}
2326 \$rc5_obj      = $table{$target}->{rc5_obj}
2327 \$wp_obj       = $table{$target}->{wp_obj}
2328 \$cmll_obj     = $table{$target}->{cmll_obj}
2329 \$modes_obj    = $table{$target}->{modes_obj}
2330 \$engines_obj  = $table{$target}->{engines_obj}
2331 \$perlasm_scheme = $table{$target}->{perlasm_scheme}
2332 \$dso_scheme   = $table{$target}->{dso_scheme}
2333 \$shared_target= $table{$target}->{shared_target}
2334 \$shared_cflag = $table{$target}->{shared_cflag}
2335 \$shared_ldflag = $table{$target}->{shared_ldflag}
2336 \$shared_extension = $table{$target}->{shared_extension}
2337 \$ranlib       = $table{$target}->{ranlib}
2338 \$arflags      = $table{$target}->{arflags}
2339 \$multilib     = $table{$target}->{multilib}
2340 EOF
2341         } elsif ($type eq "HASH") {
2342             my @sequence = (
2343                 "cc",
2344                 "cflags",
2345                 "debug_cflags",
2346                 "release_cflags",
2347                 "unistd",
2348                 "thread_cflag",
2349                 "sys_id",
2350                 "lflags",
2351                 "debug_lflags",
2352                 "release_lflags",
2353                 "bn_ops",
2354                 "cpuid_obj",
2355                 "bn_obj",
2356                 "ec_obj",
2357                 "des_obj",
2358                 "aes_obj",
2359                 "bf_obj",
2360                 "md5_obj",
2361                 "sha1_obj",
2362                 "cast_obj",
2363                 "rc4_obj",
2364                 "rmd160_obj",
2365                 "rc5_obj",
2366                 "wp_obj",
2367                 "cmll_obj",
2368                 "modes_obj",
2369                 "engines_obj",
2370                 "perlasm_scheme",
2371                 "dso_scheme",
2372                 "shared_target",
2373                 "shared_cflag",
2374                 "shared_ldflag",
2375                 "shared_extension",
2376                 "ranlib",
2377                 "arflags",
2378                 "multilib",
2379                 );
2380             my $largest =
2381                 length((sort { length($a) <=> length($b) } @sequence)[-1]);
2382             print "    '$target' => {\n";
2383             foreach (@sequence) {
2384                 if ($table{$target}->{$_}) {
2385                     print "      '",$_,"'"," " x ($largest - length($_))," => '",$table{$target}->{$_},"',\n";
2386                 }
2387             }
2388             print "    },\n";
2389         }
2390         }
2391
2392 sub test_sanity
2393         {
2394         my $errorcnt = 0;
2395
2396         print STDERR "=" x 70, "\n";
2397         print STDERR "=== SANITY TESTING!\n";
2398         print STDERR "=== No configuration will be done, all other arguments will be ignored!\n";
2399         print STDERR "=" x 70, "\n";
2400
2401         foreach $target (sort keys %table)
2402                 {
2403                 my $pre_dso_scheme = "perlasm_scheme";
2404                 my $dso_scheme = "dso_scheme";
2405                 my $post_dso_scheme = "shared_target";
2406
2407
2408                 if ($table{$target}->{$pre_dso_scheme} =~ /^(beos|dl|dlfcn|win32|vms)$/)
2409                         {
2410                         $errorcnt++;
2411                         print STDERR "SANITY ERROR: '$target' has the dso_scheme values\n";
2412                         print STDERR "              in the previous field\n";
2413                         }
2414                 elsif ($table{$target}->{$post_dso_scheme} =~ /^(beos|dl|dlfcn|win32|vms)$/)
2415                         {
2416                         $errorcnt++;
2417                         print STDERR "SANITY ERROR: '$target' has the dso_scheme values\n";
2418                         print STDERR "              in the following field\n";
2419                         }
2420                 elsif ($table{$target}->{$dso_scheme} !~ /^(beos|dl|dlfcn|win32|vms|)$/)
2421                         {
2422                         $errorcnt++;
2423                         print STDERR "SANITY ERROR: '$target' has the dso_scheme field = ",$table{$target}->{$dso_scheme},"\n";
2424                         print STDERR "              valid values are 'beos', 'dl', 'dlfcn', 'win32' and 'vms'\n";
2425                         }
2426                 }
2427         print STDERR "No sanity errors detected!\n" if $errorcnt == 0;
2428         return $errorcnt;
2429         }