Refactor config - @MK1MF_Builds out, general build scheme in
[openssl.git] / Configure
index 594d917b362a4cba19a0db910a2d308c29ca053f..96f88b253de343d2ca500880c767a41aa4800b51 100755 (executable)
--- a/Configure
+++ b/Configure
@@ -14,25 +14,27 @@ use File::Spec::Functions;
 
 # see INSTALL for instructions.
 
-my $usage="Usage: Configure [no-<cipher> ...] [enable-<cipher> ...] [experimental-<cipher> ...] [-Dxxx] [-lxxx] [-Lxxx] [-fxxx] [-Kxxx] [no-hw-xxx|no-hw] [[no-]threads] [[no-]shared] [[no-]zlib|zlib-dynamic] [no-asm] [no-dso] [no-egd] [sctp] [386] [--prefix=DIR] [--openssldir=OPENSSLDIR] [--with-xxx[=vvv]] [--test-sanity] [--config=FILE] os/compiler[:flags]\n";
+my $usage="Usage: Configure [no-<cipher> ...] [enable-<cipher> ...] [experimental-<cipher> ...] [-Dxxx] [-lxxx] [-Lxxx] [-fxxx] [-Kxxx] [no-hw-xxx|no-hw] [[no-]threads] [[no-]shared] [[no-]zlib|zlib-dynamic] [no-asm] [no-dso] [no-egd] [sctp] [386] [--prefix=DIR] [--openssldir=OPENSSLDIR] [--with-xxx[=vvv]] [--config=FILE] os/compiler[:flags]\n";
 
 # Options:
 #
 # --config      add the given configuration file, which will be read after
 #               any "Configurations*" files that are found in the same
 #               directory as this script.
-# --openssldir  install OpenSSL in OPENSSLDIR (Default: DIR/ssl if the
-#               --prefix option is given; /usr/local/ssl otherwise)
-# --prefix      prefix for the OpenSSL include, lib and bin directories
-#               (Default: the OPENSSLDIR directory)
+# --prefix      prefix for the OpenSSL installation, which includes the
+#               directories bin, lib, include, share/man, share/doc/openssl
+#               This becomes the value of INSTALLTOP in Makefile
+#               (Default: /usr/local)
+# --openssldir  OpenSSL data area, such as openssl.cnf, certificates and keys.
+#               If it's a relative directory, it will be added on the directory
+#               given with --prefix.
+#               This becomes the value of OPENSSLDIR in Makefile and in C.
+#               (Default: PREFIX/ssl)
 #
 # --install_prefix  Additional prefix for package builders (empty by
 #               default).  This needn't be set in advance, you can
 #               just as well use "make INSTALL_PREFIX=/whatever install".
 #
-# --test-sanity Make a number of sanity checks on the data in this file.
-#               This is a debugging tool for OpenSSL developers.
-#
 # --cross-compile-prefix Add specified prefix to binutils components.
 #
 # --api         One of 0.9.8, 1.0.0 or 1.1.0.  Do not compile support for
@@ -146,283 +148,8 @@ my $apitable = {
     "0.9.8" => "0x00908000L",
 };
 
-# table of known configurations, read in from files
-#
-# The content of each entry comes in the form of config hash table,
-# which has additional attributes for debug and non-debug flags to be
-# added to the common flags, for cflags and lflags:
-#
-#      {
-#        cc => $cc,
-#        cflags => $cflags,
-#        debug_cflags => $debug_cflags,
-#        release_cflags => $release_cflags,
-#        unistd => $unistd,
-#        thread_cflag => $thread_cflag,
-#        sys_id => $sys_id,
-#        lflags => $lflags,
-#        debug_lflags => $debug_lflags,
-#        release_lflags => $release_lflags,
-#        bn_ops => $bn_ops,
-#        cpuid_obj => $cpuid_obj,
-#        bn_obj => $bn_obj,
-#        ec_obj => $ec_obj,
-#        des_obj => $des_obj,
-#        aes_obj => $aes_obj,
-#        bf_obj => $bf_obj,
-#        md5_obj => $md5_obj,
-#        sha1_obj => $sha1_obj,
-#        cast_obj => $cast_obj,
-#        rc4_obj => $rc4_obj,
-#        rmd160_obj => $rmd160_obj,
-#        rc5_obj => $rc5_obj,
-#        wp_obj => $wp_obj,
-#        cmll_obj => $cmll_obj,
-#        modes_obj => $modes_obj,
-#        engines_obj => $engines_obj,
-#        chacha_obj => $wp_obj,
-#        poly1305_obj => $cmll_obj,
-#        dso_scheme => $dso_scheme,
-#        shared_target => $shared_target,
-#        shared_cflag => $shared_cflag,
-#        shared_ldflag => $shared_ldflag,
-#        shared_extension => $shared_extension,
-#        ranlib => $ranlib,
-#        arflags => $arflags,
-#        multilib => $multilib
-#      }
-#
-# The configuration hashes can refer to templates in two different manners:
-#
-# - as part of the hash, one can have a key called 'inherit_from' that
-#   indicate what other configuration hashes to inherit data from.
-#   These are resolved recursively.
-#
-#   Inheritance works as a set of default values that can be overriden
-#   by corresponding attribute values in the inheriting configuration.
-#
-#   If several configurations are given in the 'inherit_from' array, the
-#   values of same attribute are concatenated with space separation.
-#   With this, it's possible to have several smaller templates for
-#   different configuration aspects that can be combined into a complete
-#   configuration.
-#
-#   Example:
-#
-#      "foo" => {
-#              template => 1,
-#              haha => "haha",
-#              hoho => "ho"
-#      },
-#      "bar" => {
-#              template => 1,
-#              hoho => "ho",
-#              hehe => "hehe"
-#      },
-#      "laughter" => {
-#              inherit_from => [ "foo", "bar" ],
-#      }
-#
-#      The entry for "foo" will become as follows after processing:
-#
-#      "laughter" => {
-#              haha => "haha",
-#              hoho => "ho ho",
-#              hehe => "hehe"
-#      }
-#
-#   Note 1: any entry from the table can be used as a template.
-#   Note 2: pure templates have the attribute 'template => 1' and cannot
-#           be used as targets.
-#
-# - instead of a string, one can have a code block of the form
-#   'sub { /* your code here */ }', where the arguments are the list of
-#   inherited values for that key.  In fact, the concatenation of strings
-#   is really done by using 'sub { join(" ",@_) }' on the list of inherited
-#   values.
-#
-#   Example:
-#
-#      "foo" => {
-#              template => 1,
-#              haha => "ha ha",
-#              hoho => "ho",
-#              ignored => "This should not appear in the end result",
-#      },
-#      "bar" => {
-#              template => 1,
-#              haha => "ah",
-#              hoho => "haho",
-#              hehe => "hehe"
-#      },
-#      "laughter" => {
-#              inherit_from => [ "foo", "bar" ],
-#              hehe => sub { join(" ",(@_,"!!!")) },
-#              ignored => "",
-#      }
-#
-#      The entry for "foo" will become as follows after processing:
-#
-#      "laughter" => {
-#              haha => "ha ha ah",
-#              hoho => "ho haho",
-#              hehe => "hehe !!!",
-#              ignored => ""
-#      }
-#
-
-our %table=(
-
-    # All these templates are merely a translation of the corresponding
-    # variables further up.
-    #
-    # Note: as long as someone might use old style configuration strings,
-    # or we bother supporting that, those variables need to stay
-
-    x86_asm => {
-       template        => 1,
-       cpuid_obj       => "x86cpuid.o",
-       bn_obj          => "bn-586.o co-586.o x86-mont.o x86-gf2m.o",
-       ec_obj          => "ecp_nistz256.o ecp_nistz256-x86.o",
-       des_obj         => "des-586.o crypt586.o",
-       aes_obj         => "aes-586.o vpaes-x86.o aesni-x86.o",
-       bf_obj          => "bf-586.o",
-       md5_obj         => "md5-586.o",
-       sha1_obj        => "sha1-586.o sha256-586.o sha512-586.o",
-       rc4_obj         => "rc4-586.o",
-       rmd160_obj      => "rmd-586.o",
-       rc5_obj         => "rc5-586.o",
-       wp_obj          => "wp_block.o wp-mmx.o",
-       cmll_obj        => "cmll-x86.o",
-       modes_obj       => "ghash-x86.o",
-       engines_obj     => "e_padlock-x86.o"
-    },
-    x86_elf_asm => {
-       template        => 1,
-       inherit_from    => [ "x86_asm" ],
-       perlasm_scheme  => "elf"
-    },
-    x86_64_asm => {
-       template        => 1,
-       cpuid_obj       => "x86_64cpuid.o",
-       bn_obj          => "x86_64-gcc.o x86_64-mont.o x86_64-mont5.o x86_64-gf2m.o rsaz_exp.o rsaz-x86_64.o rsaz-avx2.o",
-       ec_obj          => "ecp_nistz256.o ecp_nistz256-x86_64.o",
-       aes_obj         => "aes-x86_64.o vpaes-x86_64.o bsaes-x86_64.o aesni-x86_64.o aesni-sha1-x86_64.o aesni-sha256-x86_64.o aesni-mb-x86_64.o",
-       md5_obj         => "md5-x86_64.o",
-       sha1_obj        => "sha1-x86_64.o sha256-x86_64.o sha512-x86_64.o sha1-mb-x86_64.o sha256-mb-x86_64.o",
-       rc4_obj         => "rc4-x86_64.o rc4-md5-x86_64.o",
-       wp_obj          => "wp-x86_64.o",
-       cmll_obj        => "cmll-x86_64.o cmll_misc.o",
-       modes_obj       => "ghash-x86_64.o aesni-gcm-x86_64.o",
-       engines_obj     => "e_padlock-x86_64.o"
-    },
-    ia64_asm => {
-       template        => 1,
-       cpuid_obj       => "ia64cpuid.o",
-       bn_obj          => "bn-ia64.o ia64-mont.o",
-       aes_obj         => "aes_core.o aes_cbc.o aes-ia64.o",
-       md5_obj         => "md5-ia64.o",
-       sha1_obj        => "sha1-ia64.o sha256-ia64.o sha512-ia64.o",
-       rc4_obj         => "rc4-ia64.o rc4_skey.o",
-       modes_obj       => "ghash-ia64.o",
-       perlasm_scheme  => "void"
-    },
-    sparcv9_asm => {
-       template        => 1,
-       cpuid_obj       => "sparcv9cap.o sparccpuid.o",
-       bn_obj          => "bn-sparcv9.o sparcv9-mont.o sparcv9a-mont.o vis3-mont.o sparct4-mont.o sparcv9-gf2m.o",
-        ec_obj          => "ecp_nistz256.o ecp_nistz256-sparcv9.o",
-       des_obj         => "des_enc-sparc.o fcrypt_b.o dest4-sparcv9.o",
-       aes_obj         => "aes_core.o aes_cbc.o aes-sparcv9.o aest4-sparcv9.o",
-       md5_obj         => "md5-sparcv9.o",
-       sha1_obj        => "sha1-sparcv9.o sha256-sparcv9.o sha512-sparcv9.o",
-       cmll_obj        => "camellia.o cmll_misc.o cmll_cbc.o cmllt4-sparcv9.o",
-       modes_obj       => "ghash-sparcv9.o",
-       perlasm_scheme  => "void"
-    },
-    sparcv8_asm => {
-       template        => 1,
-       cpuid_obj       => "",
-       bn_obj          => "sparcv8.o",
-       des_obj         => "des_enc-sparc.o fcrypt_b.o",
-       perlasm_scheme  => "void"
-    },
-    alpha_asm => {
-       template        => 1,
-       cpuid_obj       => "alphacpuid.o",
-       bn_obj          => "bn_asm.o alpha-mont.o",
-       sha1_obj        => "sha1-alpha.o",
-       modes_obj       => "ghash-alpha.o",
-       perlasm_scheme  => "void"
-    },
-    mips32_asm => {
-       template        => 1,
-       bn_obj          => "bn-mips.o mips-mont.o",
-       aes_obj         => "aes_cbc.o aes-mips.o",
-       sha1_obj        => "sha1-mips.o sha256-mips.o",
-    },
-    mips64_asm => {
-       inherit_from    => [ "mips32_asm" ],
-       template        => 1,
-       sha1_obj        => sub { join(" ", @_, "sha512-mips.o") }
-    },
-    s390x_asm => {
-       template        => 1,
-       cpuid_obj       => "s390xcap.o s390xcpuid.o",
-       bn_obj          => "bn-s390x.o s390x-mont.o s390x-gf2m.o",
-       aes_obj         => "aes-s390x.o aes-ctr.o aes-xts.o",
-       sha1_obj        => "sha1-s390x.o sha256-s390x.o sha512-s390x.o",
-       rc4_obj         => "rc4-s390x.o",
-       modes_obj       => "ghash-s390x.o",
-    },
-    armv4_asm => {
-       template        => 1,
-       cpuid_obj       => "armcap.o armv4cpuid.o",
-       bn_obj          => "bn_asm.o armv4-mont.o armv4-gf2m.o",
-       ec_obj          => "ecp_nistz256.o ecp_nistz256-armv4.o",
-       aes_obj         => "aes_cbc.o aes-armv4.o bsaes-armv7.o aesv8-armx.o",
-       sha1_obj        => "sha1-armv4-large.o sha256-armv4.o sha512-armv4.o",
-       modes_obj       => "ghash-armv4.o ghashv8-armx.o",
-       perlasm_scheme  => "void"
-    },
-    aarch64_asm => {
-       template        => 1,
-       cpuid_obj       => "armcap.o arm64cpuid.o mem_clr.o",
-       ec_obj          => "ecp_nistz256.o ecp_nistz256-armv8.o",
-       bn_obj          => "bn_asm.o armv8-mont.o",
-       aes_obj         => "aes_core.o aes_cbc.o aesv8-armx.o vpaes-armv8.o",
-       sha1_obj        => "sha1-armv8.o sha256-armv8.o sha512-armv8.o",
-       modes_obj       => "ghashv8-armx.o",
-    },
-    parisc11_asm => {
-       template        => 1,
-       cpuid_obj       => "pariscid.o",
-       bn_obj          => "bn_asm.o parisc-mont.o",
-       aes_obj         => "aes_core.o aes_cbc.o aes-parisc.o",
-       sha1_obj        => "sha1-parisc.o sha256-parisc.o sha512-parisc.o",
-       rc4_obj         => "rc4-parisc.o",
-       modes_obj       => "ghash-parisc.o",
-       perlasm_scheme  => "32"
-    },
-    parisc20_64_asm => {
-       template        => 1,
-       inherit_from    => [ "parisc11_asm" ],
-       bn_obj          => sub { my $r=join(" ",@_); $r=~s/bn_asm/pa-risc2W/; $r; },
-       perlasm_scheme  => "64",
-    },
-    ppc64_asm => {
-       template        => 1,
-       cpuid_obj       => "ppccpuid.o ppccap.o",
-       bn_obj          => "bn-ppc.o ppc-mont.o ppc64-mont.o",
-       aes_obj         => "aes_core.o aes_cbc.o aes-ppc.o vpaes-ppc.o aesp8-ppc.o",
-       sha1_obj        => "sha1-ppc.o sha256-ppc.o sha512-ppc.o sha256p8-ppc.o sha512p8-ppc.o",
-       modes_obj       => "ghashp8-ppc.o",
-    },
-    ppc32_asm => {
-       inherit_from    => [ "ppc64_asm" ],
-       template        => 1
-    },
-);
+my $base_target = "BASE";   # The template that all other inherit from
+our %table = ();
 
 # Forward declarations ###############################################
 
@@ -445,13 +172,6 @@ foreach (sort glob($pattern) ) {
     &read_config($_);
 }
 
-my @MK1MF_Builds=qw(VC-WIN64I VC-WIN64A
-                   debug-VC-WIN64I debug-VC-WIN64A
-                   VC-NT VC-CE VC-WIN32 debug-VC-WIN32
-                   BC-32
-                   netware-clib netware-clib-bsdsock
-                   netware-libc netware-libc-bsdsock);
-
 my $prefix="";
 my $libdir="";
 my $openssldir="";
@@ -470,24 +190,6 @@ my $no_asm=0;
 my $no_dso=0;
 my @skip=();
 my $Makefile="Makefile";
-my $des_locl="crypto/des/des_locl.h";
-my $des        ="include/openssl/des.h";
-my $bn ="include/openssl/bn.h";
-my $md2        ="include/openssl/md2.h";
-my $rc4        ="include/openssl/rc4.h";
-my $rc4_locl="crypto/rc4/rc4_locl.h";
-my $idea       ="include/openssl/idea.h";
-my $rc2        ="include/openssl/rc2.h";
-my $bf ="crypto/bf/bf_locl.h";
-my $bn_asm     ="bn_asm.o";
-my $des_enc="des_enc.o fcrypt_b.o";
-my $aes_enc="aes_core.o aes_cbc.o";
-my $bf_enc     ="bf_enc.o";
-my $cast_enc="c_enc.o";
-my $rc4_enc="rc4_enc.o rc4_skey.o";
-my $rc5_enc="rc5_enc.o";
-my $cmll_enc="camellia.o cmll_misc.o cmll_cbc.o";
-my $chacha_enc="chacha_enc.o";
 my $processor="";
 my $default_ranlib;
 my $perl;
@@ -602,9 +304,72 @@ my %disabled = ( # "what"         => "comment" [or special keyword "experimental
               );
 my @experimental = ();
 
-# This is what $depflags will look like with the above defaults
-# (we need this to see if we should advise the user to run "make depend"):
-my $default_depflags = " -DOPENSSL_NO_CRYPTO_MDEBUG -DOPENSSL_NO_EC_NISTP_64_GCC_128 -DOPENSSL_NO_JPAKE -DOPENSSL_NO_MD2 -DOPENSSL_NO_RC5 -DOPENSSL_NO_SCTP -DOPENSSL_NO_SSL_TRACE -DOPENSSL_NO_STORE -DOPENSSL_NO_UNIT_TEST";
+# Note: => pair form used for aesthetics, not to truly make a hash table
+my @disable_cascades = (
+    # "what"           => [ "cascade", ... ]
+    sub { $processor eq "386" }
+                       => [ "sse2" ],
+    "ssl"              => [ "ssl3" ],
+    "ssl3-method"      => [ "ssl3" ],
+    "zlib"             => [ "zlib-dynamic" ],
+    "rijndael"         => [ "aes" ],
+    "des"              => [ "mdc2" ],
+    "ec"               => [ "ecdsa", "ecdh", "gost" ],
+    "dsa"              => [ "gost" ],
+    "dh"               => [ "gost" ],
+
+    "dgram"            => [ "dtls" ],
+    "dtls"             => [ @dtls ],
+
+    # SSL 3.0, (D)TLS 1.0 and TLS 1.1 require MD5 and SHA
+    "md5"              => [ "ssl", "tls1", "tls1_1", "dtls1" ],
+    "sha"              => [ "ssl", "tls1", "tls1_1", "dtls1" ],
+
+    # Additionally, SSL 3.0 requires either RSA or DSA+DH
+    sub { $disabled{rsa}
+         && ($disabled{dsa} || $disabled{dh}); }
+                       => [ "ssl" ],
+
+    # (D)TLS 1.0 and TLS 1.1 also require either RSA or DSA+DH
+    # or ECDSA + ECDH.  (D)TLS 1.2 has this requirement as well.
+    # (XXX: We don't support PSK-only builds).
+    sub { $disabled{rsa}
+         && ($disabled{dsa} || $disabled{dh})
+         && ($disabled{ecdsa} || $disabled{ecdh}); }
+                       => [ "tls1", "tls1_1", "tls1_2",
+                            "dtls1", "dtls1_2" ],
+
+    "tls"              => [ @tls ],
+
+    # SRP and HEARTBEATS require TLSEXT
+    "tlsext"           => [ "srp", "heartbeats" ],
+    );
+
+# Avoid protocol support holes.  Also disable all versions below N, if version
+# N is disabled while N+1 is enabled.
+#
+my @list = (reverse @tls);
+while ((my $first, my $second) = (shift @list, shift @list)) {
+    last unless @list;
+    push @disable_cascades, ( sub { !$disabled{$first} && $disabled{$second} }
+                             => [ @list ] );
+    unshift @list, $second;
+}
+my @list = (reverse @dtls);
+while ((my $first, my $second) = (shift @list, shift @list)) {
+    last unless @list;
+    push @disable_cascades, ( sub { !$disabled{$first} && $disabled{$second} }
+                             => [ @list ] );
+    unshift @list, $second;
+}
+
+# Construct the string of what $depflags should look like with the defaults
+# from %disabled above.  (we need this to see if we should advise the user
+# to run "make depend"):
+my $default_depflags = " ".join(" ",
+    map { my $x = $_; $x =~ tr{[a-z]-}{[A-Z]_}; "-DOPENSSL_NO_$x"; }
+    grep { $disabled{$_} !~ /\(no-depflags\)$/ }
+    sort keys %disabled);
 
 # Explicit "no-..." options will be collected in %disabled along with the defaults.
 # To remove something from %disabled, use "enable-foo" (unless it's experimental).
@@ -619,257 +384,235 @@ my $no_sse2=0;
 
 &usage if ($#ARGV < 0);
 
-my $flags;
-my $depflags;
-my $openssl_experimental_defines;
-my $openssl_algorithm_defines;
-my $openssl_thread_defines;
+my $flags="";
+my $depflags="";
+my $openssl_experimental_defines="";
+my $openssl_algorithm_defines="";
+my $openssl_thread_defines="";
 my $openssl_sys_defines="";
-my $openssl_other_defines;
-my $libs;
-my $target;
-my $options;
+my $openssl_other_defines="";
+my $libs="";
+my $target="";
+my $options="";
 my $api;
 my $make_depend=0;
 my %withargs=();
 my $build_prefix = "release_";
 
 my @argvcopy=@ARGV;
-my $argvstring="";
-my $argv_unprocessed=1;
 
-while($argv_unprocessed)
-       {
-       $flags="";
-       $depflags="";
-       $openssl_experimental_defines="";
-       $openssl_algorithm_defines="";
-       $openssl_thread_defines="";
-       $openssl_sys_defines="";
-       $openssl_other_defines="";
-       $libs="";
-       $target="";
-       $options="";
-
-       $argv_unprocessed=0;
-       $argvstring=join(' ',@argvcopy);
-
-PROCESS_ARGS:
+if (grep /^reconf(igure)?$/, @argvcopy) {
+    if (open IN, "<$Makefile") {
+       while (<IN>) {
+           chomp;
+           if (/^CONFIGURE_ARGS=\s*(.*)\s*/) {
+               my $line = $1;
+               if ($line =~ /^\s*\(/) {
+                   # New form perl expression saved in Makefile, eval it
+                   @argvcopy = eval $line;
+               } else {
+                   # Older form, we split the string and hope for the best
+                   @argvcopy = split /\s+/, $line;
+               }
+               die "Incorrect data to reconfigure, please do a normal configuration\n"
+                   if (grep(/^reconf/,@argvcopy));
+           } elsif (/^CROSS_COMPILE=\s*(.*)/) {
+               $ENV{CROSS_COMPILE}=$1;
+           } elsif (/^CC=\s*(?:\$\(CROSS_COMPILE\))?(.*?)$/) {
+               $ENV{CC}=$1;
+           }
+       }
+       print "Reconfiguring with: ", join(" ",@argvcopy), "\n";
+       print "    CROSS_COMPILE = ",$ENV{CROSS_COMPILE},"\n"
+           if $ENV{CROSS_COMPILE};
+       print "    CC = ",$ENV{CC},"\n" if $ENV{CC};
+       close IN;
+    } else {
+       die "Insufficient data to reconfigure, please do a normal configuration\n";
+    }
+}
+
+
+my %unsupported_options = ();
+foreach (@argvcopy)
        {
-       my %unsupported_options = ();
-       foreach (@argvcopy)
-               {
-               s /^-no-/no-/; # some people just can't read the instructions
+       s /^-no-/no-/; # some people just can't read the instructions
 
-               # rewrite some options in "enable-..." form
-               s /^-?-?shared$/enable-shared/;
-               s /^sctp$/enable-sctp/;
-               s /^threads$/enable-threads/;
-               s /^zlib$/enable-zlib/;
-               s /^zlib-dynamic$/enable-zlib-dynamic/;
+       # rewrite some options in "enable-..." form
+       s /^-?-?shared$/enable-shared/;
+       s /^sctp$/enable-sctp/;
+       s /^threads$/enable-threads/;
+       s /^zlib$/enable-zlib/;
+       s /^zlib-dynamic$/enable-zlib-dynamic/;
 
-               if (/^(no|disable|enable|experimental)-(.+)$/)
+        if (/^(no|disable|enable|experimental)-(.+)$/)
+               {
+               my $word = $2;
+               if (!grep { $word =~ /^${_}$/ } @disablables)
                        {
-                       my $word = $2;
-                       if (!grep { $word =~ /^${_}$/ } @disablables)
-                               {
-                               $unsupported_options{$_} = 1;
-                               next;
-                               }
+                       $unsupported_options{$_} = 1;
+                       next;
                        }
-               if (/^no-(.+)$/ || /^disable-(.+)$/)
+               }
+       if (/^no-(.+)$/ || /^disable-(.+)$/)
+               {
+               if (!($disabled{$1} eq "experimental"))
                        {
-                       if (!($disabled{$1} eq "experimental"))
+                       foreach my $proto ((@tls, @dtls))
                                {
-                               foreach my $proto ((@tls, @dtls))
-                                       {
-                                       if ($1 eq "$proto-method")
-                                               {
-                                               $disabled{"$proto"} = "option($proto-method)";
-                                               last;
-                                               }
-                                       }
-                               if ($1 eq "dtls")
-                                       {
-                                        foreach my $proto (@dtls)
-                                               {
-                                               $disabled{$proto} = "option(dtls)";
-                                               }
-                                       }
-                               elsif ($1 eq "ssl")
+                               if ($1 eq "$proto-method")
                                        {
-                                       # Last one of its kind
-                                       $disabled{"ssl3"} = "option(ssl)";
+                                       $disabled{"$proto"} = "option($proto-method)";
+                                       last;
                                        }
-                               elsif ($1 eq "tls")
+                               }
+                       if ($1 eq "dtls")
+                               {
+                                foreach my $proto (@dtls)
                                        {
-                                        # XXX: Tests will fail if all SSL/TLS
-                                        # protocols are disabled.
-                                        foreach my $proto (@tls)
-                                               {
-                                               $disabled{$proto} = "option(tls)";
-                                               }
+                                       $disabled{$proto} = "option(dtls)";
                                        }
-                               else
+                               }
+                       elsif ($1 eq "ssl")
+                               {
+                               # Last one of its kind
+                               $disabled{"ssl3"} = "option(ssl)";
+                               }
+                       elsif ($1 eq "tls")
+                               {
+                                # XXX: Tests will fail if all SSL/TLS
+                                # protocols are disabled.
+                                foreach my $proto (@tls)
                                        {
-                                       $disabled{$1} = "option";
+                                       $disabled{$proto} = "option(tls)";
                                        }
                                }
-                       }
-               elsif (/^enable-(.+)$/ || /^experimental-(.+)$/)
-                       {
-                       my $algo = $1;
-                       if ($disabled{$algo} eq "experimental")
+                       else
                                {
-                               die "You are requesting an experimental feature; please say 'experimental-$algo' if you are sure\n"
-                                       unless (/^experimental-/);
-                               push @experimental, $algo;
+                               $disabled{$1} = "option";
                                }
-                       delete $disabled{$algo};
+                       }
+               }
+       elsif (/^enable-(.+)$/ || /^experimental-(.+)$/)
+               {
+               my $algo = $1;
+               if ($disabled{$algo} eq "experimental")
+                       {
+                       die "You are requesting an experimental feature; please say 'experimental-$algo' if you are sure\n"
+                               unless (/^experimental-/);
+                       push @experimental, $algo;
+                       }
+               delete $disabled{$algo};
 
-                       $threads = 1 if ($algo eq "threads");
+               $threads = 1 if ($algo eq "threads");
+               }
+       elsif (/^--strict-warnings$/)
+               {
+               $strict_warnings = 1;
+               }
+       elsif (/^--debug$/)
+               {
+               $build_prefix = "debug_";
+               }
+       elsif (/^--release$/)
+               {
+               $build_prefix = "release_";
+               }
+       elsif (/^386$/)
+               { $processor=386; }
+       elsif (/^fips$/)
+               {
+               $fips=1;
+               }
+       elsif (/^rsaref$/)
+               {
+               # No RSAref support any more since it's not needed.
+               # The check for the option is there so scripts aren't
+               # broken
+               }
+       elsif (/^nofipscanistercheck$/)
+               {
+               $fips = 1;
+               $nofipscanistercheck = 1;
+               }
+       elsif (/^[-+]/)
+               {
+               if (/^--prefix=(.*)$/)
+                       {
+                       $prefix=$1;
                        }
-               elsif (/^--strict-warnings$/)
+               elsif (/^--api=(.*)$/)
                        {
-                       $strict_warnings = 1;
+                       $api=$1;
                        }
-               elsif (/^--debug$/)
+               elsif (/^--libdir=(.*)$/)
                        {
-                       $build_prefix = "debug_";
+                       $libdir=$1;
                        }
-               elsif (/^--release$/)
+               elsif (/^--openssldir=(.*)$/)
                        {
-                       $build_prefix = "release_";
+                       $openssldir=$1;
                        }
-               elsif (/^reconfigure/ || /^reconf/)
+               elsif (/^--install.prefix=(.*)$/)
                        {
-                       if (open(IN,"<$Makefile"))
-                               {
-                               my $config_args_found=0;
-                               while (<IN>)
-                                       {
-                                       chomp;
-                                       if (/^CONFIGURE_ARGS=(.*)/)
-                                               {
-                                               $argvstring=$1;
-                                               @argvcopy=split(' ',$argvstring);
-                                               die "Incorrect data to reconfigure, please do a normal configuration\n"
-                                                       if (grep(/^reconf/,@argvcopy));
-                                               print "Reconfiguring with: $argvstring\n";
-                                               $argv_unprocessed=1;
-                                               $config_args_found=1;
-                                               }
-                                       elsif (/^CROSS_COMPILE=\s*(.*)/)
-                                               {
-                                               $ENV{CROSS_COMPILE}=$1;
-                                               }
-                                       elsif (/^CC=\s*(?:\$\(CROSS_COMPILE\))?(.*?)$/)
-                                               {
-                                               $ENV{CC}=$1;
-                                               }
-                                       }
-                               close(IN);
-                               last PROCESS_ARGS if ($config_args_found);
-                               }
-                       die "Insufficient data to reconfigure, please do a normal configuration\n";
+                       $install_prefix=$1;
                        }
-               elsif (/^386$/)
-                       { $processor=386; }
-               elsif (/^fips$/)
+               elsif (/^--with-zlib-lib=(.*)$/)
                        {
-                       $fips=1;
+                       $withargs{"zlib-lib"}=$1;
                        }
-               elsif (/^rsaref$/)
+               elsif (/^--with-zlib-include=(.*)$/)
                        {
-                       # No RSAref support any more since it's not needed.
-                       # The check for the option is there so scripts aren't
-                       # broken
+                       $withargs{"zlib-include"}="-I$1";
                        }
-               elsif (/^nofipscanistercheck$/)
+               elsif (/^--with-fipslibdir=(.*)$/)
                        {
-                       $fips = 1;
-                       $nofipscanistercheck = 1;
+                       $fipslibdir="$1/";
                        }
-               elsif (/^[-+]/)
+               elsif (/^--with-baseaddr=(.*)$/)
                        {
-                       if (/^--prefix=(.*)$/)
-                               {
-                               $prefix=$1;
-                               }
-                       elsif (/^--api=(.*)$/)
-                               {
-                               $api=$1;
-                               }
-                       elsif (/^--libdir=(.*)$/)
-                               {
-                               $libdir=$1;
-                               }
-                       elsif (/^--openssldir=(.*)$/)
-                               {
-                               $openssldir=$1;
-                               }
-                       elsif (/^--install.prefix=(.*)$/)
-                               {
-                               $install_prefix=$1;
-                               }
-                       elsif (/^--with-zlib-lib=(.*)$/)
-                               {
-                               $withargs{"zlib-lib"}=$1;
-                               }
-                       elsif (/^--with-zlib-include=(.*)$/)
-                               {
-                               $withargs{"zlib-include"}="-I$1";
-                               }
-                       elsif (/^--with-fipslibdir=(.*)$/)
-                               {
-                               $fipslibdir="$1/";
-                               }
-                       elsif (/^--with-baseaddr=(.*)$/)
-                               {
-                               $baseaddr="$1";
-                               }
-                       elsif (/^--cross-compile-prefix=(.*)$/)
-                               {
-                               $cross_compile_prefix=$1;
-                               }
-                       elsif (/^--config=(.*)$/)
-                               {
-                               read_config $1;
-                               }
-                       elsif (/^-[lL](.*)$/ or /^-Wl,/)
-                               {
-                               $libs.=$_." ";
-                               }
-                       else    # common if (/^[-+]/), just pass down...
-                               {
-                               $_ =~ s/%([0-9a-f]{1,2})/chr(hex($1))/gei;
-                               $flags.=$_." ";
-                               }
+                       $baseaddr="$1";
                        }
-               elsif ($_ =~ /^([^:]+):(.+)$/)
+               elsif (/^--cross-compile-prefix=(.*)$/)
                        {
-                       eval "\$table{\$1} = \"$2\""; # allow $xxx constructs in the string
-                       $target=$1;
+                       $cross_compile_prefix=$1;
                        }
-               else
+               elsif (/^--config=(.*)$/)
                        {
-                       die "target already defined - $target (offending arg: $_)\n" if ($target ne "");
-                       $target=$_;
+                       read_config $1;
                        }
-
-               unless ($_ eq $target || /^no-/ || /^disable-/)
+               elsif (/^-[lL](.*)$/ or /^-Wl,/)
                        {
-                       # "no-..." follows later after implied disactivations
-                       # have been derived.  (Don't take this too seroiusly,
-                       # we really only write OPTIONS to the Makefile out of
-                       # nostalgia.)
-
-                       if ($options eq "")
-                               { $options = $_; }
-                       else
-                               { $options .= " ".$_; }
+                       $libs.=$_." ";
+                       }
+               else    # common if (/^[-+]/), just pass down...
+                       {
+                       $_ =~ s/%([0-9a-f]{1,2})/chr(hex($1))/gei;
+                       $flags.=$_." ";
                        }
                }
+       elsif ($_ =~ /^([^:]+):(.+)$/)
+               {
+               eval "\$table{\$1} = \"$2\""; # allow $xxx constructs in the string
+               $target=$1;
+               }
+       else
+               {
+               die "target already defined - $target (offending arg: $_)\n" if ($target ne "");
+               $target=$_;
+               }
+       unless ($_ eq $target || /^no-/ || /^disable-/)
+               {
+               # "no-..." follows later after implied disactivations
+               # have been derived.  (Don't take this too seroiusly,
+               # we really only write OPTIONS to the Makefile out of
+               # nostalgia.)
+
+               if ($options eq "")
+                       { $options = $_; }
+               else
+                       { $options .= " ".$_; }
+               }
 
         if (defined($api) && !exists $apitable->{$api}) {
                die "***** Unsupported api compatibility level: $api\n",
@@ -881,124 +624,26 @@ PROCESS_ARGS:
                        join(", ", keys %unsupported_options), "\n";
                }
        }
-       }
-
-
-if ($processor eq "386")
-       {
-       $disabled{"sse2"} = "forced";
-       }
-
-if (!defined($disabled{"zlib-dynamic"}))
-       {
-       # "zlib-dynamic" was specifically enabled, so enable "zlib"
-       delete $disabled{"zlib"};
-       }
-
-if (defined($disabled{"rijndael"}))
-       {
-       $disabled{"aes"} = "forced";
-       }
-if (defined($disabled{"des"}))
-       {
-       $disabled{"mdc2"} = "forced";
-       }
-if (defined($disabled{"ec"}))
-       {
-       $disabled{"ecdsa"} = "forced";
-       $disabled{"ecdh"} = "forced";
-       }
-
-# SSL 3.0 requires MD5 and SHA and either RSA or DSA+DH
-if (defined($disabled{"md5"}) || defined($disabled{"sha"})
-    || (defined($disabled{"rsa"})
-       && (defined($disabled{"dsa"}) || defined($disabled{"dh"}))))
-       {
-       $disabled{"ssl3"} = "forced";
-       $disabled{"ssl"} = "forced";
-       }
-
-# (D)TLS 1.0 and TLS 1.1 require MD5 and SHA and either RSA or DSA+DH
-# or ECDSA + ECDH.  (XXX: We don't support PSK-only builds).
-#
-if (defined($disabled{"md5"}) || defined($disabled{"sha"})
-    || (defined($disabled{"rsa"})
-       && (defined($disabled{"dsa"}) || defined($disabled{"dh"}))
-       && (defined($disabled{"ecdsa"}) || defined($disabled{"ecdh"}))))
-       {
-       $disabled{"tls1"} = "forced";
-       $disabled{"dtls1"} = "forced";
-       $disabled{"tls1_1"} = "forced";
-       }
-
-# (D)TLS 1.2 requires either RSA or DSA+DH or ECDSA + ECDH
-# So if all are missing, we can't do either TLS or DTLS.
-# (XXX: We don't support PSK-only builds).
-#
-if (defined($disabled{"rsa"})
-    && (defined($disabled{"dsa"}) || defined($disabled{"dh"}))
-    && (defined($disabled{"ecdsa"}) || defined($disabled{"ecdh"})))
-       {
-       $disabled{"tls"} = "forced";
-       $disabled{"dtls"} = "forced";
-       foreach my $proto ((@tls, @dtls))
-               {
-               $disabled{"$proto"} = "forced";
-               }
-       }
-
-
-# Avoid protocol support holes.  Also disable all versions below N, if version
-# N is disabled while N+1 is enabled.
-#
-my $prev_disabled = 1;
-my $force_disable = 0;
-foreach my $proto (reverse(@tls))
-       {
-       if ($force_disable)
-               {
-               $disabled{$proto} = 1;
-               }
-       elsif (! defined($disabled{$proto}))
-               {
-               $prev_disabled = 0;
-               }
-       elsif (! $prev_disabled)
-               {
-               $force_disable = 1;
-               }
-       }
-my $prev_disabled = 1;
-my $force_disable = 0;
-foreach my $proto (reverse(@dtls))
-       {
-       if ($force_disable)
-               {
-               $disabled{$proto} = 1;
-               }
-       elsif (! defined($disabled{$proto}))
-               {
-               $prev_disabled = 0;
-               }
-       elsif (! $prev_disabled)
-               {
-               $force_disable = 1;
-               }
-       }
 
-if (defined($disabled{"dgram"}))
+if ($fips)
        {
-       $disabled{"dtls"} = "forced";
-       $disabled{"dtls1"} = "forced";
-       $disabled{"dtls1_2"} = "forced";
+       delete $disabled{"shared"} if ($disabled{"shared"} =~ /^default/);
        }
 
-if (defined($disabled{"ec"}) || defined($disabled{"dsa"})
-    || defined($disabled{"dh"}) || defined($disabled{"stdio"}))
-       {
-       $disabled{"gost"} = "forced";
+my @tocheckfor = (keys %disabled);
+while (@tocheckfor) {
+    my %new_tocheckfor = ();
+    my @cascade_copy = (@disable_cascades);
+    while (@cascade_copy) {
+       my ($test, $descendents) = (shift @cascade_copy, shift @cascade_copy);
+       if (ref($test) eq "CODE" ? $test->() : defined($disabled{$test})) {
+           map {
+               $new_tocheckfor{$_} => 1; $disabled{$_} = "forced";
+           } grep { !defined($disabled{$_}) } @$descendents;
        }
-
+    }
+    @tocheckfor = (keys %new_tocheckfor);
+}
 
 if ($target eq "TABLE") {
        foreach $target (sort keys %table) {
@@ -1027,29 +672,6 @@ if ($target =~ m/^CygWin32(-.*)$/) {
        $target = "Cygwin".$1;
 }
 
-print "Configuring for $target\n";
-
-# Support for legacy targets having a name starting with 'debug-'
-my ($d, $t) = $target =~ m/^(debug-)?(.*)$/;
-if ($d) {
-    $build_prefix = "debug_";
-
-    # If we do not find debug-foo in the table, the target is set to foo,
-    # but only if the foo target has a noon-empty debug_cflags or debug_lflags
-    # attribute.
-    if (!$table{$target}) {
-       $target = $t;
-    }
-}
-my %target = resolve_config($target);
-
-&usage if (!%target || $target{template});
-
-if ($fips)
-       {
-       delete $disabled{"shared"} if ($disabled{"shared"} eq "default");
-       }
-
 foreach (sort (keys %disabled))
        {
        $options .= " no-$_";
@@ -1116,13 +738,27 @@ foreach (sort @experimental)
        $exp_cflags .= " -DOPENSSL_EXPERIMENTAL_$ALGO";
        }
 
-my $IsMK1MF=scalar grep /^$target$/,@MK1MF_Builds;
+print "Configuring for $target\n";
+
+# Support for legacy targets having a name starting with 'debug-'
+my ($d, $t) = $target =~ m/^(debug-)?(.*)$/;
+if ($d) {
+    $build_prefix = "debug_";
+
+    # If we do not find debug-foo in the table, the target is set to foo.
+    if (!$table{$target}) {
+       $target = $t;
+    }
+}
+
+delete $table{$base_target}->{template}; # or the next test will fail.
+my %target = ( %{$table{$base_target}}, resolve_config($target) );
+
+&usage if (!%target || $target{template});
 
 $exe_ext=".exe" if ($target eq "Cygwin" || $target eq "DJGPP" || $target =~ /^mingw/);
 $exe_ext=".nlm" if ($target =~ /netware/);
 $exe_ext=".pm"  if ($target =~ /vos/);
-$openssldir="/usr/local/ssl" if ($openssldir eq "" and $prefix eq "");
-$prefix=$openssldir if $prefix eq "";
 
 $default_ranlib= &which("ranlib") or $default_ranlib="true";
 $perl=$ENV{'PERL'} or $perl=&which("perl5") or $perl=&which("perl")
@@ -1131,15 +767,12 @@ my $make = $ENV{'MAKE'} || "make";
 
 $cross_compile_prefix=$ENV{'CROSS_COMPILE'} if $cross_compile_prefix eq "";
 
-chop $openssldir if $openssldir =~ /\/$/;
-chop $prefix if $prefix =~ /.\/$/;
-
-$openssldir=$prefix . "/ssl" if $openssldir eq "";
-$openssldir=$prefix . "/" . $openssldir if $openssldir !~ /(^\/|^[a-zA-Z]:[\\\/])/;
+$prefix = "/usr/local" if !$prefix;
+$openssldir = "ssl" if !$openssldir;
+$openssldir = catdir($prefix, $openssldir)
+    unless file_name_is_absolute($openssldir);
 
 
-print "IsMK1MF=$IsMK1MF\n";
-
 # Allow environment CC to override compiler...
 my $cc = $ENV{CC} || $target{cc};
 
@@ -1184,6 +817,9 @@ my $ranlib = $ENV{'RANLIB'} || $target{ranlib};
 my $ar = $ENV{'AR'} || "ar";
 my $arflags = $target{arflags};
 my $multilib = $target{multilib};
+my @build_scheme =
+    ref($target{build_scheme}) eq "ARRAY"
+    ? @{$target{build_scheme}} : ( $target{build_scheme} );
 
 # if $prefix/lib$multilib is not an existing directory, then
 # assume that it's not searched by linker automatically, in
@@ -1282,22 +918,9 @@ $lflags="$libs$lflags" if ($libs ne "");
 
 if ($no_asm)
        {
-       $cpuid_obj=$bn_obj=$ec_obj=
-       $des_obj=$aes_obj=$bf_obj=$cast_obj=$rc4_obj=$rc5_obj=$cmll_obj=
-       $modes_obj=$sha1_obj=$md5_obj=$rmd160_obj=$wp_obj=$engines_obj=
-       $chacha_obj=$poly1305_obj="";
        $cflags=~s/\-D[BL]_ENDIAN//             if ($fips);
        $thread_cflags=~s/\-D[BL]_ENDIAN//      if ($fips);
        }
-elsif (defined($disabled{ec2m}))
-       {
-       $bn_obj =~ s/\w+-gf2m.o//;
-       }
-
-if (!$no_shared)
-       {
-       $cast_obj="";   # CAST assembler is not PIC
-       }
 
 if ($threads)
        {
@@ -1345,7 +968,7 @@ if (!$no_shared)
                }
        }
 
-if (!$IsMK1MF)
+if ($build_scheme[0] ne "mk1mf")
        {
        # add {no-}static-engine to options to allow mkdef.pl to work without extra arguments
        if ($no_shared)
@@ -1360,8 +983,6 @@ if (!$IsMK1MF)
                }
        }
 
-$cpuid_obj.=" uplink.o uplink-x86.o" if ($cflags =~ /\-DOPENSSL_USE_APPLINK/);
-
 #
 # Platform fix-ups
 #
@@ -1421,58 +1042,44 @@ if ($ranlib eq "")
        $ranlib = $default_ranlib;
        }
 
-#my ($bn1)=split(/\s+/,$bn_obj);
-#$bn1 = "" unless defined $bn1;
-#$bn1=$bn_asm unless ($bn1 =~ /\.o$/);
-#$bn_obj="$bn1";
+if (!$no_asm) {
+    $cpuid_obj=$table{BASE}->{cpuid_obj} if ($processor eq "386");
+    $cpuid_obj.=" uplink.o uplink-x86.o" if ($cflags =~ /\-DOPENSSL_USE_APPLINK/);
 
-$cpuid_obj="" if ($processor eq "386");
+    $bn_obj =~ s/\w+-gf2m.o// if (defined($disabled{ec2m}));
 
-$bn_obj = $bn_asm unless $bn_obj ne "";
-# bn-586 is the only one implementing bn_*_part_words
-$cflags.=" -DOPENSSL_BN_ASM_PART_WORDS" if ($bn_obj =~ /bn-586/);
-$cflags.=" -DOPENSSL_IA32_SSE2" if (!$no_sse2 && $bn_obj =~ /86/);
+    # bn-586 is the only one implementing bn_*_part_words
+    $cflags.=" -DOPENSSL_BN_ASM_PART_WORDS" if ($bn_obj =~ /bn-586/);
+    $cflags.=" -DOPENSSL_IA32_SSE2" if (!$no_sse2 && $bn_obj =~ /86/);
 
-$cflags.=" -DOPENSSL_BN_ASM_MONT" if ($bn_obj =~ /-mont/);
-$cflags.=" -DOPENSSL_BN_ASM_MONT5" if ($bn_obj =~ /-mont5/);
-$cflags.=" -DOPENSSL_BN_ASM_GF2m" if ($bn_obj =~ /-gf2m/);
+    $cflags.=" -DOPENSSL_BN_ASM_MONT" if ($bn_obj =~ /-mont/);
+    $cflags.=" -DOPENSSL_BN_ASM_MONT5" if ($bn_obj =~ /-mont5/);
+    $cflags.=" -DOPENSSL_BN_ASM_GF2m" if ($bn_obj =~ /-gf2m/);
 
-if ($fips)
-       {
+    if ($fips) {
        $openssl_other_defines.="#define OPENSSL_FIPS\n";
-       }
+    }
 
-$cpuid_obj="mem_clr.o" unless ($cpuid_obj =~ /\.o$/);
-$des_obj=$des_enc      unless ($des_obj =~ /\.o$/);
-$bf_obj=$bf_enc                unless ($bf_obj =~ /\.o$/);
-$cast_obj=$cast_enc    unless ($cast_obj =~ /\.o$/);
-$rc4_obj=$rc4_enc      unless ($rc4_obj =~ /\.o$/);
-$rc5_obj=$rc5_enc      unless ($rc5_obj =~ /\.o$/);
-if ($sha1_obj =~ /\.o$/)
-       {
-#      $sha1_obj=$sha1_enc;
+    if ($sha1_obj =~ /\.o$/) {
        $cflags.=" -DSHA1_ASM"   if ($sha1_obj =~ /sx86/ || $sha1_obj =~ /sha1/);
        $cflags.=" -DSHA256_ASM" if ($sha1_obj =~ /sha256/);
        $cflags.=" -DSHA512_ASM" if ($sha1_obj =~ /sha512/);
-       if ($sha1_obj =~ /sse2/)
-           {   if ($no_sse2)
-               {   $sha1_obj =~ s/\S*sse2\S+//;        }
-               elsif ($cflags !~ /OPENSSL_IA32_SSE2/)
-               {   $cflags.=" -DOPENSSL_IA32_SSE2";    }
+       if ($sha1_obj =~ /sse2/) {
+           if ($no_sse2) {
+               $sha1_obj =~ s/\S*sse2\S+//;
+           } elsif ($cflags !~ /OPENSSL_IA32_SSE2/) {
+               $cflags.=" -DOPENSSL_IA32_SSE2";
            }
        }
-if ($md5_obj =~ /\.o$/)
-       {
-#      $md5_obj=$md5_enc;
+    }
+    if ($md5_obj =~ /\.o$/) {
        $cflags.=" -DMD5_ASM";
-       }
-if ($rmd160_obj =~ /\.o$/)
-       {
-#      $rmd160_obj=$rmd160_enc;
+    }
+    $cast_obj=$table{BASE}->{cast_obj} if (!$no_shared); # CAST assembler is not PIC
+    if ($rmd160_obj =~ /\.o$/) {
        $cflags.=" -DRMD160_ASM";
-       }
-if ($aes_obj =~ /\.o$/)
-       {
+    }
+    if ($aes_obj =~ /\.o$/) {
        $cflags.=" -DAES_ASM" if ($aes_obj =~ m/\baes\-/);;
        # aes-ctr.o is not a real file, only indication that assembler
        # module implements AES_ctr32_encrypt...
@@ -1482,32 +1089,22 @@ if ($aes_obj =~ /\.o$/)
        $aes_obj =~ s/\s*(vpaes|aesni)\-x86\.o//g if ($no_sse2);
        $cflags.=" -DVPAES_ASM" if ($aes_obj =~ m/vpaes/);
        $cflags.=" -DBSAES_ASM" if ($aes_obj =~ m/bsaes/);
-       }
-else   {
-       $aes_obj=$aes_enc;
-       }
-$wp_obj="" if ($wp_obj =~ /mmx/ && $processor eq "386");
-if ($wp_obj =~ /\.o$/ && !$disabled{"whirlpool"})
-       {
+    }
+    if ($wp_obj =~ /mmx/ && $processor eq "386") {
+       $wp_obj=$table{BASE}->{wp_obj};
+    } elsif (!$disabled{"whirlpool"}) {
        $cflags.=" -DWHIRLPOOL_ASM";
-       }
-else   {
-       $wp_obj="wp_block.o";
-       }
-$cmll_obj=$cmll_enc    unless ($cmll_obj =~ /.o$/);
-if ($modes_obj =~ /ghash\-/)
-       {
+    }
+    if ($modes_obj =~ /ghash\-/) {
        $cflags.=" -DGHASH_ASM";
-       }
-if ($ec_obj =~ /ecp_nistz256/)
-       {
+    }
+    if ($ec_obj =~ /ecp_nistz256/) {
        $cflags.=" -DECP_NISTZ256_ASM";
-       }
-$chacha_obj=$chacha_enc        unless ($chacha_obj =~ /\.o$/);
-if ($poly1305_obj =~ /\.o$/)
-       {
+    }
+    if ($poly1305_obj =~ /\.o$/) {
        $cflags.=" -DPOLY1305_ASM";
-       }
+    }
+}
 
 # "Stringify" the C flags string.  This permits it to be made part of a string
 # and works as well on command lines.
@@ -1617,6 +1214,7 @@ while (<IN>)
        s/^INSTALL_PREFIX=.*$/INSTALL_PREFIX=$install_prefix/;
        s/^PLATFORM=.*$/PLATFORM=$target/;
        s/^OPTIONS=.*$/OPTIONS=$options/;
+       my $argvstring = "(".join(", ", map { quotify("perl", $_) } @argvcopy).")";
        s/^CONFIGURE_ARGS=.*$/CONFIGURE_ARGS=$argvstring/;
        if ($cross_compile_prefix)
                {
@@ -1695,6 +1293,7 @@ close(OUT);
 rename($Makefile,"$Makefile.orig") || die "unable to rename $Makefile\n" if -e $Makefile;
 rename("$Makefile.new",$Makefile) || die "unable to rename $Makefile.new\n";
 
+print "IsMK1MF       =", ($build_scheme[0] eq "mk1mf" ? "yes" : "no"), "\n";
 print "CC            =$cc\n";
 print "CFLAG         =$cflags\n";
 print "EX_LIBS       =$lflags\n";
@@ -1833,7 +1432,6 @@ while (<IN>)
                        ($export_var_as_fn)?"define":"undef"; }
        elsif   (/^#define\s+OPENSSL_UNISTD/)
                {
-               $unistd = "<unistd.h>" if $unistd eq "";
                print OUT "#define OPENSSL_UNISTD $unistd\n";
                }
        elsif   (/^#((define)|(undef))\s+SIXTY_FOUR_BIT_LONG/)
@@ -1941,17 +1539,25 @@ find(sub {
                 $File::Find::dir;
     }, ".");
 
-{
-    my $perlguess = $perl =~ m@^/@ ? $perl : '/usr/local/bin/perl';
-
-    &dofile("tools/c_rehash",$perlguess,
-           '^#!/'              => '#!%s',
-           '^my \$dir;$'       => 'my $dir = "' . $openssldir . '";',
-           '^my \$prefix;$'    => 'my $prefix = "' . $prefix . '";');
-    &dofile("apps/CA.pl",$perl,
-           '^#!/'              => '#!%s');
-}
-if($IsMK1MF) {
+my %builders = (
+    unixmake => sub {
+       my $perlguess = $perl =~ m@^/@ ? $perl : '/usr/local/bin/perl';
+       my $make_command = "$make PERL=\'$perlguess\'";
+       my $make_targets = "";
+       $make_targets .= " depend" if $depflags ne $default_depflags && $make_depend;
+       (system $make_command.$make_targets) == 0 or die "make $make_targets failed"
+           if $make_targets ne "";
+       &dofile("tools/c_rehash",$perlguess,
+               '^#!/'           => '#!%s',
+               '^my \$dir;$'    => 'my $dir = "' . $openssldir . '";',
+               '^my \$prefix;$' => 'my $prefix = "' . $prefix . '";');
+       &dofile("apps/CA.pl",$perlguess,
+               '^#!/'           => '#!%s');
+       if ($depflags ne $default_depflags && !$make_depend) {
+            $warn_make_depend++;
+        }
+    },
+    mk1mf => sub {
        open (OUT,">crypto/buildinf.h") || die "Can't open buildinf.h";
        printf OUT <<"EOF";
 #ifndef MK1MF_BUILD
@@ -1963,28 +1569,18 @@ if($IsMK1MF) {
 #endif
 EOF
        close(OUT);
-} else {
-       my $make_command = "$make PERL=\'$perl\'";
-       my $make_targets = "";
-       $make_targets .= " depend" if $depflags ne $default_depflags && $make_depend;
-       (system $make_command.$make_targets) == 0 or die "make $make_targets failed"
-               if $make_targets ne "";
-       if ($depflags ne $default_depflags && !$make_depend) {
-            $warn_make_depend++;
-        }
-}
 
-# create the ms/version32.rc file if needed
-if ($IsMK1MF && ($target !~ /^netware/)) {
-       my ($v1, $v2, $v3, $v4);
-       if ($version_num =~ /^0x([0-9a-f]{1})([0-9a-f]{2})([0-9a-f]{2})([0-9a-f]{2})([0-9a-f]{1})L$/i) {
+       # create the ms/version32.rc file if needed
+       if (! grep /^netware/, @build_scheme) {
+           my ($v1, $v2, $v3, $v4);
+           if ($version_num =~ /^0x([0-9a-f]{1})([0-9a-f]{2})([0-9a-f]{2})([0-9a-f]{2})([0-9a-f]{1})L$/i) {
                $v1=hex $1;
                $v2=hex $2;
                $v3=hex $3;
                $v4=hex $4;
-       }
-       open (OUT,">ms/version32.rc") || die "Can't open ms/version32.rc";
-       print OUT <<"EOF";
+           }
+           open (OUT,">ms/version32.rc") || die "Can't open ms/version32.rc";
+           print OUT <<"EOF";
 #include <winver.h>
 
 LANGUAGE 0x09,0x01
@@ -2033,8 +1629,13 @@ BEGIN
     END
 END
 EOF
-       close(OUT);
-  }
+           close(OUT);
+       }
+    },
+    );
+
+my ($builder, @builder_opts) = @build_scheme;
+$builders{$builder}->(@builder_opts);
 
 print <<"EOF";
 
@@ -2085,6 +1686,43 @@ sub asm {
     }
 }
 
+# Helper function to implement adding values to already existing configuration
+# values.  It handles elements that are ARRAYs, CODEs and scalars
+sub _add {
+    my $separator = shift;
+
+    # If there's any ARRAY in the collection of values, we will return
+    # an ARRAY of combined values, otherwise a string of joined values
+    # with $separator as the separator.
+    my $found_array = 0;
+
+    my @values =
+       map {
+           if (ref($_) eq "ARRAY") {
+               $found_array = 1;
+               @$_;
+           } else {
+               $_;
+           }
+    } (@_);
+
+    if ($found_array) {
+       [ @values ];
+    } else {
+       join($separator, @values);
+    }
+}
+sub add_before {
+    my $separator = shift;
+    my @x = @_;
+    sub { _add($separator, @x, @_) };
+}
+sub add {
+    my $separator = shift;
+    my @x = @_;
+    sub { _add($separator, @_, @x) };
+}
+
 # configuration reader, evaluates the input file as a perl script and expects
 # it to fill %targets with target configurations.  Those are then added to
 # %table.
@@ -2178,7 +1816,7 @@ sub resolve_config {
     #   value.
     # - Otherwise, this target's value is assumed to be a string that
     #   will simply override the inherited list of values.
-    my $default_combiner = sub { join(' ',@_) };
+    my $default_combiner = add(" ");
 
     my %all_keys =
        map { $_ => 1 } (keys %combined_inheritance,
@@ -2198,8 +1836,8 @@ sub resolve_config {
            # arguments.
            $table{$target}->{$_} =
                $table{$target}->{$_}->(@{$combined_inheritance{$_}});
-       } elsif ($valuetype eq "") {
-           # Scalar, just leave it as is.
+       } elsif ($valuetype eq "ARRAY" || $valuetype eq "") {
+           # ARRAY or Scalar, just leave it as is.
        } else {
            # Some other type of reference that we don't handle.
            # Better to abort at this point.
@@ -2384,3 +2022,16 @@ EOF
            print "    },\n";
        }
        }
+
+sub quotify {
+    my %processors = (
+       perl    => sub { my $x = shift;
+                        $x =~ s/([\\\$\@"])/\\$1/g;
+                        return '"'.$x.'"'; },
+       );
+    my $for = shift;
+    my $processor =
+       defined($processors{$for}) ? $processors{$for} : sub { shift; };
+
+    map { $processor->($_); } @_;
+}