Update license year range to 2016
[openssl.git] / Configure
1 #! /usr/bin/env perl
2 # -*- mode: perl; -*-
3
4 ##
5 ##  Configure -- OpenSSL source tree configuration script
6 ##  If editing this file, run this command before committing
7 ##      make -f Makefile.in TABLE
8 ##
9
10 require 5.000;
11 use strict;
12 use File::Basename;
13 use File::Spec::Functions;
14
15 # see INSTALL for instructions.
16
17 my $usage="Usage: Configure [no-<cipher> ...] [enable-<cipher> ...] [experimental-<cipher> ...] [-Dxxx] [-lxxx] [-Lxxx] [-fxxx] [-Kxxx] [no-hw-xxx|no-hw] [[no-]threads] [[no-]shared] [[no-]zlib|zlib-dynamic] [no-asm] [no-dso] [no-egd] [sctp] [386] [--prefix=DIR] [--openssldir=OPENSSLDIR] [--with-xxx[=vvv]] [--test-sanity] [--config=FILE] os/compiler[:flags]\n";
18
19 # Options:
20 #
21 # --config      add the given configuration file, which will be read after
22 #               any "Configurations*" files that are found in the same
23 #               directory as this script.
24 # --openssldir  install OpenSSL in OPENSSLDIR (Default: DIR/ssl if the
25 #               --prefix option is given; /usr/local/ssl otherwise)
26 # --prefix      prefix for the OpenSSL include, lib and bin directories
27 #               (Default: the OPENSSLDIR directory)
28 #
29 # --install_prefix  Additional prefix for package builders (empty by
30 #               default).  This needn't be set in advance, you can
31 #               just as well use "make INSTALL_PREFIX=/whatever install".
32 #
33 # --test-sanity Make a number of sanity checks on the data in this file.
34 #               This is a debugging tool for OpenSSL developers.
35 #
36 # --cross-compile-prefix Add specified prefix to binutils components.
37 #
38 # --api         One of 0.9.8, 1.0.0 or 1.1.0.  Do not compile support for
39 #               interfaces deprecated as of the specified OpenSSL version.
40 #
41 # no-hw-xxx     do not compile support for specific crypto hardware.
42 #               Generic OpenSSL-style methods relating to this support
43 #               are always compiled but return NULL if the hardware
44 #               support isn't compiled.
45 # no-hw         do not compile support for any crypto hardware.
46 # [no-]threads  [don't] try to create a library that is suitable for
47 #               multithreaded applications (default is "threads" if we
48 #               know how to do it)
49 # [no-]shared   [don't] try to create shared libraries when supported.
50 # no-asm        do not use assembler
51 # no-dso        do not compile in any native shared-library methods. This
52 #               will ensure that all methods just return NULL.
53 # no-egd        do not compile support for the entropy-gathering daemon APIs
54 # [no-]zlib     [don't] compile support for zlib compression.
55 # zlib-dynamic  Like "zlib", but the zlib library is expected to be a shared
56 #               library and will be loaded in run-time by the OpenSSL library.
57 # sctp          include SCTP support
58 # 386           generate 80386 code
59 # no-sse2       disables IA-32 SSE2 code, above option implies no-sse2
60 # no-<cipher>   build without specified algorithm (rsa, idea, rc5, ...)
61 # -<xxx> +<xxx> compiler options are passed through
62 #
63 # DEBUG_SAFESTACK use type-safe stacks to enforce type-safety on stack items
64 #               provided to stack calls. Generates unique stack functions for
65 #               each possible stack type.
66 # DES_PTR       use pointer lookup vs arrays in the DES in crypto/des/des_locl.h
67 # DES_RISC1     use different DES_ENCRYPT macro that helps reduce register
68 #               dependancies but needs to more registers, good for RISC CPU's
69 # DES_RISC2     A different RISC variant.
70 # DES_UNROLL    unroll the inner DES loop, sometimes helps, somtimes hinders.
71 # DES_INT       use 'int' instead of 'long' for DES_LONG in crypto/des/des.h
72 #               This is used on the DEC Alpha where long is 8 bytes
73 #               and int is 4
74 # BN_LLONG      use the type 'long long' in crypto/bn/bn.h
75 # MD2_CHAR      use 'char' instead of 'int' for MD2_INT in crypto/md2/md2.h
76 # MD2_LONG      use 'long' instead of 'int' for MD2_INT in crypto/md2/md2.h
77 # IDEA_SHORT    use 'short' instead of 'int' for IDEA_INT in crypto/idea/idea.h
78 # IDEA_LONG     use 'long' instead of 'int' for IDEA_INT in crypto/idea/idea.h
79 # RC2_SHORT     use 'short' instead of 'int' for RC2_INT in crypto/rc2/rc2.h
80 # RC2_LONG      use 'long' instead of 'int' for RC2_INT in crypto/rc2/rc2.h
81 # RC4_CHAR      use 'char' instead of 'int' for RC4_INT in crypto/rc4/rc4.h
82 # RC4_LONG      use 'long' instead of 'int' for RC4_INT in crypto/rc4/rc4.h
83 # RC4_INDEX     define RC4_INDEX in crypto/rc4/rc4_locl.h.  This turns on
84 #               array lookups instead of pointer use.
85 # RC4_CHUNK     enables code that handles data aligned at long (natural CPU
86 #               word) boundary.
87 # RC4_CHUNK_LL  enables code that handles data aligned at long long boundary
88 #               (intended for 64-bit CPUs running 32-bit OS).
89 # BF_PTR        use 'pointer arithmatic' for Blowfish (unsafe on Alpha).
90 # BF_PTR2       intel specific version (generic version is more efficient).
91 #
92 # Following are set automatically by this script
93 #
94 # MD5_ASM       use some extra md5 assember,
95 # SHA1_ASM      use some extra sha1 assember, must define L_ENDIAN for x86
96 # RMD160_ASM    use some extra ripemd160 assember,
97 # SHA256_ASM    sha256_block is implemented in assembler
98 # SHA512_ASM    sha512_block is implemented in assembler
99 # AES_ASM       ASE_[en|de]crypt is implemented in assembler
100
101 # Minimum warning options... any contributions to OpenSSL should at least get
102 # past these.
103
104 my $gcc_devteam_warn = "-Wall -pedantic -DPEDANTIC -Wno-long-long -Wsign-compare -Wmissing-prototypes -Wshadow -Wformat -Wtype-limits -Werror -DREF_CHECK -DDEBUG_UNUSED";
105
106 # These are used in addition to $gcc_devteam_warn when the compiler is clang.
107 # TODO(openssl-team): fix problems and investigate if (at least) the
108 # following warnings can also be enabled:
109 # -Wswitch-enum, -Wunused-macros, -Wmissing-field-initializers,
110 # -Wcast-align,
111 # -Wunreachable-code -Wunused-parameter -Wlanguage-extension-token
112 # -Wextended-offsetof
113 my $clang_devteam_warn = "-Wno-unused-parameter -Wno-missing-field-initializers -Wno-language-extension-token -Wno-extended-offsetof -Wconditional-uninitialized -Qunused-arguments -Wincompatible-pointer-types-discards-qualifiers -Wmissing-variable-declarations";
114
115 # Warn that "make depend" should be run?
116 my $warn_make_depend = 0;
117
118 # These are used in addition to $gcc_devteam_warn unless this is a mingw build.
119 # This adds backtrace information to the memory leak info.
120 my $memleak_devteam_backtrace = "-rdynamic -DCRYPTO_MDEBUG_BACKTRACE";
121
122
123 my $strict_warnings = 0;
124
125 my $x86_gcc_des="DES_PTR DES_RISC1 DES_UNROLL";
126
127 # MD2_CHAR slags pentium pros
128 my $x86_gcc_opts="RC4_INDEX MD2_INT";
129
130 #$bits1="SIXTEEN_BIT ";
131 #$bits2="THIRTY_TWO_BIT ";
132 my $bits1="THIRTY_TWO_BIT ";
133 my $bits2="SIXTY_FOUR_BIT ";
134
135 # As for $BSDthreads. Idea is to maintain "collective" set of flags,
136 # which would cover all BSD flavors. -pthread applies to them all,
137 # but is treated differently. OpenBSD expands is as -D_POSIX_THREAD
138 # -lc_r, which is sufficient. FreeBSD 4.x expands it as -lc_r,
139 # which has to be accompanied by explicit -D_THREAD_SAFE and
140 # sometimes -D_REENTRANT. FreeBSD 5.x expands it as -lc_r, which
141 # seems to be sufficient?
142 my $BSDthreads="-pthread -D_THREAD_SAFE -D_REENTRANT";
143
144 #
145 # API compability name to version number mapping.
146 #
147 my $maxapi = "1.1.0";           # API for "no-deprecated" builds
148 my $apitable = {
149     "1.1.0" => "0x10100000L",
150     "1.0.0" => "0x10000000L",
151     "0.9.8" => "0x00908000L",
152 };
153
154 # table of known configurations, read in from files
155 #
156 # The content of each entry can take one of two forms:
157 #
158 # - old style config-string, colon seperated fields with exactly the
159 #   following structure.:
160 #
161 #       $cc : $cflags : $unistd : $thread_cflag : $sys_id : $lflags : $bn_ops : $cpuid_obj : $bn_obj : $ec_obj : $des_obj : $aes_obj : $bf_obj : $md5_obj : $sha1_obj : $cast_obj : $rc4_obj : $rmd160_obj : $rc5_obj : $wp_obj : $cmll_obj : $modes_obj : $engines_obj : $perlasm_scheme : $dso_scheme : $shared_target : $shared_cflag : $shared_ldflag : $shared_extension : $ranlib : $arflags : $multilib
162 #
163 #   We use the stringtohash function - defined below - to combine with the
164 #   fields and form a proper hash table from the string.
165 #
166 # - direct transfer of old style config string to hash table, using the names
167 #   of the fields as keys:
168 #
169 #       {
170 #         cc => $cc,
171 #         cflags => $cflags,
172 #         unistd => $unistd,
173 #         thread_cflag => $thread_cflag,
174 #         sys_id => $sys_id,
175 #         lflags => $lflags,
176 #         bn_ops => $bn_ops,
177 #         cpuid_obj => $cpuid_obj,
178 #         bn_obj => $bn_obj,
179 #         ec_obj => $ec_obj,
180 #         des_obj => $des_obj,
181 #         aes_obj => $aes_obj,
182 #         bf_obj => $bf_obj,
183 #         md5_obj => $md5_obj,
184 #         sha1_obj => $sha1_obj,
185 #         cast_obj => $cast_obj,
186 #         rc4_obj => $rc4_obj,
187 #         rmd160_obj => $rmd160_obj,
188 #         rc5_obj => $rc5_obj,
189 #         wp_obj => $wp_obj,
190 #         cmll_obj => $cmll_obj,
191 #         modes_obj => $modes_obj,
192 #         engines_obj => $engines_obj,
193 #         perlasm_scheme => $perlasm_scheme,
194 #         dso_scheme => $dso_scheme,
195 #         shared_target => $shared_target,
196 #         shared_cflag => $shared_cflag,
197 #         shared_ldflag => $shared_ldflag,
198 #         shared_extension => $shared_extension,
199 #         ranlib => $ranlib,
200 #         arflags => $arflags,
201 #         multilib => $multilib
202 #       }
203 #
204 # - new style config hash table, which has additional attributes for debug
205 #   and non-debug flags to be added to the common flags, for cflags and lflags:
206 #
207 #       {
208 #         cc => $cc,
209 #         cflags => $cflags,
210 #         debug_cflags => $debug_cflags,
211 #         release_cflags => $release_cflags,
212 #         unistd => $unistd,
213 #         thread_cflag => $thread_cflag,
214 #         sys_id => $sys_id,
215 #         lflags => $lflags,
216 #         debug_lflags => $debug_lflags,
217 #         release_lflags => $release_lflags,
218 #         bn_ops => $bn_ops,
219 #         cpuid_obj => $cpuid_obj,
220 #         bn_obj => $bn_obj,
221 #         ec_obj => $ec_obj,
222 #         des_obj => $des_obj,
223 #         aes_obj => $aes_obj,
224 #         bf_obj => $bf_obj,
225 #         md5_obj => $md5_obj,
226 #         sha1_obj => $sha1_obj,
227 #         cast_obj => $cast_obj,
228 #         rc4_obj => $rc4_obj,
229 #         rmd160_obj => $rmd160_obj,
230 #         rc5_obj => $rc5_obj,
231 #         wp_obj => $wp_obj,
232 #         cmll_obj => $cmll_obj,
233 #         modes_obj => $modes_obj,
234 #         engines_obj => $engines_obj,
235 #         chacha_obj => $wp_obj,
236 #         poly1305_obj => $cmll_obj,
237 #         dso_scheme => $dso_scheme,
238 #         shared_target => $shared_target,
239 #         shared_cflag => $shared_cflag,
240 #         shared_ldflag => $shared_ldflag,
241 #         shared_extension => $shared_extension,
242 #         ranlib => $ranlib,
243 #         arflags => $arflags,
244 #         multilib => $multilib
245 #       }
246 #
247 # The configuration reader will do what it can to translate everything into
248 # new style config hash tables, including merging $target and debug-$target
249 # if they are similar enough.
250 #
251 # The configuration hashes can refer to templates in two different manners:
252 #
253 # - as part of the hash, one can have a key called 'inherit_from' that
254 #   indicate what other configuration hashes to inherit data from.
255 #   These are resolved recursively.
256 #
257 #   Inheritance works as a set of default values that can be overriden
258 #   by corresponding attribute values in the inheriting configuration.
259 #
260 #   If several configurations are given in the 'inherit_from' array, the
261 #   values of same attribute are concatenated with space separation.
262 #   With this, it's possible to have several smaller templates for
263 #   different configuration aspects that can be combined into a complete
264 #   configuration.
265 #
266 #   Example:
267 #
268 #       "foo" => {
269 #               template => 1,
270 #               haha => "haha",
271 #               hoho => "ho"
272 #       },
273 #       "bar" => {
274 #               template => 1,
275 #               hoho => "ho",
276 #               hehe => "hehe"
277 #       },
278 #       "laughter" => {
279 #               inherit_from => [ "foo", "bar" ],
280 #       }
281 #
282 #       The entry for "foo" will become as follows after processing:
283 #
284 #       "laughter" => {
285 #               haha => "haha",
286 #               hoho => "ho ho",
287 #               hehe => "hehe"
288 #       }
289 #
290 #   Note 1: any entry from the table can be used as a template.
291 #   Note 2: pure templates have the attribute 'template => 1' and cannot
292 #           be used as targets.
293 #
294 # - instead of a string, one can have a code block of the form
295 #   'sub { /* your code here */ }', where the arguments are the list of
296 #   inherited values for that key.  In fact, the concatenation of strings
297 #   is really done by using 'sub { join(" ",@_) }' on the list of inherited
298 #   values.
299 #
300 #   Example:
301 #
302 #       "foo" => {
303 #               template => 1,
304 #               haha => "ha ha",
305 #               hoho => "ho",
306 #               ignored => "This should not appear in the end result",
307 #       },
308 #       "bar" => {
309 #               template => 1,
310 #               haha => "ah",
311 #               hoho => "haho",
312 #               hehe => "hehe"
313 #       },
314 #       "laughter" => {
315 #               inherit_from => [ "foo", "bar" ],
316 #               hehe => sub { join(" ",(@_,"!!!")) },
317 #               ignored => "",
318 #       }
319 #
320 #       The entry for "foo" will become as follows after processing:
321 #
322 #       "laughter" => {
323 #               haha => "ha ha ah",
324 #               hoho => "ho haho",
325 #               hehe => "hehe !!!",
326 #               ignored => ""
327 #       }
328 #
329
330 my %table=(
331
332     # All these templates are merely a translation of the corresponding
333     # variables further up.
334     #
335     # Note: as long as someone might use old style configuration strings,
336     # or we bother supporting that, those variables need to stay
337
338     x86_asm => {
339         template        => 1,
340         cpuid_obj       => "x86cpuid.o",
341         bn_obj          => "bn-586.o co-586.o x86-mont.o x86-gf2m.o",
342         ec_obj          => "ecp_nistz256.o ecp_nistz256-x86.o",
343         des_obj         => "des-586.o crypt586.o",
344         aes_obj         => "aes-586.o vpaes-x86.o aesni-x86.o",
345         bf_obj          => "bf-586.o",
346         md5_obj         => "md5-586.o",
347         sha1_obj        => "sha1-586.o sha256-586.o sha512-586.o",
348         rc4_obj         => "rc4-586.o",
349         rmd160_obj      => "rmd-586.o",
350         rc5_obj         => "rc5-586.o",
351         wp_obj          => "wp_block.o wp-mmx.o",
352         cmll_obj        => "cmll-x86.o",
353         modes_obj       => "ghash-x86.o",
354         engines_obj     => "e_padlock-x86.o"
355     },
356     x86_elf_asm => {
357         template        => 1,
358         inherit_from    => [ "x86_asm" ],
359         perlasm_scheme  => "elf"
360     },
361     x86_64_asm => {
362         template        => 1,
363         cpuid_obj       => "x86_64cpuid.o",
364         bn_obj          => "x86_64-gcc.o x86_64-mont.o x86_64-mont5.o x86_64-gf2m.o rsaz_exp.o rsaz-x86_64.o rsaz-avx2.o",
365         ec_obj          => "ecp_nistz256.o ecp_nistz256-x86_64.o",
366         aes_obj         => "aes-x86_64.o vpaes-x86_64.o bsaes-x86_64.o aesni-x86_64.o aesni-sha1-x86_64.o aesni-sha256-x86_64.o aesni-mb-x86_64.o",
367         md5_obj         => "md5-x86_64.o",
368         sha1_obj        => "sha1-x86_64.o sha256-x86_64.o sha512-x86_64.o sha1-mb-x86_64.o sha256-mb-x86_64.o",
369         rc4_obj         => "rc4-x86_64.o rc4-md5-x86_64.o",
370         wp_obj          => "wp-x86_64.o",
371         cmll_obj        => "cmll-x86_64.o cmll_misc.o",
372         modes_obj       => "ghash-x86_64.o aesni-gcm-x86_64.o",
373         engines_obj     => "e_padlock-x86_64.o"
374     },
375     ia64_asm => {
376         template        => 1,
377         cpuid_obj       => "ia64cpuid.o",
378         bn_obj          => "bn-ia64.o ia64-mont.o",
379         aes_obj         => "aes_core.o aes_cbc.o aes-ia64.o",
380         md5_obj         => "md5-ia64.o",
381         sha1_obj        => "sha1-ia64.o sha256-ia64.o sha512-ia64.o",
382         rc4_obj         => "rc4-ia64.o rc4_skey.o",
383         modes_obj       => "ghash-ia64.o",
384         perlasm_scheme  => "void"
385     },
386     sparcv9_asm => {
387         template        => 1,
388         cpuid_obj       => "sparcv9cap.o sparccpuid.o",
389         bn_obj          => "bn-sparcv9.o sparcv9-mont.o sparcv9a-mont.o vis3-mont.o sparct4-mont.o sparcv9-gf2m.o",
390         ec_obj          => "ecp_nistz256.o ecp_nistz256-sparcv9.o",
391         des_obj         => "des_enc-sparc.o fcrypt_b.o dest4-sparcv9.o",
392         aes_obj         => "aes_core.o aes_cbc.o aes-sparcv9.o aest4-sparcv9.o",
393         md5_obj         => "md5-sparcv9.o",
394         sha1_obj        => "sha1-sparcv9.o sha256-sparcv9.o sha512-sparcv9.o",
395         cmll_obj        => "camellia.o cmll_misc.o cmll_cbc.o cmllt4-sparcv9.o",
396         modes_obj       => "ghash-sparcv9.o",
397         perlasm_scheme  => "void"
398     },
399     sparcv8_asm => {
400         template        => 1,
401         cpuid_obj       => "",
402         bn_obj          => "sparcv8.o",
403         des_obj         => "des_enc-sparc.o fcrypt_b.o",
404         perlasm_scheme  => "void"
405     },
406     alpha_asm => {
407         template        => 1,
408         cpuid_obj       => "alphacpuid.o",
409         bn_obj          => "bn_asm.o alpha-mont.o",
410         sha1_obj        => "sha1-alpha.o",
411         modes_obj       => "ghash-alpha.o",
412         perlasm_scheme  => "void"
413     },
414     mips32_asm => {
415         template        => 1,
416         bn_obj          => "bn-mips.o mips-mont.o",
417         aes_obj         => "aes_cbc.o aes-mips.o",
418         sha1_obj        => "sha1-mips.o sha256-mips.o",
419     },
420     mips64_asm => {
421         inherit_from    => [ "mips32_asm" ],
422         template        => 1,
423         sha1_obj        => sub { join(" ", @_, "sha512-mips.o") }
424     },
425     s390x_asm => {
426         template        => 1,
427         cpuid_obj       => "s390xcap.o s390xcpuid.o",
428         bn_obj          => "bn-s390x.o s390x-mont.o s390x-gf2m.o",
429         aes_obj         => "aes-s390x.o aes-ctr.o aes-xts.o",
430         sha1_obj        => "sha1-s390x.o sha256-s390x.o sha512-s390x.o",
431         rc4_obj         => "rc4-s390x.o",
432         modes_obj       => "ghash-s390x.o",
433     },
434     armv4_asm => {
435         template        => 1,
436         cpuid_obj       => "armcap.o armv4cpuid.o",
437         bn_obj          => "bn_asm.o armv4-mont.o armv4-gf2m.o",
438         ec_obj          => "ecp_nistz256.o ecp_nistz256-armv4.o",
439         aes_obj         => "aes_cbc.o aes-armv4.o bsaes-armv7.o aesv8-armx.o",
440         sha1_obj        => "sha1-armv4-large.o sha256-armv4.o sha512-armv4.o",
441         modes_obj       => "ghash-armv4.o ghashv8-armx.o",
442         perlasm_scheme  => "void"
443     },
444     aarch64_asm => {
445         template        => 1,
446         cpuid_obj       => "armcap.o arm64cpuid.o mem_clr.o",
447         ec_obj          => "ecp_nistz256.o ecp_nistz256-armv8.o",
448         bn_obj          => "bn_asm.o armv8-mont.o",
449         aes_obj         => "aes_core.o aes_cbc.o aesv8-armx.o vpaes-armv8.o",
450         sha1_obj        => "sha1-armv8.o sha256-armv8.o sha512-armv8.o",
451         modes_obj       => "ghashv8-armx.o",
452     },
453     parisc11_asm => {
454         template        => 1,
455         cpuid_obj       => "pariscid.o",
456         bn_obj          => "bn_asm.o parisc-mont.o",
457         aes_obj         => "aes_core.o aes_cbc.o aes-parisc.o",
458         sha1_obj        => "sha1-parisc.o sha256-parisc.o sha512-parisc.o",
459         rc4_obj         => "rc4-parisc.o",
460         modes_obj       => "ghash-parisc.o",
461         perlasm_scheme  => "32"
462     },
463     parisc20_64_asm => {
464         template        => 1,
465         inherit_from    => [ "parisc11_asm" ],
466         bn_obj          => sub { my $r=join(" ",@_); $r=~s/bn_asm/pa-risc2W/; $r; },
467         perlasm_scheme  => "64",
468     },
469     ppc64_asm => {
470         template        => 1,
471         cpuid_obj       => "ppccpuid.o ppccap.o",
472         bn_obj          => "bn-ppc.o ppc-mont.o ppc64-mont.o",
473         aes_obj         => "aes_core.o aes_cbc.o aes-ppc.o vpaes-ppc.o aesp8-ppc.o",
474         sha1_obj        => "sha1-ppc.o sha256-ppc.o sha512-ppc.o sha256p8-ppc.o sha512p8-ppc.o",
475         modes_obj       => "ghashp8-ppc.o",
476     },
477     ppc32_asm => {
478         inherit_from    => [ "ppc64_asm" ],
479         template        => 1
480     },
481 );
482
483 {   my $no_asm_templates=0;
484     foreach (@ARGV) { $no_asm_templates=1 if (/^\-?no\-asm$/); }
485     sub asm { $no_asm_templates?():@_; }
486 }
487
488
489 sub stringtohash {
490     my $in = shift @_;
491     if (ref($in) eq "HASH") {
492         return $in;
493     }
494     my @stringsequence = (
495         "cc",
496         "cflags",
497         "unistd",
498         "thread_cflag",
499         "sys_id",
500         "lflags",
501         "bn_ops",
502         "cpuid_obj",
503         "bn_obj",
504         "ec_obj",
505         "des_obj",
506         "aes_obj",
507         "bf_obj",
508         "md5_obj",
509         "sha1_obj",
510         "cast_obj",
511         "rc4_obj",
512         "rmd160_obj",
513         "rc5_obj",
514         "wp_obj",
515         "cmll_obj",
516         "modes_obj",
517         "engines_obj",
518         "perlasm_scheme",
519         "dso_scheme",
520         "shared_target",
521         "shared_cflag",
522         "shared_ldflag",
523         "shared_extension",
524         "ranlib",
525         "arflags",
526         "multilib",
527         );
528
529     # return a ref to a hash, that's what the outer braces are for.
530     return { map { shift @stringsequence => $_ } split /:/, $in };
531 };
532
533 # Read configuration target stanzas from a file, so that people can have
534 # local files with their own definitions
535 sub read_config {
536         my $fname = shift;
537         open(CONFFILE, "< $fname")
538                 or die "Can't open configuration file '$fname'!\n";
539         my $x = $/;
540         undef $/;
541         my $content = <CONFFILE>;
542         $/ = $x;
543         close(CONFFILE);
544         my %targets = ();
545         eval $content;
546
547         # Make sure we have debug- targets first
548         my @keys =
549             sort {
550                 my $a_nd = $a =~ m/^debug-/ ? $' :$a;
551                 my $b_nd = $b =~ m/^debug-/ ? $' :$b;
552                 my $res = 0;
553
554                 if (($a_nd == $a) == ($b_nd == $b)) {
555                     # they are both debug- or not, compare them as they are
556                     $res = $a cmp $b;
557                 } elsif ($a_nd != $a) {
558                     # $a is debug-, make it lesser
559                     $res = -1;
560                 } else {
561                     # $b is debug-, make $a greater
562                     $res = 1;
563                 }
564                 $res;
565             } keys %targets;
566
567         foreach (@keys) {
568             if (ref($targets{$_}) ne "HASH") {
569                 # Value is assumed to be a string.  Split it up to
570                 # become a hash table of parameters.  Also, try to
571                 # merge debug- variants with the non-debug target.
572
573                 # Start with converting the value from a string to a
574                 # standardised hash of fields.  Using $tohash is safe,
575                 # if the input is already a hash ref, it's just returned
576                 # back.
577                 $targets{$_} = stringtohash($targets{$_});
578
579                 # If the current target is a debug target, there might
580                 # be a corresponding non-debug target that we can merge
581                 # with.  If it isn't a debug- target, we've already done
582                 # as much merging as we can and do not need to bother
583                 # with that any more.
584                 if ($_ =~ m/^debug-/) {
585                     my $debugkey = $_;
586                     my $nondebugkey = $';
587                     my $debug = $targets{$debugkey};
588                     my $nondebug;
589
590                     if ($targets{$nondebugkey}) {
591                         $nondebug = stringtohash($targets{$nondebugkey});
592                     }
593
594                     if ($nondebug) {
595                         # There's both a debug and non-debug variant of
596                         # this target, so we should try to merge them
597                         # together.
598
599                         # First, check that the non-debug variant isn't
600                         # already built up with all it should have.
601                         if ($nondebug->{debug_cflags}
602                             || $nondebug->{release_cflags}
603                             || $nondebug->{debug_lflags}
604                             || $nondebug->{release_lflags}) {
605                             warn "there's a debug target $debugkey to be merged with a target $nondebugkey, but the latter seems to already have both nodebug and debug information.  This requires human intervention.  Skipping $debugkey...";
606                             next;
607                         }
608
609                         # Now, check similarity.
610                         # For keys they have in common, support that
611                         # cflags and lflags can differ, otherwise they
612                         # must have exactly the same values for them
613                         # to be merged into one.
614                         my $similarenough = 1;
615                         for (keys %{$debug}) {
616                             if ($nondebug->{$_} ne $debug->{$_}
617                                 && $_ !~ m/^[cl]flags$/) {
618                                 $similarenough = 0;
619                                 last;
620                             }
621                         }
622
623                         if ($similarenough) {
624                             # Here's where the magic happens, split the
625                             # options in the debug and non-debug variants
626                             # cflags and ldflags into three strings each,
627                             # one with common flags, one with extra debug
628                             # flags and one with extra non-debug flags.
629
630                             # The result ends up in %h_nondebug, which
631                             # becomes the merged variant when we're done.
632                             # for each of cflags and lflags, they are
633                             # replaced with cflags, debug_cflags,
634                             # release_cflags and similar for lflags.
635                             #
636                             # The purpose is that 'cflags' should be
637                             # used together with 'debug_cflags' or
638                             # 'release_cflags' depending on what the
639                             # user asks for.
640                             foreach (("cflags", "lflags")) {
641                                 my @list_d = split /\s+/, $debug->{$_};
642                                 my @list_nd = split /\s+/, $nondebug->{$_};
643                                 my %presence = (); # bitmap
644                                                    # 1: present in @list_d
645                                                    # 2: present in @list_nd
646                                                    # 3: present in both
647                                 map { $presence{$_} += 1; } @list_d;
648                                 map { $presence{$_} += 2; } @list_nd;
649
650                                 delete $nondebug->{$_};
651                                 # Note: we build from the original lists to
652                                 # preserve order, it might be important
653                                 $nondebug->{"debug-".$_} =
654                                     join(" ",
655                                          grep { $presence{$_} == 1 } @list_d);
656                                 $nondebug->{"nodebug-".$_} =
657                                     join(" ",
658                                          grep { $presence{$_} == 2 } @list_nd);
659                                 $nondebug->{$_} =
660                                     join(" ",
661                                          grep { $presence{$_} == 3 } @list_d);
662                             }
663
664                             $targets{$nondebugkey} = $nondebug;
665                             delete $targets{$debugkey};
666                         }
667                     }
668                 }
669             }
670         }
671
672         %table = (%table, %targets);
673
674         # Local function to resolve inheritance
675         my $resolve_inheritance;
676         $resolve_inheritance =
677             sub {
678                 my $target = shift;
679                 my @breadcrumbs = @_;
680
681                 if (grep { $_ eq $target } @breadcrumbs) {
682                     die "inherit_from loop!  target backtrace:\n  "
683                         ,$target,"\n  ",join("\n  ", @breadcrumbs),"\n";
684                 }
685
686                 # Recurse through all inheritances.  They will be resolved on
687                 # the fly, so when this operation is done, they will all just
688                 # be a bunch of attributes with string values.
689                 # What we get here, though, are keys with references to lists
690                 # of the combined values of them all.  We will deal with lists
691                 # after this stage is done.
692                 my %combined_inheritance = ();
693                 if ($table{$target}->{inherit_from}) {
694                     foreach (@{$table{$target}->{inherit_from}}) {
695                         my %inherited_config =
696                             $resolve_inheritance->($_, $target, @breadcrumbs);
697
698                         # 'template' is a marker that's considered private to
699                         # the config that had it.
700                         delete $inherited_config{template};
701
702                         map {
703                             if (!$combined_inheritance{$_}) {
704                                 $combined_inheritance{$_} = [];
705                             }
706                             push @{$combined_inheritance{$_}}, $inherited_config{$_};
707                         } keys %inherited_config;
708                     }
709                 }
710
711                 # We won't need inherit_from in this target any more, since
712                 # we've resolved all the inheritances that lead to this
713                 delete $table{$target}->{inherit_from};
714
715                 # Now is the time to deal with those lists.  Here's the place
716                 # to decide what shall be done with those lists, all based on
717                 # the values of the target we're currently dealing with.
718                 # - If a value is a coderef, it will be executed with the list
719                 #   of inherited values as arguments.
720                 # - If the corresponding key doesn't have a value at all or is
721                 #   the emoty string, the inherited value list will be run
722                 #   through the default combiner (below), and the result
723                 #   becomes this target's value.
724                 # - Otherwise, this target's value is assumed to be a string
725                 #   that will simply override the inherited list of values.
726                 my $default_combiner = sub { join(' ',@_) };
727
728                 my %all_keys =
729                     map { $_ => 1 } (keys %combined_inheritance,
730                                      keys %{$table{$target}});
731                 foreach (sort keys %all_keys) {
732
733                     # Current target doesn't have a value for the current key?
734                     # Assign it the default combiner, the rest of this loop
735                     # body will handle it just like any other coderef.
736                     if (!exists $table{$target}->{$_}) {
737                         $table{$target}->{$_} = $default_combiner;
738                     }
739
740                     my $valuetype = ref($table{$target}->{$_});
741                     if ($valuetype eq "CODE") {
742                         # CODE reference, execute it with the inherited values
743                         # as arguments.
744                         $table{$target}->{$_} =
745                             $table{$target}->{$_}->(@{$combined_inheritance{$_}});
746                     } elsif ($valuetype eq "") {
747                         # Scalar, just leave it as is.
748                     } else {
749                         # Some other type of reference that we don't handle.
750                         # Better to abort at this point.
751                         die "cannot handle reference type $valuetype,"
752                             ," found in target $target -> $_\n";
753                     }
754                 }
755
756                 # Finally done, return the result.
757                 %{$table{$target}};
758         };
759
760         # Go through all new targets and resolve inheritance and template
761         # references.
762         foreach (keys %targets) {
763             # We're ignoring the returned values here, they are only valuable
764             # to the inner recursion of this function.
765             $resolve_inheritance->($_);
766         }
767 }
768
769 my ($vol, $dir, $dummy) = File::Spec->splitpath($0);
770 my $pattern = File::Spec->catpath($vol, $dir, "Configurations/*.conf");
771 foreach (sort glob($pattern) ) {
772     &read_config($_);
773 }
774
775 my @MK1MF_Builds=qw(VC-WIN64I VC-WIN64A
776                     debug-VC-WIN64I debug-VC-WIN64A
777                     VC-NT VC-CE VC-WIN32 debug-VC-WIN32
778                     BC-32
779                     netware-clib netware-clib-bsdsock
780                     netware-libc netware-libc-bsdsock);
781
782 my $prefix="";
783 my $libdir="";
784 my $openssldir="";
785 my $exe_ext="";
786 my $install_prefix= "$ENV{'INSTALL_PREFIX'}";
787 my $cross_compile_prefix="";
788 my $fipslibdir="/usr/local/ssl/fips-2.0/lib/";
789 my $nofipscanistercheck=0;
790 my $baseaddr="0xFB00000";
791 my $no_threads=0;
792 my $threads=0;
793 my $no_shared=0; # but "no-shared" is default
794 my $zlib=1;      # but "no-zlib" is default
795 my $no_rfc3779=0;
796 my $no_asm=0;
797 my $no_dso=0;
798 my @skip=();
799 my $Makefile="Makefile";
800 my $des_locl="crypto/des/des_locl.h";
801 my $des ="include/openssl/des.h";
802 my $bn  ="include/openssl/bn.h";
803 my $md2 ="include/openssl/md2.h";
804 my $rc4 ="include/openssl/rc4.h";
805 my $rc4_locl="crypto/rc4/rc4_locl.h";
806 my $idea        ="include/openssl/idea.h";
807 my $rc2 ="include/openssl/rc2.h";
808 my $bf  ="crypto/bf/bf_locl.h";
809 my $bn_asm      ="bn_asm.o";
810 my $des_enc="des_enc.o fcrypt_b.o";
811 my $aes_enc="aes_core.o aes_cbc.o";
812 my $bf_enc      ="bf_enc.o";
813 my $cast_enc="c_enc.o";
814 my $rc4_enc="rc4_enc.o rc4_skey.o";
815 my $rc5_enc="rc5_enc.o";
816 my $cmll_enc="camellia.o cmll_misc.o cmll_cbc.o";
817 my $chacha_enc="chacha_enc.o";
818 my $processor="";
819 my $default_ranlib;
820 my $perl;
821 my $fips=0;
822
823 # Known TLS and DTLS protocols
824 my @tls = qw(ssl3 tls1 tls1_1 tls1_2);
825 my @dtls = qw(dtls1 dtls1_2);
826
827 # Explicitelly known options that are possible to disable.  They can
828 # be regexps, and will be used like this: /^no-${option}$/
829 # For developers: keep it sorted alphabetically
830
831 my @disablables = (
832     "aes",
833     "asm",
834     "bf",
835     "camellia",
836     "capieng",
837     "cast",
838     "chacha",
839     "cmac",
840     "cms",
841     "comp",
842     "crypto-mdebug",
843     "ct",
844     "deprecated",
845     "des",
846     "dgram",
847     "dh",
848     "dsa",
849     "dso",
850     "dtls",
851     "dynamic[-_]engine",
852     "ec",
853     "ec2m",
854     "ecdh",
855     "ecdsa",
856     "ec_nistp_64_gcc_128",
857     "engine",
858     "err",                      # Really???
859     "gost",
860     "heartbeats",
861     "hmac",
862     "hw(-.+)?",
863     "idea",
864     "jpake",
865     "locking",                  # Really???
866     "md2",
867     "md4",
868     "md5",
869     "mdc2",
870     "md[-_]ghost94",
871     "nextprotoneg",
872     "ocb",
873     "ocsp",
874     "poly1305",
875     "posix-io",
876     "psk",
877     "rc2",
878     "rc4",
879     "rc5",
880     "rdrand",
881     "rfc3779",
882     "rijndael",                 # Old AES name
883     "rmd160",
884     "rsa",
885     "scrypt",
886     "sct",
887     "sctp",
888     "seed",
889     "sha",
890     "shared",
891     "sock",
892     "srp",
893     "srtp",
894     "sse2",
895     "ssl",
896     "ssl-trace",
897     "static-engine",
898     "stdio",
899     "store",
900     "threads",
901     "tls",
902     "unit-test",
903     "whirlpool",
904     "zlib",
905     "zlib-dynamic",
906     );
907 foreach my $proto ((@tls, @dtls))
908         {
909         push(@disablables, $proto);
910         push(@disablables, "$proto-method");
911         }
912
913 # All of the following is disabled by default (RC5 was enabled before 0.9.8):
914
915 my %disabled = ( # "what"         => "comment" [or special keyword "experimental"]
916                  "ec_nistp_64_gcc_128" => "default",
917                  "egd"            => "default",
918                  "jpake"          => "experimental",
919                  "md2"            => "default",
920                  "rc5"            => "default",
921                  "sctp"           => "default",
922                  "shared"         => "default",
923                  "ssl-trace"      => "default",
924                  "store"          => "experimental",
925                  "unit-test"      => "default",
926                  "zlib"           => "default",
927                  "zlib-dynamic"   => "default",
928                  "crypto-mdebug"  => "default",
929                );
930 my @experimental = ();
931
932 # This is what $depflags will look like with the above defaults
933 # (we need this to see if we should advise the user to run "make depend"):
934 my $default_depflags = " -DOPENSSL_NO_CRYPTO_MDEBUG -DOPENSSL_NO_EC_NISTP_64_GCC_128 -DOPENSSL_NO_JPAKE -DOPENSSL_NO_MD2 -DOPENSSL_NO_RC5 -DOPENSSL_NO_SCTP -DOPENSSL_NO_SSL_TRACE -DOPENSSL_NO_STORE -DOPENSSL_NO_UNIT_TEST";
935
936 # Explicit "no-..." options will be collected in %disabled along with the defaults.
937 # To remove something from %disabled, use "enable-foo" (unless it's experimental).
938 # For symmetry, "disable-foo" is a synonym for "no-foo".
939
940 # For features called "experimental" here, a more explicit "experimental-foo" is needed to enable.
941 # We will collect such requests in @experimental.
942 # To avoid accidental use of experimental features, applications will have to use -DOPENSSL_EXPERIMENTAL_FOO.
943
944
945 my $no_sse2=0;
946
947 &usage if ($#ARGV < 0);
948
949 my $flags;
950 my $depflags;
951 my $openssl_experimental_defines;
952 my $openssl_algorithm_defines;
953 my $openssl_thread_defines;
954 my $openssl_sys_defines="";
955 my $openssl_other_defines;
956 my $libs;
957 my $target;
958 my $options;
959 my $api;
960 my $make_depend=0;
961 my %withargs=();
962 my $build_prefix = "release_";
963
964 my @argvcopy=@ARGV;
965 my $argvstring="";
966 my $argv_unprocessed=1;
967
968 while($argv_unprocessed)
969         {
970         $flags="";
971         $depflags="";
972         $openssl_experimental_defines="";
973         $openssl_algorithm_defines="";
974         $openssl_thread_defines="";
975         $openssl_sys_defines="";
976         $openssl_other_defines="";
977         $libs="";
978         $target="";
979         $options="";
980
981         $argv_unprocessed=0;
982         $argvstring=join(' ',@argvcopy);
983
984 PROCESS_ARGS:
985         {
986         my %unsupported_options = ();
987         foreach (@argvcopy)
988                 {
989                 s /^-no-/no-/; # some people just can't read the instructions
990
991                 # rewrite some options in "enable-..." form
992                 s /^-?-?shared$/enable-shared/;
993                 s /^sctp$/enable-sctp/;
994                 s /^threads$/enable-threads/;
995                 s /^zlib$/enable-zlib/;
996                 s /^zlib-dynamic$/enable-zlib-dynamic/;
997
998                 if (/^(no|disable|enable|experimental)-(.+)$/)
999                         {
1000                         my $word = $2;
1001                         if (!grep { $word =~ /^${_}$/ } @disablables)
1002                                 {
1003                                 $unsupported_options{$_} = 1;
1004                                 next;
1005                                 }
1006                         }
1007                 if (/^no-(.+)$/ || /^disable-(.+)$/)
1008                         {
1009                         if (!($disabled{$1} eq "experimental"))
1010                                 {
1011                                 foreach my $proto ((@tls, @dtls))
1012                                         {
1013                                         if ($1 eq "$proto-method")
1014                                                 {
1015                                                 $disabled{"$proto"} = "option($proto-method)";
1016                                                 last;
1017                                                 }
1018                                         }
1019                                 if ($1 eq "dtls")
1020                                         {
1021                                         foreach my $proto (@dtls)
1022                                                 {
1023                                                 $disabled{$proto} = "option(dtls)";
1024                                                 }
1025                                         }
1026                                 elsif ($1 eq "ssl")
1027                                         {
1028                                         # Last one of its kind
1029                                         $disabled{"ssl3"} = "option(ssl)";
1030                                         }
1031                                 elsif ($1 eq "tls")
1032                                         {
1033                                         # XXX: Tests will fail if all SSL/TLS
1034                                         # protocols are disabled.
1035                                         foreach my $proto (@tls)
1036                                                 {
1037                                                 $disabled{$proto} = "option(tls)";
1038                                                 }
1039                                         }
1040                                 else
1041                                         {
1042                                         $disabled{$1} = "option";
1043                                         }
1044                                 }
1045                         }
1046                 elsif (/^enable-(.+)$/ || /^experimental-(.+)$/)
1047                         {
1048                         my $algo = $1;
1049                         if ($disabled{$algo} eq "experimental")
1050                                 {
1051                                 die "You are requesting an experimental feature; please say 'experimental-$algo' if you are sure\n"
1052                                         unless (/^experimental-/);
1053                                 push @experimental, $algo;
1054                                 }
1055                         delete $disabled{$algo};
1056
1057                         $threads = 1 if ($algo eq "threads");
1058                         }
1059                 elsif (/^--test-sanity$/)
1060                         {
1061                         exit(&test_sanity());
1062                         }
1063                 elsif (/^--strict-warnings$/)
1064                         {
1065                         $strict_warnings = 1;
1066                         }
1067                 elsif (/^--debug$/)
1068                         {
1069                         $build_prefix = "debug_";
1070                         }
1071                 elsif (/^--release$/)
1072                         {
1073                         $build_prefix = "release_";
1074                         }
1075                 elsif (/^reconfigure/ || /^reconf/)
1076                         {
1077                         if (open(IN,"<$Makefile"))
1078                                 {
1079                                 my $config_args_found=0;
1080                                 while (<IN>)
1081                                         {
1082                                         chomp;
1083                                         if (/^CONFIGURE_ARGS=(.*)/)
1084                                                 {
1085                                                 $argvstring=$1;
1086                                                 @argvcopy=split(' ',$argvstring);
1087                                                 die "Incorrect data to reconfigure, please do a normal configuration\n"
1088                                                         if (grep(/^reconf/,@argvcopy));
1089                                                 print "Reconfiguring with: $argvstring\n";
1090                                                 $argv_unprocessed=1;
1091                                                 $config_args_found=1;
1092                                                 }
1093                                         elsif (/^CROSS_COMPILE=\s*(.*)/)
1094                                                 {
1095                                                 $ENV{CROSS_COMPILE}=$1;
1096                                                 }
1097                                         elsif (/^CC=\s*(?:\$\(CROSS_COMPILE\))?(.*?)$/)
1098                                                 {
1099                                                 $ENV{CC}=$1;
1100                                                 }
1101                                         }
1102                                 close(IN);
1103                                 last PROCESS_ARGS if ($config_args_found);
1104                                 }
1105                         die "Insufficient data to reconfigure, please do a normal configuration\n";
1106                         }
1107                 elsif (/^386$/)
1108                         { $processor=386; }
1109                 elsif (/^fips$/)
1110                         {
1111                         $fips=1;
1112                         }
1113                 elsif (/^rsaref$/)
1114                         {
1115                         # No RSAref support any more since it's not needed.
1116                         # The check for the option is there so scripts aren't
1117                         # broken
1118                         }
1119                 elsif (/^nofipscanistercheck$/)
1120                         {
1121                         $fips = 1;
1122                         $nofipscanistercheck = 1;
1123                         }
1124                 elsif (/^[-+]/)
1125                         {
1126                         if (/^--prefix=(.*)$/)
1127                                 {
1128                                 $prefix=$1;
1129                                 }
1130                         elsif (/^--api=(.*)$/)
1131                                 {
1132                                 $api=$1;
1133                                 }
1134                         elsif (/^--libdir=(.*)$/)
1135                                 {
1136                                 $libdir=$1;
1137                                 }
1138                         elsif (/^--openssldir=(.*)$/)
1139                                 {
1140                                 $openssldir=$1;
1141                                 }
1142                         elsif (/^--install.prefix=(.*)$/)
1143                                 {
1144                                 $install_prefix=$1;
1145                                 }
1146                         elsif (/^--with-zlib-lib=(.*)$/)
1147                                 {
1148                                 $withargs{"zlib-lib"}=$1;
1149                                 }
1150                         elsif (/^--with-zlib-include=(.*)$/)
1151                                 {
1152                                 $withargs{"zlib-include"}="-I$1";
1153                                 }
1154                         elsif (/^--with-fipslibdir=(.*)$/)
1155                                 {
1156                                 $fipslibdir="$1/";
1157                                 }
1158                         elsif (/^--with-baseaddr=(.*)$/)
1159                                 {
1160                                 $baseaddr="$1";
1161                                 }
1162                         elsif (/^--cross-compile-prefix=(.*)$/)
1163                                 {
1164                                 $cross_compile_prefix=$1;
1165                                 }
1166                         elsif (/^--config=(.*)$/)
1167                                 {
1168                                 read_config $1;
1169                                 }
1170                         elsif (/^-[lL](.*)$/ or /^-Wl,/)
1171                                 {
1172                                 $libs.=$_." ";
1173                                 }
1174                         else    # common if (/^[-+]/), just pass down...
1175                                 {
1176                                 $_ =~ s/%([0-9a-f]{1,2})/chr(hex($1))/gei;
1177                                 $flags.=$_." ";
1178                                 }
1179                         }
1180                 elsif ($_ =~ /^([^:]+):(.+)$/)
1181                         {
1182                         eval "\$table{\$1} = \"$2\""; # allow $xxx constructs in the string
1183                         $target=$1;
1184                         }
1185                 else
1186                         {
1187                         die "target already defined - $target (offending arg: $_)\n" if ($target ne "");
1188                         $target=$_;
1189                         }
1190
1191                 unless ($_ eq $target || /^no-/ || /^disable-/)
1192                         {
1193                         # "no-..." follows later after implied disactivations
1194                         # have been derived.  (Don't take this too seroiusly,
1195                         # we really only write OPTIONS to the Makefile out of
1196                         # nostalgia.)
1197
1198                         if ($options eq "")
1199                                 { $options = $_; }
1200                         else
1201                                 { $options .= " ".$_; }
1202                         }
1203                 }
1204
1205         if (defined($api) && !exists $apitable->{$api}) {
1206                 die "***** Unsupported api compatibility level: $api\n",
1207         }
1208
1209         if (keys %unsupported_options)
1210                 {
1211                 die "***** Unsupported options: ",
1212                         join(", ", keys %unsupported_options), "\n";
1213                 }
1214         }
1215         }
1216
1217
1218 if ($processor eq "386")
1219         {
1220         $disabled{"sse2"} = "forced";
1221         }
1222
1223 if (!defined($disabled{"zlib-dynamic"}))
1224         {
1225         # "zlib-dynamic" was specifically enabled, so enable "zlib"
1226         delete $disabled{"zlib"};
1227         }
1228
1229 if (defined($disabled{"rijndael"}))
1230         {
1231         $disabled{"aes"} = "forced";
1232         }
1233 if (defined($disabled{"des"}))
1234         {
1235         $disabled{"mdc2"} = "forced";
1236         }
1237 if (defined($disabled{"ec"}))
1238         {
1239         $disabled{"ecdsa"} = "forced";
1240         $disabled{"ecdh"} = "forced";
1241         }
1242
1243 # SSL 3.0 requires MD5 and SHA and either RSA or DSA+DH
1244 if (defined($disabled{"md5"}) || defined($disabled{"sha"})
1245     || (defined($disabled{"rsa"})
1246         && (defined($disabled{"dsa"}) || defined($disabled{"dh"}))))
1247         {
1248         $disabled{"ssl3"} = "forced";
1249         $disabled{"ssl"} = "forced";
1250         }
1251
1252 # (D)TLS 1.0 and TLS 1.1 require MD5 and SHA and either RSA or DSA+DH
1253 # or ECDSA + ECDH.  (XXX: We don't support PSK-only builds).
1254 #
1255 if (defined($disabled{"md5"}) || defined($disabled{"sha"})
1256     || (defined($disabled{"rsa"})
1257         && (defined($disabled{"dsa"}) || defined($disabled{"dh"}))
1258         && (defined($disabled{"ecdsa"}) || defined($disabled{"ecdh"}))))
1259         {
1260         $disabled{"tls1"} = "forced";
1261         $disabled{"dtls1"} = "forced";
1262         $disabled{"tls1_1"} = "forced";
1263         }
1264
1265 # (D)TLS 1.2 requires either RSA or DSA+DH or ECDSA + ECDH
1266 # So if all are missing, we can't do either TLS or DTLS.
1267 # (XXX: We don't support PSK-only builds).
1268 #
1269 if (defined($disabled{"rsa"})
1270     && (defined($disabled{"dsa"}) || defined($disabled{"dh"}))
1271     && (defined($disabled{"ecdsa"}) || defined($disabled{"ecdh"})))
1272         {
1273         $disabled{"tls"} = "forced";
1274         $disabled{"dtls"} = "forced";
1275         foreach my $proto ((@tls, @dtls))
1276                 {
1277                 $disabled{"$proto"} = "forced";
1278                 }
1279         }
1280
1281
1282 # Avoid protocol support holes.  Also disable all versions below N, if version
1283 # N is disabled while N+1 is enabled.
1284 #
1285 my $prev_disabled = 1;
1286 my $force_disable = 0;
1287 foreach my $proto (reverse(@tls))
1288         {
1289         if ($force_disable)
1290                 {
1291                 $disabled{$proto} = 1;
1292                 }
1293         elsif (! defined($disabled{$proto}))
1294                 {
1295                 $prev_disabled = 0;
1296                 }
1297         elsif (! $prev_disabled)
1298                 {
1299                 $force_disable = 1;
1300                 }
1301         }
1302 my $prev_disabled = 1;
1303 my $force_disable = 0;
1304 foreach my $proto (reverse(@dtls))
1305         {
1306         if ($force_disable)
1307                 {
1308                 $disabled{$proto} = 1;
1309                 }
1310         elsif (! defined($disabled{$proto}))
1311                 {
1312                 $prev_disabled = 0;
1313                 }
1314         elsif (! $prev_disabled)
1315                 {
1316                 $force_disable = 1;
1317                 }
1318         }
1319
1320 if (defined($disabled{"dgram"}))
1321         {
1322         $disabled{"dtls"} = "forced";
1323         $disabled{"dtls1"} = "forced";
1324         $disabled{"dtls1_2"} = "forced";
1325         }
1326
1327 if (defined($disabled{"ec"}) || defined($disabled{"dsa"})
1328     || defined($disabled{"dh"}) || defined($disabled{"stdio"}))
1329         {
1330         $disabled{"gost"} = "forced";
1331         }
1332
1333
1334 if ($target eq "TABLE") {
1335         foreach $target (sort keys %table) {
1336                 print_table_entry($target, "TABLE");
1337         }
1338         exit 0;
1339 }
1340
1341 if ($target eq "LIST") {
1342         foreach (sort keys %table) {
1343                 print;
1344                 print "\n";
1345         }
1346         exit 0;
1347 }
1348
1349 if ($target eq "HASH") {
1350         print "%table = (\n";
1351         foreach (sort keys %table) {
1352                 print_table_entry($_, "HASH");
1353         }
1354         exit 0;
1355 }
1356
1357 if ($target =~ m/^CygWin32(-.*)$/) {
1358         $target = "Cygwin".$1;
1359 }
1360
1361 print "Configuring for $target\n";
1362
1363 # Support for legacy targets having a name starting with 'debug-'
1364 my ($d, $t) = $target =~ m/^(debug-)?(.*)$/;
1365 if ($d) {
1366     $build_prefix = "debug_";
1367
1368     # If we do not find debug-foo in the table, the target is set to foo,
1369     # but only if the foo target has a noon-empty debug_cflags or debug_lflags
1370     # attribute.
1371     if (!$table{$target}) {
1372         $target = $t;
1373     }
1374 }
1375
1376 &usage if (!defined($table{$target}) || $table{$target}->{template});
1377
1378 if ($fips)
1379         {
1380         delete $disabled{"shared"} if ($disabled{"shared"} eq "default");
1381         }
1382
1383 foreach (sort (keys %disabled))
1384         {
1385         $options .= " no-$_";
1386
1387         printf "    no-%-12s %-10s", $_, "[$disabled{$_}]";
1388
1389         if (/^dso$/)
1390                 { $no_dso = 1; }
1391         elsif (/^threads$/)
1392                 { $no_threads = 1; }
1393         elsif (/^shared$/)
1394                 { $no_shared = 1; }
1395         elsif (/^zlib$/)
1396                 { $zlib = 0; }
1397         elsif (/^static-engine$/)
1398                 { }
1399         elsif (/^zlib-dynamic$/)
1400                 { }
1401         elsif (/^sse2$/)
1402                 { $no_sse2 = 1; }
1403         else
1404                 {
1405                 my ($ALGO, $algo);
1406                 ($ALGO = $algo = $_) =~ tr/[\-a-z]/[_A-Z]/;
1407
1408                 if (/^asm$/ || /^err$/ || /^hw$/ || /^hw-/)
1409                         {
1410                         $openssl_other_defines .= "#define OPENSSL_NO_$ALGO\n";
1411                         print " OPENSSL_NO_$ALGO";
1412
1413                         if (/^err$/)    { $flags .= "-DOPENSSL_NO_ERR "; }
1414                         elsif (/^asm$/) { $no_asm = 1; }
1415                         }
1416                 else
1417                         {
1418                         ($ALGO,$algo) = ("RMD160","rmd160") if ($algo eq "ripemd");
1419
1420                         $openssl_algorithm_defines .= "#define OPENSSL_NO_$ALGO\n";
1421                         print " OPENSSL_NO_$ALGO";
1422
1423                         push @skip, $algo;
1424                         # fix-up crypto/directory name(s)
1425                         $skip[$#skip]="whrlpool" if $algo eq "whirlpool";
1426                         $skip[$#skip]="ripemd" if $algo eq "rmd160";
1427
1428                         print " (skip dir)";
1429
1430                         $depflags .= " -DOPENSSL_NO_$ALGO";
1431                         }
1432                 }
1433
1434         print "\n";
1435         }
1436
1437 my $exp_cflags = "";
1438
1439 foreach (sort @experimental)
1440         {
1441         my $ALGO;
1442         ($ALGO = $_) =~ tr/[a-z]/[A-Z]/;
1443
1444         # opensslconf.h will set OPENSSL_NO_... unless OPENSSL_EXPERIMENTAL_... is defined
1445         $openssl_experimental_defines .= "#define OPENSSL_NO_$ALGO\n";
1446         $exp_cflags .= " -DOPENSSL_EXPERIMENTAL_$ALGO";
1447         }
1448
1449 my $IsMK1MF=scalar grep /^$target$/,@MK1MF_Builds;
1450
1451 $exe_ext=".exe" if ($target eq "Cygwin" || $target eq "DJGPP" || $target =~ /^mingw/);
1452 $exe_ext=".nlm" if ($target =~ /netware/);
1453 $exe_ext=".pm"  if ($target =~ /vos/);
1454 $openssldir="/usr/local/ssl" if ($openssldir eq "" and $prefix eq "");
1455 $prefix=$openssldir if $prefix eq "";
1456
1457 $default_ranlib= &which("ranlib") or $default_ranlib="true";
1458 $perl=$ENV{'PERL'} or $perl=&which("perl5") or $perl=&which("perl")
1459   or $perl="perl";
1460 my $make = $ENV{'MAKE'} || "make";
1461
1462 $cross_compile_prefix=$ENV{'CROSS_COMPILE'} if $cross_compile_prefix eq "";
1463
1464 chop $openssldir if $openssldir =~ /\/$/;
1465 chop $prefix if $prefix =~ /.\/$/;
1466
1467 $openssldir=$prefix . "/ssl" if $openssldir eq "";
1468 $openssldir=$prefix . "/" . $openssldir if $openssldir !~ /(^\/|^[a-zA-Z]:[\\\/])/;
1469
1470
1471 print "IsMK1MF=$IsMK1MF\n";
1472
1473 # Allow environment CC to override compiler...
1474 my $cc = $ENV{CC} || $table{$target}->{cc};
1475
1476 # For cflags and lflags, add the debug_ or release_ attributes
1477 # Do it in such a way that no spurious space is appended (hence the grep).
1478 my $cflags = join(" ",
1479                   grep { $_ } ($table{$target}->{cflags},
1480                                $table{$target}->{$build_prefix."cflags"}));
1481 my $lflags = join(" ",
1482                   grep { $_ } ($table{$target}->{lflags},
1483                                $table{$target}->{$build_prefix."lflags"}));
1484
1485 my $unistd = $table{$target}->{unistd};
1486 my $thread_cflag = $table{$target}->{thread_cflag};
1487 my $sys_id = $table{$target}->{sys_id};
1488 my $bn_ops = $table{$target}->{bn_ops};
1489 my $cpuid_obj = $table{$target}->{cpuid_obj};
1490 my $bn_obj = $table{$target}->{bn_obj};
1491 my $ec_obj = $table{$target}->{ec_obj};
1492 my $des_obj = $table{$target}->{des_obj};
1493 my $aes_obj = $table{$target}->{aes_obj};
1494 my $bf_obj = $table{$target}->{bf_obj};
1495 my $md5_obj = $table{$target}->{md5_obj};
1496 my $sha1_obj = $table{$target}->{sha1_obj};
1497 my $cast_obj = $table{$target}->{cast_obj};
1498 my $rc4_obj = $table{$target}->{rc4_obj};
1499 my $rmd160_obj = $table{$target}->{rmd160_obj};
1500 my $rc5_obj = $table{$target}->{rc5_obj};
1501 my $wp_obj = $table{$target}->{wp_obj};
1502 my $cmll_obj = $table{$target}->{cmll_obj};
1503 my $modes_obj = $table{$target}->{modes_obj};
1504 my $engines_obj = $table{$target}->{engines_obj};
1505 my $chacha_obj = $table{$target}->{chacha_obj};
1506 my $poly1305_obj = $table{$target}->{poly1305_obj};
1507 my $perlasm_scheme = $table{$target}->{perlasm_scheme};
1508 my $dso_scheme = $table{$target}->{dso_scheme};
1509 my $shared_target = $table{$target}->{shared_target};
1510 my $shared_cflag = $table{$target}->{shared_cflag};
1511 my $shared_ldflag = $table{$target}->{shared_ldflag};
1512 my $shared_extension = $table{$target}->{shared_extension};
1513 my $ranlib = $ENV{'RANLIB'} || $table{$target}->{ranlib};
1514 my $ar = $ENV{'AR'} || "ar";
1515 my $arflags = $table{$target}->{arflags};
1516 my $multilib = $table{$target}->{multilib};
1517
1518 # if $prefix/lib$multilib is not an existing directory, then
1519 # assume that it's not searched by linker automatically, in
1520 # which case adding $multilib suffix causes more grief than
1521 # we're ready to tolerate, so don't...
1522 $multilib="" if !-d "$prefix/lib$multilib";
1523
1524 $libdir="lib$multilib" if $libdir eq "";
1525
1526 $cflags = "$cflags$exp_cflags";
1527
1528 # '%' in $lflags is used to split flags to "pre-" and post-flags
1529 my ($prelflags,$postlflags)=split('%',$lflags);
1530 if (defined($postlflags))       { $lflags=$postlflags;  }
1531 else                            { $lflags=$prelflags; undef $prelflags; }
1532
1533 if ($target =~ /^mingw/ && `$cc --target-help 2>&1` !~ m/\-mno\-cygwin/m)
1534         {
1535         $cflags =~ s/\-mno\-cygwin\s*//;
1536         $shared_ldflag =~ s/\-mno\-cygwin\s*//;
1537         }
1538
1539 if ($target =~ /linux.*\-mips/ && !$no_asm && $flags !~ /\-m(ips|arch=)/) {
1540         # minimally required architecture flags for assembly modules
1541         $cflags="-mips2 $cflags" if ($target =~ /mips32/);
1542         $cflags="-mips3 $cflags" if ($target =~ /mips64/);
1543 }
1544
1545 my $no_shared_warn=0;
1546 my $no_user_cflags=0;
1547
1548 if ($flags ne "")       { $cflags="$flags$cflags"; }
1549 else                    { $no_user_cflags=1;       }
1550
1551 # The DSO code currently always implements all functions so that no
1552 # applications will have to worry about that from a compilation point
1553 # of view. However, the "method"s may return zero unless that platform
1554 # has support compiled in for them. Currently each method is enabled
1555 # by a define "DSO_<name>" ... we translate the "dso_scheme" config
1556 # string entry into using the following logic;
1557 my $dso_cflags;
1558 if (!$no_dso && $dso_scheme ne "")
1559         {
1560         $dso_scheme =~ tr/[a-z]/[A-Z]/;
1561         if ($dso_scheme eq "DLFCN")
1562                 {
1563                 $dso_cflags = "-DDSO_DLFCN -DHAVE_DLFCN_H";
1564                 }
1565         elsif ($dso_scheme eq "DLFCN_NO_H")
1566                 {
1567                 $dso_cflags = "-DDSO_DLFCN";
1568                 }
1569         else
1570                 {
1571                 $dso_cflags = "-DDSO_$dso_scheme";
1572                 }
1573         $cflags = "$dso_cflags $cflags";
1574         }
1575
1576 my $thread_cflags;
1577 my $thread_defines;
1578 if ($thread_cflag ne "(unknown)" && !$no_threads)
1579         {
1580         # If we know how to do it, support threads by default.
1581         $threads = 1;
1582         }
1583 if ($thread_cflag eq "(unknown)" && $threads)
1584         {
1585         # If the user asked for "threads", [s]he is also expected to
1586         # provide any system-dependent compiler options that are
1587         # necessary.
1588         if ($no_user_cflags)
1589                 {
1590                 print "You asked for multi-threading support, but didn't\n";
1591                 print "provide any system-specific compiler options\n";
1592                 exit(1);
1593                 }
1594         $thread_cflags="-DOPENSSL_THREADS $cflags" ;
1595         $thread_defines .= "#define OPENSSL_THREADS\n";
1596         }
1597 else
1598         {
1599         $thread_cflags="-DOPENSSL_THREADS $thread_cflag $cflags";
1600         $thread_defines .= "#define OPENSSL_THREADS\n";
1601 #       my $def;
1602 #       foreach $def (split ' ',$thread_cflag)
1603 #               {
1604 #               if ($def =~ s/^-D// && $def !~ /^_/)
1605 #                       {
1606 #                       $thread_defines .= "#define $def\n";
1607 #                       }
1608 #               }
1609         }
1610
1611 $lflags="$libs$lflags" if ($libs ne "");
1612
1613 if ($no_asm)
1614         {
1615         $cpuid_obj=$bn_obj=$ec_obj=
1616         $des_obj=$aes_obj=$bf_obj=$cast_obj=$rc4_obj=$rc5_obj=$cmll_obj=
1617         $modes_obj=$sha1_obj=$md5_obj=$rmd160_obj=$wp_obj=$engines_obj=
1618         $chacha_obj=$poly1305_obj="";
1619         $cflags=~s/\-D[BL]_ENDIAN//             if ($fips);
1620         $thread_cflags=~s/\-D[BL]_ENDIAN//      if ($fips);
1621         }
1622 elsif (defined($disabled{ec2m}))
1623         {
1624         $bn_obj =~ s/\w+-gf2m.o//;
1625         }
1626
1627 if (!$no_shared)
1628         {
1629         $cast_obj="";   # CAST assembler is not PIC
1630         }
1631
1632 if ($threads)
1633         {
1634         $cflags=$thread_cflags;
1635         $openssl_thread_defines .= $thread_defines;
1636         }
1637
1638 if ($zlib)
1639         {
1640         $cflags = "-DZLIB $cflags";
1641         if (defined($disabled{"zlib-dynamic"}))
1642                 {
1643                 if (defined($withargs{"zlib-lib"}))
1644                         {
1645                         $lflags = "$lflags -L" . $withargs{"zlib-lib"} . " -lz";
1646                         }
1647                 else
1648                         {
1649                         $lflags = "$lflags -lz";
1650                         }
1651                 }
1652         else
1653                 {
1654                 $cflags = "-DZLIB_SHARED $cflags";
1655                 }
1656         }
1657
1658 # With "deprecated" disable all deprecated features.
1659 if (defined($disabled{"deprecated"})) {
1660         $api = $maxapi;
1661 }
1662
1663 # You will find shlib_mark1 and shlib_mark2 explained in Makefile.in
1664 my $shared_mark = "";
1665 if ($shared_target eq "")
1666         {
1667         $no_shared_warn = 1 if !$no_shared && !$fips;
1668         $no_shared = 1;
1669         }
1670 if (!$no_shared)
1671         {
1672         if ($shared_cflag ne "")
1673                 {
1674                 $cflags = "$shared_cflag -DOPENSSL_PIC $cflags";
1675                 }
1676         }
1677
1678 if (!$IsMK1MF)
1679         {
1680         # add {no-}static-engine to options to allow mkdef.pl to work without extra arguments
1681         if ($no_shared)
1682                 {
1683                 $openssl_other_defines.="#define OPENSSL_NO_DYNAMIC_ENGINE\n";
1684                 $options.=" static-engine";
1685                 }
1686         else
1687                 {
1688                 $openssl_other_defines.="#define OPENSSL_NO_STATIC_ENGINE\n";
1689                 $options.=" no-static-engine";
1690                 }
1691         }
1692
1693 $cpuid_obj.=" uplink.o uplink-x86.o" if ($cflags =~ /\-DOPENSSL_USE_APPLINK/);
1694
1695 #
1696 # Platform fix-ups
1697 #
1698 if ($target =~ /\-icc$/)        # Intel C compiler
1699         {
1700         my $iccver=0;
1701         if (open(FD,"$cc -V 2>&1 |"))
1702                 {
1703                 while(<FD>) { $iccver=$1 if (/Version ([0-9]+)\./); }
1704                 close(FD);
1705                 }
1706         if ($iccver>=8)
1707                 {
1708                 $cflags=~s/\-KPIC/-fPIC/;
1709                 # Eliminate unnecessary dependency from libirc.a. This is
1710                 # essential for shared library support, as otherwise
1711                 # apps/openssl can end up in endless loop upon startup...
1712                 $cflags.=" -Dmemcpy=__builtin_memcpy -Dmemset=__builtin_memset";
1713                 }
1714         if ($iccver>=9)
1715                 {
1716                 $lflags.=" -i-static";
1717                 $lflags=~s/\-no_cpprt/-no-cpprt/;
1718                 }
1719         if ($iccver>=10)
1720                 {
1721                 $lflags=~s/\-i\-static/-static-intel/;
1722                 }
1723         if ($iccver>=11)
1724                 {
1725                 $cflags.=" -no-intel-extensions";       # disable Cilk
1726                 $lflags=~s/\-no\-cpprt/-no-cxxlib/;
1727                 }
1728         }
1729
1730 # Unlike other OSes (like Solaris, Linux, Tru64, IRIX) BSD run-time
1731 # linkers (tested OpenBSD, NetBSD and FreeBSD) "demand" RPATH set on
1732 # .so objects. Apparently application RPATH is not global and does
1733 # not apply to .so linked with other .so. Problem manifests itself
1734 # when libssl.so fails to load libcrypto.so. One can argue that we
1735 # should engrave this into Makefile.shared rules or into BSD-* config
1736 # lines above. Meanwhile let's try to be cautious and pass -rpath to
1737 # linker only when --prefix is not /usr.
1738 if ($target =~ /^BSD\-/)
1739         {
1740         $shared_ldflag.=" -Wl,-rpath,\$(LIBRPATH)" if ($prefix !~ m|^/usr[/]*$|);
1741         }
1742
1743 if ($sys_id ne "")
1744         {
1745         #$cflags="-DOPENSSL_SYS_$sys_id $cflags";
1746         $openssl_sys_defines="#define OPENSSL_SYS_$sys_id\n";
1747         }
1748
1749 if ($ranlib eq "")
1750         {
1751         $ranlib = $default_ranlib;
1752         }
1753
1754 #my ($bn1)=split(/\s+/,$bn_obj);
1755 #$bn1 = "" unless defined $bn1;
1756 #$bn1=$bn_asm unless ($bn1 =~ /\.o$/);
1757 #$bn_obj="$bn1";
1758
1759 $cpuid_obj="" if ($processor eq "386");
1760
1761 $bn_obj = $bn_asm unless $bn_obj ne "";
1762 # bn-586 is the only one implementing bn_*_part_words
1763 $cflags.=" -DOPENSSL_BN_ASM_PART_WORDS" if ($bn_obj =~ /bn-586/);
1764 $cflags.=" -DOPENSSL_IA32_SSE2" if (!$no_sse2 && $bn_obj =~ /86/);
1765
1766 $cflags.=" -DOPENSSL_BN_ASM_MONT" if ($bn_obj =~ /-mont/);
1767 $cflags.=" -DOPENSSL_BN_ASM_MONT5" if ($bn_obj =~ /-mont5/);
1768 $cflags.=" -DOPENSSL_BN_ASM_GF2m" if ($bn_obj =~ /-gf2m/);
1769
1770 if ($fips)
1771         {
1772         $openssl_other_defines.="#define OPENSSL_FIPS\n";
1773         }
1774
1775 $cpuid_obj="mem_clr.o"  unless ($cpuid_obj =~ /\.o$/);
1776 $des_obj=$des_enc       unless ($des_obj =~ /\.o$/);
1777 $bf_obj=$bf_enc         unless ($bf_obj =~ /\.o$/);
1778 $cast_obj=$cast_enc     unless ($cast_obj =~ /\.o$/);
1779 $rc4_obj=$rc4_enc       unless ($rc4_obj =~ /\.o$/);
1780 $rc5_obj=$rc5_enc       unless ($rc5_obj =~ /\.o$/);
1781 if ($sha1_obj =~ /\.o$/)
1782         {
1783 #       $sha1_obj=$sha1_enc;
1784         $cflags.=" -DSHA1_ASM"   if ($sha1_obj =~ /sx86/ || $sha1_obj =~ /sha1/);
1785         $cflags.=" -DSHA256_ASM" if ($sha1_obj =~ /sha256/);
1786         $cflags.=" -DSHA512_ASM" if ($sha1_obj =~ /sha512/);
1787         if ($sha1_obj =~ /sse2/)
1788             {   if ($no_sse2)
1789                 {   $sha1_obj =~ s/\S*sse2\S+//;        }
1790                 elsif ($cflags !~ /OPENSSL_IA32_SSE2/)
1791                 {   $cflags.=" -DOPENSSL_IA32_SSE2";    }
1792             }
1793         }
1794 if ($md5_obj =~ /\.o$/)
1795         {
1796 #       $md5_obj=$md5_enc;
1797         $cflags.=" -DMD5_ASM";
1798         }
1799 if ($rmd160_obj =~ /\.o$/)
1800         {
1801 #       $rmd160_obj=$rmd160_enc;
1802         $cflags.=" -DRMD160_ASM";
1803         }
1804 if ($aes_obj =~ /\.o$/)
1805         {
1806         $cflags.=" -DAES_ASM" if ($aes_obj =~ m/\baes\-/);;
1807         # aes-ctr.o is not a real file, only indication that assembler
1808         # module implements AES_ctr32_encrypt...
1809         $cflags.=" -DAES_CTR_ASM" if ($aes_obj =~ s/\s*aes\-ctr\.o//);
1810         # aes-xts.o indicates presence of AES_xts_[en|de]crypt...
1811         $cflags.=" -DAES_XTS_ASM" if ($aes_obj =~ s/\s*aes\-xts\.o//);
1812         $aes_obj =~ s/\s*(vpaes|aesni)\-x86\.o//g if ($no_sse2);
1813         $cflags.=" -DVPAES_ASM" if ($aes_obj =~ m/vpaes/);
1814         $cflags.=" -DBSAES_ASM" if ($aes_obj =~ m/bsaes/);
1815         }
1816 else    {
1817         $aes_obj=$aes_enc;
1818         }
1819 $wp_obj="" if ($wp_obj =~ /mmx/ && $processor eq "386");
1820 if ($wp_obj =~ /\.o$/ && !$disabled{"whirlpool"})
1821         {
1822         $cflags.=" -DWHIRLPOOL_ASM";
1823         }
1824 else    {
1825         $wp_obj="wp_block.o";
1826         }
1827 $cmll_obj=$cmll_enc     unless ($cmll_obj =~ /.o$/);
1828 if ($modes_obj =~ /ghash\-/)
1829         {
1830         $cflags.=" -DGHASH_ASM";
1831         }
1832 if ($ec_obj =~ /ecp_nistz256/)
1833         {
1834         $cflags.=" -DECP_NISTZ256_ASM";
1835         }
1836 $chacha_obj=$chacha_enc unless ($chacha_obj =~ /\.o$/);
1837 if ($poly1305_obj =~ /\.o$/)
1838         {
1839         $cflags.=" -DPOLY1305_ASM";
1840         }
1841
1842 # "Stringify" the C flags string.  This permits it to be made part of a string
1843 # and works as well on command lines.
1844 $cflags =~ s/([\\\"])/\\\1/g;
1845
1846 my $version = "unknown";
1847 my $version_num = "unknown";
1848 my $major = "unknown";
1849 my $minor = "unknown";
1850 my $shlib_version_number = "unknown";
1851 my $shlib_version_history = "unknown";
1852 my $shlib_major = "unknown";
1853 my $shlib_minor = "unknown";
1854
1855 open(IN,'<include/openssl/opensslv.h') || die "unable to read opensslv.h:$!\n";
1856 while (<IN>)
1857         {
1858         $version=$1 if /OPENSSL.VERSION.TEXT.*OpenSSL (\S+) /;
1859         $version_num=$1 if /OPENSSL.VERSION.NUMBER.*(0x\S+)/;
1860         $shlib_version_number=$1 if /SHLIB_VERSION_NUMBER *"([^"]+)"/;
1861         $shlib_version_history=$1 if /SHLIB_VERSION_HISTORY *"([^"]*)"/;
1862         }
1863 close(IN);
1864 if ($shlib_version_history ne "") { $shlib_version_history .= ":"; }
1865
1866 if ($version =~ /(^[0-9]*)\.([0-9\.]*)/)
1867         {
1868         $major=$1;
1869         $minor=$2;
1870         }
1871
1872 if ($shlib_version_number =~ /(^[0-9]*)\.([0-9\.]*)/)
1873         {
1874         $shlib_major=$1;
1875         $shlib_minor=$2;
1876         }
1877
1878 if (defined($api)) {
1879     my $apiflag = sprintf("-DOPENSSL_API_COMPAT=%s", $apitable->{$api});
1880     $default_depflags .= " $apiflag";
1881     $cflags .= " $apiflag";
1882 }
1883
1884 my $ecc = $cc;
1885 $ecc = "clang" if `$cc --version 2>&1` =~ /clang/;
1886
1887 if ($strict_warnings)
1888         {
1889         my $wopt;
1890         die "ERROR --strict-warnings requires gcc or clang" unless ($ecc =~ /gcc(-\d(\.\d)*)?$/ or $ecc =~ /clang$/);
1891         foreach $wopt (split /\s+/, $gcc_devteam_warn)
1892                 {
1893                 $cflags .= " $wopt" unless ($cflags =~ /(^|\s)$wopt(\s|$)/)
1894                 }
1895         if ($ecc eq "clang")
1896                 {
1897                 foreach $wopt (split /\s+/, $clang_devteam_warn)
1898                         {
1899                         $cflags .= " $wopt" unless ($cflags =~ /(^|\s)$wopt(\s|$)/)
1900                         }
1901                 }
1902         if ($target !~ /^mingw/)
1903                 {
1904                 foreach $wopt (split /\s+/, $memleak_devteam_backtrace)
1905                         {
1906                         $cflags .= " $wopt" unless ($cflags =~ /(^|\s)$wopt(\s|$)/)
1907                         }
1908                 if ($target =~ /^BSD-/)
1909                         {
1910                         $lflags .= " -lexecinfo";
1911                         }
1912                 }
1913         }
1914
1915 open(IN,"<Makefile.in") || die "unable to read Makefile.in$!\n";
1916 unlink("$Makefile.new") || die "unable to remove old $Makefile.new:$!\n" if -e "$Makefile.new";
1917 open(OUT,">$Makefile.new") || die "unable to create $Makefile.new:$!\n";
1918 print OUT "### Generated automatically from Makefile.in by Configure.\n\n";
1919 my $sdirs=0;
1920
1921 while (<IN>)
1922         {
1923         chomp;
1924         $sdirs = 1 if /^SDIRS=/;
1925         if ($sdirs) {
1926                 my $dir;
1927                 foreach $dir (@skip) {
1928                         s/(\s)$dir /$1/;
1929                         s/\s$dir$//;
1930                         }
1931                 }
1932         $sdirs = 0 unless /\\$/;
1933         s/fips // if (/^DIRS=/ && !$fips);
1934         s/engines // if (/^DIRS=/ && $disabled{"engine"});
1935         s/ccgost// if (/^ENGDIRS=/ && $disabled{"gost"});
1936         s/^VERSION=.*/VERSION=$version/;
1937         s/^MAJOR=.*/MAJOR=$major/;
1938         s/^MINOR=.*/MINOR=$minor/;
1939         s/^SHLIB_VERSION_NUMBER=.*/SHLIB_VERSION_NUMBER=$shlib_version_number/;
1940         s/^SHLIB_VERSION_HISTORY=.*/SHLIB_VERSION_HISTORY=$shlib_version_history/;
1941         s/^SHLIB_MAJOR=.*/SHLIB_MAJOR=$shlib_major/;
1942         s/^SHLIB_MINOR=.*/SHLIB_MINOR=$shlib_minor/;
1943         s/^SHLIB_EXT=.*/SHLIB_EXT=$shared_extension/;
1944         s/^INSTALLTOP=.*$/INSTALLTOP=$prefix/;
1945         s/^MULTILIB=.*$/MULTILIB=$multilib/;
1946         s/^OPENSSLDIR=.*$/OPENSSLDIR=$openssldir/;
1947         s/^LIBDIR=.*$/LIBDIR=$libdir/;
1948         s/^INSTALL_PREFIX=.*$/INSTALL_PREFIX=$install_prefix/;
1949         s/^PLATFORM=.*$/PLATFORM=$target/;
1950         s/^OPTIONS=.*$/OPTIONS=$options/;
1951         s/^CONFIGURE_ARGS=.*$/CONFIGURE_ARGS=$argvstring/;
1952         if ($cross_compile_prefix)
1953                 {
1954                 s/^CC=.*$/CROSS_COMPILE= $cross_compile_prefix\nCC= \$\(CROSS_COMPILE\)$cc/;
1955                 s/^AR=\s*/AR= \$\(CROSS_COMPILE\)/;
1956                 s/^NM=\s*/NM= \$\(CROSS_COMPILE\)/;
1957                 s/^RANLIB=\s*/RANLIB= \$\(CROSS_COMPILE\)/;
1958                 s/^MAKEDEPPROG=.*$/MAKEDEPPROG= \$\(CROSS_COMPILE\)$cc/ if $cc eq "gcc";
1959                 }
1960         else    {
1961                 s/^CC=.*$/CC= $cc/;
1962                 s/^AR=\s*ar/AR= $ar/;
1963                 s/^RANLIB=.*/RANLIB= $ranlib/;
1964                 s/^MAKEDEPPROG=.*$/MAKEDEPPROG= $cc/ if $ecc eq "gcc" || $ecc eq "clang";
1965                 }
1966         s/^CFLAG=.*$/CFLAG= $cflags/;
1967         s/^DEPFLAG=.*$/DEPFLAG=$depflags/;
1968         s/^PEX_LIBS=.*$/PEX_LIBS= $prelflags/;
1969         s/^EX_LIBS=.*$/EX_LIBS= $lflags/;
1970         s/^EXE_EXT=.*$/EXE_EXT= $exe_ext/;
1971         s/^CPUID_OBJ=.*$/CPUID_OBJ= $cpuid_obj/;
1972         s/^BN_ASM=.*$/BN_ASM= $bn_obj/;
1973         s/^EC_ASM=.*$/EC_ASM= $ec_obj/;
1974         s/^DES_ENC=.*$/DES_ENC= $des_obj/;
1975         s/^AES_ENC=.*$/AES_ENC= $aes_obj/;
1976         s/^BF_ENC=.*$/BF_ENC= $bf_obj/;
1977         s/^CAST_ENC=.*$/CAST_ENC= $cast_obj/;
1978         s/^RC4_ENC=.*$/RC4_ENC= $rc4_obj/;
1979         s/^RC5_ENC=.*$/RC5_ENC= $rc5_obj/;
1980         s/^MD5_ASM_OBJ=.*$/MD5_ASM_OBJ= $md5_obj/;
1981         s/^SHA1_ASM_OBJ=.*$/SHA1_ASM_OBJ= $sha1_obj/;
1982         s/^RMD160_ASM_OBJ=.*$/RMD160_ASM_OBJ= $rmd160_obj/;
1983         s/^WP_ASM_OBJ=.*$/WP_ASM_OBJ= $wp_obj/;
1984         s/^CMLL_ENC=.*$/CMLL_ENC= $cmll_obj/;
1985         s/^MODES_ASM_OBJ.=*$/MODES_ASM_OBJ= $modes_obj/;
1986         s/^CHACHA_ENC=.*$/CHACHA_ENC= $chacha_obj/;
1987         s/^POLY1305_ASM_OBJ=.*$/POLY1305_ASM_OBJ= $poly1305_obj/;
1988         s/^ENGINES_ASM_OBJ.=*$/ENGINES_ASM_OBJ= $engines_obj/;
1989         s/^PERLASM_SCHEME=.*$/PERLASM_SCHEME= $perlasm_scheme/;
1990         s/^PROCESSOR=.*/PROCESSOR= $processor/;
1991         s/^ARFLAGS=.*/ARFLAGS= $arflags/;
1992         s/^PERL=.*/PERL= $perl/;
1993         s/^LIBZLIB=.*/LIBZLIB=$withargs{"zlib-lib"}/;
1994         s/^ZLIB_INCLUDE=.*/ZLIB_INCLUDE=$withargs{"zlib-include"}/;
1995         s/^FIPSLIBDIR=.*/FIPSLIBDIR=$fipslibdir/;
1996         s/^FIPSCANLIB=.*/FIPSCANLIB=libcrypto/ if $fips;
1997         s/^SHARED_FIPS=.*/SHARED_FIPS=/;
1998         s/^SHLIBDIRS=.*/SHLIBDIRS= crypto ssl/;
1999         s/^BASEADDR=.*/BASEADDR=$baseaddr/;
2000         s/^SHLIB_TARGET=.*/SHLIB_TARGET=$shared_target/;
2001         s/^SHLIB_MARK=.*/SHLIB_MARK=$shared_mark/;
2002         s/^SHARED_LIBS=.*/SHARED_LIBS=\$(SHARED_CRYPTO) \$(SHARED_SSL)/ if (!$no_shared);
2003         if ($shared_extension ne "" && $shared_extension =~ /^\.s([ol])\.[^\.]*$/)
2004                 {
2005                 my $sotmp = $1;
2006                 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.s$sotmp/;
2007                 }
2008         elsif ($shared_extension ne "" && $shared_extension =~ /^\.[^\.]*\.dylib$/)
2009                 {
2010                 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.dylib/;
2011                 }
2012         elsif ($shared_extension ne "" && $shared_extension =~ /^\.s([ol])\.[^\.]*\.[^\.]*$/)
2013                 {
2014                 my $sotmp = $1;
2015                 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.s$sotmp.\$(SHLIB_MAJOR) .s$sotmp/;
2016                 }
2017         elsif ($shared_extension ne "" && $shared_extension =~ /^\.[^\.]*\.[^\.]*\.dylib$/)
2018                 {
2019                 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.\$(SHLIB_MAJOR).dylib .dylib/;
2020                 }
2021         s/^SHARED_LDFLAGS=.*/SHARED_LDFLAGS=$shared_ldflag/;
2022         print OUT $_."\n";
2023         }
2024 close(IN);
2025 close(OUT);
2026 rename($Makefile,"$Makefile.orig") || die "unable to rename $Makefile\n" if -e $Makefile;
2027 rename("$Makefile.new",$Makefile) || die "unable to rename $Makefile.new\n";
2028
2029 print "CC            =$cc\n";
2030 print "CFLAG         =$cflags\n";
2031 print "EX_LIBS       =$lflags\n";
2032 print "CPUID_OBJ     =$cpuid_obj\n";
2033 print "BN_ASM        =$bn_obj\n";
2034 print "EC_ASM        =$ec_obj\n";
2035 print "DES_ENC       =$des_obj\n";
2036 print "AES_ENC       =$aes_obj\n";
2037 print "BF_ENC        =$bf_obj\n";
2038 print "CAST_ENC      =$cast_obj\n";
2039 print "RC4_ENC       =$rc4_obj\n";
2040 print "RC5_ENC       =$rc5_obj\n";
2041 print "MD5_OBJ_ASM   =$md5_obj\n";
2042 print "SHA1_OBJ_ASM  =$sha1_obj\n";
2043 print "RMD160_OBJ_ASM=$rmd160_obj\n";
2044 print "CMLL_ENC      =$cmll_obj\n";
2045 print "MODES_OBJ     =$modes_obj\n";
2046 print "ENGINES_OBJ   =$engines_obj\n";
2047 print "CHACHA_ENC    =$chacha_obj\n";
2048 print "POLY1305_OBJ  =$poly1305_obj\n";
2049 print "PROCESSOR     =$processor\n";
2050 print "RANLIB        =$ranlib\n";
2051 print "ARFLAGS       =$arflags\n";
2052 print "PERL          =$perl\n";
2053
2054 my $des_ptr=0;
2055 my $des_risc1=0;
2056 my $des_risc2=0;
2057 my $des_unroll=0;
2058 my $bn_ll=0;
2059 my $def_int=2;
2060 my $rc4_int=$def_int;
2061 my $md2_int=$def_int;
2062 my $idea_int=$def_int;
2063 my $rc2_int=$def_int;
2064 my $rc4_idx=0;
2065 my $rc4_chunk=0;
2066 my $bf_ptr=0;
2067 my @type=("char","short","int","long");
2068 my ($b64l,$b64,$b32,$b16,$b8)=(0,0,1,0,0);
2069 my $export_var_as_fn=0;
2070
2071 my $des_int;
2072
2073 foreach (sort split(/\s+/,$bn_ops))
2074         {
2075         $des_ptr=1 if /DES_PTR/;
2076         $des_risc1=1 if /DES_RISC1/;
2077         $des_risc2=1 if /DES_RISC2/;
2078         $des_unroll=1 if /DES_UNROLL/;
2079         $des_int=1 if /DES_INT/;
2080         $bn_ll=1 if /BN_LLONG/;
2081         $rc4_int=0 if /RC4_CHAR/;
2082         $rc4_int=3 if /RC4_LONG/;
2083         $rc4_idx=1 if /RC4_INDEX/;
2084         $rc4_chunk=1 if /RC4_CHUNK/;
2085         $rc4_chunk=2 if /RC4_CHUNK_LL/;
2086         $md2_int=0 if /MD2_CHAR/;
2087         $md2_int=3 if /MD2_LONG/;
2088         $idea_int=1 if /IDEA_SHORT/;
2089         $idea_int=3 if /IDEA_LONG/;
2090         $rc2_int=1 if /RC2_SHORT/;
2091         $rc2_int=3 if /RC2_LONG/;
2092         $bf_ptr=1 if $_ eq "BF_PTR";
2093         $bf_ptr=2 if $_ eq "BF_PTR2";
2094         ($b64l,$b64,$b32,$b16,$b8)=(0,1,0,0,0) if /SIXTY_FOUR_BIT/;
2095         ($b64l,$b64,$b32,$b16,$b8)=(1,0,0,0,0) if /SIXTY_FOUR_BIT_LONG/;
2096         ($b64l,$b64,$b32,$b16,$b8)=(0,0,1,0,0) if /THIRTY_TWO_BIT/;
2097         ($b64l,$b64,$b32,$b16,$b8)=(0,0,0,1,0) if /SIXTEEN_BIT/;
2098         ($b64l,$b64,$b32,$b16,$b8)=(0,0,0,0,1) if /EIGHT_BIT/;
2099         $export_var_as_fn=1 if /EXPORT_VAR_AS_FN/;
2100         }
2101
2102 open(IN,'<crypto/opensslconf.h.in') || die "unable to read crypto/opensslconf.h.in:$!\n";
2103 unlink("include/openssl/opensslconf.h.new") || die "unable to remove old include/openssl/opensslconf.h.new:$!\n" if -e "include/openssl/opensslconf.h.new";
2104 open(OUT,'>include/openssl/opensslconf.h.new') || die "unable to create include/openssl/opensslconf.h.new:$!\n";
2105 print OUT "/* opensslconf.h */\n";
2106 print OUT "/* WARNING: Generated automatically from opensslconf.h.in by Configure. */\n\n";
2107
2108 print OUT "#ifdef  __cplusplus\n";
2109 print OUT "extern \"C\" {\n";
2110 print OUT "#endif\n";
2111 print OUT "/* OpenSSL was configured with the following options: */\n";
2112
2113 my $openssl_api_defines = "";
2114 if (defined($api)) {
2115     $openssl_api_defines = sprintf "#define OPENSSL_MIN_API %s\n", $apitable->{$api};
2116 }
2117 my $openssl_algorithm_defines_trans = $openssl_algorithm_defines;
2118 $openssl_experimental_defines =~ s/^\s*#\s*define\s+OPENSSL_NO_(.*)/#ifndef OPENSSL_EXPERIMENTAL_$1\n# ifndef OPENSSL_NO_$1\n#  define OPENSSL_NO_$1\n# endif\n#endif/mg;
2119 $openssl_algorithm_defines_trans =~ s/^\s*#\s*define\s+OPENSSL_(.*)/# if defined(OPENSSL_$1) \&\& !defined($1)\n#  define $1\n# endif/mg;
2120 $openssl_algorithm_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
2121 $openssl_algorithm_defines = "   /* no ciphers excluded */\n" if $openssl_algorithm_defines eq "";
2122 $openssl_thread_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
2123 $openssl_sys_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
2124 $openssl_other_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
2125
2126 print OUT $openssl_sys_defines;
2127 print OUT "#ifndef OPENSSL_DOING_MAKEDEPEND\n\n";
2128 print OUT $openssl_experimental_defines;
2129 print OUT $openssl_api_defines;
2130 print OUT "\n";
2131 print OUT $openssl_algorithm_defines;
2132 print OUT "\n#endif /* OPENSSL_DOING_MAKEDEPEND */\n\n";
2133 print OUT $openssl_thread_defines;
2134 print OUT $openssl_other_defines,"\n";
2135
2136 print OUT "/* The OPENSSL_NO_* macros are also defined as NO_* if the application\n";
2137 print OUT "   asks for it.  This is a transient feature that is provided for those\n";
2138 print OUT "   who haven't had the time to do the appropriate changes in their\n";
2139 print OUT "   applications.  */\n";
2140 print OUT "#ifdef OPENSSL_ALGORITHM_DEFINES\n";
2141 print OUT $openssl_algorithm_defines_trans;
2142 print OUT "#endif\n\n";
2143
2144 print OUT "#define OPENSSL_CPUID_OBJ\n\n" if ($cpuid_obj ne "mem_clr.o");
2145
2146 while (<IN>)
2147         {
2148         if      (/^#define\s+OPENSSLDIR/)
2149                 {
2150                 my $foo = $openssldir;
2151                 $foo =~ s/\\/\\\\/g;
2152                 print OUT "#define OPENSSLDIR \"$foo\"\n";
2153                 }
2154         elsif   (/^#define\s+ENGINESDIR/)
2155                 {
2156                 my $foo = "$prefix/$libdir/engines";
2157                 $foo =~ s/\\/\\\\/g;
2158                 print OUT "#define ENGINESDIR \"$foo\"\n";
2159                 }
2160         elsif   (/^#((define)|(undef))\s+OPENSSL_EXPORT_VAR_AS_FUNCTION/)
2161                 { printf OUT "#undef OPENSSL_EXPORT_VAR_AS_FUNCTION\n"
2162                         if $export_var_as_fn;
2163                   printf OUT "#%s OPENSSL_EXPORT_VAR_AS_FUNCTION\n",
2164                         ($export_var_as_fn)?"define":"undef"; }
2165         elsif   (/^#define\s+OPENSSL_UNISTD/)
2166                 {
2167                 $unistd = "<unistd.h>" if $unistd eq "";
2168                 print OUT "#define OPENSSL_UNISTD $unistd\n";
2169                 }
2170         elsif   (/^#((define)|(undef))\s+SIXTY_FOUR_BIT_LONG/)
2171                 { printf OUT "#%s SIXTY_FOUR_BIT_LONG\n",($b64l)?"define":"undef"; }
2172         elsif   (/^#((define)|(undef))\s+SIXTY_FOUR_BIT/)
2173                 { printf OUT "#%s SIXTY_FOUR_BIT\n",($b64)?"define":"undef"; }
2174         elsif   (/^#((define)|(undef))\s+THIRTY_TWO_BIT/)
2175                 { printf OUT "#%s THIRTY_TWO_BIT\n",($b32)?"define":"undef"; }
2176         elsif   (/^#((define)|(undef))\s+SIXTEEN_BIT/)
2177                 { printf OUT "#%s SIXTEEN_BIT\n",($b16)?"define":"undef"; }
2178         elsif   (/^#((define)|(undef))\s+EIGHT_BIT/)
2179                 { printf OUT "#%s EIGHT_BIT\n",($b8)?"define":"undef"; }
2180         elsif   (/^#((define)|(undef))\s+BN_LLONG\s*$/)
2181                 { printf OUT "#%s BN_LLONG\n",($bn_ll)?"define":"undef"; }
2182         elsif   (/^\#define\s+OSSL_DES_LONG\s+.*/)
2183                 { printf OUT "#define OSSL_DES_LONG unsigned %s\n",
2184                         ($des_int)?'int':'long'; }
2185         elsif   (/^\#(define|undef)\s+DES_PTR/)
2186                 { printf OUT "#%s DES_PTR\n",($des_ptr)?'define':'undef'; }
2187         elsif   (/^\#(define|undef)\s+DES_RISC1/)
2188                 { printf OUT "#%s DES_RISC1\n",($des_risc1)?'define':'undef'; }
2189         elsif   (/^\#(define|undef)\s+DES_RISC2/)
2190                 { printf OUT "#%s DES_RISC2\n",($des_risc2)?'define':'undef'; }
2191         elsif   (/^\#(define|undef)\s+DES_UNROLL/)
2192                 { printf OUT "#%s DES_UNROLL\n",($des_unroll)?'define':'undef'; }
2193         elsif   (/^#define\s+RC4_INT\s/)
2194                 { printf OUT "#define RC4_INT unsigned %s\n",$type[$rc4_int]; }
2195         elsif   (/^#undef\s+RC4_CHUNK/)
2196                 {
2197                 printf OUT "#undef RC4_CHUNK\n" if $rc4_chunk==0;
2198                 printf OUT "#define RC4_CHUNK unsigned long\n" if $rc4_chunk==1;
2199                 printf OUT "#define RC4_CHUNK unsigned long long\n" if $rc4_chunk==2;
2200                 }
2201         elsif   (/^#((define)|(undef))\s+RC4_INDEX/)
2202                 { printf OUT "#%s RC4_INDEX\n",($rc4_idx)?"define":"undef"; }
2203         elsif (/^#(define|undef)\s+I386_ONLY/)
2204                 { printf OUT "#%s I386_ONLY\n", ($processor eq "386")?
2205                         "define":"undef"; }
2206         elsif   (/^#define\s+MD2_INT\s/)
2207                 { printf OUT "#define MD2_INT unsigned %s\n",$type[$md2_int]; }
2208         elsif   (/^#define\s+IDEA_INT\s/)
2209                 {printf OUT "#define IDEA_INT unsigned %s\n",$type[$idea_int];}
2210         elsif   (/^#define\s+RC2_INT\s/)
2211                 {printf OUT "#define RC2_INT unsigned %s\n",$type[$rc2_int];}
2212         elsif (/^#(define|undef)\s+BF_PTR/)
2213                 {
2214                 printf OUT "#undef BF_PTR\n" if $bf_ptr == 0;
2215                 printf OUT "#define BF_PTR\n" if $bf_ptr == 1;
2216                 printf OUT "#define BF_PTR2\n" if $bf_ptr == 2;
2217                 }
2218         else
2219                 { print OUT $_; }
2220         }
2221 close(IN);
2222 print OUT "#ifdef  __cplusplus\n";
2223 print OUT "}\n";
2224 print OUT "#endif\n";
2225 close(OUT);
2226 rename("include/openssl/opensslconf.h","include/openssl/opensslconf.h.bak") || die "unable to rename include/openssl/opensslconf.h\n" if -e "include/openssl/opensslconf.h";
2227 rename("include/openssl/opensslconf.h.new","include/openssl/opensslconf.h") || die "unable to rename include/openssl/opensslconf.h.new\n";
2228
2229
2230 # Fix the date
2231
2232 print "SIXTY_FOUR_BIT_LONG mode\n" if $b64l;
2233 print "SIXTY_FOUR_BIT mode\n" if $b64;
2234 print "THIRTY_TWO_BIT mode\n" if $b32;
2235 print "SIXTEEN_BIT mode\n" if $b16;
2236 print "EIGHT_BIT mode\n" if $b8;
2237 print "DES_PTR used\n" if $des_ptr;
2238 print "DES_RISC1 used\n" if $des_risc1;
2239 print "DES_RISC2 used\n" if $des_risc2;
2240 print "DES_UNROLL used\n" if $des_unroll;
2241 print "DES_INT used\n" if $des_int;
2242 print "BN_LLONG mode\n" if $bn_ll;
2243 print "RC4 uses u$type[$rc4_int]\n" if $rc4_int != $def_int;
2244 print "RC4_INDEX mode\n" if $rc4_idx;
2245 print "RC4_CHUNK is undefined\n" if $rc4_chunk==0;
2246 print "RC4_CHUNK is unsigned long\n" if $rc4_chunk==1;
2247 print "RC4_CHUNK is unsigned long long\n" if $rc4_chunk==2;
2248 print "MD2 uses u$type[$md2_int]\n" if $md2_int != $def_int;
2249 print "IDEA uses u$type[$idea_int]\n" if $idea_int != $def_int;
2250 print "RC2 uses u$type[$rc2_int]\n" if $rc2_int != $def_int;
2251 print "BF_PTR used\n" if $bf_ptr == 1;
2252 print "BF_PTR2 used\n" if $bf_ptr == 2;
2253
2254 # Copy all Makefile.in to Makefile (except top-level)
2255 use File::Find;
2256 use IO::File;
2257 find(sub {
2258         return if ($_ ne "Makefile.in" || $File::Find::dir eq ".");
2259         my $in = IO::File->new($_, "r") or
2260             die sprintf "Error reading Makefile.in in %s: !$\n",
2261                 $File::Find::dir;
2262         my $out = IO::File->new("Makefile", "w") or
2263             die sprintf "Error writing Makefile in %s: !$\n",
2264                 $File::Find::dir;
2265         print $out "# Generated from $_, do not edit\n";
2266         while (my $line = <$in>) { print $out $line }
2267         $in->close() or
2268             die sprintf "Error reading Makefile.in in %s: !$\n",
2269                 $File::Find::dir;
2270         $out->close() or
2271             die sprintf "Error writing Makefile in %s: !$\n",
2272                 $File::Find::dir;
2273     }, ".");
2274
2275 {
2276     my $perlguess = $perl =~ m@^/@ ? $perl : '/usr/local/bin/perl';
2277
2278     &dofile("tools/c_rehash",$perlguess,
2279             '^#!/'              => '#!%s',
2280             '^my \$dir;$'       => 'my $dir = "' . $openssldir . '";',
2281             '^my \$prefix;$'    => 'my $prefix = "' . $prefix . '";');
2282     &dofile("apps/CA.pl",$perl,
2283             '^#!/'              => '#!%s');
2284 }
2285 if($IsMK1MF) {
2286         open (OUT,">crypto/buildinf.h") || die "Can't open buildinf.h";
2287         printf OUT <<EOF;
2288 #ifndef MK1MF_BUILD
2289   /* auto-generated by Configure for crypto/cversion.c:
2290    * for Unix builds, crypto/Makefile.ssl generates functional definitions;
2291    * Windows builds (and other mk1mf builds) compile cversion.c with
2292    * -DMK1MF_BUILD and use definitions added to this file by util/mk1mf.pl. */
2293   #error "Windows builds (PLATFORM=$target) use mk1mf.pl-created Makefiles"
2294 #endif
2295 EOF
2296         close(OUT);
2297 } else {
2298         my $make_command = "$make PERL=\'$perl\'";
2299         my $make_targets = "";
2300         $make_targets .= " depend" if $depflags ne $default_depflags && $make_depend;
2301         (system $make_command.$make_targets) == 0 or die "make $make_targets failed"
2302                 if $make_targets ne "";
2303         if ($depflags ne $default_depflags && !$make_depend) {
2304             $warn_make_depend++;
2305         }
2306 }
2307
2308 # create the ms/version32.rc file if needed
2309 if ($IsMK1MF && ($target !~ /^netware/)) {
2310         my ($v1, $v2, $v3, $v4);
2311         if ($version_num =~ /^0x([0-9a-f]{1})([0-9a-f]{2})([0-9a-f]{2})([0-9a-f]{2})([0-9a-f]{1})L$/i) {
2312                 $v1=hex $1;
2313                 $v2=hex $2;
2314                 $v3=hex $3;
2315                 $v4=hex $4;
2316         }
2317         open (OUT,">ms/version32.rc") || die "Can't open ms/version32.rc";
2318         print OUT <<EOF;
2319 #include <winver.h>
2320
2321 LANGUAGE 0x09,0x01
2322
2323 1 VERSIONINFO
2324   FILEVERSION $v1,$v2,$v3,$v4
2325   PRODUCTVERSION $v1,$v2,$v3,$v4
2326   FILEFLAGSMASK 0x3fL
2327 #ifdef _DEBUG
2328   FILEFLAGS 0x01L
2329 #else
2330   FILEFLAGS 0x00L
2331 #endif
2332   FILEOS VOS__WINDOWS32
2333   FILETYPE VFT_DLL
2334   FILESUBTYPE 0x0L
2335 BEGIN
2336     BLOCK "StringFileInfo"
2337     BEGIN
2338         BLOCK "040904b0"
2339         BEGIN
2340             // Required:
2341             VALUE "CompanyName", "The OpenSSL Project, http://www.openssl.org/\\0"
2342             VALUE "FileDescription", "OpenSSL Shared Library\\0"
2343             VALUE "FileVersion", "$version\\0"
2344 #if defined(CRYPTO)
2345             VALUE "InternalName", "libeay32\\0"
2346             VALUE "OriginalFilename", "libeay32.dll\\0"
2347 #elif defined(SSL)
2348             VALUE "InternalName", "ssleay32\\0"
2349             VALUE "OriginalFilename", "ssleay32.dll\\0"
2350 #endif
2351             VALUE "ProductName", "The OpenSSL Toolkit\\0"
2352             VALUE "ProductVersion", "$version\\0"
2353             // Optional:
2354             //VALUE "Comments", "\\0"
2355             VALUE "LegalCopyright", "Copyright Â© 1998-2015 The OpenSSL Project. Copyright Â© 1995-1998 Eric A. Young, Tim J. Hudson. All rights reserved.\\0"
2356             //VALUE "LegalTrademarks", "\\0"
2357             //VALUE "PrivateBuild", "\\0"
2358             //VALUE "SpecialBuild", "\\0"
2359         END
2360     END
2361     BLOCK "VarFileInfo"
2362     BEGIN
2363         VALUE "Translation", 0x409, 0x4b0
2364     END
2365 END
2366 EOF
2367         close(OUT);
2368   }
2369
2370 print <<EOF;
2371
2372 Configured for $target.
2373 EOF
2374
2375 print <<\EOF if (!$no_threads && !$threads);
2376
2377 The library could not be configured for supporting multi-threaded
2378 applications as the compiler options required on this system are not known.
2379 See file INSTALL for details if you need multi-threading.
2380 EOF
2381
2382 print <<\EOF if ($no_shared_warn);
2383
2384 You gave the option 'shared', which is not supported on this platform, so
2385 we will pretend you gave the option 'no-shared'.  If you know how to implement
2386 shared libraries, please let us know (but please first make sure you have
2387 tried with a current version of OpenSSL).
2388 EOF
2389
2390 print <<EOF if ($warn_make_depend);
2391
2392 *** Because of configuration changes, you MUST do the following before
2393 *** building:
2394
2395         make depend
2396 EOF
2397
2398 exit(0);
2399
2400 sub usage
2401         {
2402         print STDERR $usage;
2403         print STDERR "\npick os/compiler from:\n";
2404         my $j=0;
2405         my $i;
2406         my $k=0;
2407         foreach $i (sort keys %table)
2408                 {
2409                 next if $i =~ /^debug/;
2410                 $k += length($i) + 1;
2411                 if ($k > 78)
2412                         {
2413                         print STDERR "\n";
2414                         $k=length($i);
2415                         }
2416                 print STDERR $i . " ";
2417                 }
2418         foreach $i (sort keys %table)
2419                 {
2420                 next if $i !~ /^debug/;
2421                 $k += length($i) + 1;
2422                 if ($k > 78)
2423                         {
2424                         print STDERR "\n";
2425                         $k=length($i);
2426                         }
2427                 print STDERR $i . " ";
2428                 }
2429         print STDERR "\n\nNOTE: If in doubt, on Unix-ish systems use './config'.\n";
2430         exit(1);
2431         }
2432
2433 sub which
2434         {
2435         my($name)=@_;
2436         my $path;
2437         foreach $path (split /:/, $ENV{PATH})
2438                 {
2439                 if (-f "$path/$name$exe_ext" and -x _)
2440                         {
2441                         return "$path/$name$exe_ext" unless ($name eq "perl" and
2442                          system("$path/$name$exe_ext -e " . '\'exit($]<5.0);\''));
2443                         }
2444                 }
2445         }
2446
2447 sub dofile
2448         {
2449         my $f; my $p; my %m; my @a; my $k; my $ff;
2450         ($f,$p,%m)=@_;
2451
2452         open(IN,"<$f.in") || open(IN,"<$f") || die "unable to open $f:$!\n";
2453         @a=<IN>;
2454         close(IN);
2455         foreach $k (keys %m)
2456                 {
2457                 grep(/$k/ && ($_=sprintf($m{$k}."\n",$p)),@a);
2458                 }
2459         open(OUT,">$f.new") || die "unable to open $f.new:$!\n";
2460         print OUT @a;
2461         close(OUT);
2462         rename($f,"$f.bak") || die "unable to rename $f\n" if -e $f;
2463         rename("$f.new",$f) || die "unable to rename $f.new\n";
2464         }
2465
2466 sub print_table_entry
2467         {
2468         my $target = shift;
2469         my $type = shift;
2470
2471         # Don't print the templates
2472         return if $table{$target}->{template};
2473
2474         if ($type eq "TABLE") {
2475             print <<EOF
2476
2477 *** $target
2478 \$cc           = $table{$target}->{cc}
2479 \$cflags       = $table{$target}->{cflags}
2480 \$debug_cflags   = $table{$target}->{debug_cflags}
2481 \$release_cflags = $table{$target}->{release_cflags}
2482 \$unistd       = $table{$target}->{unistd}
2483 \$thread_cflag = $table{$target}->{thread_cflag}
2484 \$sys_id       = $table{$target}->{sys_id}
2485 \$lflags       = $table{$target}->{lflags}
2486 \$debug_lflags   = $table{$target}->{debug_lflags}
2487 \$release_lflags = $table{$target}->{release_lflags}
2488 \$bn_ops       = $table{$target}->{bn_ops}
2489 \$cpuid_obj    = $table{$target}->{cpuid_obj}
2490 \$bn_obj       = $table{$target}->{bn_obj}
2491 \$ec_obj       = $table{$target}->{ec_obj}
2492 \$des_obj      = $table{$target}->{des_obj}
2493 \$aes_obj      = $table{$target}->{aes_obj}
2494 \$bf_obj       = $table{$target}->{bf_obj}
2495 \$md5_obj      = $table{$target}->{md5_obj}
2496 \$sha1_obj     = $table{$target}->{sha1_obj}
2497 \$cast_obj     = $table{$target}->{cast_obj}
2498 \$rc4_obj      = $table{$target}->{rc4_obj}
2499 \$rmd160_obj   = $table{$target}->{rmd160_obj}
2500 \$rc5_obj      = $table{$target}->{rc5_obj}
2501 \$wp_obj       = $table{$target}->{wp_obj}
2502 \$cmll_obj     = $table{$target}->{cmll_obj}
2503 \$modes_obj    = $table{$target}->{modes_obj}
2504 \$engines_obj  = $table{$target}->{engines_obj}
2505 \$chacha_obj   = $table{$target}->{chacha_obj}
2506 \$poly1305_obj = $table{$target}->{poly1305_obj}
2507 \$perlasm_scheme = $table{$target}->{perlasm_scheme}
2508 \$dso_scheme   = $table{$target}->{dso_scheme}
2509 \$shared_target= $table{$target}->{shared_target}
2510 \$shared_cflag = $table{$target}->{shared_cflag}
2511 \$shared_ldflag = $table{$target}->{shared_ldflag}
2512 \$shared_extension = $table{$target}->{shared_extension}
2513 \$ranlib       = $table{$target}->{ranlib}
2514 \$arflags      = $table{$target}->{arflags}
2515 \$multilib     = $table{$target}->{multilib}
2516 EOF
2517         } elsif ($type eq "HASH") {
2518             my @sequence = (
2519                 "cc",
2520                 "cflags",
2521                 "debug_cflags",
2522                 "release_cflags",
2523                 "unistd",
2524                 "thread_cflag",
2525                 "sys_id",
2526                 "lflags",
2527                 "debug_lflags",
2528                 "release_lflags",
2529                 "bn_ops",
2530                 "cpuid_obj",
2531                 "bn_obj",
2532                 "ec_obj",
2533                 "des_obj",
2534                 "aes_obj",
2535                 "bf_obj",
2536                 "md5_obj",
2537                 "sha1_obj",
2538                 "cast_obj",
2539                 "rc4_obj",
2540                 "rmd160_obj",
2541                 "rc5_obj",
2542                 "wp_obj",
2543                 "cmll_obj",
2544                 "modes_obj",
2545                 "engines_obj",
2546                 "chacha_obj",
2547                 "poly1305_obj",
2548                 "perlasm_scheme",
2549                 "dso_scheme",
2550                 "shared_target",
2551                 "shared_cflag",
2552                 "shared_ldflag",
2553                 "shared_extension",
2554                 "ranlib",
2555                 "arflags",
2556                 "multilib",
2557                 );
2558             my $largest =
2559                 length((sort { length($a) <=> length($b) } @sequence)[-1]);
2560             print "    '$target' => {\n";
2561             foreach (@sequence) {
2562                 if ($table{$target}->{$_}) {
2563                     print "      '",$_,"'"," " x ($largest - length($_))," => '",$table{$target}->{$_},"',\n";
2564                 }
2565             }
2566             print "    },\n";
2567         }
2568         }
2569
2570 sub test_sanity
2571         {
2572         my $errorcnt = 0;
2573
2574         print STDERR "=" x 70, "\n";
2575         print STDERR "=== SANITY TESTING!\n";
2576         print STDERR "=== No configuration will be done, all other arguments will be ignored!\n";
2577         print STDERR "=" x 70, "\n";
2578
2579         foreach $target (sort keys %table)
2580                 {
2581                 my $pre_dso_scheme = "perlasm_scheme";
2582                 my $dso_scheme = "dso_scheme";
2583                 my $post_dso_scheme = "shared_target";
2584
2585
2586                 if ($table{$target}->{$pre_dso_scheme} =~ /^(beos|dl|dlfcn|win32|vms)$/)
2587                         {
2588                         $errorcnt++;
2589                         print STDERR "SANITY ERROR: '$target' has the dso_scheme values\n";
2590                         print STDERR "              in the previous field\n";
2591                         }
2592                 elsif ($table{$target}->{$post_dso_scheme} =~ /^(beos|dl|dlfcn|win32|vms)$/)
2593                         {
2594                         $errorcnt++;
2595                         print STDERR "SANITY ERROR: '$target' has the dso_scheme values\n";
2596                         print STDERR "              in the following field\n";
2597                         }
2598                 elsif ($table{$target}->{$dso_scheme} !~ /^(beos|dl|dlfcn|win32|vms|)$/)
2599                         {
2600                         $errorcnt++;
2601                         print STDERR "SANITY ERROR: '$target' has the dso_scheme field = ",$table{$target}->{$dso_scheme},"\n";
2602                         print STDERR "              valid values are 'beos', 'dl', 'dlfcn', 'win32' and 'vms'\n";
2603                         }
2604                 }
2605         print STDERR "No sanity errors detected!\n" if $errorcnt == 0;
2606         return $errorcnt;
2607         }