Workaround for VisualStudio 2015 bug
[openssl.git] / util / mkdef.pl
index 995e1dd27d444d4bf192ccc309a4efe1947daab8..c7160036f06bc0745f3910136f4dbee2e88ab615 100755 (executable)
@@ -5,30 +5,14 @@
 # It does this by parsing the header files and looking for the
 # prototyped functions: it then prunes the output.
 #
-# Intermediary files are created, call libeay.num and ssleay.num,...
-# Previously, they had the following format:
+# Intermediary files are created, call libeay.num and ssleay.num,
+# The format of these files is:
 #
-#      routine-name    nnnn
+#      routine-name    nnnn    vers    info
 #
-# But that isn't enough for a number of reasons, the first on being that
-# this format is (needlessly) very Win32-centric, and even then...
-# One of the biggest problems is that there's no information about what
-# routines should actually be used, which varies with what crypto algorithms
-# are disabled.  Also, some operating systems (for example VMS with VAX C)
-# need to keep track of the global variables as well as the functions.
-#
-# So, a remake of this script is done so as to include information on the
-# kind of symbol it is (function or variable) and what algorithms they're
-# part of.  This will allow easy translating to .def files or the corresponding
-# file in other operating systems (a .opt file for VMS, possibly with a .mar
-# file).
-#
-# The format now becomes:
-#
-#      routine-name    nnnn    info
-#
-# and the "info" part is actually a colon-separated string of fields with
-# the following meaning:
+# The "nnnn" and "vers" fields are the numeric id and version for the symbol
+# respectively. The "info" part is actually a colon-separated string of fields
+# with the following meaning:
 #
 #      existence:platform:kind:algorithms
 #
 # - "platforms" is empty if it exists on all platforms, otherwise it contains
 #   comma-separated list of the platform, just as they are if the symbol exists
 #   for those platforms, or prepended with a "!" if not.  This helps resolve
-#   symbol name replacements for platforms where the names are too long for the
+#   symbol name variants for platforms where the names are too long for the
 #   compiler or linker, or if the systems is case insensitive and there is a
-#   clash.  This script assumes those redefinitions are place in the file
-#   crypto/symhacks.h.
-#   The semantics for the platforms list is a bit complicated.  The rule of
-#   thumb is that the list is exclusive, but it seems to mean different things.
-#   So, if the list is all negatives (like "!VMS,!WIN16"), the symbol exists
-#   on all platforms except those listed.  If the list is all positives (like
-#   "VMS,WIN16"), the symbol exists only on those platforms and nowhere else.
-#   The combination of positives and negatives will act as if the positives
-#   weren't there.
+#   clash, or the symbol is implemented differently (see
+#   EXPORT_VAR_AS_FUNCTION).  This script assumes renaming of symbols is found
+#   in the file crypto/symhacks.h.
+#   The semantics for the platforms is that every item is checked against the
+#   environment.  For the negative items ("!FOO"), if any of them is false
+#   (i.e. "FOO" is true) in the environment, the corresponding symbol can't be
+#   used.  For the positive itms, if all of them are false in the environment,
+#   the corresponding symbol can't be used.  Any combination of positive and
+#   negative items are possible, and of course leave room for some redundancy.
 # - "kind" is "FUNCTION" or "VARIABLE".  The meaning of that is obvious.
 # - "algorithms" is a comma-separated list of algorithm names.  This helps
 #   exclude symbols that are part of an algorithm that some user wants to
 #   exclude.
 #
 
-my $crypto_num= "util/libeay.num";
-my $ssl_num=    "util/ssleay.num";
+use lib ".";
+use configdata;
+use File::Spec::Functions;
+
+my $debug=0;
+
+my $crypto_num= catfile($config{sourcedir},"util","libeay.num");
+my $ssl_num=    catfile($config{sourcedir},"util","ssleay.num");
+my $libname;
 
 my $do_update = 0;
-my $do_rewrite = 0;
+my $do_rewrite = 1;
 my $do_crypto = 0;
 my $do_ssl = 0;
 my $do_ctest = 0;
 my $do_ctestall = 0;
 my $do_checkexist = 0;
 
+my $VMSVAX=0;
+my $VMSNonVAX=0;
 my $VMS=0;
 my $W32=0;
-my $W16=0;
 my $NT=0;
+my $OS2=0;
+my $linux=0;
 # Set this to make typesafe STACK definitions appear in DEF
 my $safe_stack_def = 0;
 
-my @known_platforms = ( "__FreeBSD__", "VMS", "WIN16", "WIN32",
-                       "WINNT", "PERL5", "NeXT" );
+my @known_platforms = ( "__FreeBSD__", "PERL5",
+                       "EXPORT_VAR_AS_FUNCTION", "ZLIB"
+                       );
+my @known_ossl_platforms = ( "VMS", "WIN32", "WINNT", "OS2" );
 my @known_algorithms = ( "RC2", "RC4", "RC5", "IDEA", "DES", "BF",
                         "CAST", "MD2", "MD4", "MD5", "SHA", "SHA0", "SHA1",
-                        "RIPEMD",
-                        "MDC2", "RSA", "DSA", "DH", "HMAC", "AES",
+                        "SHA256", "SHA512", "RMD160",
+                        "MDC2", "WHIRLPOOL", "RSA", "DSA", "DH", "EC", "EC2M",
+                        "HMAC", "AES", "CAMELLIA", "SEED", "GOST",
+                         "SCRYPT", "CHACHA", "POLY1305",
+                        # EC_NISTP_64_GCC_128
+                        "EC_NISTP_64_GCC_128",
                         # Envelope "algorithms"
                         "EVP", "X509", "ASN1_TYPEDEFS",
                         # Helper "algorithms"
                         "BIO", "COMP", "BUFFER", "LHASH", "STACK", "ERR",
                         "LOCKING",
                         # External "algorithms"
-                        "FP_API", "STDIO", "SOCK", "KRB5" );
-
-my $options="";
-open(IN,"<Makefile.ssl") || die "unable to open Makefile.ssl!\n";
-while(<IN>) {
-    $options=$1 if (/^OPTIONS=(.*)$/);
+                        "FP_API", "STDIO", "SOCK", "DGRAM",
+                         "CRYPTO_MDEBUG",
+                        # Engines
+                         "STATIC_ENGINE", "ENGINE", "HW", "GMP",
+                        # Entropy Gathering
+                        "EGD",
+                        # Certificate Transparency
+                        "CT",
+                        # RFC3779
+                        "RFC3779",
+                        # TLS
+                        "PSK", "SRP", "HEARTBEATS",
+                        # CMS
+                        "CMS",
+                        # CryptoAPI Engine
+                        "CAPIENG",
+                        # SSL v3 method
+                        "SSL3_METHOD",
+                        # NEXTPROTONEG
+                        "NEXTPROTONEG",
+                        # Deprecated functions
+                        "DEPRECATEDIN_0_9_8",
+                        "DEPRECATEDIN_1_0_0",
+                        "DEPRECATEDIN_1_1_0",
+                        # SCTP
+                        "SCTP",
+                        # SRTP
+                        "SRTP",
+                        # SSL TRACE
+                        "SSL_TRACE",
+                        # Unit testing
+                        "UNIT_TEST",
+                        # OCB mode
+                        "OCB",
+                         # APPLINK (win build feature?)
+                         "APPLINK"
+                     );
+
+my %disabled_algorithms;
+
+foreach (@known_algorithms) {
+    $disabled_algorithms{$_} = 0;
 }
-close(IN);
-
-# The following ciphers may be excluded (by Configure). This means functions
-# defined with ifndef(NO_XXX) are not included in the .def file, and everything
-# in directory xxx is ignored.
-my $no_rc2; my $no_rc4; my $no_rc5; my $no_idea; my $no_des; my $no_bf;
-my $no_cast;
-my $no_md2; my $no_md4; my $no_md5; my $no_sha; my $no_ripemd; my $no_mdc2;
-my $no_rsa; my $no_dsa; my $no_dh; my $no_hmac=0; my $no_aes; my $no_krb5;
-my $no_fp_api;
-
-foreach (@ARGV, split(/ /, $options))
+# disabled by default
+$disabled_algorithms{"STATIC_ENGINE"} = 1;
+
+my $zlib;
+
+foreach (@ARGV, split(/ /, $config{options}))
        {
+       $debug=1 if $_ eq "debug";
        $W32=1 if $_ eq "32";
-       $W16=1 if $_ eq "16";
+       die "win16 not supported" if $_ eq "16";
        if($_ eq "NT") {
                $W32 = 1;
                $NT = 1;
        }
-       $VMS=1 if $_ eq "VMS";
+       if ($_ eq "VMS-VAX") {
+               $VMS=1;
+               $VMSVAX=1;
+       }
+       if ($_ eq "VMS-NonVAX") {
+               $VMS=1;
+               $VMSNonVAX=1;
+       }
+       if ($_ eq "linux") {
+               $linux=1;
+       }
+       $VMS=$VMSNonVAX=1 if $_ eq "VMS";
+       $OS2=1 if $_ eq "OS2";
+       if ($_ eq "zlib" || $_ eq "enable-zlib" || $_ eq "zlib-dynamic"
+                        || $_ eq "enable-zlib-dynamic") {
+               $zlib = 1;
+       }
 
        $do_ssl=1 if $_ eq "ssleay";
-       $do_ssl=1 if $_ eq "ssl";
+       if ($_ eq "ssl") {
+               $do_ssl=1; 
+               $libname=$_
+       }
        $do_crypto=1 if $_ eq "libeay";
-       $do_crypto=1 if $_ eq "crypto";
+       if ($_ eq "crypto") {
+               $do_crypto=1;
+               $libname=$_;
+       }
        $do_update=1 if $_ eq "update";
        $do_rewrite=1 if $_ eq "rewrite";
        $do_ctest=1 if $_ eq "ctest";
        $do_ctestall=1 if $_ eq "ctestall";
        $do_checkexist=1 if $_ eq "exist";
-       #$safe_stack_def=1 if $_ eq "-DDEBUG_SAFESTACK";
-
-       if    (/^no-rc2$/)      { $no_rc2=1; }
-       elsif (/^no-rc4$/)      { $no_rc4=1; }
-       elsif (/^no-rc5$/)      { $no_rc5=1; }
-       elsif (/^no-idea$/)     { $no_idea=1; }
-       elsif (/^no-des$/)      { $no_des=1; $no_mdc2=1; }
-       elsif (/^no-bf$/)       { $no_bf=1; }
-       elsif (/^no-cast$/)     { $no_cast=1; }
-       elsif (/^no-md2$/)      { $no_md2=1; }
-       elsif (/^no-md4$/)      { $no_md4=1; }
-       elsif (/^no-md5$/)      { $no_md5=1; }
-       elsif (/^no-sha$/)      { $no_sha=1; }
-       elsif (/^no-ripemd$/)   { $no_ripemd=1; }
-       elsif (/^no-mdc2$/)     { $no_mdc2=1; }
-       elsif (/^no-rsa$/)      { $no_rsa=1; }
-       elsif (/^no-dsa$/)      { $no_dsa=1; }
-       elsif (/^no-dh$/)       { $no_dh=1; }
-       elsif (/^no-hmac$/)     { $no_hmac=1; }
-       elsif (/^no-aes$/)      { $no_aes=1; }
-       elsif (/^no-evp$/)      { $no_evp=1; }
-       elsif (/^no-lhash$/)    { $no_lhash=1; }
-       elsif (/^no-stack$/)    { $no_stack=1; }
-       elsif (/^no-err$/)      { $no_err=1; }
-       elsif (/^no-buffer$/)   { $no_buffer=1; }
-       elsif (/^no-bio$/)      { $no_bio=1; }
-       #elsif (/^no-locking$/) { $no_locking=1; }
-       elsif (/^no-comp$/)     { $no_comp=1; }
-       elsif (/^no-dso$/)      { $no_dso=1; }
-       elsif (/^no-krb5$/)     { $no_krb5=1; }
+       if (/^--api=(\d+)\.(\d+)\.(\d+)$/) {
+               my $apiv = sprintf "%x%02x%02x", $1, $2, $3;
+               foreach (keys %disabled_algorithms) {
+                       if (/^DEPRECATEDIN_(\d+)_(\d+)_(\d+)$/) {
+                               my $depv = sprintf "%x%02x%02x", $1, $2, $3;
+                               $disabled_algorithms{$_} = 1 if $apiv ge $depv;
+                       }
+               }
+       }
+       if (/^no-deprecated$/) {
+               foreach (keys %disabled_algorithms) {
+                       if (/^DEPRECATEDIN_/) {
+                               $disabled_algorithms{$_} = 1;
+                       }
+               }
+       }
+       elsif (/^(enable|disable|no)-(.*)$/) {
+               my $alg = uc $2;
+        $alg =~ tr/-/_/;
+               if (exists $disabled_algorithms{$alg}) {
+                       $disabled_algorithms{$alg} = $1 eq "enable" ? 0 : 1;
+               }
        }
 
+       }
 
-# If no platform is given, assume WIN32
-if ($W32 + $W16 + $VMS == 0) {
-       $W32 = 1;
+if (!$libname) { 
+       if ($do_ssl) {
+               $libname="SSLEAY";
+       }
+       if ($do_crypto) {
+               $libname="LIBEAY";
+       }
 }
 
-# Add extra knowledge
-if ($W16) {
-       $no_fp_api=1;
+# If no platform is given, assume WIN32
+if ($W32 + $VMS + $OS2 + $linux == 0) {
+       $W32 = 1;
 }
+die "Please, only one platform at a time"
+    if ($W32 + $VMS + $OS2 + $linux > 1);
 
 if (!$do_ssl && !$do_crypto)
        {
-       print STDERR "usage: $0 ( ssl | crypto ) [ 16 | 32 | NT ]\n";
+       print STDERR "usage: $0 ( ssl | crypto ) [ 16 | 32 | NT | OS2 | linux | VMS ]\n";
        exit(1);
        }
 
@@ -175,60 +227,76 @@ $max_ssl = $max_num;
 %crypto_list=&load_numbers($crypto_num);
 $max_crypto = $max_num;
 
-my $ssl="ssl/ssl.h";
-$ssl.=" ssl/kssl.h";
-
-my $crypto ="crypto/crypto.h";
-$crypto.=" crypto/des/des.h" unless $no_des;
-$crypto.=" crypto/idea/idea.h" unless $no_idea;
-$crypto.=" crypto/rc4/rc4.h" unless $no_rc4;
-$crypto.=" crypto/rc5/rc5.h" unless $no_rc5;
-$crypto.=" crypto/rc2/rc2.h" unless $no_rc2;
-$crypto.=" crypto/bf/blowfish.h" unless $no_bf;
-$crypto.=" crypto/cast/cast.h" unless $no_cast;
-$crypto.=" crypto/md2/md2.h" unless $no_md2;
-$crypto.=" crypto/md4/md4.h" unless $no_md4;
-$crypto.=" crypto/md5/md5.h" unless $no_md5;
-$crypto.=" crypto/mdc2/mdc2.h" unless $no_mdc2;
-$crypto.=" crypto/sha/sha.h" unless $no_sha;
-$crypto.=" crypto/ripemd/ripemd.h" unless $no_ripemd;
-$crypto.=" crypto/rijndael/rijndael.h" unless $no_aes;
-$crypto.=" crypto/rijndael/rd_fst.h" unless $no_aes;
-
-$crypto.=" crypto/bn/bn.h";
-$crypto.=" crypto/rsa/rsa.h" unless $no_rsa;
-$crypto.=" crypto/dsa/dsa.h" unless $no_dsa;
-$crypto.=" crypto/dh/dh.h" unless $no_dh;
-$crypto.=" crypto/hmac/hmac.h" unless $no_hmac;
-
-$crypto.=" crypto/engine/engine.h";
-$crypto.=" crypto/stack/stack.h" unless $no_stack;
-$crypto.=" crypto/buffer/buffer.h" unless $no_buffer;
-$crypto.=" crypto/bio/bio.h" unless $no_bio;
-$crypto.=" crypto/dso/dso.h" unless $no_dso;
-$crypto.=" crypto/lhash/lhash.h" unless $no_lhash;
-$crypto.=" crypto/conf/conf.h";
-$crypto.=" crypto/txt_db/txt_db.h";
-
-$crypto.=" crypto/evp/evp.h" unless $no_evp;
-$crypto.=" crypto/objects/objects.h";
-$crypto.=" crypto/pem/pem.h";
-#$crypto.=" crypto/meth/meth.h";
-$crypto.=" crypto/asn1/asn1.h";
-$crypto.=" crypto/asn1/asn1t.h";
-$crypto.=" crypto/asn1/asn1_mac.h";
-$crypto.=" crypto/err/err.h" unless $no_err;
-$crypto.=" crypto/pkcs7/pkcs7.h";
-$crypto.=" crypto/pkcs12/pkcs12.h";
-$crypto.=" crypto/x509/x509.h";
-$crypto.=" crypto/x509/x509_vfy.h";
-$crypto.=" crypto/x509v3/x509v3.h";
-$crypto.=" crypto/rand/rand.h";
-$crypto.=" crypto/comp/comp.h" unless $no_comp;
-$crypto.=" crypto/ocsp/ocsp.h";
-$crypto.=" crypto/tmdiff.h";
-
-my $symhacks="crypto/symhacks.h";
+my $ssl="include/openssl/ssl.h";
+$ssl.=" include/openssl/tls1.h";
+$ssl.=" include/openssl/srtp.h";
+
+# We use headers found in include/openssl and include/internal only.
+# The latter is needed so libssl.so/.dll/.exe can link properly.
+my $crypto ="include/openssl/crypto.h";
+$crypto.=" include/internal/o_dir.h";
+$crypto.=" include/internal/o_str.h";
+$crypto.=" include/internal/threads.h";
+$crypto.=" include/openssl/des.h" ; # unless $no_des;
+$crypto.=" include/openssl/idea.h" ; # unless $no_idea;
+$crypto.=" include/openssl/rc4.h" ; # unless $no_rc4;
+$crypto.=" include/openssl/rc5.h" ; # unless $no_rc5;
+$crypto.=" include/openssl/rc2.h" ; # unless $no_rc2;
+$crypto.=" include/openssl/blowfish.h" ; # unless $no_bf;
+$crypto.=" include/openssl/cast.h" ; # unless $no_cast;
+$crypto.=" include/openssl/whrlpool.h" ;
+$crypto.=" include/openssl/md2.h" ; # unless $no_md2;
+$crypto.=" include/openssl/md4.h" ; # unless $no_md4;
+$crypto.=" include/openssl/md5.h" ; # unless $no_md5;
+$crypto.=" include/openssl/mdc2.h" ; # unless $no_mdc2;
+$crypto.=" include/openssl/sha.h" ; # unless $no_sha;
+$crypto.=" include/openssl/ripemd.h" ; # unless $no_ripemd;
+$crypto.=" include/openssl/aes.h" ; # unless $no_aes;
+$crypto.=" include/openssl/camellia.h" ; # unless $no_camellia;
+$crypto.=" include/openssl/seed.h"; # unless $no_seed;
+
+$crypto.=" include/openssl/bn.h";
+$crypto.=" include/openssl/rsa.h" ; # unless $no_rsa;
+$crypto.=" include/openssl/dsa.h" ; # unless $no_dsa;
+$crypto.=" include/openssl/dh.h" ; # unless $no_dh;
+$crypto.=" include/openssl/ec.h" ; # unless $no_ec;
+$crypto.=" include/openssl/hmac.h" ; # unless $no_hmac;
+$crypto.=" include/openssl/cmac.h" ;
+
+$crypto.=" include/openssl/engine.h"; # unless $no_engine;
+$crypto.=" include/openssl/stack.h" ; # unless $no_stack;
+$crypto.=" include/openssl/buffer.h" ; # unless $no_buffer;
+$crypto.=" include/openssl/bio.h" ; # unless $no_bio;
+$crypto.=" include/openssl/dso.h" ; # unless $no_dso;
+$crypto.=" include/openssl/lhash.h" ; # unless $no_lhash;
+$crypto.=" include/openssl/conf.h";
+$crypto.=" include/openssl/txt_db.h";
+
+$crypto.=" include/openssl/evp.h" ; # unless $no_evp;
+$crypto.=" include/openssl/objects.h";
+$crypto.=" include/openssl/pem.h";
+#$crypto.=" include/openssl/meth.h";
+$crypto.=" include/openssl/asn1.h";
+$crypto.=" include/openssl/asn1t.h";
+$crypto.=" include/openssl/err.h" ; # unless $no_err;
+$crypto.=" include/openssl/pkcs7.h";
+$crypto.=" include/openssl/pkcs12.h";
+$crypto.=" include/openssl/x509.h";
+$crypto.=" include/openssl/x509_vfy.h";
+$crypto.=" include/openssl/x509v3.h";
+$crypto.=" include/openssl/ts.h";
+$crypto.=" include/openssl/rand.h";
+$crypto.=" include/openssl/comp.h" ; # unless $no_comp;
+$crypto.=" include/openssl/ocsp.h";
+$crypto.=" include/openssl/ui.h";
+#$crypto.=" include/openssl/store.h";
+$crypto.=" include/openssl/cms.h";
+$crypto.=" include/openssl/srp.h";
+$crypto.=" include/openssl/modes.h";
+$crypto.=" include/openssl/async.h";
+$crypto.=" include/openssl/ct.h";
+
+my $symhacks="include/openssl/symhacks.h";
 
 my @ssl_symbols = &do_defs("SSLEAY", $ssl, $symhacks);
 my @crypto_symbols = &do_defs("LIBEAY", $crypto, $symhacks);
@@ -241,7 +309,6 @@ if ($do_ssl == 1) {
        if ($do_rewrite == 1) {
                open(OUT, ">$ssl_num");
                &rewrite_numbers(*OUT,"SSLEAY",*ssl_list,@ssl_symbols);
-               close OUT;
        } else {
                open(OUT, ">>$ssl_num");
        }
@@ -288,10 +355,10 @@ EOF
 
 } else {
 
-       &print_def_file(*STDOUT,"SSLEAY",*ssl_list,@ssl_symbols)
+       &print_def_file(*STDOUT,$libname,*ssl_list,@ssl_symbols)
                if $do_ssl == 1;
 
-       &print_def_file(*STDOUT,"LIBEAY",*crypto_list,@crypto_symbols)
+       &print_def_file(*STDOUT,$libname,*crypto_list,@crypto_symbols)
                if $do_crypto == 1;
 
 }
@@ -306,17 +373,24 @@ sub do_defs
        my %platform;           # For anything undefined, we assume ""
        my %kind;               # For anything undefined, we assume "FUNCTION"
        my %algorithm;          # For anything undefined, we assume ""
-       my %rename;
+       my %variant;
+       my %variant_cnt;        # To be able to allocate "name{n}" if "name"
+                               # is the same name as the original.
        my $cpp;
        my %unknown_algorithms = ();
+       my $parens = 0;
 
        foreach $file (split(/\s+/,$symhacksfile." ".$files))
                {
-               open(IN,"<$file") || die "unable to open $file:$!\n";
+               my $fn = catfile($config{sourcedir},$file);
+               print STDERR "DEBUG: starting on $fn:\n" if $debug;
+               open(IN,"<$fn") || die "unable to open $fn:$!\n";
                my $line = "", my $def= "";
                my %tag = (
                        (map { $_ => 0 } @known_platforms),
-                       (map { "NO_".$_ => 0 } @known_algorithms),
+                       (map { "OPENSSL_SYS_".$_ => 0 } @known_ossl_platforms),
+                       (map { "OPENSSL_NO_".$_ => 0 } @known_algorithms),
+                       (map { "OPENSSL_USE_".$_ => 0 } @known_algorithms),
                        NOPROTO         => 0,
                        PERL5           => 0,
                        _WINDLL         => 0,
@@ -327,82 +401,218 @@ sub do_defs
                my @current_platforms = ();
                my @current_algorithms = ();
 
+               # params: symbol, alias, platforms, kind
+               # The reason to put this subroutine in a variable is that
+               # it will otherwise create it's own, unshared, version of
+               # %tag and %variant...
+               my $make_variant = sub
+               {
+                       my ($s, $a, $p, $k) = @_;
+                       my ($a1, $a2);
+
+                       print STDERR "DEBUG: make_variant: Entered with ",$s,", ",$a,", ",(defined($p)?$p:""),", ",(defined($k)?$k:""),"\n" if $debug;
+                       if (defined($p))
+                       {
+                               $a1 = join(",",$p,
+                                          grep(!/^$/,
+                                               map { $tag{$_} == 1 ? $_ : "" }
+                                               @known_platforms));
+                       }
+                       else
+                       {
+                               $a1 = join(",",
+                                          grep(!/^$/,
+                                               map { $tag{$_} == 1 ? $_ : "" }
+                                               @known_platforms));
+                       }
+                       $a2 = join(",",
+                                  grep(!/^$/,
+                                       map { $tag{"OPENSSL_SYS_".$_} == 1 ? $_ : "" }
+                                       @known_ossl_platforms));
+                       print STDERR "DEBUG: make_variant: a1 = $a1; a2 = $a2\n" if $debug;
+                       if ($a1 eq "") { $a1 = $a2; }
+                       elsif ($a1 ne "" && $a2 ne "") { $a1 .= ",".$a2; }
+                       if ($a eq $s)
+                       {
+                               if (!defined($variant_cnt{$s}))
+                               {
+                                       $variant_cnt{$s} = 0;
+                               }
+                               $variant_cnt{$s}++;
+                               $a .= "{$variant_cnt{$s}}";
+                       }
+                       my $toadd = $a.":".$a1.(defined($k)?":".$k:"");
+                       my $togrep = $s.'(\{[0-9]+\})?:'.$a1.(defined($k)?":".$k:"");
+                       if (!grep(/^$togrep$/,
+                                 split(/;/, defined($variant{$s})?$variant{$s}:""))) {
+                               if (defined($variant{$s})) { $variant{$s} .= ";"; }
+                               $variant{$s} .= $toadd;
+                       }
+                       print STDERR "DEBUG: make_variant: Exit with variant of ",$s," = ",$variant{$s},"\n" if $debug;
+               };
+
+               print STDERR "DEBUG: parsing ----------\n" if $debug;
                while(<IN>) {
-                       last if (/BEGIN ERROR CODES/);
+                       if($parens > 0) {
+                               #Inside a DEPRECATEDIN
+                               $stored_multiline .= $_;
+                               $stored_multiline =~ s|\R$||; # Better chomp
+                               print STDERR "DEBUG: Continuing multiline DEPRECATEDIN: $stored_multiline\n" if $debug;
+                               $parens = count_parens($stored_multiline);
+                               if ($parens == 0) {
+                                       $def .= do_deprecated($stored_multiline,
+                                                       \@current_platforms,
+                                                       \@current_algorithms);
+                               }
+                               next;
+                       }
+                       if (/\/\* Error codes for the \w+ functions\. \*\//)
+                               {
+                               undef @tag;
+                               last;
+                               }
                        if ($line ne '') {
                                $_ = $line . $_;
                                $line = '';
                        }
 
                        if (/\\$/) {
-                               $line = $_;
+                               $line = $`; # keep what was before the backslash
                                next;
                        }
 
-                       $cpp = 1 if /^\#.*ifdef.*cplusplus/;
+                       if(/\/\*/) {
+                               if (not /\*\//) {       # multiline comment...
+                                       $line = $_;     # ... just accumulate
+                                       next;
+                               } else {
+                                       s/\/\*.*?\*\///gs;# wipe it
+                               }
+                       }
+
                        if ($cpp) {
-                               $cpp = 0 if /^\#.*endif/;
+                               $cpp++ if /^#\s*if/;
+                               $cpp-- if /^#\s*endif/;
+                               next;
+                       }
+                       if (/^#.*ifdef.*cplusplus/) {
+                               $cpp = 1;
                                next;
-                       }
+                       }
 
-                       s/\/\*.*?\*\///gs;                   # ignore comments
                        s/{[^{}]*}//gs;                      # ignore {} blocks
-                       #print STDERR "DEBUG: \$_=\"$_\"\n";
+                       print STDERR "DEBUG: \$def=\"$def\"\n" if $debug && $def ne "";
+                       print STDERR "DEBUG: \$_=\"$_\"\n" if $debug;
                        if (/^\#\s*ifndef\s+(.*)/) {
+                               push(@tag,"-");
                                push(@tag,$1);
                                $tag{$1}=-1;
+                               print STDERR "DEBUG: $file: found tag $1 = -1\n" if $debug;
                        } elsif (/^\#\s*if\s+!defined\(([^\)]+)\)/) {
-                               push(@tag,$1);
-                               $tag{$1}=-1;
-                       } elsif (/^\#\s*ifdef\s+(.*)/) {
+                               push(@tag,"-");
+                               if (/^\#\s*if\s+(!defined\(([^\)]+)\)(\s+\&\&\s+!defined\(([^\)]+)\))*)$/) {
+                                       my $tmp_1 = $1;
+                                       my $tmp_;
+                                       foreach $tmp_ (split '\&\&',$tmp_1) {
+                                               $tmp_ =~ /!defined\(([^\)]+)\)/;
+                                               print STDERR "DEBUG: $file: found tag $1 = -1\n" if $debug;
+                                               push(@tag,$1);
+                                               $tag{$1}=-1;
+                                       }
+                               } else {
+                                       print STDERR "Warning: $file: complicated expression: $_" if $debug; # because it is O...
+                                       print STDERR "DEBUG: $file: found tag $1 = -1\n" if $debug;
+                                       push(@tag,$1);
+                                       $tag{$1}=-1;
+                               }
+                       } elsif (/^\#\s*ifdef\s+(\S*)/) {
+                               push(@tag,"-");
                                push(@tag,$1);
                                $tag{$1}=1;
+                               print STDERR "DEBUG: $file: found tag $1 = 1\n" if $debug;
                        } elsif (/^\#\s*if\s+defined\(([^\)]+)\)/) {
-                               push(@tag,$1);
-                               $tag{$1}=1;
+                               push(@tag,"-");
+                               if (/^\#\s*if\s+(defined\(([^\)]+)\)(\s+\|\|\s+defined\(([^\)]+)\))*)$/) {
+                                       my $tmp_1 = $1;
+                                       my $tmp_;
+                                       foreach $tmp_ (split '\|\|',$tmp_1) {
+                                               $tmp_ =~ /defined\(([^\)]+)\)/;
+                                               print STDERR "DEBUG: $file: found tag $1 = 1\n" if $debug;
+                                               push(@tag,$1);
+                                               $tag{$1}=1;
+                                       }
+                               } else {
+                                       print STDERR "Warning: $file: complicated expression: $_\n" if $debug; # because it is O...
+                                       print STDERR "DEBUG: $file: found tag $1 = 1\n" if $debug;
+                                       push(@tag,$1);
+                                       $tag{$1}=1;
+                               }
                        } elsif (/^\#\s*error\s+(\w+) is disabled\./) {
-                               if ($tag[$#tag] eq "NO_".$1) {
-                                       $tag{$tag[$#tag]}=2;
+                               my $tag_i = $#tag;
+                               while($tag[$tag_i] ne "-") {
+                                       if ($tag[$tag_i] eq "OPENSSL_NO_".$1) {
+                                               $tag{$tag[$tag_i]}=2;
+                                               print STDERR "DEBUG: $file: chaged tag $1 = 2\n" if $debug;
+                                       }
+                                       $tag_i--;
                                }
                        } elsif (/^\#\s*endif/) {
-                               my $oldtag=$tag[$#tag];
-                               #print STDERR "DEBUG: \$oldtag=\"$oldtag\"\n";
-                               if ($tag{$tag[$#tag]}==2) {
-                                       $tag{$tag[$#tag]}=-1;
-                               } else {
-                                       $tag{$tag[$#tag]}=0;
+                               my $tag_i = $#tag;
+                               while($tag_i > 0 && $tag[$tag_i] ne "-") {
+                                       my $t=$tag[$tag_i];
+                                       print STDERR "DEBUG: \$t=\"$t\"\n" if $debug;
+                                       if ($tag{$t}==2) {
+                                               $tag{$t}=-1;
+                                       } else {
+                                               $tag{$t}=0;
+                                       }
+                                       print STDERR "DEBUG: $file: changed tag ",$t," = ",$tag{$t},"\n" if $debug;
+                                       pop(@tag);
+                                       if ($t =~ /^OPENSSL_NO_([A-Z0-9_]+)$/) {
+                                               $t=$1;
+                                       } elsif($t =~ /^OPENSSL_USE_([A-Z0-9_]+)$/) {
+                                               $t=$1;
+                                       } else {
+                                               $t="";
+                                       }
+                                       if ($t ne ""
+                                           && !grep(/^$t$/, @known_algorithms)) {
+                                               $unknown_algorithms{$t} = 1;
+                                               #print STDERR "DEBUG: Added as unknown algorithm: $t\n" if $debug;
+                                       }
+                                       $tag_i--;
                                }
                                pop(@tag);
-                               if ($oldtag =~ /^NO_([A-Z0-9_]+)$/) {
-                                       $oldtag=$1;
-                               } else {
-                                       $oldtag="";
-                               }
-                               if ($oldtag ne ""
-                                   && !grep(/^$oldtag$/, @known_algorithms)) {
-                                       $unknown_algorithms{$oldtag} = 1;
-                                       #print STDERR "DEBUG: Added as unknown algorithm: $oldtag\n";
-                               }
                        } elsif (/^\#\s*else/) {
-                               my $t=$tag[$#tag];
-                               $tag{$t}= -$tag{$t};
+                               my $tag_i = $#tag;
+                               die "$file unmatched else\n" if $tag_i < 0;
+                               while($tag[$tag_i] ne "-") {
+                                       my $t=$tag[$tag_i];
+                                       $tag{$t}= -$tag{$t};
+                                       print STDERR "DEBUG: $file: changed tag ",$t," = ",$tag{$t},"\n" if $debug;
+                                       $tag_i--;
+                               }
                        } elsif (/^\#\s*if\s+1/) {
+                               push(@tag,"-");
                                # Dummy tag
                                push(@tag,"TRUE");
                                $tag{"TRUE"}=1;
+                               print STDERR "DEBUG: $file: found 1\n" if $debug;
                        } elsif (/^\#\s*if\s+0/) {
+                               push(@tag,"-");
                                # Dummy tag
                                push(@tag,"TRUE");
                                $tag{"TRUE"}=-1;
+                               print STDERR "DEBUG: $file: found 0\n" if $debug;
+                       } elsif (/^\#\s*if\s+/) {
+                               #Some other unrecognized "if" style
+                               push(@tag,"-");
                        } elsif (/^\#\s*define\s+(\w+)\s+(\w+)/
-                                && $symhacking) {
-                               my $s = $1;
-                               my $a =
-                                   $2.":".join(",", grep(!/^$/,
-                                                         map { $tag{$_} == 1 ?
-                                                                   $_ : "" }
-                                                         @known_platforms));
-                               $rename{$s} = $a;
+                                && $symhacking && $tag{'TRUE'} != -1) {
+                               # This is for aliasing.  When we find an alias,
+                               # we have to invert
+                               &$make_variant($1,$2);
+                               print STDERR "DEBUG: $file: defined $1 = $2\n" if $debug;
                        }
                        if (/^\#/) {
                                @current_platforms =
@@ -410,9 +620,19 @@ sub do_defs
                                         map { $tag{$_} == 1 ? $_ :
                                                   $tag{$_} == -1 ? "!".$_  : "" }
                                         @known_platforms);
+                               push @current_platforms
+                                   , grep(!/^$/,
+                                          map { $tag{"OPENSSL_SYS_".$_} == 1 ? $_ :
+                                                    $tag{"OPENSSL_SYS_".$_} == -1 ? "!".$_  : "" }
+                                          @known_ossl_platforms);
+                               @current_algorithms = ();
                                @current_algorithms =
                                    grep(!/^$/,
-                                        map { $tag{"NO_".$_} == -1 ? $_ : "" }
+                                        map { $tag{"OPENSSL_NO_".$_} == -1 ? $_ : "" }
+                                        @known_algorithms);
+                               push @current_algorithms
+                                   , grep(!/^$/,
+                                        map { $tag{"OPENSSL_USE_".$_} == 1 ? $_ : "" }
                                         @known_algorithms);
                                $def .=
                                    "#INFO:"
@@ -420,95 +640,241 @@ sub do_defs
                                            .join(',',@current_algorithms).";";
                                next;
                        }
-                       if (/^\s*DECLARE_STACK_OF\s*\(\s*(\w*)\s*\)/) {
-                               next;
-                       } elsif (/^\s*DECLARE_ASN1_ENCODE_FUNCTIONS\s*\(\s*(\w*)\s*,\s*(\w*)\s*,\s*(\w*)\s*\)/) {
-                               $def .= "int d2i_$3(void);";
-                               $def .= "int i2d_$3(void);";
-                               $def .= "OPENSSL_EXTERN int $2_it;";
-                               next;
-                       } elsif (/^\s*DECLARE_ASN1_FUNCTIONS_fname\s*\(\s*(\w*)\s*,\s*(\w*)\s*,\s*(\w*)\s*\)/) {
-                               $def .= "int d2i_$3(void);";
-                               $def .= "int i2d_$3(void);";
-                               $def .= "int $3_free(void);";
-                               $def .= "int $3_new(void);";
-                               $def .= "OPENSSL_EXTERN int $2_it;";
-                       } elsif (/^\s*DECLARE_ASN1_FUNCTIONS\s*\(\s*(\w*)\s*\)/ ||
-                               /^\s*DECLARE_ASN1_FUNCTIONS_const\s*\(\s*(\w*)\s*\)/) {
-                               $def .= "int d2i_$1(void);";
-                               $def .= "int i2d_$1(void);";
-                               $def .= "int $1_free(void);";
-                               $def .= "int $1_new(void);";
-                               $def .= "OPENSSL_EXTERN int $1_it;";
-                               next;
-                       } elsif (/^\s*DECLARE_ASN1_ENCODE_FUNCTIONS_const\s*\(\s*(\w*)\s*,\s*(\w*)\s*\)/) {
-                               $def .= "int d2i_$2(void);";
-                               $def .= "int i2d_$2(void);";
-                               $def .= "OPENSSL_EXTERN int $2_it;";
-                               next;
-                       } elsif (/^\s*DECLARE_ASN1_FUNCTIONS_name\s*\(\s*(\w*)\s*,\s*(\w*)\s*\)/) {
-                               $def .= "int d2i_$2(void);";
-                               $def .= "int i2d_$2(void);";
-                               $def .= "int $2_free(void);";
-                               $def .= "int $2_new(void);";
-                               $def .= "OPENSSL_EXTERN int $2_it;";
-                               next;
-                       } elsif (/^\s*DECLARE_ASN1_ITEM\s*\(\s*(\w*)\s*,(\w*)\s*\)/) {
-                               $def .= "OPENSSL_EXTERN int $1_it;";
-                               next;
-                       } elsif (/^\s*DECLARE_PKCS12_STACK_OF\s*\(\s*(\w*)\s*\)/) {
-                               next;
-                       } elsif (/^\s*DECLARE_ASN1_SET_OF\s*\(\s*(\w*)\s*\)/) {
-                               next;
-                       } elsif (/^DECLARE_PEM_rw\s*\(\s*(\w*)\s*,/ ||
-                                /^DECLARE_PEM_rw_cb\s*\(\s*(\w*)\s*,/ ) {
-                               # Things not in Win16
-                               $def .=
-                                   "#INFO:"
-                                       .join(',',"!WIN16",@current_platforms).":"
-                                           .join(',',@current_algorithms).";";
-                               $def .= "int PEM_read_$1(void);";
-                               $def .= "int PEM_write_$1(void);";
-                               $def .=
-                                   "#INFO:"
-                                       .join(',',@current_platforms).":"
-                                           .join(',',@current_algorithms).";";
-                               # Things that are everywhere
-                               $def .= "int PEM_read_bio_$1(void);";
-                               $def .= "int PEM_write_bio_$1(void);";
-                       } elsif (/^DECLARE_PEM_write\s*\(\s*(\w*)\s*,/ ||
-                                    /^DECLARE_PEM_write_cb\s*\(\s*(\w*)\s*,/ ) {
-                               # Things not in Win16
-                               $def .=
-                                   "#INFO:"
-                                       .join(',',"!WIN16",@current_platforms).":"
-                                           .join(',',@current_algorithms).";";
-                               $def .= "int PEM_write_$1(void);";
-                               $def .=
-                                   "#INFO:"
-                                       .join(',',@current_platforms).":"
-                                           .join(',',@current_algorithms).";";
-                               # Things that are everywhere
-                               $def .= "int PEM_write_bio_$1(void);";
-                       } elsif (/^DECLARE_PEM_read\s*\(\s*(\w*)\s*,/ ||
-                                    /^DECLARE_PEM_read_cb\s*\(\s*(\w*)\s*,/ ) {
-                               # Things not in Win16
-                               $def .=
-                                   "#INFO:"
-                                       .join(',',"!WIN16",@current_platforms).":"
-                                           .join(',',@current_algorithms).";";
-                               $def .= "int PEM_read_$1(void);";
-                               $def .=
-                                   "#INFO:"
-                                       .join(',',@current_platforms).":"
-                                           .join(',',@current_algorithms).";";
-                               # Things that are everywhere
-                               $def .= "int PEM_read_bio_$1(void);";
-                       } elsif (
-                               ($tag{'TRUE'} != -1)
-                               && ($tag{'CONST_STRICT'} != 1)
-                                )
-                               {
+                       if ($tag{'TRUE'} != -1) {
+                               if (/^\s*DEFINE_STACK_OF\s*\(\s*(\w*)\s*\)/
+                                               || /^\s*DEFINE_STACK_OF_CONST\s*\(\s*(\w*)\s*\)/) {
+                                       next;
+                               } elsif (/^\s*DECLARE_ASN1_ENCODE_FUNCTIONS\s*\(\s*(\w*)\s*,\s*(\w*)\s*,\s*(\w*)\s*\)/) {
+                                       $def .= "int d2i_$3(void);";
+                                       $def .= "int i2d_$3(void);";
+                                       # Variant for platforms that do not
+                                       # have to access globale variables
+                                       # in shared libraries through functions
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',"!EXPORT_VAR_AS_FUNCTION",@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       $def .= "OPENSSL_EXTERN int $2_it;";
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       # Variant for platforms that have to
+                                       # access globale variables in shared
+                                       # libraries through functions
+                                       &$make_variant("$2_it","$2_it",
+                                                     "EXPORT_VAR_AS_FUNCTION",
+                                                     "FUNCTION");
+                                       next;
+                               } elsif (/^\s*DECLARE_ASN1_FUNCTIONS_fname\s*\(\s*(\w*)\s*,\s*(\w*)\s*,\s*(\w*)\s*\)/) {
+                                       $def .= "int d2i_$3(void);";
+                                       $def .= "int i2d_$3(void);";
+                                       $def .= "int $3_free(void);";
+                                       $def .= "int $3_new(void);";
+                                       # Variant for platforms that do not
+                                       # have to access globale variables
+                                       # in shared libraries through functions
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',"!EXPORT_VAR_AS_FUNCTION",@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       $def .= "OPENSSL_EXTERN int $2_it;";
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       # Variant for platforms that have to
+                                       # access globale variables in shared
+                                       # libraries through functions
+                                       &$make_variant("$2_it","$2_it",
+                                                     "EXPORT_VAR_AS_FUNCTION",
+                                                     "FUNCTION");
+                                       next;
+                               } elsif (/^\s*DECLARE_ASN1_FUNCTIONS\s*\(\s*(\w*)\s*\)/ ||
+                                        /^\s*DECLARE_ASN1_FUNCTIONS_const\s*\(\s*(\w*)\s*\)/) {
+                                       $def .= "int d2i_$1(void);";
+                                       $def .= "int i2d_$1(void);";
+                                       $def .= "int $1_free(void);";
+                                       $def .= "int $1_new(void);";
+                                       # Variant for platforms that do not
+                                       # have to access globale variables
+                                       # in shared libraries through functions
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',"!EXPORT_VAR_AS_FUNCTION",@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       $def .= "OPENSSL_EXTERN int $1_it;";
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       # Variant for platforms that have to
+                                       # access globale variables in shared
+                                       # libraries through functions
+                                       &$make_variant("$1_it","$1_it",
+                                                     "EXPORT_VAR_AS_FUNCTION",
+                                                     "FUNCTION");
+                                       next;
+                               } elsif (/^\s*DECLARE_ASN1_ENCODE_FUNCTIONS_const\s*\(\s*(\w*)\s*,\s*(\w*)\s*\)/) {
+                                       $def .= "int d2i_$2(void);";
+                                       $def .= "int i2d_$2(void);";
+                                       # Variant for platforms that do not
+                                       # have to access globale variables
+                                       # in shared libraries through functions
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',"!EXPORT_VAR_AS_FUNCTION",@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       $def .= "OPENSSL_EXTERN int $2_it;";
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       # Variant for platforms that have to
+                                       # access globale variables in shared
+                                       # libraries through functions
+                                       &$make_variant("$2_it","$2_it",
+                                                     "EXPORT_VAR_AS_FUNCTION",
+                                                     "FUNCTION");
+                                       next;
+                               } elsif (/^\s*DECLARE_ASN1_ALLOC_FUNCTIONS\s*\(\s*(\w*)\s*\)/) {
+                                       $def .= "int $1_free(void);";
+                                       $def .= "int $1_new(void);";
+                                       next;
+                               } elsif (/^\s*DECLARE_ASN1_FUNCTIONS_name\s*\(\s*(\w*)\s*,\s*(\w*)\s*\)/) {
+                                       $def .= "int d2i_$2(void);";
+                                       $def .= "int i2d_$2(void);";
+                                       $def .= "int $2_free(void);";
+                                       $def .= "int $2_new(void);";
+                                       # Variant for platforms that do not
+                                       # have to access globale variables
+                                       # in shared libraries through functions
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',"!EXPORT_VAR_AS_FUNCTION",@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       $def .= "OPENSSL_EXTERN int $2_it;";
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       # Variant for platforms that have to
+                                       # access globale variables in shared
+                                       # libraries through functions
+                                       &$make_variant("$2_it","$2_it",
+                                                     "EXPORT_VAR_AS_FUNCTION",
+                                                     "FUNCTION");
+                                       next;
+                               } elsif (/^\s*DECLARE_ASN1_ITEM\s*\(\s*(\w*)\s*\)/) {
+                                       # Variant for platforms that do not
+                                       # have to access globale variables
+                                       # in shared libraries through functions
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',"!EXPORT_VAR_AS_FUNCTION",@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       $def .= "OPENSSL_EXTERN int $1_it;";
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       # Variant for platforms that have to
+                                       # access globale variables in shared
+                                       # libraries through functions
+                                       &$make_variant("$1_it","$1_it",
+                                                     "EXPORT_VAR_AS_FUNCTION",
+                                                     "FUNCTION");
+                                       next;
+                               } elsif (/^\s*DECLARE_ASN1_NDEF_FUNCTION\s*\(\s*(\w*)\s*\)/) {
+                                       $def .= "int i2d_$1_NDEF(void);";
+                               } elsif (/^\s*DECLARE_ASN1_SET_OF\s*\(\s*(\w*)\s*\)/) {
+                                       next;
+                               } elsif (/^\s*DECLARE_ASN1_PRINT_FUNCTION\s*\(\s*(\w*)\s*\)/) {
+                                       $def .= "int $1_print_ctx(void);";
+                                       next;
+                               } elsif (/^\s*DECLARE_ASN1_PRINT_FUNCTION_name\s*\(\s*(\w*)\s*,\s*(\w*)\s*\)/) {
+                                       $def .= "int $2_print_ctx(void);";
+                                       next;
+                               } elsif (/^\s*DECLARE_PKCS12_STACK_OF\s*\(\s*(\w*)\s*\)/) {
+                                       next;
+                               } elsif (/^DECLARE_PEM_rw\s*\(\s*(\w*)\s*,/ ||
+                                        /^DECLARE_PEM_rw_cb\s*\(\s*(\w*)\s*,/ ||
+                                        /^DECLARE_PEM_rw_const\s*\(\s*(\w*)\s*,/ ) {
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       $def .= "int PEM_read_$1(void);";
+                                       $def .= "int PEM_write_$1(void);";
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       # Things that are everywhere
+                                       $def .= "int PEM_read_bio_$1(void);";
+                                       $def .= "int PEM_write_bio_$1(void);";
+                                       next;
+                               } elsif (/^DECLARE_PEM_write\s*\(\s*(\w*)\s*,/ ||
+                                       /^DECLARE_PEM_write_const\s*\(\s*(\w*)\s*,/ ||
+                                        /^DECLARE_PEM_write_cb\s*\(\s*(\w*)\s*,/ ) {
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       $def .= "int PEM_write_$1(void);";
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       # Things that are everywhere
+                                       $def .= "int PEM_write_bio_$1(void);";
+                                       next;
+                               } elsif (/^DECLARE_PEM_read\s*\(\s*(\w*)\s*,/ ||
+                                        /^DECLARE_PEM_read_cb\s*\(\s*(\w*)\s*,/ ) {
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       $def .= "int PEM_read_$1(void);";
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       # Things that are everywhere
+                                       $def .= "int PEM_read_bio_$1(void);";
+                                       next;
+                               } elsif (/^OPENSSL_DECLARE_GLOBAL\s*\(\s*(\w*)\s*,\s*(\w*)\s*\)/) {
+                                       # Variant for platforms that do not
+                                       # have to access globale variables
+                                       # in shared libraries through functions
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',"!EXPORT_VAR_AS_FUNCTION",@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       $def .= "OPENSSL_EXTERN int _shadow_$2;";
+                                       $def .=
+                                           "#INFO:"
+                                               .join(',',@current_platforms).":"
+                                                   .join(',',@current_algorithms).";";
+                                       # Variant for platforms that have to
+                                       # access globale variables in shared
+                                       # libraries through functions
+                                       &$make_variant("_shadow_$2","_shadow_$2",
+                                                     "EXPORT_VAR_AS_FUNCTION",
+                                                     "FUNCTION");
+                               } elsif (/^\s*DEPRECATEDIN/) {
+                                       $parens = count_parens($_);
+                                       if ($parens == 0) {
+                                               $def .= do_deprecated($_,
+                                                       \@current_platforms,
+                                                       \@current_algorithms);
+                                       } else {
+                                               $stored_multiline = $_;
+                                               $stored_multiline =~ s|\R$||;
+                                               print STDERR "DEBUG: Found multiline DEPRECATEDIN starting with: $stored_multiline\n" if $debug;
+                                               next;
+                                       }
+                               } elsif ($tag{'CONST_STRICT'} != 1) {
                                        if (/\{|\/\*|\([^\)]*$/) {
                                                $line = $_;
                                        } else {
@@ -516,11 +882,14 @@ sub do_defs
                                        }
                                }
                        }
+               }
                close(IN);
+               die "$file: Unmatched tags\n" if $#tag >= 0;
 
                my $algs;
                my $plays;
 
+               print STDERR "DEBUG: postprocessing ----------\n" if $debug;
                foreach (split /;/, $def) {
                        my $s; my $k = "FUNCTION"; my $p; my $a;
                        s/^[\n\s]*//g;
@@ -529,26 +898,33 @@ sub do_defs
                        next if(/typedef\W/);
                        next if(/\#define/);
 
+                       # Reduce argument lists to empty ()
+                       # fold round brackets recursively: (t(*v)(t),t) -> (t{}{},t) -> {}
+                       while(/\(.*\)/s) {
+                               s/\([^\(\)]+\)/\{\}/gs;
+                               s/\(\s*\*\s*(\w+)\s*\{\}\s*\)/$1/gs;    #(*f{}) -> f
+                       }
+                       # pretend as we didn't use curly braces: {} -> ()
+                       s/\{\}/\(\)/gs;
+
+                       s/STACK_OF\(\)/void/gs;
+                       s/LHASH_OF\(\)/void/gs;
+
+                       print STDERR "DEBUG: \$_ = \"$_\"\n" if $debug;
                        if (/^\#INFO:([^:]*):(.*)$/) {
                                $plats = $1;
                                $algs = $2;
+                               print STDERR "DEBUG: found info on platforms ($plats) and algorithms ($algs)\n" if $debug;
                                next;
-                       } elsif (/^\s*OPENSSL_EXTERN\s.*?(\w+)(\[[0-9]*\])*\s*$/) {
+                       } elsif (/^\s*OPENSSL_EXTERN\s.*?(\w+(\{[0-9]+\})?)(\[[0-9]*\])*\s*$/) {
                                $s = $1;
                                $k = "VARIABLE";
-                       } elsif (/\(\*(\w*)\([^\)]+/) {
-                               $s = $1;
-                       } elsif (/\w+\W+(\w+)\W*\(\s*\)$/s) {
-                               # K&R C
+                               print STDERR "DEBUG: found external variable $s\n" if $debug;
+                       } elsif (/TYPEDEF_\w+_OF/s) {
                                next;
-                       } elsif (/\w+\W+\w+\W*\(.*\)$/s) {
-                               while (not /\(\)$/s) {
-                                       s/[^\(\)]*\)$/\)/s;
-                                       s/\([^\(\)]*\)\)$/\)/s;
-                               }
-                               s/\(void\)//;
-                               /(\w+)\W*\(\)/s;
-                               $s = $1;
+                       } elsif (/(\w+)\s*\(\).*/s) {   # first token prior [first] () is
+                               $s = $1;                # a function name!
+                               print STDERR "DEBUG: found function $s\n" if $debug;
                        } elsif (/\(/ and not (/=/)) {
                                print STDERR "File $file: cannot parse: $_;\n";
                                next;
@@ -561,61 +937,50 @@ sub do_defs
 
                        $p = $plats;
                        $a = $algs;
-                       $a .= ",BF" if($s =~ /EVP_bf/);
-                       $a .= ",CAST" if($s =~ /EVP_cast/);
-                       $a .= ",DES" if($s =~ /EVP_des/);
-                       $a .= ",DSA" if($s =~ /EVP_dss/);
-                       $a .= ",IDEA" if($s =~ /EVP_idea/);
-                       $a .= ",MD2" if($s =~ /EVP_md2/);
-                       $a .= ",MD4" if($s =~ /EVP_md4/);
-                       $a .= ",MD5" if($s =~ /EVP_md5/);
-                       $a .= ",RC2" if($s =~ /EVP_rc2/);
-                       $a .= ",RC4" if($s =~ /EVP_rc4/);
-                       $a .= ",RC5" if($s =~ /EVP_rc5/);
-                       $a .= ",RIPEMD" if($s =~ /EVP_ripemd/);
-                       $a .= ",SHA" if($s =~ /EVP_sha/);
-                       $a .= ",RSA" if($s =~ /EVP_(Open|Seal)(Final|Init)/);
-                       $a .= ",RSA" if($s =~ /PEM_Seal(Final|Init|Update)/);
-                       $a .= ",RSA" if($s =~ /RSAPrivateKey/);
-                       $a .= ",RSA" if($s =~ /SSLv23?_((client|server)_)?method/);
-
-                       $platform{$s} .= ','.$p;
+
+                       $platform{$s} =
+                           &reduce_platforms((defined($platform{$s})?$platform{$s}.',':"").$p);
                        $algorithm{$s} .= ','.$a;
 
-                       if (defined($rename{$s})) {
-                               (my $r, my $p) = split(/:/,$rename{$s});
-                               my @ip = map { /^!(.*)$/ ? $1 : "!".$_ } split /,/, $p;
-                               $syms{$r} = 1;
-                               $kind{$r} = $kind{$s}."(".$s.")";
-                               $algorithm{$r} = $algorithm{$s};
-                               $platform{$r} = $platform{$s}.",".$p;
-                               $platform{$s} .= ','.join(',', @ip).','.join(',', @ip);
+                       if (defined($variant{$s})) {
+                               foreach $v (split /;/,$variant{$s}) {
+                                       (my $r, my $p, my $k) = split(/:/,$v);
+                                       my $ip = join ',',map({ /^!(.*)$/ ? $1 : "!".$_ } split /,/, $p);
+                                       $syms{$r} = 1;
+                                       if (!defined($k)) { $k = $kind{$s}; }
+                                       $kind{$r} = $k."(".$s.")";
+                                       $algorithm{$r} = $algorithm{$s};
+                                       $platform{$r} = &reduce_platforms($platform{$s}.",".$p.",".$p);
+                                       $platform{$s} = &reduce_platforms($platform{$s}.','.$ip.','.$ip);
+                                       print STDERR "DEBUG: \$variant{\"$s\"} = ",$v,"; \$r = $r; \$p = ",$platform{$r},"; \$a = ",$algorithm{$r},"; \$kind = ",$kind{$r},"\n" if $debug;
+                               }
                        }
+                       print STDERR "DEBUG: \$s = $s; \$p = ",$platform{$s},"; \$a = ",$algorithm{$s},"; \$kind = ",$kind{$s},"\n" if $debug;
                }
        }
 
        # Prune the returned symbols
 
-       $platform{"crypt"} .= ",!PERL5,!__FreeBSD__,!NeXT";
-
-        delete $syms{"SSL_add_dir_cert_subjects_to_stack"};
         delete $syms{"bn_dump1"};
+       $platform{"BIO_s_log"} .= ",!WIN32,!macintosh";
+
+       $platform{"PEM_read_NS_CERT_SEQ"} = "VMS";
+       $platform{"PEM_write_NS_CERT_SEQ"} = "VMS";
+       $platform{"PEM_read_P8_PRIV_KEY_INFO"} = "VMS";
+       $platform{"PEM_write_P8_PRIV_KEY_INFO"} = "VMS";
+       $platform{"EVP_sha384"} = "!VMSVAX";
+       $platform{"EVP_sha512"} = "!VMSVAX";
+       $platform{"SHA384_Init"} = "!VMSVAX";
+       $platform{"SHA384_Transform"} = "!VMSVAX";
+       $platform{"SHA384_Update"} = "!VMSVAX";
+       $platform{"SHA384_Final"} = "!VMSVAX";
+       $platform{"SHA384"} = "!VMSVAX";
+       $platform{"SHA512_Init"} = "!VMSVAX";
+       $platform{"SHA512_Transform"} = "!VMSVAX";
+       $platform{"SHA512_Update"} = "!VMSVAX";
+       $platform{"SHA512_Final"} = "!VMSVAX";
+       $platform{"SHA512"} = "!VMSVAX";
 
-       $platform{"BIO_s_file_internal"} .= ",WIN16";
-       $platform{"BIO_new_file_internal"} .= ",WIN16";
-       $platform{"BIO_new_fp_internal"} .= ",WIN16";
-
-       $platform{"BIO_s_file"} .= ",!WIN16";
-       $platform{"BIO_new_file"} .= ",!WIN16";
-       $platform{"BIO_new_fp"} .= ",!WIN16";
-
-       $platform{"BIO_s_log"} .= ",!WIN32,!WIN16,!macintosh";
-
-       if(exists $syms{"ERR_load_CRYPTO_strings"}) {
-               $platform{"ERR_load_CRYPTO_strings"} .= ",!VMS,!WIN16";
-               $syms{"ERR_load_CRYPTOlib_strings"} = 1;
-               $platform{"ERR_load_CRYPTOlib_strings"} .= ",VMS,WIN16";
-       }
 
        # Info we know about
 
@@ -631,16 +996,16 @@ sub do_defs
        return(@ret);
 }
 
-sub info_string {
-       (my $symbol, my $exist, my $platforms, my $kind, my $algorithms) = @_;
-
-       my %a = defined($algorithms) ?
-           map { $_ => 1 } split /,/, $algorithms : ();
+# Param: string of comma-separated platform-specs.
+sub reduce_platforms
+{
+       my ($platforms) = @_;
        my $pl = defined($platforms) ? $platforms : "";
        my %p = map { $_ => 0 } split /,/, $pl;
-       my $k = defined($kind) ? $kind : "FUNCTION";
        my $ret;
 
+       print STDERR "DEBUG: Entered reduce_platforms with \"$platforms\"\n"
+           if $debug;
        # We do this, because if there's code like the following, it really
        # means the function exists in all cases and should therefore be
        # everywhere.  By increasing and decreasing, we may attain 0:
@@ -662,195 +1027,330 @@ sub info_string {
        }
 
        delete $p{""};
+
+       $ret = join(',',sort(map { $p{$_} < 0 ? "!".$_ : $_ } keys %p));
+       print STDERR "DEBUG: Exiting reduce_platforms with \"$ret\"\n"
+           if $debug;
+       return $ret;
+}
+
+sub info_string
+{
+       (my $symbol, my $exist, my $platforms, my $kind, my $algorithms) = @_;
+
+       my %a = defined($algorithms) ?
+           map { $_ => 1 } split /,/, $algorithms : ();
+       my $k = defined($kind) ? $kind : "FUNCTION";
+       my $ret;
+       my $p = &reduce_platforms($platforms);
+
        delete $a{""};
 
        $ret = $exist;
-       $ret .= ":".join(',',map { $p{$_} < 0 ? "!".$_ : $_ } keys %p);
+       $ret .= ":".$p;
        $ret .= ":".$k;
-       $ret .= ":".join(',',keys %a);
+       $ret .= ":".join(',',sort keys %a);
        return $ret;
 }
 
-sub maybe_add_info {
+sub maybe_add_info
+{
        (my $name, *nums, my @symbols) = @_;
        my $sym;
        my $new_info = 0;
        my %syms=();
 
-       print STDERR "Updating $name info\n";
        foreach $sym (@symbols) {
                (my $s, my $i) = split /\\/, $sym;
-               $i =~ s/^(.*?:.*?:\w+)(\(\w+\))?/$1/;
                if (defined($nums{$s})) {
-                       (my $n, my $dummy) = split /\\/, $nums{$s};
+                       $i =~ s/^(.*?:.*?:\w+)(\(\w+\))?/$1/;
+                       (my $n, my $vers, my $dummy) = split /\\/, $nums{$s};
                        if (!defined($dummy) || $i ne $dummy) {
-                               $nums{$s} = $n."\\".$i;
+                               $nums{$s} = $n."\\".$vers."\\".$i;
                                $new_info++;
-                               #print STDERR "DEBUG: maybe_add_info for $s: \"$dummy\" => \"$i\"\n";
+                               print STDERR "DEBUG: maybe_add_info for $s: \"$dummy\" => \"$i\"\n" if $debug;
                        }
                }
-               $syms{sym} = 1;
+               $syms{$s} = 1;
        }
 
        my @s=sort { &parse_number($nums{$a},"n") <=> &parse_number($nums{$b},"n") } keys %nums;
        foreach $sym (@s) {
-               (my $n, my $i) = split /\\/, $nums{$sym};
-               if (!defined($syms{sym})) {
+               (my $n, my $vers, my $i) = split /\\/, $nums{$sym};
+               if (!defined($syms{$sym}) && $i !~ /^NOEXIST:/) {
                        $new_info++;
-                       #print STDERR "DEBUG: maybe_add_info for $sym: -> undefined\n";
+                       print STDERR "DEBUG: maybe_add_info for $sym: -> undefined\n" if $debug;
                }
        }
        if ($new_info) {
-               print STDERR "$new_info old symbols got an info update\n";
+               print STDERR "$name: $new_info old symbols have updated info\n";
                if (!$do_rewrite) {
                        print STDERR "You should do a rewrite to fix this.\n";
                }
        } else {
-               print STDERR "No old symbols needed info update\n";
        }
 }
 
+# Param: string of comma-separated keywords, each possibly prefixed with a "!"
+sub is_valid
+{
+       my ($keywords_txt,$platforms) = @_;
+       my (@keywords) = split /,/,$keywords_txt;
+       my ($falsesum, $truesum) = (0, 1);
+
+       # Param: one keyword
+       sub recognise
+       {
+               my ($keyword,$platforms) = @_;
+
+               if ($platforms) {
+                       # platforms
+                       if ($keyword eq "VMSVAX" && $VMSVAX) { return 1; }
+                       if ($keyword eq "VMSNonVAX" && $VMSNonVAX) { return 1; }
+                       if ($keyword eq "VMS" && $VMS) { return 1; }
+                       if ($keyword eq "WIN32" && $W32) { return 1; }
+                       if ($keyword eq "WINNT" && $NT) { return 1; }
+                       if ($keyword eq "OS2" && $OS2) { return 1; }
+                       # Special platforms:
+                       # EXPORT_VAR_AS_FUNCTION means that global variables
+                       # will be represented as functions.  This currently
+                       # only happens on VMS-VAX.
+                       if ($keyword eq "EXPORT_VAR_AS_FUNCTION" && ($VMSVAX || $W32)) {
+                               return 1;
+                       }
+                       if ($keyword eq "ZLIB" && $zlib) { return 1; }
+                       return 0;
+               } else {
+                       # algorithms
+                       if ($disabled_algorithms{$keyword} == 1) { return 0;}
+
+                       # Nothing recognise as true
+                       return 1;
+               }
+       }
+
+       foreach $k (@keywords) {
+               if ($k =~ /^!(.*)$/) {
+                       $falsesum += &recognise($1,$platforms);
+               } else {
+                       $truesum *= &recognise($k,$platforms);
+               }
+       }
+       print STDERR "DEBUG: [",$#keywords,",",$#keywords < 0,"] is_valid($keywords_txt) => (\!$falsesum) && $truesum = ",(!$falsesum) && $truesum,"\n" if $debug;
+       return (!$falsesum) && $truesum;
+}
+
 sub print_test_file
 {
-       (*OUT,my $name,*nums,my @symbols)=@_;
+       (*OUT,my $name,*nums,my $testall,my @symbols)=@_;
        my $n = 1; my @e; my @r;
        my $sym; my $prev = ""; my $prefSSLeay;
 
-       (@e)=grep(/^SSLeay\\.*?:.*?:FUNCTION/,@symbols);
-       (@r)=grep(/^\w+\\.*?:.*?:FUNCTION/ && !/^SSLeay\\.*?:.*?:FUNCTION/,@symbols);
+       (@e)=grep(/^SSLeay(\{[0-9]+\})?\\.*?:.*?:.*/,@symbols);
+       (@r)=grep(/^\w+(\{[0-9]+\})?\\.*?:.*?:.*/ && !/^SSLeay(\{[0-9]+\})?\\.*?:.*?:.*/,@symbols);
        @symbols=((sort @e),(sort @r));
 
        foreach $sym (@symbols) {
                (my $s, my $i) = $sym =~ /^(.*?)\\(.*)$/;
-               if ($s ne $prev) {
-                       if (!defined($nums{$s})) {
-                               printf STDERR "Warning: $s does not have a number assigned\n"
-                                               if(!$do_update);
+               my $v = 0;
+               $v = 1 if $i=~ /^.*?:.*?:VARIABLE/;
+               my $p = ($i =~ /^[^:]*:([^:]*):/,$1);
+               my $a = ($i =~ /^[^:]*:[^:]*:[^:]*:([^:]*)/,$1);
+               if (!defined($nums{$s})) {
+                       print STDERR "Warning: $s does not have a number assigned\n"
+                           if(!$do_update);
+               } elsif (is_valid($p,1) && is_valid($a,0)) {
+                       my $s2 = ($s =~ /^(.*?)(\{[0-9]+\})?$/, $1);
+                       if ($prev eq $s2) {
+                               print OUT "\t/* The following has already appeared previously */\n";
+                               print STDERR "Warning: Symbol '",$s2,"' redefined. old=",($nums{$prev} =~ /^(.*?)\\/,$1),", new=",($nums{$s2} =~ /^(.*?)\\/,$1),"\n";
+                       }
+                       $prev = $s2;    # To warn about duplicates...
+
+                       (my $nn, my $vers, my $ni) = split /\\/, $nums{$s2};
+                       if ($v) {
+                               print OUT "\textern int $s2; /* type unknown */ /* $nn $ni */\n";
                        } else {
-                               $n=$nums{$s};
-                               print OUT "\t$s();\n";
+                               print OUT "\textern int $s2(); /* type unknown */ /* $nn $ni */\n";
                        }
                }
-               $prev = $s;     # To avoid duplicates...
        }
 }
 
+sub get_version
+{
+   return $config{version};
+}
+
 sub print_def_file
 {
        (*OUT,my $name,*nums,my @symbols)=@_;
-       my $n = 1; my @e; my @r; my @v;
+       my $n = 1; my @e; my @r; my @v; my $prev="";
+       my $liboptions="";
+       my $libname = $name;
+       my $http_vendor = 'www.openssl.org/';
+       my $version = get_version();
+       my $what = "OpenSSL: implementation of Secure Socket Layer";
+       my $description = "$what $version, $name - http://$http_vendor";
+       my $prevsymversion = "", $prevprevsymversion = "";
+        # For VMS
+        my $prevnum = 0;
+        my $symvtextcount = 0;
 
        if ($W32)
-               { $name.="32"; }
-       else
-               { $name.="16"; }
+               { $libname.="32"; }
+       elsif ($OS2)
+               { # DLL names should not clash on the whole system.
+                 # However, they should not have any particular relationship
+                 # to the name of the static library.  Chose descriptive names
+                 # (must be at most 8 chars).
+                 my %translate = (ssl => 'open_ssl', crypto => 'cryptssl');
+                 $libname = $translate{$name} || $name;
+                 $liboptions = <<EOO;
+INITINSTANCE
+DATA MULTIPLE NONSHARED
+EOO
+                 # Vendor field can't contain colon, drat; so we omit http://
+                 $description = "\@#$http_vendor:$version#\@$what; DLL for library $name.  Build for EMX -Zmtd";
+               }
 
-       print OUT <<"EOF";
+        if ($W32 || $OS2)
+                {
+                print OUT <<"EOF";
 ;
 ; Definition file for the DLL version of the $name library from OpenSSL
 ;
 
-LIBRARY         $name
-
-DESCRIPTION     'OpenSSL $name - http://www.openssl.org/'
+LIBRARY         $libname       $liboptions
 
 EOF
 
-       if (!$W32) {
-               print <<"EOF";
-CODE            PRELOAD MOVEABLE
-DATA            PRELOAD MOVEABLE SINGLE
-
-EXETYPE                WINDOWS
-
-HEAPSIZE       4096
-STACKSIZE      8192
-
+               print "EXPORTS\n";
+                }
+        elsif ($VMS)
+                {
+                print OUT <<"EOF";
+CASE_SENSITIVE=YES
+SYMBOL_VECTOR=(-
 EOF
-       }
-
-       print "EXPORTS\n";
-
-       (@e)=grep(/^SSLeay\\.*?:.*?:FUNCTION/,@symbols);
-       (@r)=grep(/^\w+\\.*?:.*?:FUNCTION/ && !/^SSLeay\\.*?:.*?:FUNCTION/,@symbols);
-       (@v)=grep(/^\w+\\.*?:.*?:VARIABLE/,@symbols);
-       @symbols=((sort @e),(sort @r), (sort @v));
-
-
-       foreach $sym (@symbols) {
-               (my $s, my $i) = $sym =~ /^(.*?)\\(.*)$/;
-               my $v = 0;
-               $v = 1 if $sym=~ /^\w+\\.*?:.*?:VARIABLE/;
-               if (!defined($nums{$s})) {
-                       printf STDERR "Warning: $s does not have a number assigned\n"
-                                       if(!$do_update);
+                $symvtextcount = 16; # length of "SYMBOL_VECTOR=(-"
+                }
+
+       (@r)=grep(/^\w+(\{[0-9]+\})?\\.*?:.*?:FUNCTION/,@symbols);
+       (@v)=grep(/^\w+(\{[0-9]+\})?\\.*?:.*?:VARIABLE/,@symbols);
+        if ($VMS) {
+            # VMS needs to have the symbols on slot number order
+            @symbols=(map { $_->[1] }
+                      sort { $a->[0] <=> $b->[0] }
+                      map { (my $s, my $i) = $_ =~ /^(.*?)\\(.*)$/;
+                            die "Error: $s doesn't have a number assigned\n"
+                                if !defined($nums{$s});
+                            (my $n, my @rest) = split /\\/, $nums{$s};
+                            [ $n, $_ ] } (@e, @r, @v));
+        } else {
+            @symbols=((sort @e),(sort @r), (sort @v));
+        }
+
+       my ($baseversion, $currversion) = get_openssl_version();
+       my $thisversion;
+       do {
+               if (!defined($thisversion)) {
+                       $thisversion = $baseversion;
                } else {
-                       (my $n, my $i) = split /\\/, $nums{$s};
-                       my %pf = ();
-                       my @p = split(/,/, ($i =~ /^[^:]*:([^:]*):/,$1));
-                       my @a = split(/,/, ($i =~ /^[^:]*:[^:]*:[^:]*:([^:]*)/,$1));
-                       # @p_purged must contain hardware platforms only
-                       my @p_purged = ();
-                       foreach $ptmp (@p) {
-                               push @p_purged, $ptmp;
-                       }
-                       my $negatives = !!grep(/^!/,@p);
-                       # It is very important to check NT before W32
-                       if ((($NT && (!@p_purged
-                                     || (!$negatives && grep(/^WINNT$/,@p))
-                                     || ($negatives && !grep(/^!WINNT$/,@p))))
-                            || ($W32 && (!@p_purged
-                                         || (!$negatives && grep(/^WIN32$/,@p))
-                                         || ($negatives && !grep(/^!WIN32$/,@p))))
-                            || ($W16 && (!@p_purged
-                                         || (!$negatives && grep(/^WIN16$/,@p))
-                                         || ($negatives && !grep(/^!WIN16$/,@p)))))
-                           && (!@a || (!$no_rc2 || !grep(/^RC2$/,@a)))
-                           && (!@a || (!$no_rc4 || !grep(/^RC4$/,@a)))
-                           && (!@a || (!$no_rc5 || !grep(/^RC5$/,@a)))
-                           && (!@a || (!$no_idea || !grep(/^IDEA$/,@a)))
-                           && (!@a || (!$no_des || !grep(/^DES$/,@a)))
-                           && (!@a || (!$no_bf || !grep(/^BF$/,@a)))
-                           && (!@a || (!$no_cast || !grep(/^CAST$/,@a)))
-                           && (!@a || (!$no_md2 || !grep(/^MD2$/,@a)))
-                           && (!@a || (!$no_md4 || !grep(/^MD4$/,@a)))
-                           && (!@a || (!$no_md5 || !grep(/^MD5$/,@a)))
-                           && (!@a || (!$no_sha || !grep(/^SHA$/,@a)))
-                           && (!@a || (!$no_ripemd || !grep(/^RIPEMD$/,@a)))
-                           && (!@a || (!$no_mdc2 || !grep(/^MDC2$/,@a)))
-                           && (!@a || (!$no_rsa || !grep(/^RSA$/,@a)))
-                           && (!@a || (!$no_dsa || !grep(/^DSA$/,@a)))
-                           && (!@a || (!$no_dh || !grep(/^DH$/,@a)))
-                           && (!@a || (!$no_hmac || !grep(/^HMAC$/,@a)))
-                           && (!@a || (!$no_aes || !grep(/^AES$/,@a)))
-                           && (!@a || (!$no_krb5 || !grep(/^KRB5$/,@a)))
-                           && (!@a || (!$no_fp_api || !grep(/^FP_API$/,@a)))
-                           ) {
-                               if($v) {
-                                       printf OUT "    %s%-40s@%-8d DATA\n",($W32)?"":"_",$s,$n;
-                               } else {
-                                       printf OUT "    %s%-40s@%d\n",($W32)?"":"_",$s,$n;
+                       $thisversion = get_next_version($thisversion);
+               }
+               foreach $sym (@symbols) {
+                       (my $s, my $i) = $sym =~ /^(.*?)\\(.*)$/;
+                       my $v = 0;
+                       $v = 1 if $i =~ /^.*?:.*?:VARIABLE/;
+                       if (!defined($nums{$s})) {
+                               die "Error: $s does not have a number assigned\n"
+                                       if(!$do_update);
+                       } else {
+                               (my $n, my $symversion, my $dummy) = split /\\/, $nums{$s};
+                               next if $symversion ne $thisversion;
+                               my %pf = ();
+                               my $p = ($i =~ /^[^:]*:([^:]*):/,$1);
+                               my $a = ($i =~ /^[^:]*:[^:]*:[^:]*:([^:]*)/,$1);
+                               if (is_valid($p,1) && is_valid($a,0)) {
+                                       my $s2 = ($s =~ /^(.*?)(\{[0-9]+\})?$/, $1);
+                                       if ($prev eq $s2) {
+                                               print STDERR "Warning: Symbol '",$s2,
+                                                       "' redefined. old=",($nums{$prev} =~ /^(.*?)\\/,$1),
+                                                       ", new=",($nums{$s2} =~ /^(.*?)\\/,$1),"\n";
+                                       }
+                                       $prev = $s2;    # To warn about duplicates...
+                                       if($linux) {
+                                               if ($symversion ne $prevsymversion) {
+                                                       if ($prevsymversion ne "") {
+                                                               if ($prevprevsymversion ne "") {
+                                                                       print OUT "} OPENSSL_"
+                                                                                               ."$prevprevsymversion;\n\n";
+                                                               } else {
+                                                                       print OUT "};\n\n";
+                                                               }
+                                                       }
+                                                       print OUT "OPENSSL_$symversion {\n    global:\n";
+                                                       $prevprevsymversion = $prevsymversion;
+                                                       $prevsymversion = $symversion;
+                                               }
+                                               print OUT "        $s2;\n";
+                                        } elsif ($VMS) {
+                                            while(++$prevnum < $n) {
+                                                my $symline=" ,SPARE -\n  ,SPARE -\n";
+                                                if ($symvtextcount + length($symline) - 2 > 1024) {
+                                                    print OUT ")\nSYMBOL_VECTOR=(-\n";
+                                                    $symvtextcount = 16; # length of "SYMBOL_VECTOR=(-"
+                                                }
+                                                if ($symvtextcount == 16) {
+                                                    # Take away first comma
+                                                    $symline =~ s/,//;
+                                                }
+                                                print OUT $symline;
+                                                $symvtextcount += length($symline) - 2;
+                                            }
+                                            (my $s_uc = $s) =~ tr/a-z/A-Z/;
+                                            my $symtype=
+                                                $v ? "DATA" : "PROCEDURE";
+                                            my $symline=
+                                                ($s_uc ne $s
+                                                 ? " ,$s_uc/$s=$symtype -\n  ,$s=$symtype -\n"
+                                                 : " ,$s=$symtype -\n  ,SPARE -\n");
+                                            if ($symvtextcount + length($symline) - 2 > 1024) {
+                                                print OUT ")\nSYMBOL_VECTOR=(-\n";
+                                                $symvtextcount = 16; # length of "SYMBOL_VECTOR=(-"
+                                            }
+                                            if ($symvtextcount == 16) {
+                                                # Take away first comma
+                                                $symline =~ s/,//;
+                                            }
+                                            print OUT $symline;
+                                            $symvtextcount += length($symline) - 2;
+                                       } elsif($v && !$OS2) {
+                                               printf OUT "    %s%-39s @%-8d DATA\n",
+                                                               ($W32)?"":"_",$s2,$n;
+                                       } else {
+                                               printf OUT "    %s%-39s @%d\n",
+                                                               ($W32||$OS2)?"":"_",$s2,$n;
+                                       }
                                }
-#                      } else {
-#                              print STDERR "DEBUG: \"$sym\" (@p):",
-#                              " rsaref:", !!(!@p
-#                                             || (!$negatives
-#                                                 && ($rsaref || !grep(/^RSAREF$/,@p)))
-#                                             || ($negatives
-#                                                 && (!$rsaref || !grep(/^!RSAREF$/,@p))))?1:0,
-#                              " 16:", !!($W16 && (!@p_purged
-#                                                  || (!$negatives && grep(/^WIN16$/,@p))
-#                                                  || ($negatives && !grep(/^!WIN16$/,@p)))),
-#                              " 32:", !!($W32 && (!@p_purged
-#                                                  || (!$negatives && grep(/^WIN32$/,@p))
-#                                                  || ($negatives && !grep(/^!WIN32$/,@p)))),
-#                              " NT:", !!($NT && (!@p_purged
-#                                                 || (!$negatives && grep(/^WINNT$/,@p))
-#                                                 || ($negatives && !grep(/^!WINNT$/,@p)))),
-#                              "\n";
                        }
                }
-       }
+       } while ($thisversion ne $currversion);
+       if ($linux) {
+               if ($prevprevsymversion ne "") {
+                       print OUT "    local: *;\n} OPENSSL_$prevprevsymversion;\n\n";
+               } else {
+                       print OUT "    local: *;\n};\n\n";
+               }
+       } elsif ($VMS) {
+            print OUT ")\n";
+            (my $libvmaj, my $libvmin, my $libvedit) =
+                $currversion =~ /^(\d+)_(\d+)_(\d+)$/;
+            # The reason to multiply the edit number with 100 is to make space
+            # for the possibility that we want to encode the patch letters
+            print OUT "GSMATCH=LEQUAL,",($libvmaj * 100 + $libvmin),",",($libvedit * 100),"\n";
+        }
        printf OUT "\n";
 }
 
@@ -858,33 +1358,51 @@ sub load_numbers
 {
        my($name)=@_;
        my(@a,%ret);
+       my $prevversion;
 
        $max_num = 0;
        $num_noinfo = 0;
        $prev = "";
+       $prev_cnt = 0;
+
+       my ($baseversion, $currversion) = get_openssl_version();
 
        open(IN,"<$name") || die "unable to open $name:$!\n";
        while (<IN>) {
-               chop;
+               s|\R$||;        # Better chomp
                s/#.*$//;
                next if /^\s*$/;
                @a=split;
                if (defined $ret{$a[0]}) {
-                       print STDERR "Warning: Symbol '",$a[0],"' redefined. old=",$ret{$a[0]},", new=",$a[1],"\n";
+                       # This is actually perfectly OK
+                       #print STDERR "Warning: Symbol '",$a[0],"' redefined. old=",$ret{$a[0]},", new=",$a[1],"\n";
                }
                if ($max_num > $a[1]) {
                        print STDERR "Warning: Number decreased from ",$max_num," to ",$a[1],"\n";
                }
-               if ($max_num == $a[1]) {
+               elsif ($max_num == $a[1]) {
                        # This is actually perfectly OK
                        #print STDERR "Warning: Symbol ",$a[0]," has same number as previous ",$prev,": ",$a[1],"\n";
+                       if ($a[0] eq $prev) {
+                               $prev_cnt++;
+                               $a[0] .= "{$prev_cnt}";
+                       }
+               }
+               else {
+                       $prev_cnt = 0;
                }
                if ($#a < 2) {
                        # Existence will be proven later, in do_defs
                        $ret{$a[0]}=$a[1];
                        $num_noinfo++;
                } else {
-                       $ret{$a[0]}=$a[1]."\\".$a[2]; # \\ is a special marker
+                       #Sanity check the version number
+                       if (defined $prevversion) {
+                               check_version_lte($prevversion, $a[2]);
+                       }
+                       check_version_lte($a[2], $currversion);
+                       $prevversion = $a[2];
+                       $ret{$a[0]}=$a[1]."\\".$a[2]."\\".$a[3]; # \\ is a special marker
                }
                $max_num = $a[1] if $a[1] > $max_num;
                $prev=$a[0];
@@ -904,7 +1422,7 @@ sub load_numbers
 sub parse_number
 {
        (my $str, my $what) = @_;
-       (my $n, my $i) = split(/\\/,$str);
+       (my $n, my $v, my $i) = split(/\\/,$str);
        if ($what eq "n") {
                return $n;
        } else {
@@ -917,9 +1435,7 @@ sub rewrite_numbers
        (*OUT,$name,*nums,@symbols)=@_;
        my $thing;
 
-       print STDERR "Rewriting $name\n";
-
-       my @r = grep(/^\w+\\.*?:.*?:\w+\(\w+\)/,@symbols);
+       my @r = grep(/^\w+(\{[0-9]+\})?\\.*?:.*?:\w+\(\w+\)/,@symbols);
        my $r; my %r; my %rsyms;
        foreach $r (@r) {
                (my $s, my $i) = split /\\/, $r;
@@ -935,17 +1451,25 @@ sub rewrite_numbers
                $syms{$n} = 1;
        }
 
-       my @s=sort { &parse_number($nums{$a},"n") <=> &parse_number($nums{$b},"n") } keys %nums;
+       my @s=sort {
+           &parse_number($nums{$a},"n") <=> &parse_number($nums{$b},"n")
+           || $a cmp $b
+       } keys %nums;
        foreach $sym (@s) {
-               (my $n, my $i) = split /\\/, $nums{$sym};
+               (my $n, my $vers, my $i) = split /\\/, $nums{$sym};
                next if defined($i) && $i =~ /^.*?:.*?:\w+\(\w+\)/;
                next if defined($rsyms{$sym});
+               print STDERR "DEBUG: rewrite_numbers for sym = ",$sym,": i = ",$i,", n = ",$n,", rsym{sym} = ",$rsyms{$sym},"syms{sym} = ",$syms{$sym},"\n" if $debug;
                $i="NOEXIST::FUNCTION:"
                        if !defined($i) || $i eq "" || !defined($syms{$sym});
-               printf OUT "%s%-40s%d\t%s\n","",$sym,$n,$i;
+               my $s2 = $sym;
+               $s2 =~ s/\{[0-9]+\}$//;
+               printf OUT "%s%-39s %d\t%s\t%s\n","",$s2,$n,$vers,$i;
                if (exists $r{$sym}) {
                        (my $s, $i) = split /\\/,$r{$sym};
-                       printf OUT "%s%-40s%d\t%s\n","",$s,$n,$i;
+                       my $s2 = $s;
+                       $s2 =~ s/\{[0-9]+\}$//;
+                       printf OUT "%s%-39s %d\t%s\t%s\n","",$s2,$n,$vers,$i;
                }
        }
 }
@@ -954,10 +1478,12 @@ sub update_numbers
 {
        (*OUT,$name,*nums,my $start_num, my @symbols)=@_;
        my $new_syms = 0;
+       my $basevers;
+       my $vers;
 
-       print STDERR "Updating $name numbers\n";
+       ($basevers, $vers) = get_openssl_version();
 
-       my @r = grep(/^\w+\\.*?:.*?:\w+\(\w+\)/,@symbols);
+       my @r = grep(/^\w+(\{[0-9]+\})?\\.*?:.*?:\w+\(\w+\)/,@symbols);
        my $r; my %r; my %rsyms;
        foreach $r (@r) {
                (my $s, my $i) = split /\\/, $r;
@@ -975,17 +1501,20 @@ sub update_numbers
                    if $i eq "";
                if (!exists $nums{$s}) {
                        $new_syms++;
-                       printf OUT "%s%-40s%d\t%s\n","",$s, ++$start_num,$i;
+                       my $s2 = $s;
+                       $s2 =~ s/\{[0-9]+\}$//;
+                       printf OUT "%s%-39s %d\t%s\t%s\n","",$s2, ++$start_num,$vers,$i;
                        if (exists $r{$s}) {
                                ($s, $i) = split /\\/,$r{$s};
-                               printf OUT "%s%-40s%d\t%s\n","",$s, $start_num,$i;
+                               $s =~ s/\{[0-9]+\}$//;
+                               printf OUT "%s%-39s %d\t%s\t%s\n","",$s, $start_num,$vers,$i;
                        }
                }
        }
        if($new_syms) {
-               print STDERR "$new_syms New symbols added\n";
+               print STDERR "$name: Added $new_syms new symbols\n";
        } else {
-               print STDERR "No New symbols Added\n";
+               print STDERR "$name: No new symbols added\n";
        }
 }
 
@@ -1011,3 +1540,157 @@ sub check_existing
        }
 }
 
+sub count_parens
+{
+       my $line = shift(@_);
+
+       my $open = $line =~ tr/\(//;
+       my $close = $line =~ tr/\)//;
+
+       return $open - $close;
+}
+
+#Parse opensslv.h to get the current version number. Also work out the base
+#version, i.e. the lowest version number that is binary compatible with this
+#version
+sub get_openssl_version()
+{
+       my $fn = catfile($config{sourcedir},"include","openssl","opensslv.h");
+       open (IN, "$fn") || die "Can't open opensslv.h";
+
+       while(<IN>) {
+               if (/OPENSSL_VERSION_TEXT\s+"OpenSSL (\d\.\d\.)(\d[a-z]*)(-| )/) {
+                       my $suffix = $2;
+                       (my $baseversion = $1) =~ s/\./_/g;
+                       close IN;
+                       return ($baseversion."0", $baseversion.$suffix);
+               }
+       }
+       die "Can't find OpenSSL version number\n";
+}
+
+#Given an OpenSSL version number, calculate the next version number. If the
+#version number gets to a.b.czz then we go to a.b.(c+1)
+sub get_next_version()
+{
+       my $thisversion = shift;
+
+       my ($base, $letter) = $thisversion =~ /^(\d_\d_\d)([a-z]{0,2})$/;
+
+       if ($letter eq "zz") {
+               my $lastnum = substr($base, -1);
+               return substr($base, 0, length($base)-1).(++$lastnum);
+       }
+       return $base.get_next_letter($letter);
+}
+
+#Given the letters off the end of an OpenSSL version string, calculate what
+#the letters for the next release would be.
+sub get_next_letter()
+{
+       my $thisletter = shift;
+       my $baseletter = "";
+       my $endletter;
+
+       if ($thisletter eq "") {
+               return "a";
+       }
+       if ((length $thisletter) > 1) {
+               ($baseletter, $endletter) = $thisletter =~ /([a-z]+)([a-z])/;
+       } else {
+               $endletter = $thisletter;
+       }
+
+       if ($endletter eq "z") {
+               return $thisletter."a";
+       } else {
+               return $baseletter.(++$endletter);
+       }
+}
+
+#Check if a version is less than or equal to the current version. Its a fatal
+#error if not. They must also only differ in letters, or the last number (i.e.
+#the first two numbers must be the same)
+sub check_version_lte()
+{
+       my ($testversion, $currversion) = @_;
+       my $lentv;
+       my $lencv;
+       my $cvbase;
+
+       my ($cvnums) = $currversion =~ /^(\d_\d_\d)[a-z]*$/;
+       my ($tvnums) = $testversion =~ /^(\d_\d_\d)[a-z]*$/;
+
+       #Die if we can't parse the version numbers or they don't look sane
+       die "Invalid version number: $testversion and $currversion\n"
+               if (!defined($cvnums) || !defined($tvnums)
+                       || length($cvnums) != 5
+                       || length($tvnums) != 5);
+
+       #If the base versions (without letters) don't match check they only differ
+       #in the last number
+       if ($cvnums ne $tvnums) {
+               die "Invalid version number: $testversion "
+                       ."for current version $currversion\n"
+                       if (substr($cvnums, -1) < substr($tvnums, -1)
+                               || substr($cvnums, 0, 4) ne substr($tvnums, 0, 4));
+               return;
+       }
+       #If we get here then the base version (i.e. the numbers) are the same - they
+       #only differ in the letters
+
+       $lentv = length $testversion;
+       $lencv = length $currversion;
+
+       #If the testversion has more letters than the current version then it must
+       #be later (or malformed)
+       if ($lentv > $lencv) {
+               die "Invalid version number: $testversion "
+                       ."is greater than $currversion\n";
+       }
+
+       #Get the last letter from the current version
+       my ($cvletter) = $currversion =~ /([a-z])$/;
+       if (defined $cvletter) {
+               ($cvbase) = $currversion =~ /(\d_\d_\d[a-z]*)$cvletter$/;
+       } else {
+               $cvbase = $currversion;
+       }
+       die "Unable to parse version number $currversion" if (!defined $cvbase);
+       my $tvbase;
+       my ($tvletter) = $testversion =~ /([a-z])$/;
+       if (defined $tvletter) {
+               ($tvbase) = $testversion =~ /(\d_\d_\d[a-z]*)$tvletter$/;
+       } else {
+               $tvbase = $testversion;
+       }
+       die "Unable to parse version number $testversion" if (!defined $tvbase);
+
+       if ($lencv > $lentv) {
+               #If current version has more letters than testversion then testversion
+               #minus the final letter must be a substring of the current version
+               die "Invalid version number $testversion "
+                       ."is greater than $currversion or is invalid\n"
+                       if (index($cvbase, $tvbase) != 0);
+       } else {
+               #If both versions have the same number of letters then they must be
+               #equal up to the last letter, and the last letter in testversion must
+               #be less than or equal to the last letter in current version.
+               die "Invalid version number $testversion "
+                       ."is greater than $currversion\n"
+                       if (($cvbase ne $tvbase) && ($tvletter gt $cvletter));
+       }
+}
+
+sub do_deprecated()
+{
+       my ($decl, $plats, $algs) = @_;
+       $decl =~ /^\s*(DEPRECATEDIN_\d+_\d+_\d+)\s*\((.*)\)\s*$/
+            or die "Bad DEPRECTEDIN: $decl\n";
+       my $info1 .= "#INFO:";
+       $info1 .= join(',', @{$plats}) . ":";
+       my $info2 = $info1;
+       $info1 .= join(',',@{$algs}, $1) . ";";
+       $info2 .= join(',',@{$algs}) . ";";
+       return $info1 . $2 . ";" . $info2;
+}