Since SSL_add_dir_cert_subjects_to_stack isn't impemented on VMS,
[openssl.git] / util / mkdef.pl
index 8ec1d07989a9fe597dde14dca672e7decdd3b248..d76226bb68edc2078cd7b1dc1b495db8080fb39b 100755 (executable)
@@ -54,6 +54,8 @@
 #   exclude.
 #
 
+my $debug=0;
+
 my $crypto_num= "util/libeay.num";
 my $ssl_num=    "util/ssleay.num";
 
@@ -63,7 +65,7 @@ my $do_crypto = 0;
 my $do_ssl = 0;
 my $do_ctest = 0;
 my $do_ctestall = 0;
-my $rsaref = 0;
+my $do_checkexist = 0;
 
 my $VMS=0;
 my $W32=0;
@@ -72,11 +74,19 @@ my $NT=0;
 # Set this to make typesafe STACK definitions appear in DEF
 my $safe_stack_def = 0;
 
-my @known_platforms = ( "__FreeBSD__", "VMS", "WIN16", "WIN32",
-                       "WINNT", "PERL5", "NeXT" );
+my @known_platforms = ( "__FreeBSD__", "PERL5", "NeXT" );
+my @known_ossl_platforms = ( "VMS", "WIN16", "WIN32", "WINNT" );
 my @known_algorithms = ( "RC2", "RC4", "RC5", "IDEA", "DES", "BF",
-                        "CAST", "MD2", "MD4", "MD5", "SHA", "RIPEMD",
-                        "MDC2", "RSA", "DSA", "DH", "HMAC", "FP_API" );
+                        "CAST", "MD2", "MD4", "MD5", "SHA", "SHA0", "SHA1",
+                        "RIPEMD",
+                        "MDC2", "RSA", "DSA", "DH", "HMAC", "AES",
+                        # Envelope "algorithms"
+                        "EVP", "X509", "ASN1_TYPEDEFS",
+                        # Helper "algorithms"
+                        "BIO", "COMP", "BUFFER", "LHASH", "STACK", "ERR",
+                        "LOCKING",
+                        # External "algorithms"
+                        "FP_API", "STDIO", "SOCK", "KRB5" );
 
 my $options="";
 open(IN,"<Makefile.ssl") || die "unable to open Makefile.ssl!\n";
@@ -91,7 +101,7 @@ close(IN);
 my $no_rc2; my $no_rc4; my $no_rc5; my $no_idea; my $no_des; my $no_bf;
 my $no_cast;
 my $no_md2; my $no_md4; my $no_md5; my $no_sha; my $no_ripemd; my $no_mdc2;
-my $no_rsa; my $no_dsa; my $no_dh; my $no_hmac=0;
+my $no_rsa; my $no_dsa; my $no_dh; my $no_hmac=0; my $no_aes; my $no_krb5;
 my $no_fp_api;
 
 foreach (@ARGV, split(/ /, $options))
@@ -103,7 +113,6 @@ foreach (@ARGV, split(/ /, $options))
                $NT = 1;
        }
        $VMS=1 if $_ eq "VMS";
-       $rsaref=1 if $_ eq "rsaref";
 
        $do_ssl=1 if $_ eq "ssleay";
        $do_ssl=1 if $_ eq "ssl";
@@ -113,6 +122,7 @@ foreach (@ARGV, split(/ /, $options))
        $do_rewrite=1 if $_ eq "rewrite";
        $do_ctest=1 if $_ eq "ctest";
        $do_ctestall=1 if $_ eq "ctestall";
+       $do_checkexist=1 if $_ eq "exist";
        #$safe_stack_def=1 if $_ eq "-DDEBUG_SAFESTACK";
 
        if    (/^no-rc2$/)      { $no_rc2=1; }
@@ -132,6 +142,17 @@ foreach (@ARGV, split(/ /, $options))
        elsif (/^no-dsa$/)      { $no_dsa=1; }
        elsif (/^no-dh$/)       { $no_dh=1; }
        elsif (/^no-hmac$/)     { $no_hmac=1; }
+       elsif (/^no-aes$/)      { $no_aes=1; }
+       elsif (/^no-evp$/)      { $no_evp=1; }
+       elsif (/^no-lhash$/)    { $no_lhash=1; }
+       elsif (/^no-stack$/)    { $no_stack=1; }
+       elsif (/^no-err$/)      { $no_err=1; }
+       elsif (/^no-buffer$/)   { $no_buffer=1; }
+       elsif (/^no-bio$/)      { $no_bio=1; }
+       #elsif (/^no-locking$/) { $no_locking=1; }
+       elsif (/^no-comp$/)     { $no_comp=1; }
+       elsif (/^no-dso$/)      { $no_dso=1; }
+       elsif (/^no-krb5$/)     { $no_krb5=1; }
        }
 
 
@@ -147,7 +168,7 @@ if ($W16) {
 
 if (!$do_ssl && !$do_crypto)
        {
-       print STDERR "usage: $0 ( ssl | crypto ) [ 16 | 32 | NT ] [rsaref]\n";
+       print STDERR "usage: $0 ( ssl | crypto ) [ 16 | 32 | NT ]\n";
        exit(1);
        }
 
@@ -157,6 +178,7 @@ $max_ssl = $max_num;
 $max_crypto = $max_num;
 
 my $ssl="ssl/ssl.h";
+$ssl.=" ssl/kssl.h";
 
 my $crypto ="crypto/crypto.h";
 $crypto.=" crypto/des/des.h" unless $no_des;
@@ -172,6 +194,8 @@ $crypto.=" crypto/md5/md5.h" unless $no_md5;
 $crypto.=" crypto/mdc2/mdc2.h" unless $no_mdc2;
 $crypto.=" crypto/sha/sha.h" unless $no_sha;
 $crypto.=" crypto/ripemd/ripemd.h" unless $no_ripemd;
+$crypto.=" crypto/rijndael/rijndael.h" unless $no_aes;
+$crypto.=" crypto/rijndael/rd_fst.h" unless $no_aes;
 
 $crypto.=" crypto/bn/bn.h";
 $crypto.=" crypto/rsa/rsa.h" unless $no_rsa;
@@ -179,28 +203,31 @@ $crypto.=" crypto/dsa/dsa.h" unless $no_dsa;
 $crypto.=" crypto/dh/dh.h" unless $no_dh;
 $crypto.=" crypto/hmac/hmac.h" unless $no_hmac;
 
-$crypto.=" crypto/stack/stack.h";
-$crypto.=" crypto/buffer/buffer.h";
-$crypto.=" crypto/bio/bio.h";
-$crypto.=" crypto/dso/dso.h";
-$crypto.=" crypto/lhash/lhash.h";
+$crypto.=" crypto/engine/engine.h";
+$crypto.=" crypto/stack/stack.h" unless $no_stack;
+$crypto.=" crypto/buffer/buffer.h" unless $no_buffer;
+$crypto.=" crypto/bio/bio.h" unless $no_bio;
+$crypto.=" crypto/dso/dso.h" unless $no_dso;
+$crypto.=" crypto/lhash/lhash.h" unless $no_lhash;
 $crypto.=" crypto/conf/conf.h";
 $crypto.=" crypto/txt_db/txt_db.h";
 
-$crypto.=" crypto/evp/evp.h";
+$crypto.=" crypto/evp/evp.h" unless $no_evp;
 $crypto.=" crypto/objects/objects.h";
 $crypto.=" crypto/pem/pem.h";
 #$crypto.=" crypto/meth/meth.h";
 $crypto.=" crypto/asn1/asn1.h";
+$crypto.=" crypto/asn1/asn1t.h";
 $crypto.=" crypto/asn1/asn1_mac.h";
-$crypto.=" crypto/err/err.h";
+$crypto.=" crypto/err/err.h" unless $no_err;
 $crypto.=" crypto/pkcs7/pkcs7.h";
 $crypto.=" crypto/pkcs12/pkcs12.h";
 $crypto.=" crypto/x509/x509.h";
 $crypto.=" crypto/x509/x509_vfy.h";
 $crypto.=" crypto/x509v3/x509v3.h";
 $crypto.=" crypto/rand/rand.h";
-$crypto.=" crypto/comp/comp.h";
+$crypto.=" crypto/comp/comp.h" unless $no_comp;
+$crypto.=" crypto/ocsp/ocsp.h";
 $crypto.=" crypto/tmdiff.h";
 
 my $symhacks="crypto/symhacks.h";
@@ -237,6 +264,11 @@ if($do_crypto == 1) {
        close OUT;
 } 
 
+} elsif ($do_checkexist) {
+       &check_existing(*ssl_list, @ssl_symbols)
+               if $do_ssl == 1;
+       &check_existing(*crypto_list, @crypto_symbols)
+               if $do_crypto == 1;
 } elsif ($do_ctest || $do_ctestall) {
 
        print <<"EOF";
@@ -278,6 +310,7 @@ sub do_defs
        my %algorithm;          # For anything undefined, we assume ""
        my %rename;
        my $cpp;
+       my %unknown_algorithms = ();
 
        foreach $file (split(/\s+/,$symhacksfile." ".$files))
                {
@@ -285,7 +318,8 @@ sub do_defs
                my $line = "", my $def= "";
                my %tag = (
                        (map { $_ => 0 } @known_platforms),
-                       (map { "NO_".$_ => 0 } @known_algorithms),
+                       (map { "OPENSSL_SYS_".$_ => 0 } @known_ossl_platforms),
+                       (map { "OPENSSL_NO_".$_ => 0 } @known_algorithms),
                        NOPROTO         => 0,
                        PERL5           => 0,
                        _WINDLL         => 0,
@@ -293,6 +327,9 @@ sub do_defs
                        TRUE            => 1,
                );
                my $symhacking = $file eq $symhacksfile;
+               my @current_platforms = ();
+               my @current_algorithms = ();
+
                while(<IN>) {
                        last if (/BEGIN ERROR CODES/);
                        if ($line ne '') {
@@ -301,6 +338,8 @@ sub do_defs
                        }
 
                        if (/\\$/) {
+                               chomp; # remove eol
+                               chop; # remove ending backslash
                                $line = $_;
                                next;
                        }
@@ -313,63 +352,181 @@ sub do_defs
 
                        s/\/\*.*?\*\///gs;                   # ignore comments
                        s/{[^{}]*}//gs;                      # ignore {} blocks
-                       if (/^\#\s*ifndef (.*)/) {
+                       print STDERR "DEBUG: \$_=\"$_\"\n" if $debug;
+                       if (/^\#\s*ifndef\s+(.*)/) {
+                               push(@tag,"-");
                                push(@tag,$1);
                                $tag{$1}=-1;
-                       } elsif (/^\#\s*if !defined\(([^\)]+)\)/) {
-                               push(@tag,$1);
-                               $tag{$1}=-1;
-                       } elsif (/^\#\s*ifdef (.*)/) {
-                               push(@tag,$1);
-                               $tag{$1}=1;
-                       } elsif (/^\#\s*if defined\(([^\)]+)\)/) {
+                               print STDERR "DEBUG: $file: found tag $1 = -1\n" if $debug;
+                       } elsif (/^\#\s*if\s+!defined\(([^\)]+)\)/) {
+                               push(@tag,"-");
+                               if (/^\#\s*if\s+(!defined\(([^\)]+)\)(\s+\&\&\s+!defined\(([^\)]+)\))*)$/) {
+                                       my $tmp_1 = $1;
+                                       my $tmp_;
+                                       foreach $tmp_ (split '\&\&',$tmp_1) {
+                                               $tmp_ =~ /!defined\(([^\)]+)\)/;
+                                               print STDERR "DEBUG: $file: found tag $1 = -1\n" if $debug;
+                                               push(@tag,$1);
+                                               $tag{$1}=-1;
+                                       }
+                               } else {
+                                       print STDERR "Warning: $file: complicated expression: $_" if $debug; # because it is O...
+                                       print STDERR "DEBUG: $file: found tag $1 = -1\n" if $debug;
+                                       push(@tag,$1);
+                                       $tag{$1}=-1;
+                               }
+                       } elsif (/^\#\s*ifdef\s+(.*)/) {
+                               push(@tag,"-");
                                push(@tag,$1);
                                $tag{$1}=1;
+                               print STDERR "DEBUG: $file: found tag $1 = 1\n" if $debug;
+                       } elsif (/^\#\s*if\s+defined\(([^\)]+)\)/) {
+                               push(@tag,"-");
+                               if (/^\#\s*if\s+(defined\(([^\)]+)\)(\s+\|\|\s+defined\(([^\)]+)\))*)$/) {
+                                       my $tmp_1 = $1;
+                                       my $tmp_;
+                                       foreach $tmp_ (split '\|\|',$tmp_1) {
+                                               $tmp_ =~ /defined\(([^\)]+)\)/;
+                                               print STDERR "DEBUG: $file: found tag $1 = 1\n" if $debug;
+                                               push(@tag,$1);
+                                               $tag{$1}=1;
+                                       }
+                               } else {
+                                       print STDERR "Warning: $file: complicated expression: $_\n" if $debug; # because it is O...
+                                       print STDERR "DEBUG: $file: found tag $1 = 1\n" if $debug;
+                                       push(@tag,$1);
+                                       $tag{$1}=1;
+                               }
                        } elsif (/^\#\s*error\s+(\w+) is disabled\./) {
-                               if ($tag[$#tag] eq "NO_".$1) {
-                                       $tag{$tag[$#tag]}=2;
+                               my $tag_i = $#tag;
+                               while($tag[$tag_i] ne "-") {
+                                       if ($tag[$tag_i] eq "OPENSSL_NO_".$1) {
+                                               $tag{$tag[$tag_i]}=2;
+                                               print STDERR "DEBUG: $file: chaged tag $1 = 2\n" if $debug;
+                                       }
+                                       $tag_i--;
                                }
                        } elsif (/^\#\s*endif/) {
-                               if ($tag{$tag[$#tag]}==2) {
-                                       $tag{$tag[$#tag]}=-1;
-                               } else {
-                                       $tag{$tag[$#tag]}=0;
+                               my $tag_i = $#tag;
+                               while($tag[$tag_i] ne "-") {
+                                       my $t=$tag[$tag_i];
+                                       print STDERR "DEBUG: \$t=\"$t\"\n" if $debug;
+                                       if ($tag{$t}==2) {
+                                               $tag{$t}=-1;
+                                       } else {
+                                               $tag{$t}=0;
+                                       }
+                                       print STDERR "DEBUG: $file: changed tag ",$t," = ",$tag{$t},"\n" if $debug;
+                                       pop(@tag);
+                                       if ($t =~ /^OPENSSL_NO_([A-Z0-9_]+)$/) {
+                                               $t=$1;
+                                       } else {
+                                               $t="";
+                                       }
+                                       if ($t ne ""
+                                           && !grep(/^$t$/, @known_algorithms)) {
+                                               $unknown_algorithms{$t} = 1;
+                                               #print STDERR "DEBUG: Added as unknown algorithm: $t\n" if $debug;
+                                       }
+                                       $tag_i--;
                                }
                                pop(@tag);
                        } elsif (/^\#\s*else/) {
-                               my $t=$tag[$#tag];
-                               $tag{$t}= -$tag{$t};
+                               my $tag_i = $#tag;
+                               while($tag[$tag_i] ne "-") {
+                                       my $t=$tag[$tag_i];
+                                       $tag{$t}= -$tag{$t};
+                                       print STDERR "DEBUG: $file: changed tag ",$t," = ",$tag{$t},"\n" if $debug;
+                                       $tag_i--;
+                               }
                        } elsif (/^\#\s*if\s+1/) {
+                               push(@tag,"-");
                                # Dummy tag
                                push(@tag,"TRUE");
                                $tag{"TRUE"}=1;
+                               print STDERR "DEBUG: $file: found 1\n" if $debug;
                        } elsif (/^\#\s*if\s+0/) {
+                               push(@tag,"-");
                                # Dummy tag
                                push(@tag,"TRUE");
                                $tag{"TRUE"}=-1;
+                               print STDERR "DEBUG: $file: found 0\n" if $debug;
                        } elsif (/^\#\s*define\s+(\w+)\s+(\w+)/
                                 && $symhacking) {
                                my $s = $1;
-                               my $a =
-                                   $2.":".join(",", grep(!/^$/,
-                                                         map { $tag{$_} == 1 ?
-                                                                   $_ : "" }
-                                                         @known_platforms));
-                               $rename{$s} = $a;
+                               my $a = $2;
+                               my $a1 = join(",",
+                                             grep(!/^$/,
+                                                  map { $tag{$_} == 1 ?
+                                                            $_ : "" }
+                                                  @known_platforms));
+                               my $a2 = join(",",
+                                             grep(!/^$/,
+                                                  map { $tag{"OPENSSL_SYS_".$_} == 1 ?
+                                                            $_ : "" }
+                                                  @known_ossl_platforms));
+                               if ($a1 eq "") { $a1 = $a2; }
+                               elsif ($a1 ne "" && $a2 ne "") { $a1 .= ",".$a2; }
+                               $rename{$s} = $a.":".$a1;
+                               print STDERR "DEBUG: $file: defined $s = $a\n" if $debug;
                        }
                        if (/^\#/) {
-                               my @p = grep(!/^$/,
-                                            map { $tag{$_} == 1 ? $_ :
-                                                      $tag{$_} == -1 ? "!".$_  : "" }
-                                            @known_platforms);
-                               my @a = grep(!/^$/,
-                                            map { $tag{"NO_".$_} == -1 ? $_ : "" }
-                                            @known_algorithms);
-                               $def .= "#INFO:".join(',',@p).":".join(',',@a).";";
+                               @current_platforms =
+                                   grep(!/^$/,
+                                        map { $tag{$_} == 1 ? $_ :
+                                                  $tag{$_} == -1 ? "!".$_  : "" }
+                                        @known_platforms);
+                               push @current_platforms
+                                   , grep(!/^$/,
+                                          map { $tag{"OPENSSL_SYS_".$_} == 1 ? $_ :
+                                                    $tag{"OPENSSL_SYS_".$_} == -1 ? "!".$_  : "" }
+                                          @known_ossl_platforms);
+                               @current_algorithms =
+                                   grep(!/^$/,
+                                        map { $tag{"OPENSSL_NO_".$_} == -1 ? $_ : "" }
+                                        @known_algorithms);
+                               $def .=
+                                   "#INFO:"
+                                       .join(',',@current_platforms).":"
+                                           .join(',',@current_algorithms).";";
                                next;
                        }
                        if (/^\s*DECLARE_STACK_OF\s*\(\s*(\w*)\s*\)/) {
                                next;
+                       } elsif (/^\s*DECLARE_ASN1_ENCODE_FUNCTIONS\s*\(\s*(\w*)\s*,\s*(\w*)\s*,\s*(\w*)\s*\)/) {
+                               $def .= "int d2i_$3(void);";
+                               $def .= "int i2d_$3(void);";
+                               $def .= "OPENSSL_EXTERN int $2_it;";
+                               next;
+                       } elsif (/^\s*DECLARE_ASN1_FUNCTIONS_fname\s*\(\s*(\w*)\s*,\s*(\w*)\s*,\s*(\w*)\s*\)/) {
+                               $def .= "int d2i_$3(void);";
+                               $def .= "int i2d_$3(void);";
+                               $def .= "int $3_free(void);";
+                               $def .= "int $3_new(void);";
+                               $def .= "OPENSSL_EXTERN int $2_it;";
+                       } elsif (/^\s*DECLARE_ASN1_FUNCTIONS\s*\(\s*(\w*)\s*\)/ ||
+                               /^\s*DECLARE_ASN1_FUNCTIONS_const\s*\(\s*(\w*)\s*\)/) {
+                               $def .= "int d2i_$1(void);";
+                               $def .= "int i2d_$1(void);";
+                               $def .= "int $1_free(void);";
+                               $def .= "int $1_new(void);";
+                               $def .= "OPENSSL_EXTERN int $1_it;";
+                               next;
+                       } elsif (/^\s*DECLARE_ASN1_ENCODE_FUNCTIONS_const\s*\(\s*(\w*)\s*,\s*(\w*)\s*\)/) {
+                               $def .= "int d2i_$2(void);";
+                               $def .= "int i2d_$2(void);";
+                               $def .= "OPENSSL_EXTERN int $2_it;";
+                               next;
+                       } elsif (/^\s*DECLARE_ASN1_FUNCTIONS_name\s*\(\s*(\w*)\s*,\s*(\w*)\s*\)/) {
+                               $def .= "int d2i_$2(void);";
+                               $def .= "int i2d_$2(void);";
+                               $def .= "int $2_free(void);";
+                               $def .= "int $2_new(void);";
+                               $def .= "OPENSSL_EXTERN int $2_it;";
+                               next;
+                       } elsif (/^\s*DECLARE_ASN1_ITEM\s*\(\s*(\w*)\s*,(\w*)\s*\)/) {
+                               $def .= "OPENSSL_EXTERN int $1_it;";
+                               next;
                        } elsif (/^\s*DECLARE_PKCS12_STACK_OF\s*\(\s*(\w*)\s*\)/) {
                                next;
                        } elsif (/^\s*DECLARE_ASN1_SET_OF\s*\(\s*(\w*)\s*\)/) {
@@ -377,65 +534,47 @@ sub do_defs
                        } elsif (/^DECLARE_PEM_rw\s*\(\s*(\w*)\s*,/ ||
                                 /^DECLARE_PEM_rw_cb\s*\(\s*(\w*)\s*,/ ) {
                                # Things not in Win16
-                               $syms{"PEM_read_${1}"} = 1;
-                               $platform{"PEM_read_${1}"} = "!WIN16";
-                               $syms{"PEM_write_${1}"} = 1;
-                               $platform{"PEM_write_${1}"} = "!WIN16";
+                               $def .=
+                                   "#INFO:"
+                                       .join(',',"!WIN16",@current_platforms).":"
+                                           .join(',',@current_algorithms).";";
+                               $def .= "int PEM_read_$1(void);";
+                               $def .= "int PEM_write_$1(void);";
+                               $def .=
+                                   "#INFO:"
+                                       .join(',',@current_platforms).":"
+                                           .join(',',@current_algorithms).";";
                                # Things that are everywhere
-                               $syms{"PEM_read_bio_${1}"} = 1;
-                               $syms{"PEM_write_bio_${1}"} = 1;
-                               if ($1 eq "RSAPrivateKey" ||
-                                   $1 eq "RSAPublicKey" ||
-                                   $1 eq "RSA_PUBKEY") {
-                                       $algorithm{"PEM_read_${1}"} = "RSA";
-                                       $algorithm{"PEM_write_${1}"} = "RSA";
-                                       $algorithm{"PEM_read_bio_${1}"} = "RSA";
-                                       $algorithm{"PEM_write_bio_${1}"} = "RSA";
-                               }
-                               elsif ($1 eq "DSAPrivateKey" ||
-                                      $1 eq "DSAparams" ||
-                                      $1 eq "RSA_PUBKEY") {
-                                       $algorithm{"PEM_read_${1}"} = "DSA";
-                                       $algorithm{"PEM_write_${1}"} = "DSA";
-                                       $algorithm{"PEM_read_bio_${1}"} = "DSA";
-                                       $algorithm{"PEM_write_bio_${1}"} = "DSA";
-                               }
-                               elsif ($1 eq "DHparams") {
-                                       $algorithm{"PEM_read_${1}"} = "DH";
-                                       $algorithm{"PEM_write_${1}"} = "DH";
-                                       $algorithm{"PEM_read_bio_${1}"} = "DH";
-                                       $algorithm{"PEM_write_bio_${1}"} = "DH";
-                               }
+                               $def .= "int PEM_read_bio_$1(void);";
+                               $def .= "int PEM_write_bio_$1(void);";
                        } elsif (/^DECLARE_PEM_write\s*\(\s*(\w*)\s*,/ ||
                                     /^DECLARE_PEM_write_cb\s*\(\s*(\w*)\s*,/ ) {
                                # Things not in Win16
-                               $syms{"PEM_write_${1}"} = 1;
-                               $platform{"PEM_write_${1}"} .= ",!WIN16";
+                               $def .=
+                                   "#INFO:"
+                                       .join(',',"!WIN16",@current_platforms).":"
+                                           .join(',',@current_algorithms).";";
+                               $def .= "int PEM_write_$1(void);";
+                               $def .=
+                                   "#INFO:"
+                                       .join(',',@current_platforms).":"
+                                           .join(',',@current_algorithms).";";
                                # Things that are everywhere
-                               $syms{"PEM_write_bio_${1}"} = 1;
-                               if ($1 eq "RSAPrivateKey" ||
-                                   $1 eq "RSAPublicKey" ||
-                                   $1 eq "RSA_PUBKEY") {
-                                       $algorithm{"PEM_write_${1}"} = "RSA";
-                                       $algorithm{"PEM_write_bio_${1}"} = "RSA";
-                               }
-                               elsif ($1 eq "DSAPrivateKey" ||
-                                      $1 eq "DSAparams" ||
-                                      $1 eq "RSA_PUBKEY") {
-                                       $algorithm{"PEM_write_${1}"} = "DSA";
-                                       $algorithm{"PEM_write_bio_${1}"} = "DSA";
-                               }
-                               elsif ($1 eq "DHparams") {
-                                       $algorithm{"PEM_write_${1}"} = "DH";
-                                       $algorithm{"PEM_write_bio_${1}"} = "DH";
-                               }
+                               $def .= "int PEM_write_bio_$1(void);";
                        } elsif (/^DECLARE_PEM_read\s*\(\s*(\w*)\s*,/ ||
                                     /^DECLARE_PEM_read_cb\s*\(\s*(\w*)\s*,/ ) {
                                # Things not in Win16
-                               $syms{"PEM_read_${1}"} = 1;
-                               $platform{"PEM_read_${1}"} .= ",!WIN16";
+                               $def .=
+                                   "#INFO:"
+                                       .join(',',"!WIN16",@current_platforms).":"
+                                           .join(',',@current_algorithms).";";
+                               $def .= "int PEM_read_$1(void);";
+                               $def .=
+                                   "#INFO:"
+                                       .join(',',@current_platforms).":"
+                                           .join(',',@current_algorithms).";";
                                # Things that are everywhere
-                               $syms{"PEM_read_bio_${1}"} = 1;
+                               $def .= "int PEM_read_bio_$1(void);";
                        } elsif (
                                ($tag{'TRUE'} != -1)
                                && ($tag{'CONST_STRICT'} != 1)
@@ -528,37 +667,20 @@ sub do_defs
 
        # Prune the returned symbols
 
-       $platform{"crypt"} .= ",!PERL5,!__FreeBSD__,!NeXT";
-
-        delete $syms{"SSL_add_dir_cert_subjects_to_stack"};
         delete $syms{"bn_dump1"};
-
-       $platform{"BIO_s_file_internal"} .= ",WIN16";
-       $platform{"BIO_new_file_internal"} .= ",WIN16";
-       $platform{"BIO_new_fp_internal"} .= ",WIN16";
-
-       $platform{"BIO_s_file"} .= ",!WIN16";
-       $platform{"BIO_new_file"} .= ",!WIN16";
-       $platform{"BIO_new_fp"} .= ",!WIN16";
-
        $platform{"BIO_s_log"} .= ",!WIN32,!WIN16,!macintosh";
 
-       if(exists $syms{"ERR_load_CRYPTO_strings"}) {
-               $platform{"ERR_load_CRYPTO_strings"} .= ",!VMS,!WIN16";
-               $syms{"ERR_load_CRYPTOlib_strings"} = 1;
-               $platform{"ERR_load_CRYPTOlib_strings"} .= ",VMS,WIN16";
-       }
-
        # Info we know about
 
-       $platform{"RSA_PKCS1_RSAref"} = "RSAREF";
-       $algorithm{"RSA_PKCS1_RSAref"} = "RSA";
-
        push @ret, map { $_."\\".&info_string($_,"EXIST",
                                              $platform{$_},
                                              $kind{$_},
                                              $algorithm{$_}) } keys %syms;
 
+       if (keys %unknown_algorithms) {
+               print STDERR "WARNING: mkdef.pl doesn't know the following algorithms:\n";
+               print STDERR "\t",join("\n\t",keys %unknown_algorithms),"\n";
+       }
        return(@ret);
 }
 
@@ -606,6 +728,7 @@ sub maybe_add_info {
        (my $name, *nums, my @symbols) = @_;
        my $sym;
        my $new_info = 0;
+       my %syms=();
 
        print STDERR "Updating $name info\n";
        foreach $sym (@symbols) {
@@ -616,9 +739,19 @@ sub maybe_add_info {
                        if (!defined($dummy) || $i ne $dummy) {
                                $nums{$s} = $n."\\".$i;
                                $new_info++;
-                               #print STDERR "DEBUG: maybe_add_info for $s: \"$dummy\" => \"$i\"\n";
+                               print STDERR "DEBUG: maybe_add_info for $s: \"$dummy\" => \"$i\"\n" if $debug;
                        }
                }
+               $syms{sym} = 1;
+       }
+
+       my @s=sort { &parse_number($nums{$a},"n") <=> &parse_number($nums{$b},"n") } keys %nums;
+       foreach $sym (@s) {
+               (my $n, my $i) = split /\\/, $nums{$sym};
+               if (!defined($syms{sym})) {
+                       $new_info++;
+                       print STDERR "DEBUG: maybe_add_info for $sym: -> undefined\n if $debug";
+               }
        }
        if ($new_info) {
                print STDERR "$new_info old symbols got an info update\n";
@@ -643,8 +776,8 @@ sub print_test_file
        foreach $sym (@symbols) {
                (my $s, my $i) = $sym =~ /^(.*?)\\(.*)$/;
                if ($s ne $prev) {
-                       if (!defined($nums{$sym})) {
-                               printf STDERR "Warning: $sym does not have a number assigned\n"
+                       if (!defined($nums{$s})) {
+                               print STDERR "Warning: $s does not have a number assigned\n"
                                                if(!$do_update);
                        } else {
                                $n=$nums{$s};
@@ -658,7 +791,7 @@ sub print_test_file
 sub print_def_file
 {
        (*OUT,my $name,*nums,my @symbols)=@_;
-       my $n = 1; my @e; my @r;
+       my $n = 1; my @e; my @r; my @v;
 
        if ($W32)
                { $name.="32"; }
@@ -693,11 +826,14 @@ EOF
 
        (@e)=grep(/^SSLeay\\.*?:.*?:FUNCTION/,@symbols);
        (@r)=grep(/^\w+\\.*?:.*?:FUNCTION/ && !/^SSLeay\\.*?:.*?:FUNCTION/,@symbols);
-       @symbols=((sort @e),(sort @r));
+       (@v)=grep(/^\w+\\.*?:.*?:VARIABLE/,@symbols);
+       @symbols=((sort @e),(sort @r), (sort @v));
 
 
        foreach $sym (@symbols) {
                (my $s, my $i) = $sym =~ /^(.*?)\\(.*)$/;
+               my $v = 0;
+               $v = 1 if $sym=~ /^\w+\\.*?:.*?:VARIABLE/;
                if (!defined($nums{$s})) {
                        printf STDERR "Warning: $s does not have a number assigned\n"
                                        if(!$do_update);
@@ -709,7 +845,6 @@ EOF
                        # @p_purged must contain hardware platforms only
                        my @p_purged = ();
                        foreach $ptmp (@p) {
-                               next if $ptmp =~ /^!?RSAREF$/;
                                push @p_purged, $ptmp;
                        }
                        my $negatives = !!grep(/^!/,@p);
@@ -723,11 +858,6 @@ EOF
                             || ($W16 && (!@p_purged
                                          || (!$negatives && grep(/^WIN16$/,@p))
                                          || ($negatives && !grep(/^!WIN16$/,@p)))))
-                           && (!@p
-                               || (!$negatives
-                                   && ($rsaref || !grep(/^RSAREF$/,@p)))
-                               || ($negatives
-                                   && (!$rsaref || !grep(/^!RSAREF$/,@p))))
                            && (!@a || (!$no_rc2 || !grep(/^RC2$/,@a)))
                            && (!@a || (!$no_rc4 || !grep(/^RC4$/,@a)))
                            && (!@a || (!$no_rc5 || !grep(/^RC5$/,@a)))
@@ -745,9 +875,15 @@ EOF
                            && (!@a || (!$no_dsa || !grep(/^DSA$/,@a)))
                            && (!@a || (!$no_dh || !grep(/^DH$/,@a)))
                            && (!@a || (!$no_hmac || !grep(/^HMAC$/,@a)))
+                           && (!@a || (!$no_aes || !grep(/^AES$/,@a)))
+                           && (!@a || (!$no_krb5 || !grep(/^KRB5$/,@a)))
                            && (!@a || (!$no_fp_api || !grep(/^FP_API$/,@a)))
                            ) {
-                               printf OUT "    %s%-40s@%d\n",($W32)?"":"_",$s,$n;
+                               if($v) {
+                                       printf OUT "    %s%-40s@%-8d DATA\n",($W32)?"":"_",$s,$n;
+                               } else {
+                                       printf OUT "    %s%-40s@%d\n",($W32)?"":"_",$s,$n;
+                               }
 #                      } else {
 #                              print STDERR "DEBUG: \"$sym\" (@p):",
 #                              " rsaref:", !!(!@p
@@ -846,12 +982,20 @@ sub rewrite_numbers
                $rsyms{$s} = 1;
        }
 
+       my %syms = ();
+       foreach $_ (@symbols) {
+               (my $n, my $i) = split /\\/;
+               $syms{$n} = 1;
+       }
+
        my @s=sort { &parse_number($nums{$a},"n") <=> &parse_number($nums{$b},"n") } keys %nums;
        foreach $sym (@s) {
                (my $n, my $i) = split /\\/, $nums{$sym};
+               print STDERR "DEBUG: rewrite_numbers for sym = ",$sym,": i = ",$i,", n = ",$n,", rsym{sym} = ",$rsyms{$sym},"syms{sym} = ",$syms{$sym},"\n" if $debug;
                next if defined($i) && $i =~ /^.*?:.*?:\w+\(\w+\)/;
                next if defined($rsyms{$sym});
-               $i="NOEXIST::FUNCTION:" if !defined($i) || $i eq "";
+               $i="NOEXIST::FUNCTION:"
+                       if !defined($i) || $i eq "" || !defined($syms{$sym});
                printf OUT "%s%-40s%d\t%s\n","",$sym,$n,$i;
                if (exists $r{$sym}) {
                        (my $s, $i) = split /\\/,$r{$sym};