042bfcefda947e984b90119899cd0a30f8300fe7
[oweals/openssl.git] / Configure
1 :
2 eval 'exec perl -S $0 ${1+"$@"}'
3     if $running_under_some_shell;
4 ##
5 ##  Configure -- OpenSSL source tree configuration script
6 ##
7
8 require 5.000;
9 eval 'use strict;';
10
11 print STDERR "Warning: perl module strict not found.\n" if ($@);
12
13 # see INSTALL for instructions.
14
15 my $usage="Usage: Configure [no-<cipher> ...] [enable-<cipher> ...] [-Dxxx] [-lxxx] [-Lxxx] [-fxxx] [-Kxxx] [no-hw-xxx|no-hw] [[no-]threads] [[no-]shared] [[no-]zlib|zlib-dynamic] [no-asm] [no-dso] [no-krb5] [386] [--prefix=DIR] [--openssldir=OPENSSLDIR] [--with-xxx[=vvv]] [--test-sanity] os/compiler[:flags]\n";
16
17 # Options:
18 #
19 # --openssldir  install OpenSSL in OPENSSLDIR (Default: DIR/ssl if the
20 #               --prefix option is given; /usr/local/ssl otherwise)
21 # --prefix      prefix for the OpenSSL include, lib and bin directories
22 #               (Default: the OPENSSLDIR directory)
23 #
24 # --install_prefix  Additional prefix for package builders (empty by
25 #               default).  This needn't be set in advance, you can
26 #               just as well use "make INSTALL_PREFIX=/whatever install".
27 #
28 # --with-krb5-dir  Declare where Kerberos 5 lives.  The libraries are expected
29 #               to live in the subdirectory lib/ and the header files in
30 #               include/.  A value is required.
31 # --with-krb5-lib  Declare where the Kerberos 5 libraries live.  A value is
32 #               required.
33 #               (Default: KRB5_DIR/lib)
34 # --with-krb5-include  Declare where the Kerberos 5 header files live.  A
35 #               value is required.
36 #               (Default: KRB5_DIR/include)
37 # --with-krb5-flavor  Declare what flavor of Kerberos 5 is used.  Currently
38 #               supported values are "MIT" and "Heimdal".  A value is required.
39 #
40 # --test-sanity Make a number of sanity checks on the data in this file.
41 #               This is a debugging tool for OpenSSL developers.
42 #
43 # no-hw-xxx     do not compile support for specific crypto hardware.
44 #               Generic OpenSSL-style methods relating to this support
45 #               are always compiled but return NULL if the hardware
46 #               support isn't compiled.
47 # no-hw         do not compile support for any crypto hardware.
48 # [no-]threads  [don't] try to create a library that is suitable for
49 #               multithreaded applications (default is "threads" if we
50 #               know how to do it)
51 # [no-]shared   [don't] try to create shared libraries when supported.
52 # no-asm        do not use assembler
53 # no-dso        do not compile in any native shared-library methods. This
54 #               will ensure that all methods just return NULL.
55 # no-krb5       do not compile in any KRB5 library or code.
56 # [no-]zlib     [don't] compile support for zlib compression.
57 # zlib-dynamic  Like "zlib", but the zlib library is expected to be a shared
58 #               library and will be loaded in run-time by the OpenSSL library.
59 # 386           generate 80386 code
60 # no-sse2       disables IA-32 SSE2 code, above option implies no-sse2
61 # no-<cipher>   build without specified algorithm (rsa, idea, rc5, ...)
62 # -<xxx> +<xxx> compiler options are passed through 
63 #
64 # DEBUG_SAFESTACK use type-safe stacks to enforce type-safety on stack items
65 #               provided to stack calls. Generates unique stack functions for
66 #               each possible stack type.
67 # DES_PTR       use pointer lookup vs arrays in the DES in crypto/des/des_locl.h
68 # DES_RISC1     use different DES_ENCRYPT macro that helps reduce register
69 #               dependancies but needs to more registers, good for RISC CPU's
70 # DES_RISC2     A different RISC variant.
71 # DES_UNROLL    unroll the inner DES loop, sometimes helps, somtimes hinders.
72 # DES_INT       use 'int' instead of 'long' for DES_LONG in crypto/des/des.h
73 #               This is used on the DEC Alpha where long is 8 bytes
74 #               and int is 4
75 # BN_LLONG      use the type 'long long' in crypto/bn/bn.h
76 # MD2_CHAR      use 'char' instead of 'int' for MD2_INT in crypto/md2/md2.h
77 # MD2_LONG      use 'long' instead of 'int' for MD2_INT in crypto/md2/md2.h
78 # IDEA_SHORT    use 'short' instead of 'int' for IDEA_INT in crypto/idea/idea.h
79 # IDEA_LONG     use 'long' instead of 'int' for IDEA_INT in crypto/idea/idea.h
80 # RC2_SHORT     use 'short' instead of 'int' for RC2_INT in crypto/rc2/rc2.h
81 # RC2_LONG      use 'long' instead of 'int' for RC2_INT in crypto/rc2/rc2.h
82 # RC4_CHAR      use 'char' instead of 'int' for RC4_INT in crypto/rc4/rc4.h
83 # RC4_LONG      use 'long' instead of 'int' for RC4_INT in crypto/rc4/rc4.h
84 # RC4_INDEX     define RC4_INDEX in crypto/rc4/rc4_locl.h.  This turns on
85 #               array lookups instead of pointer use.
86 # RC4_CHUNK     enables code that handles data aligned at long (natural CPU
87 #               word) boundary.
88 # RC4_CHUNK_LL  enables code that handles data aligned at long long boundary
89 #               (intended for 64-bit CPUs running 32-bit OS).
90 # BF_PTR        use 'pointer arithmatic' for Blowfish (unsafe on Alpha).
91 # BF_PTR2       intel specific version (generic version is more efficient).
92 #
93 # Following are set automatically by this script
94 #
95 # MD5_ASM       use some extra md5 assember,
96 # SHA1_ASM      use some extra sha1 assember, must define L_ENDIAN for x86
97 # RMD160_ASM    use some extra ripemd160 assember,
98 # SHA256_ASM    sha256_block is implemented in assembler
99 # SHA512_ASM    sha512_block is implemented in assembler
100 # AES_ASM       ASE_[en|de]crypt is implemented in assembler
101
102 my $x86_gcc_des="DES_PTR DES_RISC1 DES_UNROLL";
103
104 # MD2_CHAR slags pentium pros
105 my $x86_gcc_opts="RC4_INDEX MD2_INT";
106
107 # MODIFY THESE PARAMETERS IF YOU ARE GOING TO USE THE 'util/speed.sh SCRIPT
108 # Don't worry about these normally
109
110 my $tcc="cc";
111 my $tflags="-fast -Xa";
112 my $tbn_mul="";
113 my $tlib="-lnsl -lsocket";
114 #$bits1="SIXTEEN_BIT ";
115 #$bits2="THIRTY_TWO_BIT ";
116 my $bits1="THIRTY_TWO_BIT ";
117 my $bits2="SIXTY_FOUR_BIT ";
118
119 my $x86_elf_asm="x86cpuid-elf.o:bn86-elf.o co86-elf.o mo86-elf.o:dx86-elf.o yx86-elf.o:ax86-elf.o:bx86-elf.o:mx86-elf.o:sx86-elf.o s512sse2-elf.o:cx86-elf.o:rx86-elf.o:rm86-elf.o:r586-elf.o";
120 my $x86_coff_asm="x86cpuid-cof.o:bn86-cof.o co86-cof.o mo86-cof.o:dx86-cof.o yx86-cof.o:ax86-cof.o:bx86-cof.o:mx86-cof.o:sx86-cof.o s512sse2-cof.o:cx86-cof.o:rx86-cof.o:rm86-cof.o:r586-cof.o";
121 my $x86_out_asm="x86cpuid-out.o:bn86-out.o co86-out.o mo86-out.o:dx86-out.o yx86-out.o:ax86-out.o:bx86-out.o:mx86-out.o:sx86-out.o s512sse2-out.o:cx86-out.o:rx86-out.o:rm86-out.o:r586-out.o";
122
123 my $x86_64_asm="x86_64cpuid.o:x86_64-gcc.o x86_64-mont.o::aes-x86_64.o::md5-x86_64.o:sha1-x86_64.o sha256-x86_64.o sha512-x86_64.o::rc4-x86_64.o::";
124
125 my $no_asm="::::::::::";
126
127 my $ia64_asm=$no_asm;
128 my $s390x_asm=$no_asm;
129
130 # As for $BSDthreads. Idea is to maintain "collective" set of flags,
131 # which would cover all BSD flavors. -pthread applies to them all, 
132 # but is treated differently. OpenBSD expands is as -D_POSIX_THREAD
133 # -lc_r, which is sufficient. FreeBSD 4.x expands it as -lc_r,
134 # which has to be accompanied by explicit -D_THREAD_SAFE and
135 # sometimes -D_REENTRANT. FreeBSD 5.x expands it as -lc_r, which
136 # seems to be sufficient?
137 my $BSDthreads="-pthread -D_THREAD_SAFE -D_REENTRANT";
138
139 #config-string  $cc : $cflags : $unistd : $thread_cflag : $sys_id : $lflags : $bn_ops : $cpuid_obj : $bn_obj : $des_obj : $aes_obj : $bf_obj : $md5_obj : $sha1_obj : $cast_obj : $rc4_obj : $rmd160_obj : $rc5_obj : $dso_scheme : $shared_target : $shared_cflag : $shared_ldflag : $shared_extension : $ranlib : $arflags
140
141 my %table=(
142 # File 'TABLE' (created by 'make TABLE') contains the data from this list,
143 # formatted for better readability.
144
145
146 #"b",           "${tcc}:${tflags}::${tlib}:${bits1}:${tbn_mul}::",
147 #"bl-4c-2c",    "${tcc}:${tflags}::${tlib}:${bits1}BN_LLONG RC4_CHAR MD2_CHAR:${tbn_mul}::",
148 #"bl-4c-ri",    "${tcc}:${tflags}::${tlib}:${bits1}BN_LLONG RC4_CHAR RC4_INDEX:${tbn_mul}::",
149 #"b2-is-ri-dp", "${tcc}:${tflags}::${tlib}:${bits2}IDEA_SHORT RC4_INDEX DES_PTR:${tbn_mul}::",
150
151 # Our development configs
152 "purify",       "purify gcc:-g -DPURIFY -Wall::(unknown)::-lsocket -lnsl::::",
153 "debug",        "gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DOPENSSL_NO_ASM -ggdb -g2 -Wformat -Wshadow -Wmissing-prototypes -Wmissing-declarations -Werror::(unknown)::-lefence::::",
154 "debug-ben",    "gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DPEDANTIC -DDEBUG_SAFESTACK -O2 -pedantic -Wall -Wshadow -Werror -pipe::(unknown):::::bn86-elf.o co86-elf.o",
155 "debug-ben-openbsd","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DPEDANTIC -DDEBUG_SAFESTACK -DOPENSSL_OPENBSD_DEV_CRYPTO -DOPENSSL_NO_ASM -O2 -pedantic -Wall -Wshadow -Werror -pipe::(unknown)::::",
156 "debug-ben-openbsd-debug","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DPEDANTIC -DDEBUG_SAFESTACK -DOPENSSL_OPENBSD_DEV_CRYPTO -DOPENSSL_NO_ASM -g3 -O2 -pedantic -Wall -Wshadow -Werror -pipe::(unknown)::::",
157 "debug-ben-debug",      "gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DPEDANTIC -DDEBUG_SAFESTACK -g3 -O2 -pedantic -Wall -Wshadow -Werror -pipe::(unknown)::::::",
158 "debug-ben-strict",     "gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DCONST_STRICT -O2 -Wall -Wshadow -Werror -Wpointer-arith -Wcast-qual -Wwrite-strings -pipe::(unknown)::::::",
159 "debug-rse","cc:-DTERMIOS -DL_ENDIAN -pipe -O -g -ggdb3 -Wall::(unknown):::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}",
160 "debug-bodo",   "gcc:-DL_ENDIAN -DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBIO_PAIR_DEBUG -DPEDANTIC -g -march=i486 -pedantic -Wshadow -Wall::-D_REENTRANT:::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}",
161 "debug-ulf", "gcc:-DTERMIOS -DL_ENDIAN -march=i486 -Wall -DBN_DEBUG -DBN_DEBUG_RAND -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DOPENSSL_NO_ASM -g -Wformat -Wshadow -Wmissing-prototypes -Wmissing-declarations:::CYGWIN32:::${no_asm}:win32:cygwin-shared:::.dll",
162 "debug-steve",  "gcc:-DL_ENDIAN -DREF_CHECK -DCONF_DEBUG -DDEBUG_SAFESTACK -DCRYPTO_MDEBUG_ALL -DPEDANTIC -g -m32 -pedantic -Wno-long-long -Wall -Werror -Wshadow -pipe::-D_REENTRANT::-rdynamic -ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared",
163 "debug-steve-linux-pseudo64",   "gcc:-DL_ENDIAN -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DDEBUG_SAFESTACK -DCRYPTO_MDEBUG_ALL -DOPENSSL_NO_ASM -g -mcpu=i486 -Wall -Werror -Wshadow -pipe::-D_REENTRANT::-rdynamic -ldl:SIXTY_FOUR_BIT:${no_asm}:dlfcn:linux-shared",
164 "debug-levitte-linux-elf","gcc:-DLEVITTE_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_DEBUG -DBN_DEBUG_RAND -DCRYPTO_MDEBUG -DENGINE_CONF_DEBUG -DL_ENDIAN -DTERMIO -D_POSIX_SOURCE -DPEDANTIC -ggdb -g3 -mcpu=i486 -pedantic -ansi -Wall -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wno-long-long -Wundef -Wconversion -pipe::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
165 "debug-levitte-linux-noasm","gcc:-DLEVITTE_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_DEBUG -DBN_DEBUG_RAND -DCRYPTO_MDEBUG -DENGINE_CONF_DEBUG -DOPENSSL_NO_ASM -DL_ENDIAN -DTERMIO -D_POSIX_SOURCE -DPEDANTIC -ggdb -g3 -mcpu=i486 -pedantic -ansi -Wall -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wno-long-long -Wundef -Wconversion -pipe::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
166 "debug-levitte-linux-elf-extreme","gcc:-DLEVITTE_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_DEBUG -DBN_DEBUG_RAND -DCRYPTO_MDEBUG -DENGINE_CONF_DEBUG -DL_ENDIAN -DTERMIO -D_POSIX_SOURCE -DPEDANTIC -ggdb -g3 -mcpu=i486 -pedantic -ansi -Wall -W -Wundef -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wno-long-long -Wundef -Wconversion -pipe::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
167 "debug-levitte-linux-noasm-extreme","gcc:-DLEVITTE_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_DEBUG -DBN_DEBUG_RAND -DCRYPTO_MDEBUG -DENGINE_CONF_DEBUG -DOPENSSL_NO_ASM -DL_ENDIAN -DTERMIO -D_POSIX_SOURCE -DPEDANTIC -ggdb -g3 -mcpu=i486 -pedantic -ansi -Wall -W -Wundef -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wno-long-long -Wundef -Wconversion -pipe::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
168 "debug-geoff","gcc:-DBN_DEBUG -DBN_DEBUG_RAND -DBN_STRICT -DPURIFY -DOPENSSL_NO_DEPRECATED -DOPENSSL_NO_ASM -DOPENSSL_NO_INLINE_ASM -DL_ENDIAN -DTERMIO -DPEDANTIC -O1 -ggdb2 -Wall -Werror -Wundef -pedantic -Wshadow -Wpointer-arith -Wbad-function-cast -Wcast-align -Wsign-compare -Wmissing-prototypes -Wmissing-declarations -Wno-long-long::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
169 "debug-linux-pentium","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DL_ENDIAN -DTERMIO -g -mcpu=pentium -Wall::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn",
170 "debug-linux-ppro","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DL_ENDIAN -DTERMIO -g -mcpu=pentiumpro -Wall::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn",
171 "debug-linux-elf","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DL_ENDIAN -DTERMIO -g -march=i486 -Wall::-D_REENTRANT::-lefence -ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
172 "debug-linux-elf-noefence","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DL_ENDIAN -DTERMIO -g -march=i486 -Wall::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
173 "dist",         "cc:-O::(unknown)::::::",
174
175 # Basic configs that should work on any (32 and less bit) box
176 "gcc",          "gcc:-O3::(unknown):::BN_LLONG:::",
177 "cc",           "cc:-O::(unknown)::::::",
178
179 ####VOS Configurations
180 "vos-gcc","gcc:-O3 -Wall -D_POSIX_C_SOURCE=200112L -D_BSD -DB_ENDIAN::(unknown):VOS:-Wl,-map:BN_LLONG:${no_asm}:::::.so:",
181 "debug-vos-gcc","gcc:-O0 -g -Wall -D_POSIX_C_SOURCE=200112L -D_BSD -DB_ENDIAN -DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG::(unknown):VOS:-Wl,-map:BN_LLONG:${no_asm}:::::.so:",
182
183 #### Solaris x86 with GNU C setups
184 # -DOPENSSL_NO_INLINE_ASM switches off inline assembler. We have to do it
185 # here because whenever GNU C instantiates an assembler template it
186 # surrounds it with #APP #NO_APP comment pair which (at least Solaris
187 # 7_x86) /usr/ccs/bin/as fails to assemble with "Illegal mnemonic"
188 # error message.
189 "solaris-x86-gcc","gcc:-O3 -fomit-frame-pointer -march=pentium -Wall -DL_ENDIAN -DOPENSSL_NO_INLINE_ASM::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
190 # -shared -static-libgcc might appear controversial, but modules taken
191 # from static libgcc do not have relocations and linking them into our
192 # shared objects doesn't have any negative side-effects. On the contrary,
193 # doing so makes it possible to use gcc shared build with Sun C. Given
194 # that gcc generates faster code [thanks to inline assembler], I would
195 # actually recommend to consider using gcc shared build even with vendor
196 # compiler:-)
197 #                                               <appro@fy.chalmers.se>
198 "solaris64-x86_64-gcc","gcc:-m64 -O3 -Wall -DL_ENDIAN -DMD32_REG_T=int::-D_REENTRANT::-lsocket -lnsl -ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK BF_PTR2 DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:solaris-shared:-fPIC:-m64 -shared -static-libgcc:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
199  
200 #### Solaris x86 with Sun C setups
201 "solaris-x86-cc","cc:-fast -O -Xa::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_PTR DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
202 "solaris64-x86_64-cc","cc:-fast -xarch=amd64 -xstrconst -Xa -DL_ENDIAN::-D_REENTRANT::-lsocket -lnsl -ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK BF_PTR2 DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:solaris-shared:-KPIC:-xarch=amd64 -G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
203
204 #### SPARC Solaris with GNU C setups
205 "solaris-sparcv7-gcc","gcc:-O3 -fomit-frame-pointer -Wall -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
206 "solaris-sparcv8-gcc","gcc:-mv8 -O3 -fomit-frame-pointer -Wall -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
207 # -m32 should be safe to add as long as driver recognizes -mcpu=ultrasparc
208 "solaris-sparcv9-gcc","gcc:-m32 -mcpu=ultrasparc -O3 -fomit-frame-pointer -Wall -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
209 "solaris64-sparcv9-gcc","gcc:-m64 -mcpu=ultrasparc -O3 -Wall -DB_ENDIAN::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_PTR DES_RISC1 DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-fPIC:-m64 -shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
210 ####
211 "debug-solaris-sparcv8-gcc","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG_ALL -O -g -mv8 -Wall -DB_ENDIAN::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
212 "debug-solaris-sparcv9-gcc","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG_ALL -DPEDANTIC -O -g -mcpu=ultrasparc -pedantic -ansi -Wall -Wshadow -Wno-long-long -D__EXTENSIONS__ -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
213
214 #### SPARC Solaris with Sun C setups
215 # SC4.0 doesn't pass 'make test', upgrade to SC5.0 or SC4.2.
216 # SC4.2 is ok, better than gcc even on bn as long as you tell it -xarch=v8
217 # SC5.0 note: Compiler common patch 107357-01 or later is required!
218 "solaris-sparcv7-cc","cc:-xO5 -xstrconst -xdepend -Xa -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_PTR DES_RISC1 DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
219 "solaris-sparcv8-cc","cc:-xarch=v8 -xO5 -xstrconst -xdepend -Xa -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_PTR DES_RISC1 DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
220 "solaris-sparcv9-cc","cc:-xtarget=ultra -xarch=v8plus -xO5 -xstrconst -xdepend -Xa -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK_LL DES_PTR DES_RISC1 DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
221 "solaris64-sparcv9-cc","cc:-xtarget=ultra -xarch=v9 -xO5 -xstrconst -xdepend -Xa -DB_ENDIAN::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_PTR DES_RISC1 DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-xarch=v9 -G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR):/usr/ccs/bin/ar rs",
222 ####
223 "debug-solaris-sparcv8-cc","cc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG_ALL -xarch=v8 -g -O -xstrconst -Xa -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_PTR DES_RISC1 DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
224 "debug-solaris-sparcv9-cc","cc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG_ALL -xtarget=ultra -xarch=v8plus -g -O -xstrconst -Xa -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK_LL DES_PTR DES_RISC1 DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)", 
225
226 #### SunOS configs, assuming sparc for the gcc one.
227 #"sunos-cc", "cc:-O4 -DNOPROTO -DNOCONST::(unknown):SUNOS::DES_UNROLL:${no_asm}::",
228 "sunos-gcc","gcc:-O3 -mv8 -Dssize_t=int::(unknown):SUNOS::BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL DES_PTR DES_RISC1:${no_asm}::",
229
230 #### IRIX 5.x configs
231 # -mips2 flag is added by ./config when appropriate.
232 "irix-gcc","gcc:-O3 -DTERMIOS -DB_ENDIAN::(unknown):::BN_LLONG MD2_CHAR RC4_INDEX RC4_CHAR RC4_CHUNK DES_UNROLL DES_RISC2 DES_PTR BF_PTR:${no_asm}:dlfcn:irix-shared:::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
233 "irix-cc", "cc:-O2 -use_readonly_const -DTERMIOS -DB_ENDIAN::(unknown):::BN_LLONG RC4_CHAR RC4_CHUNK DES_PTR DES_RISC2 DES_UNROLL BF_PTR:${no_asm}:dlfcn:irix-shared:::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
234 #### IRIX 6.x configs
235 # Only N32 and N64 ABIs are supported. If you need O32 ABI build, invoke
236 # './Configure irix-cc -o32' manually.
237 "irix-mips3-gcc","gcc:-mabi=n32 -O3 -DTERMIOS -DB_ENDIAN -DBN_DIV3W::-D_SGI_MP_SOURCE:::MD2_CHAR RC4_INDEX RC4_CHAR RC4_CHUNK_LL DES_UNROLL DES_RISC2 DES_PTR BF_PTR SIXTY_FOUR_BIT:${no_asm}:dlfcn:irix-shared::-mabi=n32:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
238 "irix-mips3-cc", "cc:-n32 -mips3 -O2 -use_readonly_const -G0 -rdata_shared -DTERMIOS -DB_ENDIAN -DBN_DIV3W::-D_SGI_MP_SOURCE:::DES_PTR RC4_CHAR RC4_CHUNK_LL DES_RISC2 DES_UNROLL BF_PTR SIXTY_FOUR_BIT:${no_asm}:dlfcn:irix-shared::-n32:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
239 # N64 ABI builds.
240 "irix64-mips4-gcc","gcc:-mabi=64 -mips4 -O3 -DTERMIOS -DB_ENDIAN -DBN_DIV3W::-D_SGI_MP_SOURCE:::RC4_CHAR RC4_CHUNK DES_RISC2 DES_UNROLL SIXTY_FOUR_BIT_LONG:${no_asm}:dlfcn:irix-shared::-mabi=64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
241 "irix64-mips4-cc", "cc:-64 -mips4 -O2 -use_readonly_const -G0 -rdata_shared -DTERMIOS -DB_ENDIAN -DBN_DIV3W::-D_SGI_MP_SOURCE:::RC4_CHAR RC4_CHUNK DES_RISC2 DES_UNROLL SIXTY_FOUR_BIT_LONG:${no_asm}:dlfcn:irix-shared::-64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
242
243 #### Unified HP-UX ANSI C configs.
244 # Special notes:
245 # - Originally we were optimizing at +O4 level. It should be noted
246 #   that the only difference between +O3 and +O4 is global inter-
247 #   procedural analysis. As it has to be performed during the link
248 #   stage the compiler leaves behind certain pseudo-code in lib*.a
249 #   which might be release or even patch level specific. Generating
250 #   the machine code for and analyzing the *whole* program appears
251 #   to be *extremely* memory demanding while the performance gain is
252 #   actually questionable. The situation is intensified by the default
253 #   HP-UX data set size limit (infamous 'maxdsiz' tunable) of 64MB
254 #   which is way too low for +O4. In other words, doesn't +O3 make
255 #   more sense?
256 # - Keep in mind that the HP compiler by default generates code
257 #   suitable for execution on the host you're currently compiling at.
258 #   If the toolkit is ment to be used on various PA-RISC processors
259 #   consider './config +DAportable'.
260 # - +DD64 is chosen in favour of +DA2.0W because it's meant to be
261 #   compatible with *future* releases.
262 # - If you run ./Configure hpux-parisc-[g]cc manually don't forget to
263 #   pass -D_REENTRANT on HP-UX 10 and later.
264 # - -DMD32_XARRAY triggers workaround for compiler bug we ran into in
265 #   32-bit message digests. (For the moment of this writing) HP C
266 #   doesn't seem to "digest" too many local variables (they make "him"
267 #   chew forever:-). For more details look-up MD32_XARRAY comment in
268 #   crypto/sha/sha_lcl.h.
269 #                                       <appro@fy.chalmers.se>
270 #
271 # Since there is mention of this in shlib/hpux10-cc.sh
272 "hpux-parisc-cc-o4","cc:-Ae +O4 +ESlit -z -DB_ENDIAN -DBN_DIV2W -DMD32_XARRAY::-D_REENTRANT::-ldld:BN_LLONG DES_PTR DES_UNROLL DES_RISC1:${no_asm}:dl:hpux-shared:+Z:-b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
273 "hpux-parisc-gcc","gcc:-O3 -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-Wl,+s -ldld:BN_LLONG DES_PTR DES_UNROLL DES_RISC1:${no_asm}:dl:hpux-shared:-fPIC:-shared:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
274 "hpux-parisc2-gcc","gcc:-march=2.0 -O3 -DB_ENDIAN -D_REENTRANT::::-Wl,+s -ldld:SIXTY_FOUR_BIT RC4_CHAR RC4_CHUNK DES_PTR DES_UNROLL DES_RISC1:${no_asm}:dl:hpux-shared:-fPIC:-shared:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
275 "hpux64-parisc2-gcc","gcc:-O3 -DB_ENDIAN -D_REENTRANT::::-ldl:SIXTY_FOUR_BIT_LONG MD2_CHAR RC4_INDEX RC4_CHAR DES_UNROLL DES_RISC1 DES_INT:${no_asm}:dlfcn:hpux-shared:-fpic:-shared:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
276
277 # More attempts at unified 10.X and 11.X targets for HP C compiler.
278 #
279 # Chris Ruemmler <ruemmler@cup.hp.com>
280 # Kevin Steves <ks@hp.se>
281 "hpux-parisc-cc","cc:+O3 +Optrs_strongly_typed -Ae +ESlit -DB_ENDIAN -DBN_DIV2W -DMD32_XARRAY::-D_REENTRANT::-Wl,+s -ldld:MD2_CHAR RC4_INDEX RC4_CHAR DES_UNROLL DES_RISC1 DES_INT:${no_asm}:dl:hpux-shared:+Z:-b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
282 "hpux-parisc1_0-cc","cc:+DAportable +O3 +Optrs_strongly_typed -Ae +ESlit -DB_ENDIAN -DMD32_XARRAY::-D_REENTRANT::-Wl,+s -ldld:MD2_CHAR RC4_INDEX RC4_CHAR DES_UNROLL DES_RISC1 DES_INT:${no_asm}:dl:hpux-shared:+Z:-b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
283 "hpux-parisc2-cc","cc:+DA2.0 +DS2.0 +O3 +Optrs_strongly_typed -Ae +ESlit -DB_ENDIAN -DMD32_XARRAY -D_REENTRANT::::-Wl,+s -ldld:SIXTY_FOUR_BIT MD2_CHAR RC4_INDEX RC4_CHAR DES_UNROLL DES_RISC1 DES_INT:${no_asm}:dl:hpux-shared:+Z:-b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
284 "hpux64-parisc2-cc","cc:+DD64 +O3 +Optrs_strongly_typed -Ae +ESlit -DB_ENDIAN -DMD32_XARRAY -D_REENTRANT::::-ldl:SIXTY_FOUR_BIT_LONG MD2_CHAR RC4_INDEX RC4_CHAR DES_UNROLL DES_RISC1 DES_INT:${no_asm}:dlfcn:hpux-shared:+Z:+DD64 -b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
285
286 # HP/UX IA-64 targets
287 "hpux-ia64-cc","cc:-Ae +DD32 +O2 +Olit=all -z -DB_ENDIAN -D_REENTRANT::::-ldl:SIXTY_FOUR_BIT MD2_CHAR RC4_INDEX DES_UNROLL DES_RISC1 DES_INT:${ia64_asm}:dlfcn:hpux-shared:+Z:+DD32 -b:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
288 # Frank Geurts <frank.geurts@nl.abnamro.com> has patiently assisted with
289 # with debugging of the following config.
290 "hpux64-ia64-cc","cc:-Ae +DD64 +O3 +Olit=all -z -DB_ENDIAN -D_REENTRANT::::-ldl:SIXTY_FOUR_BIT_LONG MD2_CHAR RC4_INDEX DES_UNROLL DES_RISC1 DES_INT:${ia64_asm}:dlfcn:hpux-shared:+Z:+DD64 -b:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
291 # GCC builds...
292 "hpux-ia64-gcc","gcc:-O3 -DB_ENDIAN -D_REENTRANT::::-ldl:SIXTY_FOUR_BIT MD2_CHAR RC4_INDEX DES_UNROLL DES_RISC1 DES_INT:${ia64_asm}:dlfcn:hpux-shared:-fpic:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
293 "hpux64-ia64-gcc","gcc:-mlp64 -O3 -DB_ENDIAN -D_REENTRANT::::-ldl:SIXTY_FOUR_BIT_LONG MD2_CHAR RC4_INDEX DES_UNROLL DES_RISC1 DES_INT:${ia64_asm}:dlfcn:hpux-shared:-fpic:-mlp64 -shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)", 
294
295 # Legacy HPUX 9.X configs...
296 "hpux-cc",      "cc:-DB_ENDIAN -DBN_DIV2W -DMD32_XARRAY -Ae +ESlit +O2 -z::(unknown)::-Wl,+s -ldld:DES_PTR DES_UNROLL DES_RISC1:${no_asm}:dl:hpux-shared:+Z:-b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
297 "hpux-gcc",     "gcc:-DB_ENDIAN -DBN_DIV2W -O3::(unknown)::-Wl,+s -ldld:DES_PTR DES_UNROLL DES_RISC1:${no_asm}:dl:hpux-shared:-fPIC:-shared:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
298
299 #### HP MPE/iX http://jazz.external.hp.com/src/openssl/
300 "MPE/iX-gcc",   "gcc:-D_ENDIAN -DBN_DIV2W -O3 -D_POSIX_SOURCE -D_SOCKET_SOURCE -I/SYSLOG/PUB::(unknown):MPE:-L/SYSLOG/PUB -lsyslog -lsocket -lcurses:BN_LLONG DES_PTR DES_UNROLL DES_RISC1:::",
301
302 # DEC Alpha OSF/1/Tru64 targets.
303 #
304 #       "What's in a name? That which we call a rose
305 #        By any other word would smell as sweet."
306 #
307 # - William Shakespeare, "Romeo & Juliet", Act II, scene II.
308 #
309 # For gcc, the following gave a %50 speedup on a 164 over the 'DES_INT' version
310 #
311 "osf1-alpha-gcc", "gcc:-O3::(unknown):::SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_UNROLL DES_RISC1:${no_asm}:dlfcn:alpha-osf1-shared:::.so",
312 "osf1-alpha-cc",  "cc:-std1 -tune host -O4 -readonly_strings::(unknown):::SIXTY_FOUR_BIT_LONG RC4_CHUNK:${no_asm}:dlfcn:alpha-osf1-shared:::.so",
313 "tru64-alpha-cc", "cc:-std1 -tune host -fast -readonly_strings::-pthread:::SIXTY_FOUR_BIT_LONG RC4_CHUNK:${no_asm}:dlfcn:alpha-osf1-shared::-msym:.so",
314
315 ####
316 #### Variety of LINUX:-)
317 ####
318 # *-generic* is endian-neutral target, but ./config is free to
319 # throw in -D[BL]_ENDIAN, whichever appropriate...
320 "linux-generic32","gcc:-DTERMIO -O3 -fomit-frame-pointer -Wall::-D_REENTRANT::-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_INT DES_UNROLL BF_PTR:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
321 "linux-ppc",    "gcc:-DB_ENDIAN -DTERMIO -O3 -Wall::-D_REENTRANT::-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_RISC1 DES_UNROLL:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
322 #### IA-32 targets...
323 "linux-ia32-icc",       "icc:-DL_ENDIAN -DTERMIO -O2 -no_cpprt::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-KPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
324 "linux-elf",    "gcc:-DL_ENDIAN -DTERMIO -O3 -fomit-frame-pointer -Wall::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
325 "linux-aout",   "gcc:-DL_ENDIAN -DTERMIO -O3 -fomit-frame-pointer -march=i486 -Wall::(unknown):::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_out_asm}",
326 ####
327 "linux-generic64","gcc:-DTERMIO -O3 -Wall::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_UNROLL BF_PTR:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
328 "linux-ppc64",  "gcc:-m64 -DB_ENDIAN -DTERMIO -O3 -Wall::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_RISC1 DES_UNROLL:${no_asm}:dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
329 "linux-ia64",   "gcc:-DL_ENDIAN -DTERMIO -O3 -Wall::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK:${ia64_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
330 "linux-ia64-ecc","ecc:-DL_ENDIAN -DTERMIO -O2 -Wall -no_cpprt::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK:${ia64_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
331 "linux-ia64-icc","icc:-DL_ENDIAN -DTERMIO -O2 -Wall -no_cpprt::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK:${ia64_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
332 "linux-x86_64", "gcc:-m64 -DL_ENDIAN -DTERMIO -O3 -Wall -DMD32_REG_T=int::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK BF_PTR2 DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
333 "linux-s390x",  "gcc:-m64 -DB_ENDIAN -DTERMIO -O3 -Wall::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_UNROLL:${s390x_asm}:dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
334 #### SPARC Linux setups
335 # Ray Miller <ray.miller@computing-services.oxford.ac.uk> has patiently
336 # assisted with debugging of following two configs.
337 "linux-sparcv8","gcc:-mv8 -DB_ENDIAN -DTERMIO -O3 -fomit-frame-pointer -Wall -DBN_DIV2W::-D_REENTRANT::-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
338 # it's a real mess with -mcpu=ultrasparc option under Linux, but
339 # -Wa,-Av8plus should do the trick no matter what.
340 "linux-sparcv9","gcc:-m32 -mcpu=ultrasparc -DB_ENDIAN -DTERMIO -O3 -fomit-frame-pointer -Wall -Wa,-Av8plus -DBN_DIV2W::-D_REENTRANT:ULTRASPARC:-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:linux-shared:-fPIC:-m32:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
341 # GCC 3.1 is a requirement
342 "linux64-sparcv9","gcc:-m64 -mcpu=ultrasparc -DB_ENDIAN -DTERMIO -O3 -fomit-frame-pointer -Wall::-D_REENTRANT:ULTRASPARC:-ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
343 #### Alpha Linux with GNU C and Compaq C setups
344 # Special notes:
345 # - linux-alpha+bwx-gcc is ment to be used from ./config only. If you
346 #   ought to run './Configure linux-alpha+bwx-gcc' manually, do
347 #   complement the command line with -mcpu=ev56, -mcpu=ev6 or whatever
348 #   which is appropriate.
349 # - If you use ccc keep in mind that -fast implies -arch host and the
350 #   compiler is free to issue instructions which gonna make elder CPU
351 #   choke. If you wish to build "blended" toolkit, add -arch generic
352 #   *after* -fast and invoke './Configure linux-alpha-ccc' manually.
353 #
354 #                                       <appro@fy.chalmers.se>
355 #
356 "linux-alpha-gcc","gcc:-O3 -DL_ENDIAN -DTERMIO::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_RISC1 DES_UNROLL:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
357 "linux-alpha+bwx-gcc","gcc:-O3 -DL_ENDIAN -DTERMIO::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_RISC1 DES_UNROLL:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
358 "linux-alpha-ccc","ccc:-fast -readonly_strings -DL_ENDIAN -DTERMIO::-D_REENTRANT:::SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_PTR DES_RISC1 DES_UNROLL:${no_asm}",
359 "linux-alpha+bwx-ccc","ccc:-fast -readonly_strings -DL_ENDIAN -DTERMIO::-D_REENTRANT:::SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_PTR DES_RISC1 DES_UNROLL:${no_asm}",
360
361 #### *BSD [do see comment about ${BSDthreads} above!]
362 "BSD-generic32","gcc:-DTERMIOS -O3 -fomit-frame-pointer -Wall::${BSDthreads}:::BN_LLONG RC2_CHAR RC4_INDEX DES_INT DES_UNROLL:${no_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
363 "BSD-x86",      "gcc:-DL_ENDIAN -DTERMIOS -O3 -fomit-frame-pointer -Wall::${BSDthreads}:::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_out_asm}:dlfcn:bsd-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
364 "BSD-x86-elf",  "gcc:-DL_ENDIAN -DTERMIOS -O3 -fomit-frame-pointer -Wall::${BSDthreads}:::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:bsd-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
365 "debug-BSD-x86-elf",    "gcc:-DL_ENDIAN -DTERMIOS -O3 -Wall -g::${BSDthreads}:::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:bsd-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
366 "BSD-sparcv8",  "gcc:-DB_ENDIAN -DTERMIOS -O3 -mv8 -Wall::${BSDthreads}:::BN_LLONG RC2_CHAR RC4_INDEX DES_INT DES_UNROLL:${no_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
367
368 "BSD-generic64","gcc:-DTERMIOS -O3 -Wall::${BSDthreads}:::SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_UNROLL:${no_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
369 # -DMD32_REG_T=int doesn't actually belong in sparc64 target, it
370 # simply *happens* to work around a compiler bug in gcc 3.3.3,
371 # triggered by RIPEMD160 code.
372 "BSD-sparc64",  "gcc:-DB_ENDIAN -DTERMIOS -O3 -DMD32_REG_T=int -Wall::${BSDthreads}:::SIXTY_FOUR_BIT_LONG RC2_CHAR RC4_CHUNK DES_INT DES_PTR DES_RISC2 BF_PTR:${no_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
373 "BSD-ia64",     "gcc:-DL_ENDIAN -DTERMIOS -O3 -Wall::${BSDthreads}:::SIXTY_FOUR_BIT_LONG RC4_CHUNK:${ia64_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
374 "BSD-x86_64",   "gcc:-DL_ENDIAN -DTERMIOS -O3 -DMD32_REG_T=int -Wall::${BSDthreads}:::SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
375
376 "bsdi-elf-gcc",     "gcc:-DPERL5 -DL_ENDIAN -fomit-frame-pointer -O3 -march=i486 -Wall::(unknown)::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
377
378 "nextstep",     "cc:-O -Wall:<libc.h>:(unknown):::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:::",
379 "nextstep3.3",  "cc:-O3 -Wall:<libc.h>:(unknown):::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:::",
380
381 # NCR MP-RAS UNIX ver 02.03.01
382 "ncr-scde","cc:-O6 -Xa -Hoff=BEHAVED -686 -Hwide -Hiw::(unknown)::-lsocket -lnsl -lc89:${x86_gcc_des} ${x86_gcc_opts}:::",
383
384 # QNX
385 "qnx4", "cc:-DL_ENDIAN -DTERMIO::(unknown):::${x86_gcc_des} ${x86_gcc_opts}:",
386 "qnx6", "cc:-DL_ENDIAN -DTERMIOS::(unknown)::-lsocket:${x86_gcc_des} ${x86_gcc_opts}:",
387
388 #### SCO/Caldera targets.
389 #
390 # Originally we had like unixware-*, unixware-*-pentium, unixware-*-p6, etc.
391 # Now we only have blended unixware-* as it's the only one used by ./config.
392 # If you want to optimize for particular microarchitecture, bypass ./config
393 # and './Configure unixware-7 -Kpentium_pro' or whatever appropriate.
394 # Note that not all targets include assembler support. Mostly because of
395 # lack of motivation to support out-of-date platforms with out-of-date
396 # compiler drivers and assemblers. Tim Rice <tim@multitalents.net> has
397 # patiently assisted to debug most of it.
398 #
399 # UnixWare 2.0x fails destest with -O.
400 "unixware-2.0","cc:-DFILIO_H -DNO_STRINGS_H::-Kthread::-lsocket -lnsl -lresolv -lx:${x86_gcc_des} ${x86_gcc_opts}:::",
401 "unixware-2.1","cc:-O -DFILIO_H::-Kthread::-lsocket -lnsl -lresolv -lx:${x86_gcc_des} ${x86_gcc_opts}:::",
402 "unixware-7","cc:-O -DFILIO_H -Kalloca::-Kthread::-lsocket -lnsl:BN_LLONG MD2_CHAR RC4_INDEX ${x86_gcc_des}:${x86_elf_asm}:dlfcn:svr5-shared:-Kpic::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
403 "unixware-7-gcc","gcc:-DL_ENDIAN -DFILIO_H -O3 -fomit-frame-pointer -march=pentium -Wall::-D_REENTRANT::-lsocket -lnsl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:gnu-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
404 # SCO 5 - Ben Laurie <ben@algroup.co.uk> says the -O breaks the SCO cc.
405 "sco5-cc",  "cc:-belf::(unknown)::-lsocket -lnsl:${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:svr3-shared:-Kpic::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
406 "sco5-gcc",  "gcc:-O3 -fomit-frame-pointer::(unknown)::-lsocket -lnsl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:svr3-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
407
408 #### IBM's AIX.
409 "aix3-cc",  "cc:-O -DB_ENDIAN -qmaxmem=16384::(unknown):AIX::BN_LLONG RC4_CHAR:::",
410 "aix-gcc",  "gcc:-O -DB_ENDIAN::-D_THREAD_SAFE:AIX::BN_LLONG RC4_CHAR:${no_asm}:dlfcn:aix-shared:::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)::-X 32",
411 "aix64-gcc","gcc:-maix64 -O -DB_ENDIAN::-D_THREAD_SAFE:AIX::SIXTY_FOUR_BIT_LONG RC4_CHAR:${no_asm}:dlfcn:aix-shared::-maix64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)::-X64",
412 # Below targets assume AIX 5. Idea is to effectively disregard $OBJECT_MODE
413 # at build time. $OBJECT_MODE is respected at ./config stage!
414 "aix-cc",   "cc:-q32 -O -DB_ENDIAN -qmaxmem=16384 -qro -qroconst::-qthreaded:AIX::BN_LLONG RC4_CHAR:${no_asm}:dlfcn:aix-shared::-q32:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)::-X 32",
415 "aix64-cc", "cc:-q64 -O -DB_ENDIAN -qmaxmem=16384 -qro -qroconst::-qthreaded:AIX::SIXTY_FOUR_BIT_LONG RC4_CHAR:${no_asm}:dlfcn:aix-shared::-q64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)::-X 64",
416
417 #
418 # Cray T90 and similar (SDSC)
419 # It's Big-endian, but the algorithms work properly when B_ENDIAN is NOT
420 # defined.  The T90 ints and longs are 8 bytes long, and apparently the
421 # B_ENDIAN code assumes 4 byte ints.  Fortunately, the non-B_ENDIAN and
422 # non L_ENDIAN code aligns the bytes in each word correctly.
423 #
424 # The BIT_FIELD_LIMITS define is to avoid two fatal compiler errors:
425 #'Taking the address of a bit field is not allowed. '
426 #'An expression with bit field exists as the operand of "sizeof" '
427 # (written by Wayne Schroeder <schroede@SDSC.EDU>)
428 #
429 # j90 is considered the base machine type for unicos machines,
430 # so this configuration is now called "cray-j90" ...
431 "cray-j90", "cc: -DBIT_FIELD_LIMITS -DTERMIOS::(unknown):CRAY::SIXTY_FOUR_BIT_LONG DES_INT:::",
432
433 #
434 # Cray T3E (Research Center Juelich, beckman@acl.lanl.gov)
435 #
436 # The BIT_FIELD_LIMITS define was written for the C90 (it seems).  I added
437 # another use.  Basically, the problem is that the T3E uses some bit fields
438 # for some st_addr stuff, and then sizeof and address-of fails
439 # I could not use the ams/alpha.o option because the Cray assembler, 'cam'
440 # did not like it.
441 "cray-t3e", "cc: -DBIT_FIELD_LIMITS -DTERMIOS::(unknown):CRAY::SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT:::",
442
443 # DGUX, 88100.
444 "dgux-R3-gcc",  "gcc:-O3 -fomit-frame-pointer::(unknown):::RC4_INDEX DES_UNROLL:::",
445 "dgux-R4-gcc",  "gcc:-O3 -fomit-frame-pointer::(unknown)::-lnsl -lsocket:RC4_INDEX DES_UNROLL:::",
446 "dgux-R4-x86-gcc",      "gcc:-O3 -fomit-frame-pointer -DL_ENDIAN::(unknown)::-lnsl -lsocket:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}",
447
448 # Sinix/ReliantUNIX RM400
449 # NOTE: The CDS++ Compiler up to V2.0Bsomething has the IRIX_CC_BUG optimizer problem. Better use -g  */
450 "ReliantUNIX","cc:-KPIC -g -DTERMIOS -DB_ENDIAN::-Kthread:SNI:-lsocket -lnsl -lc -L/usr/ucblib -lucb:BN_LLONG DES_PTR DES_RISC2 DES_UNROLL BF_PTR:${no_asm}:dlfcn:reliantunix-shared:::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
451 "SINIX","cc:-O::(unknown):SNI:-lsocket -lnsl -lc -L/usr/ucblib -lucb:RC4_INDEX RC4_CHAR:::",
452 "SINIX-N","/usr/ucb/cc:-O2 -misaligned::(unknown)::-lucb:RC4_INDEX RC4_CHAR:::",
453
454 # SIEMENS BS2000/OSD: an EBCDIC-based mainframe
455 "BS2000-OSD","c89:-O -XLLML -XLLMK -XL -DB_ENDIAN -DTERMIOS -DCHARSET_EBCDIC::(unknown)::-lsocket -lnsl:THIRTY_TWO_BIT DES_PTR DES_UNROLL MD2_CHAR RC4_INDEX RC4_CHAR BF_PTR:::",
456
457 # OS/390 Unix an EBCDIC-based Unix system on IBM mainframe
458 # You need to compile using the c89.sh wrapper in the tools directory, because the
459 # IBM compiler does not like the -L switch after any object modules.
460 #
461 "OS390-Unix","c89.sh:-O -DB_ENDIAN -DCHARSET_EBCDIC -DNO_SYS_PARAM_H  -D_ALL_SOURCE::(unknown):::THIRTY_TWO_BIT DES_PTR DES_UNROLL MD2_CHAR RC4_INDEX RC4_CHAR BF_PTR:::",
462
463 # Win64 targets, WIN64I denotes IA-64 and WIN64A - AMD64
464 "VC-WIN64I","cl::::WIN64I::SIXTY_FOUR_BIT RC4_CHUNK_LL DES_INT EXPORT_VAR_AS_FN:${no_asm}:win32",
465 "VC-WIN64A","cl::::WIN64A::SIXTY_FOUR_BIT RC4_CHUNK_LL DES_INT EXPORT_VAR_AS_FN:${no_asm}:win32",
466
467 # Visual C targets
468 "VC-NT","cl::::WINNT::BN_LLONG RC4_INDEX EXPORT_VAR_AS_FN ${x86_gcc_opts}:${no_asm}:win32",
469 "VC-CE","cl::::WINCE::BN_LLONG RC4_INDEX EXPORT_VAR_AS_FN ${x86_gcc_opts}:${no_asm}:win32",
470 "VC-WIN32","cl::::WIN32::BN_LLONG RC4_INDEX EXPORT_VAR_AS_FN ${x86_gcc_opts}:${no_asm}:win32",
471
472 # Borland C++ 4.5
473 "BC-32","bcc32::::WIN32::BN_LLONG DES_PTR RC4_INDEX EXPORT_VAR_AS_FN:${no_asm}:win32",
474
475 # MinGW
476 "mingw", "gcc:-mno-cygwin -DL_ENDIAN -fomit-frame-pointer -O3 -march=i486 -Wall -D_WIN32_WINNT=0x333:::MINGW32:-lwsock32 -lgdi32:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts} EXPORT_VAR_AS_FN:${x86_coff_asm}:win32:cygwin-shared:-D_WINDLL -DOPENSSL_USE_APPLINK:-mno-cygwin -shared:.dll.a",
477
478 # UWIN 
479 "UWIN", "cc:-DTERMIOS -DL_ENDIAN -O -Wall:::UWIN::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${no_asm}:win32",
480
481 # Cygwin
482 "Cygwin-pre1.3", "gcc:-DTERMIOS -DL_ENDIAN -fomit-frame-pointer -O3 -m486 -Wall::(unknown):CYGWIN32::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${no_asm}:win32",
483 "Cygwin", "gcc:-DTERMIOS -DL_ENDIAN -fomit-frame-pointer -O3 -march=i486 -Wall:::CYGWIN32::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_coff_asm}:dlfcn:cygwin-shared:-D_WINDLL:-shared:.dll.a",
484 "debug-Cygwin", "gcc:-DTERMIOS -DL_ENDIAN -march=i486 -Wall -DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DOPENSSL_NO_ASM -g -Wformat -Wshadow -Wmissing-prototypes -Wmissing-declarations -Werror:::CYGWIN32:::${no_asm}:dlfcn:cygwin-shared:-D_WINDLL:-shared:.dll.a",
485
486 # NetWare from David Ward (dsward@novell.com) - requires MetroWerks NLM development tools
487 # netware-clib => legacy CLib c-runtime support
488 "netware-clib", "mwccnlm::::::BN_LLONG ${x86_gcc_opts}::",
489 # netware-libc => LibC/NKS support
490 # NetWare defaults socket bio to WinSock sockets. However, the LibC build can be
491 # configured to use BSD sockets instead.
492 "netware-libc", "mwccnlm::::::BN_LLONG ${x86_gcc_opts}::",
493 "netware-libc-bsdsock", "mwccnlm::::::BN_LLONG ${x86_gcc_opts}::",
494 "netware-libc-gcc", "i586-netware-gcc:-nostdinc -I/ndk/libc/include -I/ndk/libc/include/winsock -DL_ENDIAN -DNETWARE_LIBC -DOPENSSL_SYSNAME_NETWARE -DTERMIO -O2 -Wall:::::BN_LLONG ${x86_gcc_opts}::",
495
496 # DJGPP
497 "DJGPP", "gcc:-I/dev/env/WATT_ROOT/inc -DTERMIOS -DL_ENDIAN -fomit-frame-pointer -O2 -Wall:::MSDOS:-L/dev/env/WATT_ROOT/lib -lwatt:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_out_asm}:",
498
499 # Ultrix from Bernhard Simon <simon@zid.tuwien.ac.at>
500 "ultrix-cc","cc:-std1 -O -Olimit 2500 -DL_ENDIAN::(unknown):::::::",
501 "ultrix-gcc","gcc:-O3 -DL_ENDIAN::(unknown):::BN_LLONG::::",
502 # K&R C is no longer supported; you need gcc on old Ultrix installations
503 ##"ultrix","cc:-O2 -DNOPROTO -DNOCONST -DL_ENDIAN::(unknown):::::::",
504
505 ##### MacOS X (a.k.a. Rhapsody or Darwin) setup
506 "rhapsody-ppc-cc","cc:-O3 -DB_ENDIAN::(unknown):MACOSX_RHAPSODY::BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}::",
507 "darwin-ppc-cc","cc:-O3 -DB_ENDIAN::-D_REENTRANT:MACOSX:-Wl,-search_paths_first%:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:darwin-shared:-fPIC -fno-common:-dynamiclib:.\$(SHLIB_MAJOR).\$(SHLIB_MINOR).dylib",
508 "darwin-i386-cc","cc:-O3 -fomit-frame-pointer -fno-common::-D_REENTRANT:MACOSX:-Wl,-search_paths_first%:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:darwin-shared:-fPIC -fno-common:-dynamiclib:.\$(SHLIB_MAJOR).\$(SHLIB_MINOR).dylib",
509 "debug-darwin-ppc-cc","cc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DB_ENDIAN -g -Wall -O::-D_REENTRANT:MACOSX::BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:darwin-shared:-fPIC -fno-common:-dynamiclib:.\$(SHLIB_MAJOR).\$(SHLIB_MINOR).dylib",
510
511 ##### A/UX
512 "aux3-gcc","gcc:-O2 -DTERMIO::(unknown):AUX:-lbsd:RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:::",
513
514 ##### Sony NEWS-OS 4.x
515 "newsos4-gcc","gcc:-O -DB_ENDIAN::(unknown):NEWS4:-lmld -liberty:BN_LLONG RC4_CHAR RC4_CHUNK DES_PTR DES_RISC1 DES_UNROLL BF_PTR::::",
516
517 ##### GNU Hurd
518 "hurd-x86",  "gcc:-DL_ENDIAN -DTERMIOS -O3 -fomit-frame-pointer -march=i486 -Wall::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC",
519
520 ##### OS/2 EMX
521 "OS2-EMX", "gcc::::::::",
522
523 ##### VxWorks for various targets
524 "vxworks-ppc405","ccppc:-g -msoft-float -mlongcall -DCPU=PPC405 -I\$(WIND_BASE)/target/h:::VXWORKS:-r:::::",
525 "vxworks-ppc750","ccppc:-ansi -nostdinc -DPPC750 -D_REENTRANT -fvolatile -fno-builtin -fno-for-scope -fsigned-char -Wall -msoft-float -mlongcall -DCPU=PPC604 -I\$(WIND_BASE)/target/h \$(DEBUG_FLAG):::VXWORKS:-r:::::",
526 "vxworks-ppc750-debug","ccppc:-ansi -nostdinc -DPPC750 -D_REENTRANT -fvolatile -fno-builtin -fno-for-scope -fsigned-char -Wall -msoft-float -mlongcall -DCPU=PPC604 -I\$(WIND_BASE)/target/h -DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DPEDANTIC -DDEBUG_SAFESTACK -DDEBUG -g:::VXWORKS:-r:::::",
527 "vxworks-ppc860","ccppc:-nostdinc -msoft-float -DCPU=PPC860 -DNO_STRINGS_H -I\$(WIND_BASE)/target/h:::VXWORKS:-r:::::",
528 "vxworks-mipsle","ccmips:-B\$(WIND_BASE)/host/\$(WIND_HOST_TYPE)/lib/gcc-lib/ -DL_ENDIAN -EL -Wl,-EL -mips2 -mno-branch-likely -G 0 -fno-builtin -msoft-float -DCPU=MIPS32 -DMIPSEL -DNO_STRINGS_H -I\$(WIND_BASE)/target/h:::VXWORKS:-r::${no_asm}::::::ranlibmips:",
529
530 ##### Compaq Non-Stop Kernel (Tandem)
531 "tandem-c89","c89:-Ww -D__TANDEM -D_XOPEN_SOURCE -D_XOPEN_SOURCE_EXTENDED=1 -D_TANDEM_SOURCE -DB_ENDIAN::(unknown):::THIRTY_TWO_BIT:::",
532
533 );
534
535 my @MK1MF_Builds=qw(VC-WIN64I VC-WIN64A
536                     VC-NT VC-CE VC-WIN32
537                     BC-32 OS2-EMX netware-clib netware-libc netware-libc-bsdsock);
538
539 my $idx = 0;
540 my $idx_cc = $idx++;
541 my $idx_cflags = $idx++;
542 my $idx_unistd = $idx++;
543 my $idx_thread_cflag = $idx++;
544 my $idx_sys_id = $idx++;
545 my $idx_lflags = $idx++;
546 my $idx_bn_ops = $idx++;
547 my $idx_cpuid_obj = $idx++;
548 my $idx_bn_obj = $idx++;
549 my $idx_des_obj = $idx++;
550 my $idx_aes_obj = $idx++;
551 my $idx_bf_obj = $idx++;
552 my $idx_md5_obj = $idx++;
553 my $idx_sha1_obj = $idx++;
554 my $idx_cast_obj = $idx++;
555 my $idx_rc4_obj = $idx++;
556 my $idx_rmd160_obj = $idx++;
557 my $idx_rc5_obj = $idx++;
558 my $idx_dso_scheme = $idx++;
559 my $idx_shared_target = $idx++;
560 my $idx_shared_cflag = $idx++;
561 my $idx_shared_ldflag = $idx++;
562 my $idx_shared_extension = $idx++;
563 my $idx_ranlib = $idx++;
564 my $idx_arflags = $idx++;
565
566 my $prefix="";
567 my $openssldir="";
568 my $exe_ext="";
569 my $install_prefix="";
570 my $fipslibdir="/usr/local/ssl/fips/lib/";
571 my $nofipscanistercheck=0;
572 my $fipsdso=0;
573 my $fipscanisterinternal="n";
574 my $baseaddr="0xFB00000";
575 my $no_threads=0;
576 my $threads=0;
577 my $no_shared=0; # but "no-shared" is default
578 my $zlib=1;      # but "no-zlib" is default
579 my $no_krb5=0;   # but "no-krb5" is implied unless "--with-krb5-..." is used
580 my $no_rfc3779=1; # but "no-rfc3779" is default
581 my $no_asm=0;
582 my $no_dso=0;
583 my $no_gmp=0;
584 my @skip=();
585 my $Makefile="Makefile";
586 my $des_locl="crypto/des/des_locl.h";
587 my $des ="crypto/des/des.h";
588 my $bn  ="crypto/bn/bn.h";
589 my $md2 ="crypto/md2/md2.h";
590 my $rc4 ="crypto/rc4/rc4.h";
591 my $rc4_locl="crypto/rc4/rc4_locl.h";
592 my $idea        ="crypto/idea/idea.h";
593 my $rc2 ="crypto/rc2/rc2.h";
594 my $bf  ="crypto/bf/bf_locl.h";
595 my $bn_asm      ="bn_asm.o";
596 my $des_enc="des_enc.o fcrypt_b.o";
597 my $fips_des_enc="fips_des_enc.o";
598 my $aes_enc="aes_core.o aes_cbc.o";
599 my $bf_enc      ="bf_enc.o";
600 my $cast_enc="c_enc.o";
601 my $rc4_enc="rc4_enc.o";
602 my $rc5_enc="rc5_enc.o";
603 my $md5_obj="";
604 my $sha1_obj="";
605 my $rmd160_obj="";
606 my $processor="";
607 my $default_ranlib;
608 my $perl;
609 my $fips=0;
610
611
612 # All of the following is disabled by default (RC5 was enabled before 0.9.8):
613
614 my %disabled = ( # "what"         => "comment"
615                  "camellia"       => "default",
616                  "gmp"            => "default",
617                  "mdc2"           => "default",
618                  "rc5"            => "default",
619                  "rfc3779"        => "default",
620                  "seed"           => "default",
621                  "shared"         => "default",
622                  "tlsext"         => "default",
623                  "zlib"           => "default",
624                  "zlib-dynamic"   => "default"
625                );
626
627 # Additional "no-..." options will be collected in %disabled.
628 # To remove something from %disabled, use e.g. "enable-rc5".
629 # For symmetry, "disable-..." is a synonym for "no-...".
630
631 # This is what $depflags will look like with the above default:
632 my $default_depflags = "-DOPENSSL_NO_CAMELLIA -DOPENSSL_NO_GMP -DOPENSSL_NO_MDC2 -DOPENSSL_NO_RC5 -DOPENSSL_NO_RFC3779 -DOPENSSL_NO_SEED ";
633
634
635 my $no_sse2=0;
636
637 &usage if ($#ARGV < 0);
638
639 my $flags;
640 my $depflags;
641 my $openssl_algorithm_defines;
642 my $openssl_thread_defines;
643 my $openssl_sys_defines="";
644 my $openssl_other_defines;
645 my $libs;
646 my $libkrb5="";
647 my $target;
648 my $options;
649 my $symlink;
650 my $make_depend=0;
651 my %withargs=();
652
653 my @argvcopy=@ARGV;
654 my $argvstring="";
655 my $argv_unprocessed=1;
656
657 while($argv_unprocessed)
658         {
659         $flags="";
660         $depflags="";
661         $openssl_algorithm_defines="";
662         $openssl_thread_defines="";
663         $openssl_sys_defines="";
664         $openssl_other_defines="";
665         $libs="";
666         $target="";
667         $options="";
668         $symlink=1;
669
670         $argv_unprocessed=0;
671         $argvstring=join(' ',@argvcopy);
672
673 PROCESS_ARGS:
674         foreach (@argvcopy)
675                 {
676                 s /^-no-/no-/; # some people just can't read the instructions
677
678                 # rewrite some options in "enable-..." form
679                 s /^-?-?shared$/enable-shared/;
680                 s /^threads$/enable-threads/;
681                 s /^zlib$/enable-zlib/;
682                 s /^zlib-dynamic$/enable-zlib-dynamic/;
683
684                 if (/^no-(.+)$/ || /^disable-(.+)$/)
685                         {
686                         if ($1 eq "ssl")
687                                 {
688                                 $disabled{"ssl2"} = "option(ssl)";
689                                 $disabled{"ssl3"} = "option(ssl)";
690                                 }
691                         elsif ($1 eq "tls")
692                                 {
693                                 $disabled{"tls1"} = "option(tls)"
694                                 }
695                         else
696                                 {
697                                 $disabled{$1} = "option";
698                                 }
699                         }                       
700                 elsif (/^enable-(.+)$/)
701                         {
702                         delete $disabled{$1};
703
704                         $threads = 1 if ($1 eq "threads");
705                         }
706                 elsif (/^--test-sanity$/)
707                         {
708                         exit(&test_sanity());
709                         }
710                 elsif (/^reconfigure/ || /^reconf/)
711                         {
712                         if (open(IN,"<$Makefile"))
713                                 {
714                                 while (<IN>)
715                                         {
716                                         chomp;
717                                         if (/^CONFIGURE_ARGS=(.*)/)
718                                                 {
719                                                 $argvstring=$1;
720                                                 @argvcopy=split(' ',$argvstring);
721                                                 die "Incorrect data to reconfigure, please do a normal configuration\n"
722                                                         if (grep(/^reconf/,@argvcopy));
723                                                 print "Reconfiguring with: $argvstring\n";
724                                                 $argv_unprocessed=1;
725                                                 close(IN);
726                                                 last PROCESS_ARGS;
727                                                 }
728                                         }
729                                 close(IN);
730                                 }
731                         die "Insufficient data to reconfigure, please do a normal configuration\n";
732                         }
733                 elsif (/^386$/)
734                         { $processor=386; }
735                 elsif (/^fips$/)
736                         {
737                         $fips=1;
738                         }
739                 elsif (/^rsaref$/)
740                         {
741                         # No RSAref support any more since it's not needed.
742                         # The check for the option is there so scripts aren't
743                         # broken
744                         }
745                 elsif (/^nofipscanistercheck$/)
746                         {
747                         $fips = 1;
748                         $nofipscanistercheck = 1;
749                         }
750                 elsif (/^fipscanisterbuild$/)
751                         {
752                         $fips = 1;
753                         $nofipscanistercheck = 1;
754                         $fipslibdir="";
755                         $fipscanisterinternal="y";
756                         }
757                 elsif (/^fipsdso$/)
758                         {
759                         $fips = 1;
760                         $nofipscanistercheck = 1;
761                         $fipslibdir="";
762                         $fipscanisterinternal="y";
763                         $fipsdso = 1;
764                         }
765                 elsif (/^[-+]/)
766                         {
767                         if (/^-[lL](.*)$/)
768                                 {
769                                 $libs.=$_." ";
770                                 }
771                         elsif (/^-[^-]/ or /^\+/)
772                                 {
773                                 $flags.=$_." ";
774                                 }
775                         elsif (/^--prefix=(.*)$/)
776                                 {
777                                 $prefix=$1;
778                                 }
779                         elsif (/^--openssldir=(.*)$/)
780                                 {
781                                 $openssldir=$1;
782                                 }
783                         elsif (/^--install.prefix=(.*)$/)
784                                 {
785                                 $install_prefix=$1;
786                                 }
787                         elsif (/^--with-krb5-(dir|lib|include|flavor)=(.*)$/)
788                                 {
789                                 $withargs{"krb5-".$1}=$2;
790                                 }
791                         elsif (/^--with-zlib-lib=(.*)$/)
792                                 {
793                                 $withargs{"zlib-lib"}=$1;
794                                 }
795                         elsif (/^--with-zlib-include=(.*)$/)
796                                 {
797                                 $withargs{"zlib-include"}="-I$1";
798                                 }
799                         elsif (/^--with-fipslibdir=(.*)$/)
800                                 {
801                                 $fipslibdir="$1/";
802                                 }
803                         elsif (/^--with-baseaddr=(.*)$/)
804                                 {
805                                 $baseaddr="$1";
806                                 }
807                         else
808                                 {
809                                 print STDERR $usage;
810                                 exit(1);
811                                 }
812                         }
813                 elsif ($_ =~ /^([^:]+):(.+)$/)
814                         {
815                         eval "\$table{\$1} = \"$2\""; # allow $xxx constructs in the string
816                         $target=$1;
817                         }
818                 else
819                         {
820                         die "target already defined - $target (offending arg: $_)\n" if ($target ne "");
821                         $target=$_;
822                         }
823
824                 unless ($_ eq $target || /^no-/ || /^disable-/)
825                         {
826                         # "no-..." follows later after implied disactivations
827                         # have been derived.  (Don't take this too seroiusly,
828                         # we really only write OPTIONS to the Makefile out of
829                         # nostalgia.)
830
831                         if ($options eq "")
832                                 { $options = $_; }
833                         else
834                                 { $options .= " ".$_; }
835                         }
836                 }
837         }
838
839
840
841 if ($processor eq "386")
842         {
843         $disabled{"sse2"} = "forced";
844         }
845
846 if (!defined($withargs{"krb5-flavor"}) || $withargs{"krb5-flavor"} eq "")
847         {
848         $disabled{"krb5"} = "krb5-flavor not specified";
849         }
850
851 if (!defined($disabled{"zlib-dynamic"}))
852         {
853         # "zlib-dynamic" was specifically enabled, so enable "zlib"
854         delete $disabled{"zlib"};
855         }
856
857 if (defined($disabled{"rijndael"}))
858         {
859         $disabled{"aes"} = "forced";
860         }
861 if (defined($disabled{"des"}))
862         {
863         $disabled{"mdc2"} = "forced";
864         }
865 if (defined($disabled{"ec"}))
866         {
867         $disabled{"ecdsa"} = "forced";
868         $disabled{"ecdh"} = "forced";
869         }
870
871 # SSL 2.0 requires MD5 and RSA
872 if (defined($disabled{"md5"}) || defined($disabled{"rsa"}))
873         {
874         $disabled{"ssl2"} = "forced";
875         }
876
877 # SSL 3.0 and TLS requires MD5 and SHA and either RSA or DSA+DH
878 if (defined($disabled{"md5"}) || defined($disabled{"sha"})
879     || (defined($disabled{"rsa"})
880         && (defined($disabled{"dsa"}) || defined($disabled{"dh"}))))
881         {
882         $disabled{"ssl3"} = "forced";
883         $disabled{"tls1"} = "forced";
884         }
885
886 if (defined($disabled{"tls1"}))
887         {
888         $disabled{"tlsext"} = "forced";
889         }
890
891 if ($target eq "TABLE") {
892         foreach $target (sort keys %table) {
893                 print_table_entry($target);
894         }
895         exit 0;
896 }
897
898 if ($target eq "LIST") {
899         foreach (sort keys %table) {
900                 print;
901                 print "\n";
902         }
903         exit 0;
904 }
905
906 if ($target =~ m/^CygWin32(-.*)$/) {
907         $target = "Cygwin".$1;
908 }
909
910 print "Configuring for $target\n";
911
912 &usage if (!defined($table{$target}));
913
914 my @fields = split(/\s*:\s*/,$table{$target} . ":" x 30 , -1);
915 my $cc = $fields[$idx_cc];
916 my $cflags = $fields[$idx_cflags];
917 my $unistd = $fields[$idx_unistd];
918 my $thread_cflag = $fields[$idx_thread_cflag];
919 my $sys_id = $fields[$idx_sys_id];
920 my $lflags = $fields[$idx_lflags];
921 my $bn_ops = $fields[$idx_bn_ops];
922 my $cpuid_obj = $fields[$idx_cpuid_obj];
923 my $bn_obj = $fields[$idx_bn_obj];
924 my $des_obj = $fields[$idx_des_obj];
925 my $aes_obj = $fields[$idx_aes_obj];
926 my $bf_obj = $fields[$idx_bf_obj];
927 my $md5_obj = $fields[$idx_md5_obj];
928 my $sha1_obj = $fields[$idx_sha1_obj];
929 my $cast_obj = $fields[$idx_cast_obj];
930 my $rc4_obj = $fields[$idx_rc4_obj];
931 my $rmd160_obj = $fields[$idx_rmd160_obj];
932 my $rc5_obj = $fields[$idx_rc5_obj];
933 my $dso_scheme = $fields[$idx_dso_scheme];
934 my $shared_target = $fields[$idx_shared_target];
935 my $shared_cflag = $fields[$idx_shared_cflag];
936 my $shared_ldflag = $fields[$idx_shared_ldflag];
937 my $shared_extension = $fields[$idx_shared_extension];
938 my $ranlib = $fields[$idx_ranlib];
939 my $arflags = $fields[$idx_arflags];
940
941 if ($fips)
942         {
943         delete $disabled{"shared"} if ($disabled{"shared"} eq "default");
944         $disabled{"asm"}="forced"
945                 if ($target !~ "VC\-.*" &&
946                     "$cpuid_obj:$bn_obj:$aes_obj:$des_obj:$sha1_obj" eq "::::");
947         }
948
949
950 foreach (sort (keys %disabled))
951         {
952         $options .= " no-$_";
953
954         printf "    no-%-12s %-10s", $_, "[$disabled{$_}]";
955
956         if (/^dso$/)
957                 { $no_dso = 1; }
958         elsif (/^threads$/)
959                 { $no_threads = 1; }
960         elsif (/^shared$/)
961                 { $no_shared = 1; }
962         elsif (/^zlib$/)
963                 { $zlib = 0; }
964         elsif (/^static-engine$/)
965                 { }
966         elsif (/^zlib-dynamic$/)
967                 { }
968         elsif (/^symlinks$/)
969                 { $symlink = 0; }
970         elsif (/^sse2$/)
971                 { $no_sse2 = 1; }
972         else
973                 {
974                 my ($ALGO, $algo);
975                 ($ALGO = $algo = $_) =~ tr/[a-z]/[A-Z]/;
976
977                 if (/^asm$/ || /^err$/ || /^hw$/ || /^hw-/)
978                         {
979                         $openssl_other_defines .= "#define OPENSSL_NO_$ALGO\n";
980                         print " OPENSSL_NO_$ALGO";
981                 
982                         if (/^err$/)    { $flags .= "-DOPENSSL_NO_ERR "; }
983                         elsif (/^asm$/) { $no_asm = 1; }
984                         }
985                 else
986                         {
987                         $openssl_algorithm_defines .= "#define OPENSSL_NO_$ALGO\n";
988                         print " OPENSSL_NO_$ALGO";
989
990                         if (/^krb5$/)
991                                 { $no_krb5 = 1; }
992                         else
993                                 {
994                                 push @skip, $algo;
995                                 print " (skip dir)";
996
997                                 $depflags .="-DOPENSSL_NO_$ALGO ";
998                                 }
999                         }
1000                 }
1001
1002         print "\n";
1003         }
1004
1005
1006 my $IsMK1MF=scalar grep /^$target$/,@MK1MF_Builds;
1007
1008 $IsMK1MF=1 if ($target eq "mingw" && $^O ne "cygwin" && !is_msys());
1009
1010 $no_shared = 0 if ($fipsdso && !$IsMK1MF);
1011
1012 $exe_ext=".exe" if ($target eq "Cygwin" || $target eq "DJGPP" || $target eq "mingw");
1013 $exe_ext=".pm"  if ($target =~ /vos/);
1014 if ($openssldir eq "" and $prefix eq "")
1015         {
1016         if ($fips)
1017                 {
1018                 $openssldir="/usr/local/ssl/fips";
1019                 }
1020         else
1021                 {
1022                 $openssldir="/usr/local/ssl";
1023                 }
1024         }
1025 $prefix=$openssldir if $prefix eq "";
1026
1027 $default_ranlib= &which("ranlib") or $default_ranlib="true";
1028 $perl=$ENV{'PERL'} or $perl=&which("perl5") or $perl=&which("perl")
1029   or $perl="perl";
1030
1031 chop $openssldir if $openssldir =~ /\/$/;
1032 chop $prefix if $prefix =~ /\/$/;
1033
1034 $openssldir=$prefix . "/ssl" if $openssldir eq "";
1035 $openssldir=$prefix . "/" . $openssldir if $openssldir !~ /(^\/|^[a-zA-Z]:[\\\/])/;
1036
1037
1038 print "IsMK1MF=$IsMK1MF\n";
1039
1040 # '%' in $lflags is used to split flags to "pre-" and post-flags
1041 my ($prelflags,$postlflags)=split('%',$lflags);
1042 if (defined($postlflags))       { $lflags=$postlflags;  }
1043 else                            { $lflags=$prelflags; undef $prelflags; }
1044
1045 my $no_shared_warn=0;
1046 my $no_user_cflags=0;
1047
1048 if ($flags ne "")       { $cflags="$flags$cflags"; }
1049 else                    { $no_user_cflags=1;       }
1050
1051 # Kerberos settings.  The flavor must be provided from outside, either through
1052 # the script "config" or manually.
1053 if (!$no_krb5)
1054         {
1055         my ($lresolv, $lpath, $lext);
1056         if ($withargs{"krb5-flavor"} =~ /^[Hh]eimdal$/)
1057                 {
1058                 die "Sorry, Heimdal is currently not supported\n";
1059                 }
1060         ##### HACK to force use of Heimdal.
1061         ##### WARNING: Since we don't really have adequate support for Heimdal,
1062         #####          using this will break the build.  You'll have to make
1063         #####          changes to the source, and if you do, please send
1064         #####          patches to openssl-dev@openssl.org
1065         if ($withargs{"krb5-flavor"} =~ /^force-[Hh]eimdal$/)
1066                 {
1067                 warn "Heimdal isn't really supported.  Your build WILL break\n";
1068                 warn "If you fix the problems, please send a patch to openssl-dev\@openssl.org\n";
1069                 $withargs{"krb5-dir"} = "/usr/heimdal"
1070                         if $withargs{"krb5-dir"} eq "";
1071                 $withargs{"krb5-lib"} = "-L".$withargs{"krb5-dir"}.
1072                         "/lib -lgssapi -lkrb5 -lcom_err"
1073                         if $withargs{"krb5-lib"} eq "" && !$IsMK1MF;
1074                 $cflags="-DKRB5_HEIMDAL $cflags";
1075                 }
1076         if ($withargs{"krb5-flavor"} =~ /^[Mm][Ii][Tt]/)
1077                 {
1078                 $withargs{"krb5-dir"} = "/usr/kerberos"
1079                         if $withargs{"krb5-dir"} eq "";
1080                 $withargs{"krb5-lib"} = "-L".$withargs{"krb5-dir"}.
1081                         "/lib -lgssapi_krb5 -lkrb5 -lcom_err -lk5crypto"
1082                         if $withargs{"krb5-lib"} eq "" && !$IsMK1MF;
1083                 $cflags="-DKRB5_MIT $cflags";
1084                 $withargs{"krb5-flavor"} =~ s/^[Mm][Ii][Tt][._-]*//;
1085                 if ($withargs{"krb5-flavor"} =~ /^1[._-]*[01]/)
1086                         {
1087                         $cflags="-DKRB5_MIT_OLD11 $cflags";
1088                         }
1089                 }
1090         LRESOLV:
1091         foreach $lpath ("/lib", "/usr/lib")
1092                 {
1093                 foreach $lext ("a", "so")
1094                         {
1095                         $lresolv = "$lpath/libresolv.$lext";
1096                         last LRESOLV    if (-r "$lresolv");
1097                         $lresolv = "";
1098                         }
1099                 }
1100         $withargs{"krb5-lib"} .= " -lresolv"
1101                 if ("$lresolv" ne "");
1102         $withargs{"krb5-include"} = "-I".$withargs{"krb5-dir"}."/include"
1103                 if $withargs{"krb5-include"} eq "" &&
1104                    $withargs{"krb5-dir"} ne "";
1105         }
1106
1107 # The DSO code currently always implements all functions so that no
1108 # applications will have to worry about that from a compilation point
1109 # of view. However, the "method"s may return zero unless that platform
1110 # has support compiled in for them. Currently each method is enabled
1111 # by a define "DSO_<name>" ... we translate the "dso_scheme" config
1112 # string entry into using the following logic;
1113 my $dso_cflags;
1114 if (!$no_dso && $dso_scheme ne "")
1115         {
1116         $dso_scheme =~ tr/[a-z]/[A-Z]/;
1117         if ($dso_scheme eq "DLFCN")
1118                 {
1119                 $dso_cflags = "-DDSO_DLFCN -DHAVE_DLFCN_H";
1120                 }
1121         elsif ($dso_scheme eq "DLFCN_NO_H")
1122                 {
1123                 $dso_cflags = "-DDSO_DLFCN";
1124                 }
1125         else
1126                 {
1127                 $dso_cflags = "-DDSO_$dso_scheme";
1128                 }
1129         $cflags = "$dso_cflags $cflags";
1130         }
1131
1132 my $thread_cflags;
1133 my $thread_defines;
1134 if ($thread_cflag ne "(unknown)" && !$no_threads)
1135         {
1136         # If we know how to do it, support threads by default.
1137         $threads = 1;
1138         }
1139 if ($thread_cflag eq "(unknown)" && $threads)
1140         {
1141         # If the user asked for "threads", [s]he is also expected to
1142         # provide any system-dependent compiler options that are
1143         # necessary.
1144         if ($no_user_cflags)
1145                 {
1146                 print "You asked for multi-threading support, but didn't\n";
1147                 print "provide any system-specific compiler options\n";
1148                 exit(1);
1149                 }
1150         $thread_cflags="-DOPENSSL_THREADS $cflags" ;
1151         $thread_defines .= "#define OPENSSL_THREADS\n";
1152         }
1153 else
1154         {
1155         $thread_cflags="-DOPENSSL_THREADS $thread_cflag $cflags";
1156         $thread_defines .= "#define OPENSSL_THREADS\n";
1157 #       my $def;
1158 #       foreach $def (split ' ',$thread_cflag)
1159 #               {
1160 #               if ($def =~ s/^-D// && $def !~ /^_/)
1161 #                       {
1162 #                       $thread_defines .= "#define $def\n";
1163 #                       }
1164 #               }
1165         }       
1166
1167 $lflags="$libs$lflags" if ($libs ne "");
1168
1169 if ($no_asm)
1170         {
1171         $cpuid_obj=$bn_obj=$des_obj=$aes_obj=$bf_obj=$cast_obj=$rc4_obj=$rc5_obj="";
1172         $sha1_obj=$md5_obj=$rmd160_obj="";
1173         $cflags=~s/\-D[BL]_ENDIAN//             if ($fips);
1174         $thread_cflags=~s/\-D[BL]_ENDIAN//      if ($fips);
1175         }
1176
1177 if (!$no_shared)
1178         {
1179         $cast_obj="";   # CAST assembler is not PIC
1180         }
1181
1182 if ($threads)
1183         {
1184         $cflags=$thread_cflags;
1185         $openssl_thread_defines .= $thread_defines;
1186         }
1187
1188 if ($zlib)
1189         {
1190         $cflags = "-DZLIB $cflags";
1191         if (defined($disabled{"zlib-dynamic"}))
1192                 {
1193                 $lflags = "$lflags -lz";
1194                 }
1195         else
1196                 {
1197                 $cflags = "-DZLIB_SHARED $cflags";
1198                 }
1199         }
1200
1201 # You will find shlib_mark1 and shlib_mark2 explained in Makefile.org
1202 my $shared_mark = "";
1203 if ($shared_target eq "")
1204         {
1205         $no_shared_warn = 1 if !$no_shared && !$fips;
1206         $no_shared = 1;
1207         }
1208 if (!$no_shared)
1209         {
1210         if ($shared_cflag ne "")
1211                 {
1212                 $cflags = "$shared_cflag -DOPENSSL_PIC $cflags";
1213                 }
1214         }
1215
1216 if (!$IsMK1MF)
1217         {
1218         if ($no_shared)
1219                 {
1220                 $openssl_other_defines.="#define OPENSSL_NO_DYNAMIC_ENGINE\n";
1221                 }
1222         else
1223                 {
1224                 $openssl_other_defines.="#define OPENSSL_NO_STATIC_ENGINE\n";
1225                 }
1226         }
1227
1228 $cpuid_obj.=" uplink.o uplink-cof.o" if ($cflags =~ /\-DOPENSSL_USE_APPLINK/);
1229
1230 #
1231 # Platform fix-ups
1232 #
1233 if ($target =~ /\-icc$/)        # Intel C compiler
1234         {
1235         my $iccver=0;
1236         if (open(FD,"$cc -V 2>&1 |"))
1237                 {
1238                 while(<FD>) { $iccver=$1 if (/Version ([0-9]+)\./); }
1239                 close(FD);
1240                 }
1241
1242         if ($iccver>=8)
1243                 {
1244                 # Eliminate unnecessary dependency from libirc.a. This is
1245                 # essential for shared library support, as otherwise
1246                 # apps/openssl can end up in endless loop upon startup...
1247                 $cflags.=" -Dmemcpy=__builtin_memcpy -Dmemset=__builtin_memset";
1248                 }
1249         if ($iccver>=9)
1250                 {
1251                 $cflags.=" -i-static";
1252                 $cflags=~s/\-no_cpprt/-no-cpprt/;
1253                 }
1254         if ($iccver>=10)
1255                 {
1256                 $cflags=~s/\-i\-static/-static-intel/;
1257                 }
1258         }
1259
1260 # Unlike other OSes (like Solaris, Linux, Tru64, IRIX) BSD run-time
1261 # linkers (tested OpenBSD, NetBSD and FreeBSD) "demand" RPATH set on
1262 # .so objects. Apparently application RPATH is not global and does
1263 # not apply to .so linked with other .so. Problem manifests itself
1264 # when libssl.so fails to load libcrypto.so. One can argue that we
1265 # should engrave this into Makefile.shared rules or into BSD-* config
1266 # lines above. Meanwhile let's try to be cautious and pass -rpath to
1267 # linker only when --prefix is not /usr.
1268 if ($target =~ /^BSD\-/)
1269         {
1270         $shared_ldflag.=" -Wl,-rpath,\$(LIBRPATH)" if ($prefix !~ m|^/usr[/]*$|);
1271         }
1272
1273 if ($sys_id ne "")
1274         {
1275         #$cflags="-DOPENSSL_SYSNAME_$sys_id $cflags";
1276         $openssl_sys_defines="#define OPENSSL_SYSNAME_$sys_id\n";
1277         }
1278
1279 if ($ranlib eq "")
1280         {
1281         $ranlib = $default_ranlib;
1282         }
1283
1284 #my ($bn1)=split(/\s+/,$bn_obj);
1285 #$bn1 = "" unless defined $bn1;
1286 #$bn1=$bn_asm unless ($bn1 =~ /\.o$/);
1287 #$bn_obj="$bn1";
1288
1289 $cpuid_obj="" if ($processor eq "386");
1290
1291 $bn_obj = $bn_asm unless $bn_obj ne "";
1292 # bn86* is the only one implementing bn_*_part_words
1293 $cflags.=" -DOPENSSL_BN_ASM_PART_WORDS" if ($bn_obj =~ /bn86/);
1294 $cflags.=" -DOPENSSL_IA32_SSE2" if (!$no_sse2 && $bn_obj =~ /bn86/);
1295
1296 $cflags.=" -DOPENSSL_BN_ASM_MONT" if ($bn_obj =~ /\-mont|mo86\-/);
1297
1298 if ($fips)
1299         {
1300         $openssl_other_defines.="#define OPENSSL_FIPS\n";
1301         }
1302
1303 $des_obj=$des_enc       unless ($des_obj =~ /\.o$/);
1304 $bf_obj=$bf_enc         unless ($bf_obj =~ /\.o$/);
1305 $cast_obj=$cast_enc     unless ($cast_obj =~ /\.o$/);
1306 $rc4_obj=$rc4_enc       unless ($rc4_obj =~ /\.o$/);
1307 $rc5_obj=$rc5_enc       unless ($rc5_obj =~ /\.o$/);
1308 if ($sha1_obj =~ /\.o$/)
1309         {
1310 #       $sha1_obj=$sha1_enc;
1311         $cflags.=" -DSHA1_ASM"   if ($sha1_obj =~ /sx86/ || $sha1_obj =~ /sha1/);
1312         $cflags.=" -DSHA256_ASM" if ($sha1_obj =~ /sha256/);
1313         $cflags.=" -DSHA512_ASM" if ($sha1_obj =~ /sha512/);
1314         if ($sha1_obj =~ /sse2/)
1315             {   if ($no_sse2)
1316                 {   $sha1_obj =~ s/\S*sse2\S+//;        }
1317                 elsif ($cflags !~ /OPENSSL_IA32_SSE2/)
1318                 {   $cflags.=" -DOPENSSL_IA32_SSE2";    }
1319             }
1320         }
1321 if ($md5_obj =~ /\.o$/)
1322         {
1323 #       $md5_obj=$md5_enc;
1324         $cflags.=" -DMD5_ASM";
1325         }
1326 if ($rmd160_obj =~ /\.o$/)
1327         {
1328 #       $rmd160_obj=$rmd160_enc;
1329         $cflags.=" -DRMD160_ASM";
1330         }
1331 if ($aes_obj =~ /\.o$/)
1332         {
1333         $cflags.=" -DAES_ASM";
1334         }
1335 else    {
1336         $aes_obj=$aes_enc;
1337         }
1338
1339 # "Stringify" the C flags string.  This permits it to be made part of a string
1340 # and works as well on command lines.
1341 $cflags =~ s/([\\\"])/\\\1/g;
1342
1343 my $version = "unknown";
1344 my $version_num = "unknown";
1345 my $major = "unknown";
1346 my $minor = "unknown";
1347 my $shlib_version_number = "unknown";
1348 my $shlib_version_history = "unknown";
1349 my $shlib_major = "unknown";
1350 my $shlib_minor = "unknown";
1351
1352 open(IN,'<crypto/opensslv.h') || die "unable to read opensslv.h:$!\n";
1353 while (<IN>)
1354         {
1355         $version=$1 if /OPENSSL.VERSION.TEXT.*OpenSSL (\S+) /;
1356         $version_num=$1 if /OPENSSL.VERSION.NUMBER.*0x(\S+)/;
1357         $shlib_version_number=$1 if /SHLIB_VERSION_NUMBER *"([^"]+)"/;
1358         $shlib_version_history=$1 if /SHLIB_VERSION_HISTORY *"([^"]*)"/;
1359         }
1360 close(IN);
1361 if ($shlib_version_history ne "") { $shlib_version_history .= ":"; }
1362
1363 if ($version =~ /(^[0-9]*)\.([0-9\.]*)/)
1364         {
1365         $major=$1;
1366         $minor=$2;
1367         }
1368
1369 if ($shlib_version_number =~ /(^[0-9]*)\.([0-9\.]*)/)
1370         {
1371         $shlib_major=$1;
1372         $shlib_minor=$2;
1373         }
1374
1375 open(IN,'<Makefile.org') || die "unable to read Makefile.org:$!\n";
1376 unlink("$Makefile.new") || die "unable to remove old $Makefile.new:$!\n" if -e "$Makefile.new";
1377 open(OUT,">$Makefile.new") || die "unable to create $Makefile.new:$!\n";
1378 print OUT "### Generated automatically from Makefile.org by Configure.\n\n";
1379 my $sdirs=0;
1380 while (<IN>)
1381         {
1382         chomp;
1383         $sdirs = 1 if /^SDIRS=/;
1384         if ($sdirs) {
1385                 my $dir;
1386                 foreach $dir (@skip) {
1387                         s/([    ])$dir /\1/;
1388                         }
1389                 }
1390         $sdirs = 0 unless /\\$/;
1391         s/^VERSION=.*/VERSION=$version/;
1392         s/^MAJOR=.*/MAJOR=$major/;
1393         s/^MINOR=.*/MINOR=$minor/;
1394         s/^SHLIB_VERSION_NUMBER=.*/SHLIB_VERSION_NUMBER=$shlib_version_number/;
1395         s/^SHLIB_VERSION_HISTORY=.*/SHLIB_VERSION_HISTORY=$shlib_version_history/;
1396         s/^SHLIB_MAJOR=.*/SHLIB_MAJOR=$shlib_major/;
1397         s/^SHLIB_MINOR=.*/SHLIB_MINOR=$shlib_minor/;
1398         s/^SHLIB_EXT=.*/SHLIB_EXT=$shared_extension/;
1399         s/^INSTALLTOP=.*$/INSTALLTOP=$prefix/;
1400         s/^OPENSSLDIR=.*$/OPENSSLDIR=$openssldir/;
1401         s/^INSTALL_PREFIX=.*$/INSTALL_PREFIX=$install_prefix/;
1402         s/^PLATFORM=.*$/PLATFORM=$target/;
1403         s/^OPTIONS=.*$/OPTIONS=$options/;
1404         s/^CONFIGURE_ARGS=.*$/CONFIGURE_ARGS=$argvstring/;
1405         s/^CC=.*$/CC= $cc/;
1406         s/^MAKEDEPPROG=.*$/MAKEDEPPROG= $cc/ if $cc eq "gcc";
1407         s/^CFLAG=.*$/CFLAG= $cflags/;
1408         s/^DEPFLAG=.*$/DEPFLAG= $depflags/;
1409         s/^PEX_LIBS=.*$/PEX_LIBS= $prelflags/;
1410         s/^EX_LIBS=.*$/EX_LIBS= $lflags/;
1411         s/^EXE_EXT=.*$/EXE_EXT= $exe_ext/;
1412         s/^CPUID_OBJ=.*$/CPUID_OBJ= $cpuid_obj/;
1413         s/^BN_ASM=.*$/BN_ASM= $bn_obj/;
1414         s/^DES_ENC=.*$/DES_ENC= $des_obj/;
1415         s/^AES_ASM_OBJ=.*$/AES_ASM_OBJ= $aes_obj/;
1416         s/^BF_ENC=.*$/BF_ENC= $bf_obj/;
1417         s/^CAST_ENC=.*$/CAST_ENC= $cast_obj/;
1418         s/^RC4_ENC=.*$/RC4_ENC= $rc4_obj/;
1419         s/^RC5_ENC=.*$/RC5_ENC= $rc5_obj/;
1420         s/^MD5_ASM_OBJ=.*$/MD5_ASM_OBJ= $md5_obj/;
1421         s/^SHA1_ASM_OBJ=.*$/SHA1_ASM_OBJ= $sha1_obj/;
1422         s/^RMD160_ASM_OBJ=.*$/RMD160_ASM_OBJ= $rmd160_obj/;
1423         s/^PROCESSOR=.*/PROCESSOR= $processor/;
1424         s/^RANLIB=.*/RANLIB= $ranlib/;
1425         s/^ARFLAGS=.*/ARFLAGS= $arflags/;
1426         s/^PERL=.*/PERL= $perl/;
1427         s/^KRB5_INCLUDES=.*/KRB5_INCLUDES=$withargs{"krb5-include"}/;
1428         s/^LIBKRB5=.*/LIBKRB5=$withargs{"krb5-lib"}/;
1429         s/^LIBZLIB=.*/LIBZLIB=$withargs{"zlib-lib"}/;
1430         s/^ZLIB_INCLUDE=.*/ZLIB_INCLUDE=$withargs{"zlib-include"}/;
1431         s/^FIPSLIBDIR=.*/FIPSLIBDIR=$fipslibdir/;
1432         if ($fipsdso)
1433                 {
1434                 s/^FIPSCANLIB=.*/FIPSCANLIB=libfips/;
1435                 s/^SHARED_FIPS=.*/SHARED_FIPS=libfips\$(SHLIB_EXT)/;
1436                 s/^SHLIBDIRS=.*/SHLIBDIRS= crypto ssl fips/;
1437                 }
1438         else
1439                 {
1440                 s/^FIPSCANLIB=.*/FIPSCANLIB=libcrypto/ if $fips;
1441                 s/^SHARED_FIPS=.*/SHARED_FIPS=/;
1442                 s/^SHLIBDIRS=.*/SHLIBDIRS= crypto ssl/;
1443                 }
1444         s/^FIPSCANISTERINTERNAL=.*/FIPSCANISTERINTERNAL=$fipscanisterinternal/;
1445         s/^BASEADDR=.*/BASEADDR=$baseaddr/;
1446         s/^SHLIB_TARGET=.*/SHLIB_TARGET=$shared_target/;
1447         s/^SHLIB_MARK=.*/SHLIB_MARK=$shared_mark/;
1448         s/^SHARED_LIBS=.*/SHARED_LIBS=\$(SHARED_FIPS) \$(SHARED_CRYPTO) \$(SHARED_SSL)/ if (!$no_shared);
1449         if ($shared_extension ne "" && $shared_extension =~ /^\.s([ol])\.[^\.]*$/)
1450                 {
1451                 my $sotmp = $1;
1452                 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.s$sotmp/;
1453                 }
1454         elsif ($shared_extension ne "" && $shared_extension =~ /^\.[^\.]*\.dylib$/)
1455                 {
1456                 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.dylib/;
1457                 }
1458         elsif ($shared_extension ne "" && $shared_extension =~ /^\.s([ol])\.[^\.]*\.[^\.]*$/)
1459                 {
1460                 my $sotmp = $1;
1461                 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.s$sotmp.\$(SHLIB_MAJOR) .s$sotmp/;
1462                 }
1463         elsif ($shared_extension ne "" && $shared_extension =~ /^\.[^\.]*\.[^\.]*\.dylib$/)
1464                 {
1465                 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.\$(SHLIB_MAJOR).dylib .dylib/;
1466                 }
1467         s/^SHARED_LDFLAGS=.*/SHARED_LDFLAGS=$shared_ldflag/;
1468         print OUT $_."\n";
1469         }
1470 close(IN);
1471 close(OUT);
1472 rename($Makefile,"$Makefile.bak") || die "unable to rename $Makefile\n" if -e $Makefile;
1473 rename("$Makefile.new",$Makefile) || die "unable to rename $Makefile.new\n";
1474
1475 print "CC            =$cc\n";
1476 print "CFLAG         =$cflags\n";
1477 print "EX_LIBS       =$lflags\n";
1478 print "CPUID_OBJ     =$cpuid_obj\n";
1479 print "BN_ASM        =$bn_obj\n";
1480 print "DES_ENC       =$des_obj\n";
1481 print "AES_ASM_OBJ   =$aes_obj\n";
1482 print "BF_ENC        =$bf_obj\n";
1483 print "CAST_ENC      =$cast_obj\n";
1484 print "RC4_ENC       =$rc4_obj\n";
1485 print "RC5_ENC       =$rc5_obj\n";
1486 print "MD5_OBJ_ASM   =$md5_obj\n";
1487 print "SHA1_OBJ_ASM  =$sha1_obj\n";
1488 print "RMD160_OBJ_ASM=$rmd160_obj\n";
1489 print "PROCESSOR     =$processor\n";
1490 print "RANLIB        =$ranlib\n";
1491 print "ARFLAGS       =$arflags\n";
1492 print "PERL          =$perl\n";
1493 print "KRB5_INCLUDES =",$withargs{"krb5-include"},"\n"
1494         if $withargs{"krb5-include"} ne "";
1495
1496 my $des_ptr=0;
1497 my $des_risc1=0;
1498 my $des_risc2=0;
1499 my $des_unroll=0;
1500 my $bn_ll=0;
1501 my $def_int=2;
1502 my $rc4_int=$def_int;
1503 my $md2_int=$def_int;
1504 my $idea_int=$def_int;
1505 my $rc2_int=$def_int;
1506 my $rc4_idx=0;
1507 my $rc4_chunk=0;
1508 my $bf_ptr=0;
1509 my @type=("char","short","int","long");
1510 my ($b64l,$b64,$b32,$b16,$b8)=(0,0,1,0,0);
1511 my $export_var_as_fn=0;
1512
1513 my $des_int;
1514
1515 foreach (sort split(/\s+/,$bn_ops))
1516         {
1517         $des_ptr=1 if /DES_PTR/;
1518         $des_risc1=1 if /DES_RISC1/;
1519         $des_risc2=1 if /DES_RISC2/;
1520         $des_unroll=1 if /DES_UNROLL/;
1521         $des_int=1 if /DES_INT/;
1522         $bn_ll=1 if /BN_LLONG/;
1523         $rc4_int=0 if /RC4_CHAR/;
1524         $rc4_int=3 if /RC4_LONG/;
1525         $rc4_idx=1 if /RC4_INDEX/;
1526         $rc4_chunk=1 if /RC4_CHUNK/;
1527         $rc4_chunk=2 if /RC4_CHUNK_LL/;
1528         $md2_int=0 if /MD2_CHAR/;
1529         $md2_int=3 if /MD2_LONG/;
1530         $idea_int=1 if /IDEA_SHORT/;
1531         $idea_int=3 if /IDEA_LONG/;
1532         $rc2_int=1 if /RC2_SHORT/;
1533         $rc2_int=3 if /RC2_LONG/;
1534         $bf_ptr=1 if $_ eq "BF_PTR";
1535         $bf_ptr=2 if $_ eq "BF_PTR2";
1536         ($b64l,$b64,$b32,$b16,$b8)=(0,1,0,0,0) if /SIXTY_FOUR_BIT/;
1537         ($b64l,$b64,$b32,$b16,$b8)=(1,0,0,0,0) if /SIXTY_FOUR_BIT_LONG/;
1538         ($b64l,$b64,$b32,$b16,$b8)=(0,0,1,0,0) if /THIRTY_TWO_BIT/;
1539         ($b64l,$b64,$b32,$b16,$b8)=(0,0,0,1,0) if /SIXTEEN_BIT/;
1540         ($b64l,$b64,$b32,$b16,$b8)=(0,0,0,0,1) if /EIGHT_BIT/;
1541         $export_var_as_fn=1 if /EXPORT_VAR_AS_FN/;
1542         }
1543
1544 open(IN,'<crypto/opensslconf.h.in') || die "unable to read crypto/opensslconf.h.in:$!\n";
1545 unlink("crypto/opensslconf.h.new") || die "unable to remove old crypto/opensslconf.h.new:$!\n" if -e "crypto/opensslconf.h.new";
1546 open(OUT,'>crypto/opensslconf.h.new') || die "unable to create crypto/opensslconf.h.new:$!\n";
1547 print OUT "/* opensslconf.h */\n";
1548 print OUT "/* WARNING: Generated automatically from opensslconf.h.in by Configure. */\n\n";
1549
1550 print OUT "/* OpenSSL was configured with the following options: */\n";
1551 my $openssl_algorithm_defines_trans = $openssl_algorithm_defines;
1552 $openssl_algorithm_defines_trans =~ s/^\s*#\s*define\s+OPENSSL_(.*)/# if defined(OPENSSL_$1) \&\& !defined($1)\n#  define $1\n# endif/mg;
1553 $openssl_algorithm_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
1554 $openssl_algorithm_defines = "   /* no ciphers excluded */\n" if $openssl_algorithm_defines eq "";
1555 $openssl_thread_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
1556 $openssl_sys_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
1557 $openssl_other_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
1558 print OUT $openssl_sys_defines;
1559 print OUT "#ifndef OPENSSL_DOING_MAKEDEPEND\n\n";
1560 print OUT $openssl_algorithm_defines;
1561 print OUT "\n#endif /* OPENSSL_DOING_MAKEDEPEND */\n";
1562 print OUT $openssl_thread_defines;
1563 print OUT $openssl_other_defines,"\n";
1564
1565 print OUT "/* The OPENSSL_NO_* macros are also defined as NO_* if the application\n";
1566 print OUT "   asks for it.  This is a transient feature that is provided for those\n";
1567 print OUT "   who haven't had the time to do the appropriate changes in their\n";
1568 print OUT "   applications.  */\n";
1569 print OUT "#ifdef OPENSSL_ALGORITHM_DEFINES\n";
1570 print OUT $openssl_algorithm_defines_trans;
1571 print OUT "#endif\n\n";
1572
1573 print OUT "#define OPENSSL_CPUID_OBJ\n\n" if ($cpuid_obj);
1574
1575 while (<IN>)
1576         {
1577         if      (/^#define\s+OPENSSLDIR/)
1578                 { print OUT "#define OPENSSLDIR \"$openssldir\"\n"; }
1579         elsif   (/^#define\s+ENGINESDIR/)
1580                 { print OUT "#define ENGINESDIR \"$prefix/lib/engines\"\n"; }
1581         elsif   (/^#((define)|(undef))\s+OPENSSL_EXPORT_VAR_AS_FUNCTION/)
1582                 { printf OUT "#undef OPENSSL_EXPORT_VAR_AS_FUNCTION\n"
1583                         if $export_var_as_fn;
1584                   printf OUT "#%s OPENSSL_EXPORT_VAR_AS_FUNCTION\n",
1585                         ($export_var_as_fn)?"define":"undef"; }
1586         elsif   (/^#define\s+OPENSSL_UNISTD/)
1587                 {
1588                 $unistd = "<unistd.h>" if $unistd eq "";
1589                 print OUT "#define OPENSSL_UNISTD $unistd\n";
1590                 }
1591         elsif   (/^#((define)|(undef))\s+SIXTY_FOUR_BIT_LONG/)
1592                 { printf OUT "#%s SIXTY_FOUR_BIT_LONG\n",($b64l)?"define":"undef"; }
1593         elsif   (/^#((define)|(undef))\s+SIXTY_FOUR_BIT/)
1594                 { printf OUT "#%s SIXTY_FOUR_BIT\n",($b64)?"define":"undef"; }
1595         elsif   (/^#((define)|(undef))\s+THIRTY_TWO_BIT/)
1596                 { printf OUT "#%s THIRTY_TWO_BIT\n",($b32)?"define":"undef"; }
1597         elsif   (/^#((define)|(undef))\s+SIXTEEN_BIT/)
1598                 { printf OUT "#%s SIXTEEN_BIT\n",($b16)?"define":"undef"; }
1599         elsif   (/^#((define)|(undef))\s+EIGHT_BIT/)
1600                 { printf OUT "#%s EIGHT_BIT\n",($b8)?"define":"undef"; }
1601         elsif   (/^#((define)|(undef))\s+BN_LLONG\s*$/)
1602                 { printf OUT "#%s BN_LLONG\n",($bn_ll)?"define":"undef"; }
1603         elsif   (/^\#define\s+DES_LONG\s+.*/)
1604                 { printf OUT "#define DES_LONG unsigned %s\n",
1605                         ($des_int)?'int':'long'; }
1606         elsif   (/^\#(define|undef)\s+DES_PTR/)
1607                 { printf OUT "#%s DES_PTR\n",($des_ptr)?'define':'undef'; }
1608         elsif   (/^\#(define|undef)\s+DES_RISC1/)
1609                 { printf OUT "#%s DES_RISC1\n",($des_risc1)?'define':'undef'; }
1610         elsif   (/^\#(define|undef)\s+DES_RISC2/)
1611                 { printf OUT "#%s DES_RISC2\n",($des_risc2)?'define':'undef'; }
1612         elsif   (/^\#(define|undef)\s+DES_UNROLL/)
1613                 { printf OUT "#%s DES_UNROLL\n",($des_unroll)?'define':'undef'; }
1614         elsif   (/^#define\s+RC4_INT\s/)
1615                 { printf OUT "#define RC4_INT unsigned %s\n",$type[$rc4_int]; }
1616         elsif   (/^#undef\s+RC4_CHUNK/)
1617                 {
1618                 printf OUT "#undef RC4_CHUNK\n" if $rc4_chunk==0;
1619                 printf OUT "#define RC4_CHUNK unsigned long\n" if $rc4_chunk==1;
1620                 printf OUT "#define RC4_CHUNK unsigned long long\n" if $rc4_chunk==2;
1621                 }
1622         elsif   (/^#((define)|(undef))\s+RC4_INDEX/)
1623                 { printf OUT "#%s RC4_INDEX\n",($rc4_idx)?"define":"undef"; }
1624         elsif (/^#(define|undef)\s+I386_ONLY/)
1625                 { printf OUT "#%s I386_ONLY\n", ($processor eq "386")?
1626                         "define":"undef"; }
1627         elsif   (/^#define\s+MD2_INT\s/)
1628                 { printf OUT "#define MD2_INT unsigned %s\n",$type[$md2_int]; }
1629         elsif   (/^#define\s+IDEA_INT\s/)
1630                 {printf OUT "#define IDEA_INT unsigned %s\n",$type[$idea_int];}
1631         elsif   (/^#define\s+RC2_INT\s/)
1632                 {printf OUT "#define RC2_INT unsigned %s\n",$type[$rc2_int];}
1633         elsif (/^#(define|undef)\s+BF_PTR/)
1634                 {
1635                 printf OUT "#undef BF_PTR\n" if $bf_ptr == 0;
1636                 printf OUT "#define BF_PTR\n" if $bf_ptr == 1;
1637                 printf OUT "#define BF_PTR2\n" if $bf_ptr == 2;
1638                 }
1639         else
1640                 { print OUT $_; }
1641         }
1642 close(IN);
1643 close(OUT);
1644 rename("crypto/opensslconf.h","crypto/opensslconf.h.bak") || die "unable to rename crypto/opensslconf.h\n" if -e "crypto/opensslconf.h";
1645 rename("crypto/opensslconf.h.new","crypto/opensslconf.h") || die "unable to rename crypto/opensslconf.h.new\n";
1646
1647
1648 # Fix the date
1649
1650 print "SIXTY_FOUR_BIT_LONG mode\n" if $b64l;
1651 print "SIXTY_FOUR_BIT mode\n" if $b64;
1652 print "THIRTY_TWO_BIT mode\n" if $b32;
1653 print "SIXTEEN_BIT mode\n" if $b16;
1654 print "EIGHT_BIT mode\n" if $b8;
1655 print "DES_PTR used\n" if $des_ptr;
1656 print "DES_RISC1 used\n" if $des_risc1;
1657 print "DES_RISC2 used\n" if $des_risc2;
1658 print "DES_UNROLL used\n" if $des_unroll;
1659 print "DES_INT used\n" if $des_int;
1660 print "BN_LLONG mode\n" if $bn_ll;
1661 print "RC4 uses u$type[$rc4_int]\n" if $rc4_int != $def_int;
1662 print "RC4_INDEX mode\n" if $rc4_idx;
1663 print "RC4_CHUNK is undefined\n" if $rc4_chunk==0;
1664 print "RC4_CHUNK is unsigned long\n" if $rc4_chunk==1;
1665 print "RC4_CHUNK is unsigned long long\n" if $rc4_chunk==2;
1666 print "MD2 uses u$type[$md2_int]\n" if $md2_int != $def_int;
1667 print "IDEA uses u$type[$idea_int]\n" if $idea_int != $def_int;
1668 print "RC2 uses u$type[$rc2_int]\n" if $rc2_int != $def_int;
1669 print "BF_PTR used\n" if $bf_ptr == 1; 
1670 print "BF_PTR2 used\n" if $bf_ptr == 2; 
1671
1672 if($IsMK1MF) {
1673         open (OUT,">crypto/buildinf.h") || die "Can't open buildinf.h";
1674         printf OUT <<EOF;
1675 #ifndef MK1MF_BUILD
1676   /* auto-generated by Configure for crypto/cversion.c:
1677    * for Unix builds, crypto/Makefile.ssl generates functional definitions;
1678    * Windows builds (and other mk1mf builds) compile cversion.c with
1679    * -DMK1MF_BUILD and use definitions added to this file by util/mk1mf.pl. */
1680   #error "Windows builds (PLATFORM=$target) use mk1mf.pl-created Makefiles"
1681 #endif
1682 EOF
1683         close(OUT);
1684 } else {
1685         my $make_command = "make PERL=\'$perl\'";
1686         my $make_targets = "";
1687         $make_targets .= " links" if $symlink;
1688         $make_targets .= " depend" if $depflags ne $default_depflags && $make_depend;
1689         $make_targets .= " gentests" if $symlink;
1690         (system $make_command.$make_targets) == 0 or exit $?
1691                 if $make_targets ne "";
1692         if ( $perl =~ m@^/@) {
1693             &dofile("tools/c_rehash",$perl,'^#!/', '#!%s','^my \$dir;$', 'my $dir = "' . $openssldir . '";');
1694             &dofile("apps/CA.pl",$perl,'^#!/', '#!%s');
1695         } else {
1696             # No path for Perl known ...
1697             &dofile("tools/c_rehash",'/usr/local/bin/perl','^#!/', '#!%s','^my \$dir;$', 'my $dir = "' . $openssldir . '";');
1698             &dofile("apps/CA.pl",'/usr/local/bin/perl','^#!/', '#!%s');
1699         }
1700         if ($depflags ne $default_depflags && !$make_depend) {
1701                 print <<EOF;
1702
1703 Since you've disabled or enabled at least one algorithm, you need to do
1704 the following before building:
1705
1706         make depend
1707 EOF
1708         }
1709 }
1710
1711 # create the ms/version32.rc file if needed
1712 if ($IsMK1MF) {
1713         my ($v1, $v2, $v3, $v4);
1714         if ($version_num =~ /(^[0-9a-f]{1})([0-9a-f]{2})([0-9a-f]{2})([0-9a-f]{2})/i) {
1715                 $v1=hex $1;
1716                 $v2=hex $2;
1717                 $v3=hex $3;
1718                 $v4=hex $4;
1719         }
1720         open (OUT,">ms/version32.rc") || die "Can't open ms/version32.rc";
1721         print OUT <<EOF;
1722 #include <winver.h>
1723
1724 LANGUAGE 0x09,0x01
1725
1726 1 VERSIONINFO
1727   FILEVERSION $v1,$v2,$v3,$v4
1728   PRODUCTVERSION $v1,$v2,$v3,$v4
1729   FILEFLAGSMASK 0x3fL
1730 #ifdef _DEBUG
1731   FILEFLAGS 0x01L
1732 #else
1733   FILEFLAGS 0x00L
1734 #endif
1735   FILEOS VOS__WINDOWS32
1736   FILETYPE VFT_DLL
1737   FILESUBTYPE 0x0L
1738 BEGIN
1739     BLOCK "StringFileInfo"
1740     BEGIN
1741         BLOCK "040904b0"
1742         BEGIN
1743 #if defined(FIPS)
1744             VALUE "Comments", "WARNING: TEST VERSION ONLY ***NOT*** FIPS 140-2 VALIDATED.\\0"
1745 #endif
1746             // Required:            
1747             VALUE "CompanyName", "The OpenSSL Project, http://www.openssl.org/\\0"
1748 #if defined(FIPS)
1749             VALUE "FileDescription", "TEST UNVALIDATED FIPS140-2 DLL\\0"
1750 #else
1751             VALUE "FileDescription", "OpenSSL Shared Library\\0"
1752 #endif
1753             VALUE "FileVersion", "$version\\0"
1754 #if defined(CRYPTO)
1755             VALUE "InternalName", "libeay32\\0"
1756             VALUE "OriginalFilename", "libeay32.dll\\0"
1757 #elif defined(SSL)
1758             VALUE "InternalName", "ssleay32\\0"
1759             VALUE "OriginalFilename", "ssleay32.dll\\0"
1760 #elif defined(FIPS)
1761             VALUE "InternalName", "libosslfips\\0"
1762             VALUE "OriginalFilename", "libosslfips.dll\\0"
1763 #endif
1764             VALUE "ProductName", "The OpenSSL Toolkit\\0"
1765             VALUE "ProductVersion", "$version\\0"
1766             // Optional:
1767             //VALUE "Comments", "\\0"
1768             VALUE "LegalCopyright", "Copyright © 1998-2007 The OpenSSL Project. Copyright © 1995-1998 Eric A. Young, Tim J. Hudson. All rights reserved.\\0"
1769             //VALUE "LegalTrademarks", "\\0"
1770             //VALUE "PrivateBuild", "\\0"
1771             //VALUE "SpecialBuild", "\\0"
1772         END
1773     END
1774     BLOCK "VarFileInfo"
1775     BEGIN
1776         VALUE "Translation", 0x409, 0x4b0
1777     END
1778 END
1779 EOF
1780         close(OUT);
1781   }
1782   
1783 print <<EOF;
1784
1785 Configured for $target.
1786 EOF
1787
1788 print <<\EOF if (!$no_threads && !$threads);
1789
1790 The library could not be configured for supporting multi-threaded
1791 applications as the compiler options required on this system are not known.
1792 See file INSTALL for details if you need multi-threading.
1793 EOF
1794
1795 print <<\EOF if ($no_shared_warn);
1796
1797 You gave the option 'shared'.  Normally, that would give you shared libraries.
1798 Unfortunately, the OpenSSL configuration doesn't include shared library support
1799 for this platform yet, so it will pretend you gave the option 'no-shared'.  If
1800 you can inform the developpers (openssl-dev\@openssl.org) how to support shared
1801 libraries on this platform, they will at least look at it and try their best
1802 (but please first make sure you have tried with a current version of OpenSSL).
1803 EOF
1804
1805 print <<\EOF if ($fipscanisterinternal eq "y");
1806
1807 WARNING: OpenSSL has been configured using unsupported option(s) to internally
1808 generate a fipscanister.o object module for TESTING PURPOSES ONLY; that
1809 compiled module is NOT FIPS 140-2 validated and CANNOT be used to replace the
1810 OpenSSL FIPS Object Module as identified by the CMVP
1811 (http://csrc.nist.gov/cryptval/) in any application requiring the use of FIPS
1812 140-2 validated software. 
1813
1814 This is an OpenSSL 0.9.8-fips test version.
1815
1816 See the file README.FIPS for details of how to build a test library.
1817
1818 EOF
1819
1820 exit(0);
1821
1822 sub usage
1823         {
1824         print STDERR $usage;
1825         print STDERR "\npick os/compiler from:\n";
1826         my $j=0;
1827         my $i;
1828         my $k=0;
1829         foreach $i (sort keys %table)
1830                 {
1831                 next if $i =~ /^debug/;
1832                 $k += length($i) + 1;
1833                 if ($k > 78)
1834                         {
1835                         print STDERR "\n";
1836                         $k=length($i);
1837                         }
1838                 print STDERR $i . " ";
1839                 }
1840         foreach $i (sort keys %table)
1841                 {
1842                 next if $i !~ /^debug/;
1843                 $k += length($i) + 1;
1844                 if ($k > 78)
1845                         {
1846                         print STDERR "\n";
1847                         $k=length($i);
1848                         }
1849                 print STDERR $i . " ";
1850                 }
1851         print STDERR "\n\nNOTE: If in doubt, on Unix-ish systems use './config'.\n";
1852         exit(1);
1853         }
1854
1855 sub which
1856         {
1857         my($name)=@_;
1858         my $path;
1859         foreach $path (split /:/, $ENV{PATH})
1860                 {
1861                 if (-f "$path/$name$exe_ext" and -x _)
1862                         {
1863                         return "$path/$name$exe_ext" unless ($name eq "perl" and
1864                          system("$path/$name$exe_ext -e " . '\'exit($]<5.0);\''));
1865                         }
1866                 }
1867         }
1868
1869 sub dofile
1870         {
1871         my $f; my $p; my %m; my @a; my $k; my $ff;
1872         ($f,$p,%m)=@_;
1873
1874         open(IN,"<$f.in") || open(IN,"<$f") || die "unable to open $f:$!\n";
1875         @a=<IN>;
1876         close(IN);
1877         foreach $k (keys %m)
1878                 {
1879                 grep(/$k/ && ($_=sprintf($m{$k}."\n",$p)),@a);
1880                 }
1881         open(OUT,">$f.new") || die "unable to open $f.new:$!\n";
1882         print OUT @a;
1883         close(OUT);
1884         rename($f,"$f.bak") || die "unable to rename $f\n" if -e $f;
1885         rename("$f.new",$f) || die "unable to rename $f.new\n";
1886         }
1887
1888 sub print_table_entry
1889         {
1890         my $target = shift;
1891
1892         (my $cc,my $cflags,my $unistd,my $thread_cflag,my $sys_id,my $lflags,
1893         my $bn_ops,my $cpuid_obj,my $bn_obj,my $des_obj,my $aes_obj, my $bf_obj,
1894         my $md5_obj,my $sha1_obj,my $cast_obj,my $rc4_obj,my $rmd160_obj,
1895         my $rc5_obj,my $dso_scheme,my $shared_target,my $shared_cflag,
1896         my $shared_ldflag,my $shared_extension,my $ranlib,my $arflags)=
1897         split(/\s*:\s*/,$table{$target} . ":" x 30 , -1);
1898                         
1899         print <<EOF
1900
1901 *** $target
1902 \$cc           = $cc
1903 \$cflags       = $cflags
1904 \$unistd       = $unistd
1905 \$thread_cflag = $thread_cflag
1906 \$sys_id       = $sys_id
1907 \$lflags       = $lflags
1908 \$bn_ops       = $bn_ops
1909 \$cpuid_obj    = $cpuid_obj
1910 \$bn_obj       = $bn_obj
1911 \$des_obj      = $des_obj
1912 \$aes_obj      = $aes_obj
1913 \$bf_obj       = $bf_obj
1914 \$md5_obj      = $md5_obj
1915 \$sha1_obj     = $sha1_obj
1916 \$cast_obj     = $cast_obj
1917 \$rc4_obj      = $rc4_obj
1918 \$rmd160_obj   = $rmd160_obj
1919 \$rc5_obj      = $rc5_obj
1920 \$dso_scheme   = $dso_scheme
1921 \$shared_target= $shared_target
1922 \$shared_cflag = $shared_cflag
1923 \$shared_ldflag = $shared_ldflag
1924 \$shared_extension = $shared_extension
1925 \$ranlib       = $ranlib
1926 \$arflags      = $arflags
1927 EOF
1928         }
1929
1930 sub test_sanity
1931         {
1932         my $errorcnt = 0;
1933
1934         print STDERR "=" x 70, "\n";
1935         print STDERR "=== SANITY TESTING!\n";
1936         print STDERR "=== No configuration will be done, all other arguments will be ignored!\n";
1937         print STDERR "=" x 70, "\n";
1938
1939         foreach $target (sort keys %table)
1940                 {
1941                 @fields = split(/\s*:\s*/,$table{$target} . ":" x 30 , -1);
1942
1943                 if ($fields[$idx_dso_scheme-1] =~ /^(dl|dlfcn|win32|vms)$/)
1944                         {
1945                         $errorcnt++;
1946                         print STDERR "SANITY ERROR: '$target' has the dso_scheme [$idx_dso_scheme] values\n";
1947                         print STDERR "              in the previous field\n";
1948                         }
1949                 elsif ($fields[$idx_dso_scheme+1] =~ /^(dl|dlfcn|win32|vms)$/)
1950                         {
1951                         $errorcnt++;
1952                         print STDERR "SANITY ERROR: '$target' has the dso_scheme [$idx_dso_scheme] values\n";
1953                         print STDERR "              in the following field\n";
1954                         }
1955                 elsif ($fields[$idx_dso_scheme] !~ /^(dl|dlfcn|win32|vms|)$/)
1956                         {
1957                         $errorcnt++;
1958                         print STDERR "SANITY ERROR: '$target' has the dso_scheme [$idx_dso_scheme] field = ",$fields[$idx_dso_scheme],"\n";
1959                         print STDERR "              valid values are 'dl', 'dlfcn', 'win32' and 'vms'\n";
1960                         }
1961                 }
1962         print STDERR "No sanity errors detected!\n" if $errorcnt == 0;
1963         return $errorcnt;
1964         }
1965
1966 # Attempt to detect MSYS environment
1967
1968 sub is_msys
1969         {
1970         return 1 if (exists $ENV{"TERM"} && $ENV{"TERM"} eq "msys");
1971         return 0;
1972         }