2 eval 'exec perl -S $0 ${1+"$@"}'
3 if $running_under_some_shell;
5 ## Configure -- OpenSSL source tree configuration script
6 ## If editing this file, run this command before committing
7 ## make -f Makefile.org TABLE
13 use File::Spec::Functions;
15 # see INSTALL for instructions.
17 my $usage="Usage: Configure [no-<cipher> ...] [enable-<cipher> ...] [experimental-<cipher> ...] [-Dxxx] [-lxxx] [-Lxxx] [-fxxx] [-Kxxx] [no-hw-xxx|no-hw] [[no-]threads] [[no-]shared] [[no-]zlib|zlib-dynamic] [no-asm] [no-dso] [no-krb5] [sctp] [386] [--prefix=DIR] [--openssldir=OPENSSLDIR] [--with-xxx[=vvv]] [--test-sanity] [--config=FILE] os/compiler[:flags]\n";
21 # --config add the given configuration file, which will be read after
22 # any "Configurations*" files that are found in the same
23 # directory as this script.
24 # --openssldir install OpenSSL in OPENSSLDIR (Default: DIR/ssl if the
25 # --prefix option is given; /usr/local/ssl otherwise)
26 # --prefix prefix for the OpenSSL include, lib and bin directories
27 # (Default: the OPENSSLDIR directory)
29 # --install_prefix Additional prefix for package builders (empty by
30 # default). This needn't be set in advance, you can
31 # just as well use "make INSTALL_PREFIX=/whatever install".
33 # --with-krb5-dir Declare where Kerberos 5 lives. The libraries are expected
34 # to live in the subdirectory lib/ and the header files in
35 # include/. A value is required.
36 # --with-krb5-lib Declare where the Kerberos 5 libraries live. A value is
38 # (Default: KRB5_DIR/lib)
39 # --with-krb5-include Declare where the Kerberos 5 header files live. A
41 # (Default: KRB5_DIR/include)
42 # --with-krb5-flavor Declare what flavor of Kerberos 5 is used. Currently
43 # supported values are "MIT" and "Heimdal". A value is required.
45 # --test-sanity Make a number of sanity checks on the data in this file.
46 # This is a debugging tool for OpenSSL developers.
48 # --cross-compile-prefix Add specified prefix to binutils components.
50 # no-hw-xxx do not compile support for specific crypto hardware.
51 # Generic OpenSSL-style methods relating to this support
52 # are always compiled but return NULL if the hardware
53 # support isn't compiled.
54 # no-hw do not compile support for any crypto hardware.
55 # [no-]threads [don't] try to create a library that is suitable for
56 # multithreaded applications (default is "threads" if we
58 # [no-]shared [don't] try to create shared libraries when supported.
59 # no-asm do not use assembler
60 # no-dso do not compile in any native shared-library methods. This
61 # will ensure that all methods just return NULL.
62 # no-krb5 do not compile in any KRB5 library or code.
63 # [no-]zlib [don't] compile support for zlib compression.
64 # zlib-dynamic Like "zlib", but the zlib library is expected to be a shared
65 # library and will be loaded in run-time by the OpenSSL library.
66 # sctp include SCTP support
67 # 386 generate 80386 code
68 # no-sse2 disables IA-32 SSE2 code, above option implies no-sse2
69 # no-<cipher> build without specified algorithm (rsa, idea, rc5, ...)
70 # -<xxx> +<xxx> compiler options are passed through
72 # DEBUG_SAFESTACK use type-safe stacks to enforce type-safety on stack items
73 # provided to stack calls. Generates unique stack functions for
74 # each possible stack type.
75 # DES_PTR use pointer lookup vs arrays in the DES in crypto/des/des_locl.h
76 # DES_RISC1 use different DES_ENCRYPT macro that helps reduce register
77 # dependancies but needs to more registers, good for RISC CPU's
78 # DES_RISC2 A different RISC variant.
79 # DES_UNROLL unroll the inner DES loop, sometimes helps, somtimes hinders.
80 # DES_INT use 'int' instead of 'long' for DES_LONG in crypto/des/des.h
81 # This is used on the DEC Alpha where long is 8 bytes
83 # BN_LLONG use the type 'long long' in crypto/bn/bn.h
84 # MD2_CHAR use 'char' instead of 'int' for MD2_INT in crypto/md2/md2.h
85 # MD2_LONG use 'long' instead of 'int' for MD2_INT in crypto/md2/md2.h
86 # IDEA_SHORT use 'short' instead of 'int' for IDEA_INT in crypto/idea/idea.h
87 # IDEA_LONG use 'long' instead of 'int' for IDEA_INT in crypto/idea/idea.h
88 # RC2_SHORT use 'short' instead of 'int' for RC2_INT in crypto/rc2/rc2.h
89 # RC2_LONG use 'long' instead of 'int' for RC2_INT in crypto/rc2/rc2.h
90 # RC4_CHAR use 'char' instead of 'int' for RC4_INT in crypto/rc4/rc4.h
91 # RC4_LONG use 'long' instead of 'int' for RC4_INT in crypto/rc4/rc4.h
92 # RC4_INDEX define RC4_INDEX in crypto/rc4/rc4_locl.h. This turns on
93 # array lookups instead of pointer use.
94 # RC4_CHUNK enables code that handles data aligned at long (natural CPU
96 # RC4_CHUNK_LL enables code that handles data aligned at long long boundary
97 # (intended for 64-bit CPUs running 32-bit OS).
98 # BF_PTR use 'pointer arithmatic' for Blowfish (unsafe on Alpha).
99 # BF_PTR2 intel specific version (generic version is more efficient).
101 # Following are set automatically by this script
103 # MD5_ASM use some extra md5 assember,
104 # SHA1_ASM use some extra sha1 assember, must define L_ENDIAN for x86
105 # RMD160_ASM use some extra ripemd160 assember,
106 # SHA256_ASM sha256_block is implemented in assembler
107 # SHA512_ASM sha512_block is implemented in assembler
108 # AES_ASM ASE_[en|de]crypt is implemented in assembler
110 # Minimum warning options... any contributions to OpenSSL should at least get
113 my $gcc_devteam_warn = "-Wall -pedantic -DPEDANTIC -Wno-long-long -Wsign-compare -Wmissing-prototypes -Wshadow -Wformat -Werror -DCRYPTO_MDEBUG_ALL -DCRYPTO_MDEBUG_ABORT -DREF_CHECK";
115 my $clang_disabled_warnings = "-Wno-language-extension-token -Wno-extended-offsetof -Wno-padded -Wno-shorten-64-to-32 -Wno-format-nonliteral -Wno-missing-noreturn -Wno-unused-parameter -Wno-sign-conversion -Wno-unreachable-code -Wno-conversion -Wno-documentation -Wno-missing-variable-declarations -Wno-cast-align -Wno-incompatible-pointer-types-discards-qualifiers -Wno-missing-variable-declarations -Wno-missing-field-initializers -Wno-unused-macros -Wno-disabled-macro-expansion -Wno-conditional-uninitialized -Wno-switch-enum";
117 my $strict_warnings = 0;
119 my $x86_gcc_des="DES_PTR DES_RISC1 DES_UNROLL";
121 # MD2_CHAR slags pentium pros
122 my $x86_gcc_opts="RC4_INDEX MD2_INT";
124 # MODIFY THESE PARAMETERS IF YOU ARE GOING TO USE THE 'util/speed.sh SCRIPT
125 # Don't worry about these normally
128 my $tflags="-fast -Xa";
130 my $tlib="-lnsl -lsocket";
131 #$bits1="SIXTEEN_BIT ";
132 #$bits2="THIRTY_TWO_BIT ";
133 my $bits1="THIRTY_TWO_BIT ";
134 my $bits2="SIXTY_FOUR_BIT ";
136 my $x86_asm="x86cpuid.o:bn-586.o co-586.o x86-mont.o x86-gf2m.o:ecp_nistz256.o ecp_nistz256-x86.o:des-586.o crypt586.o:aes-586.o vpaes-x86.o aesni-x86.o:bf-586.o:md5-586.o:sha1-586.o sha256-586.o sha512-586.o:cast-586.o:rc4-586.o:rmd-586.o:rc5-586.o:wp_block.o wp-mmx.o:cmll-x86.o:ghash-x86.o:e_padlock-x86.o";
138 my $x86_elf_asm="$x86_asm:elf";
140 my $x86_64_asm="x86_64cpuid.o:x86_64-gcc.o x86_64-mont.o x86_64-mont5.o x86_64-gf2m.o rsaz_exp.o rsaz-x86_64.o rsaz-avx2.o:ecp_nistz256.o ecp_nistz256-x86_64.o::aes-x86_64.o vpaes-x86_64.o bsaes-x86_64.o aesni-x86_64.o aesni-sha1-x86_64.o aesni-sha256-x86_64.o aesni-mb-x86_64.o::md5-x86_64.o:sha1-x86_64.o sha256-x86_64.o sha512-x86_64.o sha1-mb-x86_64.o sha256-mb-x86_64.o::rc4-x86_64.o rc4-md5-x86_64.o:::wp-x86_64.o:cmll-x86_64.o cmll_misc.o:ghash-x86_64.o aesni-gcm-x86_64.o:e_padlock-x86_64.o";
141 my $ia64_asm="ia64cpuid.o:bn-ia64.o ia64-mont.o:::aes_core.o aes_cbc.o aes-ia64.o::md5-ia64.o:sha1-ia64.o sha256-ia64.o sha512-ia64.o::rc4-ia64.o rc4_skey.o:::::ghash-ia64.o::void";
142 my $sparcv9_asm="sparcv9cap.o sparccpuid.o:bn-sparcv9.o sparcv9-mont.o sparcv9a-mont.o vis3-mont.o sparct4-mont.o sparcv9-gf2m.o::des_enc-sparc.o fcrypt_b.o dest4-sparcv9.o:aes_core.o aes_cbc.o aes-sparcv9.o aest4-sparcv9.o::md5-sparcv9.o:sha1-sparcv9.o sha256-sparcv9.o sha512-sparcv9.o::::::camellia.o cmll_misc.o cmll_cbc.o cmllt4-sparcv9.o:ghash-sparcv9.o::void";
143 my $sparcv8_asm=":sparcv8.o::des_enc-sparc.o fcrypt_b.o:::::::::::::void";
144 my $alpha_asm="alphacpuid.o:bn_asm.o alpha-mont.o::::::sha1-alpha.o:::::::ghash-alpha.o::void";
145 my $mips64_asm=":bn-mips.o mips-mont.o:::aes_cbc.o aes-mips.o:::sha1-mips.o sha256-mips.o sha512-mips.o::::::::";
146 my $mips32_asm=$mips64_asm; $mips32_asm =~ s/\s*sha512\-mips\.o//;
147 my $s390x_asm="s390xcap.o s390xcpuid.o:bn-s390x.o s390x-mont.o s390x-gf2m.o:::aes-s390x.o aes-ctr.o aes-xts.o:::sha1-s390x.o sha256-s390x.o sha512-s390x.o::rc4-s390x.o:::::ghash-s390x.o:";
148 my $armv4_asm="armcap.o armv4cpuid.o:bn_asm.o armv4-mont.o armv4-gf2m.o:ecp_nistz256.o ecp_nistz256-armv4.o::aes_cbc.o aes-armv4.o bsaes-armv7.o aesv8-armx.o:::sha1-armv4-large.o sha256-armv4.o sha512-armv4.o:::::::ghash-armv4.o ghashv8-armx.o::void";
149 my $aarch64_asm="armcap.o arm64cpuid.o mem_clr.o::::aes_core.o aes_cbc.o aesv8-armx.o:::sha1-armv8.o sha256-armv8.o sha512-armv8.o:::::::ghashv8-armx.o:";
150 my $parisc11_asm="pariscid.o:bn_asm.o parisc-mont.o:::aes_core.o aes_cbc.o aes-parisc.o:::sha1-parisc.o sha256-parisc.o sha512-parisc.o::rc4-parisc.o:::::ghash-parisc.o::32";
151 my $parisc20_asm="pariscid.o:pa-risc2W.o parisc-mont.o:::aes_core.o aes_cbc.o aes-parisc.o:::sha1-parisc.o sha256-parisc.o sha512-parisc.o::rc4-parisc.o:::::ghash-parisc.o::64";
152 my $ppc64_asm="ppccpuid.o ppccap.o:bn-ppc.o ppc-mont.o ppc64-mont.o:::aes_core.o aes_cbc.o aes-ppc.o vpaes-ppc.o aesp8-ppc.o:::sha1-ppc.o sha256-ppc.o sha512-ppc.o sha256p8-ppc.o sha512p8-ppc.o:::::::ghashp8-ppc.o:";
153 my $ppc32_asm=$ppc64_asm;
155 # As for $BSDthreads. Idea is to maintain "collective" set of flags,
156 # which would cover all BSD flavors. -pthread applies to them all,
157 # but is treated differently. OpenBSD expands is as -D_POSIX_THREAD
158 # -lc_r, which is sufficient. FreeBSD 4.x expands it as -lc_r,
159 # which has to be accompanied by explicit -D_THREAD_SAFE and
160 # sometimes -D_REENTRANT. FreeBSD 5.x expands it as -lc_r, which
161 # seems to be sufficient?
162 my $BSDthreads="-pthread -D_THREAD_SAFE -D_REENTRANT";
165 # table of known configurations, read in from files
167 # The content of each entry can take one of two forms:
169 # - old style config-string, colon seperated fields with exactly the
170 # following structure.:
172 # $cc : $cflags : $unistd : $thread_cflag : $sys_id : $lflags : $bn_ops : $cpuid_obj : $bn_obj : $ec_obj : $des_obj : $aes_obj : $bf_obj : $md5_obj : $sha1_obj : $cast_obj : $rc4_obj : $rmd160_obj : $rc5_obj : $wp_obj : $cmll_obj : $modes_obj : $engines_obj : $perlasm_scheme : $dso_scheme : $shared_target : $shared_cflag : $shared_ldflag : $shared_extension : $ranlib : $arflags : $multilib
174 # We use the stringtohash function - defined below - to combine with the
175 # fields and form a proper hash table from the string.
177 # - direct transfer of old style config string to hash table, using the names
178 # of the fields as keys:
184 # thread_cflag => $thread_cflag,
188 # cpuid_obj => $cpuid_obj,
191 # des_obj => $des_obj,
192 # aes_obj => $aes_obj,
194 # md5_obj => $md5_obj,
195 # sha1_obj => $sha1_obj,
196 # cast_obj => $cast_obj,
197 # rc4_obj => $rc4_obj,
198 # rmd160_obj => $rmd160_obj,
199 # rc5_obj => $rc5_obj,
201 # cmll_obj => $cmll_obj,
202 # modes_obj => $modes_obj,
203 # engines_obj => $engines_obj,
204 # perlasm_scheme => $perlasm_scheme,
205 # dso_scheme => $dso_scheme,
206 # shared_target => $shared_target,
207 # shared_cflag => $shared_cflag,
208 # shared_ldflag => $shared_ldflag,
209 # shared_extension => $shared_extension,
211 # arflags => $arflags,
212 # multilib => $multilib
215 # - new style config hash table, which has additional attributes for debug
216 # and non-debug flags to be added to the common flags, for cflags and lflags:
221 # debug_cflags => $debug_cflags,
222 # release_cflags => $release_cflags,
224 # thread_cflag => $thread_cflag,
227 # debug_lflags => $debug_lflags,
228 # release_lflags => $release_lflags,
230 # cpuid_obj => $cpuid_obj,
233 # des_obj => $des_obj,
234 # aes_obj => $aes_obj,
236 # md5_obj => $md5_obj,
237 # sha1_obj => $sha1_obj,
238 # cast_obj => $cast_obj,
239 # rc4_obj => $rc4_obj,
240 # rmd160_obj => $rmd160_obj,
241 # rc5_obj => $rc5_obj,
243 # cmll_obj => $cmll_obj,
244 # modes_obj => $modes_obj,
245 # engines_obj => $engines_obj,
246 # dso_scheme => $dso_scheme,
247 # shared_target => $shared_target,
248 # shared_cflag => $shared_cflag,
249 # shared_ldflag => $shared_ldflag,
250 # shared_extension => $shared_extension,
252 # arflags => $arflags,
253 # multilib => $multilib
256 # The configuration reader will do what it can to translate everything into
257 # new style config hash tables, including merging $target and debug-$target
258 # if they are similar enough.
260 # The configuration hashes can refer to templates in two different manners:
262 # - as part of the hash, one can have a key called 'inherit_from' that
263 # indicate what other configuration hashes to inherit data from.
264 # These are resolved recursively.
266 # Inheritance works as a set of default values that can be overriden
267 # by corresponding attribute values in the inheriting configuration.
269 # If several configurations are given in the 'inherit_from' array, the
270 # values of same attribute are concatenated with space separation.
271 # With this, it's possible to have several smaller templates for
272 # different configuration aspects that can be combined into a complete
288 # inherit_from => [ "foo", "bar" ],
291 # The entry for "foo" will become as follows after processing:
299 # Note 1: any entry from the table can be used as a template.
300 # Note 2: pure templates have the attribute 'template => 1' and cannot
301 # be used as targets.
303 # - instead of a string, one can have a code block of the form
304 # 'sub { /* your code here */ }', where the arguments are the list of
305 # inherited values for that key. In fact, the concatenation of strings
306 # is really done by using 'sub { join(" ",@_) }' on the list of inherited
315 # ignored => "This should not appear in the end result",
324 # inherit_from => [ "foo", "bar" ],
325 # hehe => sub { join(" ",(@_,"!!!")) },
329 # The entry for "foo" will become as follows after processing:
332 # haha => "ha ha ah",
334 # hehe => "hehe !!!",
341 # All these templates are merely a translation of the corresponding
342 # variables further up.
344 # Note: as long as someone might use old style configuration strings,
345 # or we bother supporting that, those variables need to stay
347 # Filler used for when there are no asm files.
366 perlasm_scheme => "void"
371 cpuid_obj => "x86cpuid.o",
372 bn_obj => "bn-586.o co-586.o x86-mont.o x86-gf2m.o",
373 ec_obj => "ecp_nistz256.o ecp_nistz256-x86.o",
374 des_obj => "des-586.o crypt586.o",
375 aes_obj => "aes-586.o vpaes-x86.o aesni-x86.o",
376 bf_obj => "bf-586.o",
377 md5_obj => "md5-586.o",
378 sha1_obj => "sha1-586.o sha256-586.o sha512-586.o",
379 cast_obj => "cast-586.o",
380 rc4_obj => "rc4-586.o",
381 rmd160_obj => "rmd-586.o",
382 rc5_obj => "rc5-586.o",
383 wp_obj => "wp_block.o wp-mmx.o",
384 cmll_obj => "cmll-x86.o",
385 modes_obj => "ghash-x86.o",
386 engines_obj => "e_padlock-x86.o"
390 inherit_from => [ "x86_asm" ],
391 perlasm_scheme => "elf"
396 cpuid_obj => "x86_64cpuid.o",
397 bn_obj => "x86_64-gcc.o x86_64-mont.o x86_64-mont5.o x86_64-gf2m.o rsaz_exp.o rsaz-x86_64.o rsaz-avx2.o",
398 ec_obj => "ecp_nistz256.o ecp_nistz256-x86_64.o",
399 aes_obj => "aes-x86_64.o vpaes-x86_64.o bsaes-x86_64.o aesni-x86_64.o aesni-sha1-x86_64.o aesni-sha256-x86_64.o aesni-mb-x86_64.o",
400 md5_obj => "md5-x86_64.o",
401 sha1_obj => "sha1-x86_64.o sha256-x86_64.o sha512-x86_64.o sha1-mb-x86_64.o sha256-mb-x86_64.o",
402 rc4_obj => "rc4-x86_64.o rc4-md5-x86_64.o",
403 wp_obj => "wp-x86_64.o",
404 cmll_obj => "cmll-x86_64.o cmll_misc.o",
405 modes_obj => "ghash-x86_64.o aesni-gcm-x86_64.o",
406 engines_obj => "e_padlock-x86_64.o"
410 cpuid_obj => "ia64cpuid.o",
411 bn_obj => "bn-ia64.o ia64-mont.o",
412 aes_obj => "aes_core.o aes_cbc.o aes-ia64.o",
413 md5_obj => "md5-ia64.o",
414 sha1_obj => "sha1-ia64.o sha256-ia64.o sha512-ia64.o",
415 rc4_obj => "rc4-ia64.o rc4_skey.o",
416 modes_obj => "ghash-ia64.o",
417 perlasm_scheme => "void"
421 cpuid_obj => "sparcv9cap.o sparccpuid.o",
422 bn_obj => "bn-sparcv9.o sparcv9-mont.o sparcv9a-mont.o vis3-mont.o sparct4-mont.o sparcv9-gf2m.o",
423 des_obj => "des_enc-sparc.o fcrypt_b.o dest4-sparcv9.o",
424 aes_obj => "aes_core.o aes_cbc.o aes-sparcv9.o aest4-sparcv9.o",
425 md5_obj => "md5-sparcv9.o",
426 sha1_obj => "sha1-sparcv9.o sha256-sparcv9.o sha512-sparcv9.o",
427 cmll_obj => "camellia.o cmll_misc.o cmll_cbc.o cmllt4-sparcv9.o",
428 modes_obj => "ghash-sparcv9.o",
429 perlasm_scheme => "void"
434 bn_obj => "sparcv8.o",
435 des_obj => "des_enc-sparc.o fcrypt_b.o",
436 perlasm_scheme => "void"
440 cpuid_obj => "alphacpuid.o",
441 bn_obj => "bn_asm.o alpha-mont.o",
442 sha1_obj => "sha1-alpha.o",
443 modes_obj => "ghash-alpha.o",
444 perlasm_scheme => "void"
448 bn_obj => "bn-mips.o mips-mont.o",
449 aes_obj => "aes_cbc.o aes-mips.o",
450 sha1_obj => "sha1-mips.o sha256-mips.o",
453 inherit_from => [ "mips32_asm" ],
455 sha1_obj => sub { join(" ", @_, "sha512-mips.o") }
459 cpuid_obj => "s390xcap.o s390xcpuid.o",
460 bn_obj => "bn-s390x.o s390x-mont.o s390x-gf2m.o",
461 aes_obj => "aes-s390x.o aes-ctr.o aes-xts.o",
462 sha1_obj => "sha1-s390x.o sha256-s390x.o sha512-s390x.o",
463 rc4_obj => "rc4-s390x.o",
464 modes_obj => "ghash-s390x.o",
468 cpuid_obj => "armcap.o armv4cpuid.o",
469 bn_obj => "bn_asm.o armv4-mont.o armv4-gf2m.o",
470 ec_obj => "ecp_nistz256.o ecp_nistz256-armv4.o",
471 aes_obj => "aes_cbc.o aes-armv4.o bsaes-armv7.o aesv8-armx.o",
472 sha1_obj => "sha1-armv4-large.o sha256-armv4.o sha512-armv4.o",
473 modes_obj => "ghash-armv4.o ghashv8-armx.o",
474 perlasm_scheme => "void"
478 cpuid_obj => "armcap.o arm64cpuid.o mem_clr.o",
479 aes_obj => "aes_core.o aes_cbc.o aesv8-armx.o",
480 sha1_obj => "sha1-armv8.o sha256-armv8.o sha512-armv8.o",
481 modes_obj => "ghashv8-armx.o",
485 cpuid_obj => "pariscid.o",
486 bn_obj => "bn_asm.o parisc-mont.o",
487 aes_obj => "aes_core.o aes_cbc.o aes-parisc.o",
488 sha1_obj => "sha1-parisc.o sha256-parisc.o sha512-parisc.o",
489 rc4_obj => "rc4-parisc.o",
490 modes_obj => "ghash-parisc.o",
491 perlasm_scheme => "32"
495 cpuid_obj => "pariscid.o",
496 bn_obj => "pa-risc2W.o parisc-mont.o",
497 aes_obj => "aes_core.o aes_cbc.o aes-parisc.o",
498 sha1_obj => "sha1-parisc.o sha256-parisc.o sha512-parisc.o",
499 rc4_obj => "rc4-parisc.o",
500 modes_obj => "ghash-parisc.o",
501 perlasm_scheme => "64"
505 cpuid_obj => "ppccpuid.o ppccap.o",
506 bn_obj => "bn-ppc.o ppc-mont.o ppc64-mont.o",
507 aes_obj => "aes_core.o aes_cbc.o aes-ppc.o vpaes-ppc.o aesp8-ppc.o",
508 sha1_obj => "sha1-ppc.o sha256-ppc.o sha512-ppc.o sha256p8-ppc.o sha512p8-ppc.o",
509 modes_obj => "ghashp8-ppc.o",
512 inherit_from => [ "ppc64_asm" ],
519 if (ref($in) eq "HASH") {
522 my @stringsequence = (
557 # return a ref to a hash, that's what the outer braces are for.
558 return { map { shift @stringsequence => $_ } split /:/, $in };
561 # Read configuration target stanzas from a file, so that people can have
562 # local files with their own definitions
565 open(CONFFILE, "< $fname")
566 or die "Can't open configuration file '$fname'!\n";
569 my $content = <CONFFILE>;
575 # Make sure we have debug- targets first
578 my $a_nd = $a =~ m/^debug-/ ? $' :$a;
579 my $b_nd = $b =~ m/^debug-/ ? $' :$b;
582 if (($a_nd == $a) == ($b_nd == $b)) {
583 # they are both debug- or not, compare them as they are
585 } elsif ($a_nd != $a) {
586 # $a is debug-, make it lesser
589 # $b is debug-, make $a greater
596 if (ref($targets{$_}) ne "HASH") {
597 # Value is assumed to be a string. Split it up to
598 # become a hash table of parameters. Also, try to
599 # merge debug- variants with the non-debug target.
601 # Start with converting the value from a string to a
602 # standardised hash of fields. Using $tohash is safe,
603 # if the input is already a hash ref, it's just returned
605 $targets{$_} = stringtohash($targets{$_});
607 # If the current target is a debug target, there might
608 # be a corresponding non-debug target that we can merge
609 # with. If it isn't a debug- target, we've already done
610 # as much merging as we can and do not need to bother
611 # with that any more.
612 if ($_ =~ m/^debug-/) {
614 my $nondebugkey = $';
615 my $debug = $targets{$debugkey};
618 if ($targets{$nondebugkey}) {
619 $nondebug = stringtohash($targets{$nondebugkey});
623 # There's both a debug and non-debug variant of
624 # this target, so we should try to merge them
627 # First, check that the non-debug variant isn't
628 # already built up with all it should have.
629 if ($nondebug->{debug_cflags}
630 || $nondebug->{release_cflags}
631 || $nondebug->{debug_lflags}
632 || $nondebug->{release_lflags}) {
633 warn "there's a debug target $debugkey to be merged with a target $nondebugkey, but the latter seems to already have both nodebug and debug information. This requires human intervention. Skipping $debugkey...";
637 # Now, check similarity.
638 # For keys they have in common, support that
639 # cflags and lflags can differ, otherwise they
640 # must have exactly the same values for them
641 # to be merged into one.
642 my $similarenough = 1;
643 for (keys %{$debug}) {
644 if ($nondebug->{$_} ne $debug->{$_}
645 && $_ !~ m/^[cl]flags$/) {
651 if ($similarenough) {
652 # Here's where the magic happens, split the
653 # options in the debug and non-debug variants
654 # cflags and ldflags into three strings each,
655 # one with common flags, one with extra debug
656 # flags and one with extra non-debug flags.
658 # The result ends up in %h_nondebug, which
659 # becomes the merged variant when we're done.
660 # for each of cflags and lflags, they are
661 # replaced with cflags, debug_cflags,
662 # release_cflags and similar for lflags.
664 # The purpose is that 'cflags' should be
665 # used together with 'debug_cflags' or
666 # 'release_cflags' depending on what the
668 foreach (("cflags", "lflags")) {
669 my @list_d = split /\s+/, $debug->{$_};
670 my @list_nd = split /\s+/, $nondebug->{$_};
671 my %presence = (); # bitmap
672 # 1: present in @list_d
673 # 2: present in @list_nd
675 map { $presence{$_} += 1; } @list_d;
676 map { $presence{$_} += 2; } @list_nd;
678 delete $nondebug->{$_};
679 # Note: we build from the original lists to
680 # preserve order, it might be important
681 $nondebug->{"debug-".$_} =
683 grep { $presence{$_} == 1 } @list_d);
684 $nondebug->{"nodebug-".$_} =
686 grep { $presence{$_} == 2 } @list_nd);
689 grep { $presence{$_} == 3 } @list_d);
692 $targets{$nondebugkey} = $nondebug;
693 delete $targets{$debugkey};
700 %table = (%table, %targets);
702 # Local function to resolve inheritance
703 my $resolve_inheritance;
704 $resolve_inheritance =
707 my @breadcrumbs = @_;
709 if (grep { $_ eq $target } @breadcrumbs) {
710 die "inherit_from loop! target backtrace:\n "
711 ,$target,"\n ",join("\n ", @breadcrumbs),"\n";
714 # Recurse through all inheritances. They will be resolved on
715 # the fly, so when this operation is done, they will all just
716 # be a bunch of attributes with string values.
717 # What we get here, though, are keys with references to lists
718 # of the combined values of them all. We will deal with lists
719 # after this stage is done.
720 my %combined_inheritance = ();
721 if ($table{$target}->{inherit_from}) {
722 foreach (@{$table{$target}->{inherit_from}}) {
723 my %inherited_config =
724 $resolve_inheritance->($_, $target, @breadcrumbs);
726 # 'template' is a marker that's considered private to
727 # the config that had it.
728 delete $inherited_config{template};
731 if (!$combined_inheritance{$_}) {
732 $combined_inheritance{$_} = [];
734 push @{$combined_inheritance{$_}}, $inherited_config{$_};
735 } keys %inherited_config;
739 # We won't need inherit_from in this target any more, since
740 # we've resolved all the inheritances that lead to this
741 delete $table{$target}->{inherit_from};
743 # Now is the time to deal with those lists. Here's the place
744 # to decide what shall be done with those lists, all based on
745 # the values of the target we're currently dealing with.
746 # - If a value is a coderef, it will be executed with the list
747 # of inherited values as arguments.
748 # - If the corresponding key doesn't have a value at all or is
749 # the emoty string, the inherited value list will be run
750 # through the default combiner (below), and the result
751 # becomes this target's value.
752 # - Otherwise, this target's value is assumed to be a string
753 # that will simply override the inherited list of values.
754 my $default_combiner = sub { join(' ',@_) };
757 map { $_ => 1 } (keys %combined_inheritance,
758 keys %{$table{$target}});
759 foreach (sort keys %all_keys) {
761 # Current target doesn't have a value for the current key?
762 # Assign it the default combiner, the rest of this loop
763 # body will handle it just like any other coderef.
764 if (!exists $table{$target}->{$_}) {
765 $table{$target}->{$_} = $default_combiner;
768 my $valuetype = ref($table{$target}->{$_});
769 if ($valuetype eq "CODE") {
770 # CODE reference, execute it with the inherited values
772 $table{$target}->{$_} =
773 $table{$target}->{$_}->(@{$combined_inheritance{$_}});
774 } elsif ($valuetype eq "") {
775 # Scalar, just leave it as is.
777 # Some other type of reference that we don't handle.
778 # Better to abort at this point.
779 die "cannot handle reference type $valuetype,"
780 ," found in target $target -> $_\n";
784 # Finally done, return the result.
788 # Go through all new targets and resolve inheritance and template
790 foreach (keys %targets) {
791 # We're ignoring the returned values here, they are only valuable
792 # to the inner recursion of this function.
793 $resolve_inheritance->($_);
797 my ($vol, $dir, $dummy) = File::Spec->splitpath($0);
798 my $pattern = File::Spec->catpath($vol, $dir, "Configurations/*.conf");
799 foreach (sort glob($pattern) ) {
803 my @MK1MF_Builds=qw(VC-WIN64I VC-WIN64A
804 debug-VC-WIN64I debug-VC-WIN64A
805 VC-NT VC-CE VC-WIN32 debug-VC-WIN32
807 netware-clib netware-clib-bsdsock
808 netware-libc netware-libc-bsdsock);
814 my $install_prefix= "$ENV{'INSTALL_PREFIX'}";
815 my $cross_compile_prefix="";
816 my $fipslibdir="/usr/local/ssl/fips-2.0/lib/";
817 my $nofipscanistercheck=0;
818 my $baseaddr="0xFB00000";
821 my $no_shared=0; # but "no-shared" is default
822 my $zlib=1; # but "no-zlib" is default
823 my $no_krb5=0; # but "no-krb5" is implied unless "--with-krb5-..." is used
824 my $no_rfc3779=1; # but "no-rfc3779" is default
829 my $Makefile="Makefile";
830 my $des_locl="crypto/des/des_locl.h";
831 my $des ="crypto/des/des.h";
832 my $bn ="crypto/bn/bn.h";
833 my $md2 ="crypto/md2/md2.h";
834 my $rc4 ="crypto/rc4/rc4.h";
835 my $rc4_locl="crypto/rc4/rc4_locl.h";
836 my $idea ="crypto/idea/idea.h";
837 my $rc2 ="crypto/rc2/rc2.h";
838 my $bf ="crypto/bf/bf_locl.h";
839 my $bn_asm ="bn_asm.o";
840 my $des_enc="des_enc.o fcrypt_b.o";
841 my $aes_enc="aes_core.o aes_cbc.o";
842 my $bf_enc ="bf_enc.o";
843 my $cast_enc="c_enc.o";
844 my $rc4_enc="rc4_enc.o rc4_skey.o";
845 my $rc5_enc="rc5_enc.o";
846 my $cmll_enc="camellia.o cmll_misc.o cmll_cbc.o";
852 # All of the following is disabled by default (RC5 was enabled before 0.9.8):
854 my %disabled = ( # "what" => "comment" [or special keyword "experimental"]
855 "deprecated" => "default",
856 "ec_nistp_64_gcc_128" => "default",
858 "jpake" => "experimental",
861 "rfc3779" => "default",
863 "shared" => "default",
864 "ssl-trace" => "default",
865 "store" => "experimental",
866 "unit-test" => "default",
868 "zlib-dynamic" => "default"
870 my @experimental = ();
872 # This is what $depflags will look like with the above defaults
873 # (we need this to see if we should advise the user to run "make depend"):
874 my $default_depflags = " -DOPENSSL_NO_DEPRECATED -DOPENSSL_NO_EC_NISTP_64_GCC_128 -DOPENSSL_NO_GMP -DOPENSSL_NO_JPAKE -DOPENSSL_NO_MD2 -DOPENSSL_NO_RC5 -DOPENSSL_NO_RFC3779 -DOPENSSL_NO_SCTP -DOPENSSL_NO_SSL_TRACE -DOPENSSL_NO_STORE -DOPENSSL_NO_UNIT_TEST";
876 # Explicit "no-..." options will be collected in %disabled along with the defaults.
877 # To remove something from %disabled, use "enable-foo" (unless it's experimental).
878 # For symmetry, "disable-foo" is a synonym for "no-foo".
880 # For features called "experimental" here, a more explicit "experimental-foo" is needed to enable.
881 # We will collect such requests in @experimental.
882 # To avoid accidental use of experimental features, applications will have to use -DOPENSSL_EXPERIMENTAL_FOO.
887 &usage if ($#ARGV < 0);
891 my $openssl_experimental_defines;
892 my $openssl_algorithm_defines;
893 my $openssl_thread_defines;
894 my $openssl_sys_defines="";
895 my $openssl_other_defines;
906 my $argv_unprocessed=1;
908 while($argv_unprocessed)
912 $openssl_experimental_defines="";
913 $openssl_algorithm_defines="";
914 $openssl_thread_defines="";
915 $openssl_sys_defines="";
916 $openssl_other_defines="";
923 $argvstring=join(' ',@argvcopy);
928 s /^-no-/no-/; # some people just can't read the instructions
930 # rewrite some options in "enable-..." form
931 s /^-?-?shared$/enable-shared/;
932 s /^sctp$/enable-sctp/;
933 s /^threads$/enable-threads/;
934 s /^zlib$/enable-zlib/;
935 s /^zlib-dynamic$/enable-zlib-dynamic/;
937 if (/^no-(.+)$/ || /^disable-(.+)$/)
939 if (!($disabled{$1} eq "experimental"))
943 $disabled{"ssl3"} = "option(ssl)";
947 $disabled{"tls1"} = "option(tls)"
949 elsif ($1 eq "ssl3-method")
951 $disabled{"ssl3-method"} = "option(ssl)";
952 $disabled{"ssl3"} = "option(ssl)";
956 $disabled{$1} = "option";
960 elsif (/^enable-(.+)$/ || /^experimental-(.+)$/)
963 if ($disabled{$algo} eq "experimental")
965 die "You are requesting an experimental feature; please say 'experimental-$algo' if you are sure\n"
966 unless (/^experimental-/);
967 push @experimental, $algo;
969 delete $disabled{$algo};
971 $threads = 1 if ($algo eq "threads");
973 elsif (/^--test-sanity$/)
975 exit(&test_sanity());
977 elsif (/^--strict-warnings/)
979 $strict_warnings = 1;
981 elsif (/^reconfigure/ || /^reconf/)
983 if (open(IN,"<$Makefile"))
988 if (/^CONFIGURE_ARGS=(.*)/)
991 @argvcopy=split(' ',$argvstring);
992 die "Incorrect data to reconfigure, please do a normal configuration\n"
993 if (grep(/^reconf/,@argvcopy));
994 print "Reconfiguring with: $argvstring\n";
1002 die "Insufficient data to reconfigure, please do a normal configuration\n";
1012 # No RSAref support any more since it's not needed.
1013 # The check for the option is there so scripts aren't
1016 elsif (/^nofipscanistercheck$/)
1019 $nofipscanistercheck = 1;
1023 if (/^--prefix=(.*)$/)
1027 elsif (/^--libdir=(.*)$/)
1031 elsif (/^--openssldir=(.*)$/)
1035 elsif (/^--install.prefix=(.*)$/)
1039 elsif (/^--with-krb5-(dir|lib|include|flavor)=(.*)$/)
1041 $withargs{"krb5-".$1}=$2;
1043 elsif (/^--with-zlib-lib=(.*)$/)
1045 $withargs{"zlib-lib"}=$1;
1047 elsif (/^--with-zlib-include=(.*)$/)
1049 $withargs{"zlib-include"}="-I$1";
1051 elsif (/^--with-fipslibdir=(.*)$/)
1055 elsif (/^--with-baseaddr=(.*)$/)
1059 elsif (/^--cross-compile-prefix=(.*)$/)
1061 $cross_compile_prefix=$1;
1063 elsif (/^--config=(.*)$/)
1067 elsif (/^-[lL](.*)$/ or /^-Wl,/)
1071 else # common if (/^[-+]/), just pass down...
1073 $_ =~ s/%([0-9a-f]{1,2})/chr(hex($1))/gei;
1077 elsif ($_ =~ /^([^:]+):(.+)$/)
1079 eval "\$table{\$1} = \"$2\""; # allow $xxx constructs in the string
1084 die "target already defined - $target (offending arg: $_)\n" if ($target ne "");
1088 unless ($_ eq $target || /^no-/ || /^disable-/)
1090 # "no-..." follows later after implied disactivations
1091 # have been derived. (Don't take this too seroiusly,
1092 # we really only write OPTIONS to the Makefile out of
1098 { $options .= " ".$_; }
1105 if ($processor eq "386")
1107 $disabled{"sse2"} = "forced";
1110 if (!defined($withargs{"krb5-flavor"}) || $withargs{"krb5-flavor"} eq "")
1112 $disabled{"krb5"} = "krb5-flavor not specified";
1115 if (!defined($disabled{"zlib-dynamic"}))
1117 # "zlib-dynamic" was specifically enabled, so enable "zlib"
1118 delete $disabled{"zlib"};
1121 if (defined($disabled{"rijndael"}))
1123 $disabled{"aes"} = "forced";
1125 if (defined($disabled{"des"}))
1127 $disabled{"mdc2"} = "forced";
1129 if (defined($disabled{"ec"}))
1131 $disabled{"ecdsa"} = "forced";
1132 $disabled{"ecdh"} = "forced";
1135 # SSL 3.0 and TLS requires MD5 and SHA and either RSA or DSA+DH
1136 if (defined($disabled{"md5"}) || defined($disabled{"sha"})
1137 || (defined($disabled{"rsa"})
1138 && (defined($disabled{"dsa"}) || defined($disabled{"dh"}))))
1140 $disabled{"ssl3"} = "forced";
1141 $disabled{"tls1"} = "forced";
1144 if (defined($disabled{"tls1"}))
1146 $disabled{"tlsext"} = "forced";
1149 if (defined($disabled{"ec"}) || defined($disabled{"dsa"})
1150 || defined($disabled{"dh"}))
1152 $disabled{"gost"} = "forced";
1155 # SRP and HEARTBEATS require TLSEXT
1156 if (defined($disabled{"tlsext"}))
1158 $disabled{"srp"} = "forced";
1159 $disabled{"heartbeats"} = "forced";
1162 if ($target eq "TABLE") {
1163 foreach $target (sort keys %table) {
1164 print_table_entry($target, "TABLE");
1169 if ($target eq "LIST") {
1170 foreach (sort keys %table) {
1177 if ($target eq "HASH") {
1178 print "%table = (\n";
1179 foreach (sort keys %table) {
1180 print_table_entry($_, "HASH");
1185 if ($target =~ m/^CygWin32(-.*)$/) {
1186 $target = "Cygwin".$1;
1189 print "Configuring for $target\n";
1191 my ($d, $t) = $target =~ m/^(debug-)?(.*)$/;
1192 my $debug_prefix = "release_";
1194 $debug_prefix = "debug_";
1196 # If we do not find debug-foo in the table, the target is set to foo,
1197 # but only if the foo target has a noon-empty debug_cflags or debug_lflags
1199 if (!$table{$target} && ($table{$t}->{debug_cflags}
1200 || $table{$t}->{debug_lflags})) {
1205 &usage if (!defined($table{$target}) || $table{$target}->{template});
1209 delete $disabled{"shared"} if ($disabled{"shared"} eq "default");
1212 foreach (sort (keys %disabled))
1214 $options .= " no-$_";
1216 printf " no-%-12s %-10s", $_, "[$disabled{$_}]";
1221 { $no_threads = 1; }
1226 elsif (/^static-engine$/)
1228 elsif (/^zlib-dynamic$/)
1230 elsif (/^symlinks$/)
1237 ($ALGO = $algo = $_) =~ tr/[\-a-z]/[_A-Z]/;
1239 if (/^asm$/ || /^err$/ || /^hw$/ || /^hw-/)
1241 $openssl_other_defines .= "#define OPENSSL_NO_$ALGO\n";
1242 print " OPENSSL_NO_$ALGO";
1244 if (/^err$/) { $flags .= "-DOPENSSL_NO_ERR "; }
1245 elsif (/^asm$/) { $no_asm = 1; }
1249 ($ALGO,$algo) = ("RMD160","rmd160") if ($algo eq "ripemd");
1251 $openssl_algorithm_defines .= "#define OPENSSL_NO_$ALGO\n";
1252 print " OPENSSL_NO_$ALGO";
1259 # fix-up crypto/directory name(s)
1260 $skip[$#skip]="whrlpool" if $algo eq "whirlpool";
1261 $skip[$#skip]="ripemd" if $algo eq "rmd160";
1263 print " (skip dir)";
1265 $depflags .= " -DOPENSSL_NO_$ALGO";
1273 my $exp_cflags = "";
1275 foreach (sort @experimental)
1278 ($ALGO = $_) =~ tr/[a-z]/[A-Z]/;
1280 # opensslconf.h will set OPENSSL_NO_... unless OPENSSL_EXPERIMENTAL_... is defined
1281 $openssl_experimental_defines .= "#define OPENSSL_NO_$ALGO\n";
1282 $exp_cflags .= " -DOPENSSL_EXPERIMENTAL_$ALGO";
1285 my $IsMK1MF=scalar grep /^$target$/,@MK1MF_Builds;
1287 $exe_ext=".exe" if ($target eq "Cygwin" || $target eq "DJGPP" || $target =~ /^mingw/);
1288 $exe_ext=".nlm" if ($target =~ /netware/);
1289 $exe_ext=".pm" if ($target =~ /vos/);
1290 $openssldir="/usr/local/ssl" if ($openssldir eq "" and $prefix eq "");
1291 $prefix=$openssldir if $prefix eq "";
1293 $default_ranlib= &which("ranlib") or $default_ranlib="true";
1294 $perl=$ENV{'PERL'} or $perl=&which("perl5") or $perl=&which("perl")
1296 my $make = $ENV{'MAKE'} || "make";
1298 $cross_compile_prefix=$ENV{'CROSS_COMPILE'} if $cross_compile_prefix eq "";
1300 chop $openssldir if $openssldir =~ /\/$/;
1301 chop $prefix if $prefix =~ /.\/$/;
1303 $openssldir=$prefix . "/ssl" if $openssldir eq "";
1304 $openssldir=$prefix . "/" . $openssldir if $openssldir !~ /(^\/|^[a-zA-Z]:[\\\/])/;
1307 print "IsMK1MF=$IsMK1MF\n";
1309 # Allow environment CC to override compiler...
1310 my $cc = $ENV{CC} || $table{$t}->{cc};
1312 # For cflags and lflags, add the debug_ or release_ attributes
1313 # Do it in such a way that no spurious space is appended (hence the grep).
1314 my $cflags = join(" ",
1315 grep { $_ } ($table{$t}->{cflags},
1316 $table{$t}->{$debug_prefix."cflags"}));
1317 my $lflags = join(" ",
1318 grep { $_ } ($table{$t}->{lflags},
1319 $table{$t}->{$debug_prefix."lflags"}));
1321 my $unistd = $table{$t}->{unistd};
1322 my $thread_cflag = $table{$t}->{thread_cflag};
1323 my $sys_id = $table{$t}->{sys_id};
1324 my $bn_ops = $table{$t}->{bn_ops};
1325 my $cpuid_obj = $table{$t}->{cpuid_obj};
1326 my $bn_obj = $table{$t}->{bn_obj};
1327 my $ec_obj = $table{$t}->{ec_obj};
1328 my $des_obj = $table{$t}->{des_obj};
1329 my $aes_obj = $table{$t}->{aes_obj};
1330 my $bf_obj = $table{$t}->{bf_obj};
1331 my $md5_obj = $table{$t}->{md5_obj};
1332 my $sha1_obj = $table{$t}->{sha1_obj};
1333 my $cast_obj = $table{$t}->{cast_obj};
1334 my $rc4_obj = $table{$t}->{rc4_obj};
1335 my $rmd160_obj = $table{$t}->{rmd160_obj};
1336 my $rc5_obj = $table{$t}->{rc5_obj};
1337 my $wp_obj = $table{$t}->{wp_obj};
1338 my $cmll_obj = $table{$t}->{cmll_obj};
1339 my $modes_obj = $table{$t}->{modes_obj};
1340 my $engines_obj = $table{$t}->{engines_obj};
1341 my $perlasm_scheme = $table{$t}->{perlasm_scheme};
1342 my $dso_scheme = $table{$t}->{dso_scheme};
1343 my $shared_target = $table{$t}->{shared_target};
1344 my $shared_cflag = $table{$t}->{shared_cflag};
1345 my $shared_ldflag = $table{$t}->{shared_ldflag};
1346 my $shared_extension = $table{$t}->{shared_extension};
1347 my $ranlib = $ENV{'RANLIB'} || $table{$t}->{ranlib};
1348 my $ar = $ENV{'AR'} || "ar";
1349 my $arflags = $table{$t}->{arflags};
1350 my $multilib = $table{$t}->{multilib};
1352 # if $prefix/lib$multilib is not an existing directory, then
1353 # assume that it's not searched by linker automatically, in
1354 # which case adding $multilib suffix causes more grief than
1355 # we're ready to tolerate, so don't...
1356 $multilib="" if !-d "$prefix/lib$multilib";
1358 $libdir="lib$multilib" if $libdir eq "";
1360 $cflags = "$cflags$exp_cflags";
1362 # '%' in $lflags is used to split flags to "pre-" and post-flags
1363 my ($prelflags,$postlflags)=split('%',$lflags);
1364 if (defined($postlflags)) { $lflags=$postlflags; }
1365 else { $lflags=$prelflags; undef $prelflags; }
1367 if ($target =~ /^mingw/ && `$cc --target-help 2>&1` !~ m/\-mno\-cygwin/m)
1369 $cflags =~ s/\-mno\-cygwin\s*//;
1370 $shared_ldflag =~ s/\-mno\-cygwin\s*//;
1373 if ($target =~ /linux.*\-mips/ && !$no_asm && $flags !~ /\-m(ips|arch=)/) {
1374 # minimally required architecture flags for assembly modules
1375 $cflags="-mips2 $cflags" if ($target =~ /mips32/);
1376 $cflags="-mips3 $cflags" if ($target =~ /mips64/);
1379 my $no_shared_warn=0;
1380 my $no_user_cflags=0;
1382 if ($flags ne "") { $cflags="$flags$cflags"; }
1383 else { $no_user_cflags=1; }
1385 # Kerberos settings. The flavor must be provided from outside, either through
1386 # the script "config" or manually.
1389 my ($lresolv, $lpath, $lext);
1390 if ($withargs{"krb5-flavor"} =~ /^[Hh]eimdal$/)
1392 die "Sorry, Heimdal is currently not supported\n";
1394 ##### HACK to force use of Heimdal.
1395 ##### WARNING: Since we don't really have adequate support for Heimdal,
1396 ##### using this will break the build. You'll have to make
1397 ##### changes to the source, and if you do, please send
1398 ##### patches to openssl-dev@openssl.org
1399 if ($withargs{"krb5-flavor"} =~ /^force-[Hh]eimdal$/)
1401 warn "Heimdal isn't really supported. Your build WILL break\n";
1402 warn "If you fix the problems, please send a patch to openssl-dev\@openssl.org\n";
1403 $withargs{"krb5-dir"} = "/usr/heimdal"
1404 if $withargs{"krb5-dir"} eq "";
1405 $withargs{"krb5-lib"} = "-L".$withargs{"krb5-dir"}.
1406 "/lib -lgssapi -lkrb5 -lcom_err"
1407 if $withargs{"krb5-lib"} eq "" && !$IsMK1MF;
1408 $cflags="-DKRB5_HEIMDAL $cflags";
1410 if ($withargs{"krb5-flavor"} =~ /^[Mm][Ii][Tt]/)
1412 $withargs{"krb5-dir"} = "/usr/kerberos"
1413 if $withargs{"krb5-dir"} eq "";
1414 $withargs{"krb5-lib"} = "-L".$withargs{"krb5-dir"}.
1415 "/lib -lgssapi_krb5 -lkrb5 -lcom_err -lk5crypto"
1416 if $withargs{"krb5-lib"} eq "" && !$IsMK1MF;
1417 $cflags="-DKRB5_MIT $cflags";
1418 $withargs{"krb5-flavor"} =~ s/^[Mm][Ii][Tt][._-]*//;
1419 if ($withargs{"krb5-flavor"} =~ /^1[._-]*[01]/)
1421 $cflags="-DKRB5_MIT_OLD11 $cflags";
1425 foreach $lpath ("/lib", "/usr/lib")
1427 foreach $lext ("a", "so")
1429 $lresolv = "$lpath/libresolv.$lext";
1430 last LRESOLV if (-r "$lresolv");
1434 $withargs{"krb5-lib"} .= " -lresolv"
1435 if ("$lresolv" ne "");
1436 $withargs{"krb5-include"} = "-I".$withargs{"krb5-dir"}."/include"
1437 if $withargs{"krb5-include"} eq "" &&
1438 $withargs{"krb5-dir"} ne "";
1441 # The DSO code currently always implements all functions so that no
1442 # applications will have to worry about that from a compilation point
1443 # of view. However, the "method"s may return zero unless that platform
1444 # has support compiled in for them. Currently each method is enabled
1445 # by a define "DSO_<name>" ... we translate the "dso_scheme" config
1446 # string entry into using the following logic;
1448 if (!$no_dso && $dso_scheme ne "")
1450 $dso_scheme =~ tr/[a-z]/[A-Z]/;
1451 if ($dso_scheme eq "DLFCN")
1453 $dso_cflags = "-DDSO_DLFCN -DHAVE_DLFCN_H";
1455 elsif ($dso_scheme eq "DLFCN_NO_H")
1457 $dso_cflags = "-DDSO_DLFCN";
1461 $dso_cflags = "-DDSO_$dso_scheme";
1463 $cflags = "$dso_cflags $cflags";
1468 if ($thread_cflag ne "(unknown)" && !$no_threads)
1470 # If we know how to do it, support threads by default.
1473 if ($thread_cflag eq "(unknown)" && $threads)
1475 # If the user asked for "threads", [s]he is also expected to
1476 # provide any system-dependent compiler options that are
1478 if ($no_user_cflags)
1480 print "You asked for multi-threading support, but didn't\n";
1481 print "provide any system-specific compiler options\n";
1484 $thread_cflags="-DOPENSSL_THREADS $cflags" ;
1485 $thread_defines .= "#define OPENSSL_THREADS\n";
1489 $thread_cflags="-DOPENSSL_THREADS $thread_cflag $cflags";
1490 $thread_defines .= "#define OPENSSL_THREADS\n";
1492 # foreach $def (split ' ',$thread_cflag)
1494 # if ($def =~ s/^-D// && $def !~ /^_/)
1496 # $thread_defines .= "#define $def\n";
1501 $lflags="$libs$lflags" if ($libs ne "");
1505 $cpuid_obj=$bn_obj=$ec_obj=
1506 $des_obj=$aes_obj=$bf_obj=$cast_obj=$rc4_obj=$rc5_obj=$cmll_obj=
1507 $modes_obj=$sha1_obj=$md5_obj=$rmd160_obj=$wp_obj=$engines_obj="";
1508 $cflags=~s/\-D[BL]_ENDIAN// if ($fips);
1509 $thread_cflags=~s/\-D[BL]_ENDIAN// if ($fips);
1511 elsif (defined($disabled{ec2m}))
1513 $bn_obj =~ s/\w+-gf2m.o//;
1518 $cast_obj=""; # CAST assembler is not PIC
1523 $cflags=$thread_cflags;
1524 $openssl_thread_defines .= $thread_defines;
1529 $cflags = "-DZLIB $cflags";
1530 if (defined($disabled{"zlib-dynamic"}))
1532 if (defined($withargs{"zlib-lib"}))
1534 $lflags = "$lflags -L" . $withargs{"zlib-lib"} . " -lz";
1538 $lflags = "$lflags -lz";
1543 $cflags = "-DZLIB_SHARED $cflags";
1547 #Build the library with OPENSSL_USE_DEPRECATED if deprecation is not disabled
1548 if(!defined($disabled{"deprecated"}))
1550 $cflags = "-DOPENSSL_USE_DEPRECATED $cflags";
1553 # You will find shlib_mark1 and shlib_mark2 explained in Makefile.org
1554 my $shared_mark = "";
1555 if ($shared_target eq "")
1557 $no_shared_warn = 1 if !$no_shared && !$fips;
1562 if ($shared_cflag ne "")
1564 $cflags = "$shared_cflag -DOPENSSL_PIC $cflags";
1570 # add {no-}static-engine to options to allow mkdef.pl to work without extra arguments
1573 $openssl_other_defines.="#define OPENSSL_NO_DYNAMIC_ENGINE\n";
1574 $options.=" static-engine";
1578 $openssl_other_defines.="#define OPENSSL_NO_STATIC_ENGINE\n";
1579 $options.=" no-static-engine";
1583 $cpuid_obj.=" uplink.o uplink-x86.o" if ($cflags =~ /\-DOPENSSL_USE_APPLINK/);
1588 if ($target =~ /\-icc$/) # Intel C compiler
1591 if (open(FD,"$cc -V 2>&1 |"))
1593 while(<FD>) { $iccver=$1 if (/Version ([0-9]+)\./); }
1598 $cflags=~s/\-KPIC/-fPIC/;
1599 # Eliminate unnecessary dependency from libirc.a. This is
1600 # essential for shared library support, as otherwise
1601 # apps/openssl can end up in endless loop upon startup...
1602 $cflags.=" -Dmemcpy=__builtin_memcpy -Dmemset=__builtin_memset";
1606 $lflags.=" -i-static";
1607 $lflags=~s/\-no_cpprt/-no-cpprt/;
1611 $lflags=~s/\-i\-static/-static-intel/;
1615 $cflags.=" -no-intel-extensions"; # disable Cilk
1616 $lflags=~s/\-no\-cpprt/-no-cxxlib/;
1620 # Unlike other OSes (like Solaris, Linux, Tru64, IRIX) BSD run-time
1621 # linkers (tested OpenBSD, NetBSD and FreeBSD) "demand" RPATH set on
1622 # .so objects. Apparently application RPATH is not global and does
1623 # not apply to .so linked with other .so. Problem manifests itself
1624 # when libssl.so fails to load libcrypto.so. One can argue that we
1625 # should engrave this into Makefile.shared rules or into BSD-* config
1626 # lines above. Meanwhile let's try to be cautious and pass -rpath to
1627 # linker only when --prefix is not /usr.
1628 if ($target =~ /^BSD\-/)
1630 $shared_ldflag.=" -Wl,-rpath,\$(LIBRPATH)" if ($prefix !~ m|^/usr[/]*$|);
1635 #$cflags="-DOPENSSL_SYS_$sys_id $cflags";
1636 $openssl_sys_defines="#define OPENSSL_SYS_$sys_id\n";
1641 $ranlib = $default_ranlib;
1644 #my ($bn1)=split(/\s+/,$bn_obj);
1645 #$bn1 = "" unless defined $bn1;
1646 #$bn1=$bn_asm unless ($bn1 =~ /\.o$/);
1649 $cpuid_obj="" if ($processor eq "386");
1651 $bn_obj = $bn_asm unless $bn_obj ne "";
1652 # bn-586 is the only one implementing bn_*_part_words
1653 $cflags.=" -DOPENSSL_BN_ASM_PART_WORDS" if ($bn_obj =~ /bn-586/);
1654 $cflags.=" -DOPENSSL_IA32_SSE2" if (!$no_sse2 && $bn_obj =~ /86/);
1656 $cflags.=" -DOPENSSL_BN_ASM_MONT" if ($bn_obj =~ /-mont/);
1657 $cflags.=" -DOPENSSL_BN_ASM_MONT5" if ($bn_obj =~ /-mont5/);
1658 $cflags.=" -DOPENSSL_BN_ASM_GF2m" if ($bn_obj =~ /-gf2m/);
1662 $openssl_other_defines.="#define OPENSSL_FIPS\n";
1665 $cpuid_obj="mem_clr.o" unless ($cpuid_obj =~ /\.o$/);
1666 $des_obj=$des_enc unless ($des_obj =~ /\.o$/);
1667 $bf_obj=$bf_enc unless ($bf_obj =~ /\.o$/);
1668 $cast_obj=$cast_enc unless ($cast_obj =~ /\.o$/);
1669 $rc4_obj=$rc4_enc unless ($rc4_obj =~ /\.o$/);
1670 $rc5_obj=$rc5_enc unless ($rc5_obj =~ /\.o$/);
1671 if ($sha1_obj =~ /\.o$/)
1673 # $sha1_obj=$sha1_enc;
1674 $cflags.=" -DSHA1_ASM" if ($sha1_obj =~ /sx86/ || $sha1_obj =~ /sha1/);
1675 $cflags.=" -DSHA256_ASM" if ($sha1_obj =~ /sha256/);
1676 $cflags.=" -DSHA512_ASM" if ($sha1_obj =~ /sha512/);
1677 if ($sha1_obj =~ /sse2/)
1679 { $sha1_obj =~ s/\S*sse2\S+//; }
1680 elsif ($cflags !~ /OPENSSL_IA32_SSE2/)
1681 { $cflags.=" -DOPENSSL_IA32_SSE2"; }
1684 if ($md5_obj =~ /\.o$/)
1686 # $md5_obj=$md5_enc;
1687 $cflags.=" -DMD5_ASM";
1689 if ($rmd160_obj =~ /\.o$/)
1691 # $rmd160_obj=$rmd160_enc;
1692 $cflags.=" -DRMD160_ASM";
1694 if ($aes_obj =~ /\.o$/)
1696 $cflags.=" -DAES_ASM" if ($aes_obj =~ m/\baes\-/);;
1697 # aes-ctr.o is not a real file, only indication that assembler
1698 # module implements AES_ctr32_encrypt...
1699 $cflags.=" -DAES_CTR_ASM" if ($aes_obj =~ s/\s*aes\-ctr\.o//);
1700 # aes-xts.o indicates presence of AES_xts_[en|de]crypt...
1701 $cflags.=" -DAES_XTS_ASM" if ($aes_obj =~ s/\s*aes\-xts\.o//);
1702 $aes_obj =~ s/\s*(vpaes|aesni)\-x86\.o//g if ($no_sse2);
1703 $cflags.=" -DVPAES_ASM" if ($aes_obj =~ m/vpaes/);
1704 $cflags.=" -DBSAES_ASM" if ($aes_obj =~ m/bsaes/);
1709 $wp_obj="" if ($wp_obj =~ /mmx/ && $processor eq "386");
1710 if ($wp_obj =~ /\.o$/ && !$disabled{"whirlpool"})
1712 $cflags.=" -DWHIRLPOOL_ASM";
1715 $wp_obj="wp_block.o";
1717 $cmll_obj=$cmll_enc unless ($cmll_obj =~ /.o$/);
1718 if ($modes_obj =~ /ghash\-/)
1720 $cflags.=" -DGHASH_ASM";
1722 if ($ec_obj =~ /ecp_nistz256/)
1724 $cflags.=" -DECP_NISTZ256_ASM";
1727 # "Stringify" the C flags string. This permits it to be made part of a string
1728 # and works as well on command lines.
1729 $cflags =~ s/([\\\"])/\\\1/g;
1731 my $version = "unknown";
1732 my $version_num = "unknown";
1733 my $major = "unknown";
1734 my $minor = "unknown";
1735 my $shlib_version_number = "unknown";
1736 my $shlib_version_history = "unknown";
1737 my $shlib_major = "unknown";
1738 my $shlib_minor = "unknown";
1740 open(IN,'<crypto/opensslv.h') || die "unable to read opensslv.h:$!\n";
1743 $version=$1 if /OPENSSL.VERSION.TEXT.*OpenSSL (\S+) /;
1744 $version_num=$1 if /OPENSSL.VERSION.NUMBER.*0x(\S+)/;
1745 $shlib_version_number=$1 if /SHLIB_VERSION_NUMBER *"([^"]+)"/;
1746 $shlib_version_history=$1 if /SHLIB_VERSION_HISTORY *"([^"]*)"/;
1749 if ($shlib_version_history ne "") { $shlib_version_history .= ":"; }
1751 if ($version =~ /(^[0-9]*)\.([0-9\.]*)/)
1757 if ($shlib_version_number =~ /(^[0-9]*)\.([0-9\.]*)/)
1763 if ($strict_warnings)
1766 die "ERROR --strict-warnings requires gcc or clang" unless ($cc =~ /gcc$/ or $cc =~ /clang$/);
1767 foreach $wopt (split /\s+/, $gcc_devteam_warn)
1769 $cflags .= " $wopt" unless ($cflags =~ /$wopt/)
1773 open(IN,"<Makefile.org") || die "unable to read Makefile.org:$!\n";
1774 unlink("$Makefile.new") || die "unable to remove old $Makefile.new:$!\n" if -e "$Makefile.new";
1775 open(OUT,">$Makefile.new") || die "unable to create $Makefile.new:$!\n";
1776 print OUT "### Generated automatically from Makefile.org by Configure.\n\n";
1782 $sdirs = 1 if /^SDIRS=/;
1785 foreach $dir (@skip) {
1790 $sdirs = 0 unless /\\$/;
1791 s/fips // if (/^DIRS=/ && !$fips);
1792 s/engines // if (/^DIRS=/ && $disabled{"engine"});
1793 s/ccgost// if (/^ENGDIRS=/ && $disabled{"gost"});
1794 s/^VERSION=.*/VERSION=$version/;
1795 s/^MAJOR=.*/MAJOR=$major/;
1796 s/^MINOR=.*/MINOR=$minor/;
1797 s/^SHLIB_VERSION_NUMBER=.*/SHLIB_VERSION_NUMBER=$shlib_version_number/;
1798 s/^SHLIB_VERSION_HISTORY=.*/SHLIB_VERSION_HISTORY=$shlib_version_history/;
1799 s/^SHLIB_MAJOR=.*/SHLIB_MAJOR=$shlib_major/;
1800 s/^SHLIB_MINOR=.*/SHLIB_MINOR=$shlib_minor/;
1801 s/^SHLIB_EXT=.*/SHLIB_EXT=$shared_extension/;
1802 s/^INSTALLTOP=.*$/INSTALLTOP=$prefix/;
1803 s/^MULTILIB=.*$/MULTILIB=$multilib/;
1804 s/^OPENSSLDIR=.*$/OPENSSLDIR=$openssldir/;
1805 s/^LIBDIR=.*$/LIBDIR=$libdir/;
1806 s/^INSTALL_PREFIX=.*$/INSTALL_PREFIX=$install_prefix/;
1807 s/^PLATFORM=.*$/PLATFORM=$target/;
1808 s/^OPTIONS=.*$/OPTIONS=$options/;
1809 s/^CONFIGURE_ARGS=.*$/CONFIGURE_ARGS=$argvstring/;
1810 if ($cross_compile_prefix)
1812 s/^CC=.*$/CROSS_COMPILE= $cross_compile_prefix\nCC= \$\(CROSS_COMPILE\)$cc/;
1813 s/^AR=\s*/AR= \$\(CROSS_COMPILE\)/;
1814 s/^NM=\s*/NM= \$\(CROSS_COMPILE\)/;
1815 s/^RANLIB=\s*/RANLIB= \$\(CROSS_COMPILE\)/;
1816 s/^MAKEDEPPROG=.*$/MAKEDEPPROG= \$\(CROSS_COMPILE\)$cc/ if $cc eq "gcc";
1820 s/^AR=\s*ar/AR= $ar/;
1821 s/^RANLIB=.*/RANLIB= $ranlib/;
1822 s/^MAKEDEPPROG=.*$/MAKEDEPPROG= $cc/ if $cc eq "gcc" || ($cc eq 'cc' && $target =~ /darwin/);
1824 s/^CFLAG=.*$/CFLAG= $cflags/;
1825 s/^DEPFLAG=.*$/DEPFLAG=$depflags/;
1826 s/^PEX_LIBS=.*$/PEX_LIBS= $prelflags/;
1827 s/^EX_LIBS=.*$/EX_LIBS= $lflags/;
1828 s/^EXE_EXT=.*$/EXE_EXT= $exe_ext/;
1829 s/^CPUID_OBJ=.*$/CPUID_OBJ= $cpuid_obj/;
1830 s/^BN_ASM=.*$/BN_ASM= $bn_obj/;
1831 s/^EC_ASM=.*$/EC_ASM= $ec_obj/;
1832 s/^DES_ENC=.*$/DES_ENC= $des_obj/;
1833 s/^AES_ENC=.*$/AES_ENC= $aes_obj/;
1834 s/^BF_ENC=.*$/BF_ENC= $bf_obj/;
1835 s/^CAST_ENC=.*$/CAST_ENC= $cast_obj/;
1836 s/^RC4_ENC=.*$/RC4_ENC= $rc4_obj/;
1837 s/^RC5_ENC=.*$/RC5_ENC= $rc5_obj/;
1838 s/^MD5_ASM_OBJ=.*$/MD5_ASM_OBJ= $md5_obj/;
1839 s/^SHA1_ASM_OBJ=.*$/SHA1_ASM_OBJ= $sha1_obj/;
1840 s/^RMD160_ASM_OBJ=.*$/RMD160_ASM_OBJ= $rmd160_obj/;
1841 s/^WP_ASM_OBJ=.*$/WP_ASM_OBJ= $wp_obj/;
1842 s/^CMLL_ENC=.*$/CMLL_ENC= $cmll_obj/;
1843 s/^MODES_ASM_OBJ.=*$/MODES_ASM_OBJ= $modes_obj/;
1844 s/^ENGINES_ASM_OBJ.=*$/ENGINES_ASM_OBJ= $engines_obj/;
1845 s/^PERLASM_SCHEME=.*$/PERLASM_SCHEME= $perlasm_scheme/;
1846 s/^PROCESSOR=.*/PROCESSOR= $processor/;
1847 s/^ARFLAGS=.*/ARFLAGS= $arflags/;
1848 s/^PERL=.*/PERL= $perl/;
1849 s/^KRB5_INCLUDES=.*/KRB5_INCLUDES=$withargs{"krb5-include"}/;
1850 s/^LIBKRB5=.*/LIBKRB5=$withargs{"krb5-lib"}/;
1851 s/^LIBZLIB=.*/LIBZLIB=$withargs{"zlib-lib"}/;
1852 s/^ZLIB_INCLUDE=.*/ZLIB_INCLUDE=$withargs{"zlib-include"}/;
1853 s/^FIPSLIBDIR=.*/FIPSLIBDIR=$fipslibdir/;
1854 s/^FIPSCANLIB=.*/FIPSCANLIB=libcrypto/ if $fips;
1855 s/^SHARED_FIPS=.*/SHARED_FIPS=/;
1856 s/^SHLIBDIRS=.*/SHLIBDIRS= crypto ssl/;
1857 s/^BASEADDR=.*/BASEADDR=$baseaddr/;
1858 s/^SHLIB_TARGET=.*/SHLIB_TARGET=$shared_target/;
1859 s/^SHLIB_MARK=.*/SHLIB_MARK=$shared_mark/;
1860 s/^SHARED_LIBS=.*/SHARED_LIBS=\$(SHARED_CRYPTO) \$(SHARED_SSL)/ if (!$no_shared);
1861 if ($shared_extension ne "" && $shared_extension =~ /^\.s([ol])\.[^\.]*$/)
1864 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.s$sotmp/;
1866 elsif ($shared_extension ne "" && $shared_extension =~ /^\.[^\.]*\.dylib$/)
1868 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.dylib/;
1870 elsif ($shared_extension ne "" && $shared_extension =~ /^\.s([ol])\.[^\.]*\.[^\.]*$/)
1873 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.s$sotmp.\$(SHLIB_MAJOR) .s$sotmp/;
1875 elsif ($shared_extension ne "" && $shared_extension =~ /^\.[^\.]*\.[^\.]*\.dylib$/)
1877 s/^SHARED_LIBS_LINK_EXTS=.*/SHARED_LIBS_LINK_EXTS=.\$(SHLIB_MAJOR).dylib .dylib/;
1879 s/^SHARED_LDFLAGS=.*/SHARED_LDFLAGS=$shared_ldflag/;
1884 rename($Makefile,"$Makefile.bak") || die "unable to rename $Makefile\n" if -e $Makefile;
1885 rename("$Makefile.new",$Makefile) || die "unable to rename $Makefile.new\n";
1888 print "CFLAG =$cflags\n";
1889 print "EX_LIBS =$lflags\n";
1890 print "CPUID_OBJ =$cpuid_obj\n";
1891 print "BN_ASM =$bn_obj\n";
1892 print "EC_ASM =$ec_obj\n";
1893 print "DES_ENC =$des_obj\n";
1894 print "AES_ENC =$aes_obj\n";
1895 print "BF_ENC =$bf_obj\n";
1896 print "CAST_ENC =$cast_obj\n";
1897 print "RC4_ENC =$rc4_obj\n";
1898 print "RC5_ENC =$rc5_obj\n";
1899 print "MD5_OBJ_ASM =$md5_obj\n";
1900 print "SHA1_OBJ_ASM =$sha1_obj\n";
1901 print "RMD160_OBJ_ASM=$rmd160_obj\n";
1902 print "CMLL_ENC =$cmll_obj\n";
1903 print "MODES_OBJ =$modes_obj\n";
1904 print "ENGINES_OBJ =$engines_obj\n";
1905 print "PROCESSOR =$processor\n";
1906 print "RANLIB =$ranlib\n";
1907 print "ARFLAGS =$arflags\n";
1908 print "PERL =$perl\n";
1909 print "KRB5_INCLUDES =",$withargs{"krb5-include"},"\n"
1910 if $withargs{"krb5-include"} ne "";
1918 my $rc4_int=$def_int;
1919 my $md2_int=$def_int;
1920 my $idea_int=$def_int;
1921 my $rc2_int=$def_int;
1925 my @type=("char","short","int","long");
1926 my ($b64l,$b64,$b32,$b16,$b8)=(0,0,1,0,0);
1927 my $export_var_as_fn=0;
1931 foreach (sort split(/\s+/,$bn_ops))
1933 $des_ptr=1 if /DES_PTR/;
1934 $des_risc1=1 if /DES_RISC1/;
1935 $des_risc2=1 if /DES_RISC2/;
1936 $des_unroll=1 if /DES_UNROLL/;
1937 $des_int=1 if /DES_INT/;
1938 $bn_ll=1 if /BN_LLONG/;
1939 $rc4_int=0 if /RC4_CHAR/;
1940 $rc4_int=3 if /RC4_LONG/;
1941 $rc4_idx=1 if /RC4_INDEX/;
1942 $rc4_chunk=1 if /RC4_CHUNK/;
1943 $rc4_chunk=2 if /RC4_CHUNK_LL/;
1944 $md2_int=0 if /MD2_CHAR/;
1945 $md2_int=3 if /MD2_LONG/;
1946 $idea_int=1 if /IDEA_SHORT/;
1947 $idea_int=3 if /IDEA_LONG/;
1948 $rc2_int=1 if /RC2_SHORT/;
1949 $rc2_int=3 if /RC2_LONG/;
1950 $bf_ptr=1 if $_ eq "BF_PTR";
1951 $bf_ptr=2 if $_ eq "BF_PTR2";
1952 ($b64l,$b64,$b32,$b16,$b8)=(0,1,0,0,0) if /SIXTY_FOUR_BIT/;
1953 ($b64l,$b64,$b32,$b16,$b8)=(1,0,0,0,0) if /SIXTY_FOUR_BIT_LONG/;
1954 ($b64l,$b64,$b32,$b16,$b8)=(0,0,1,0,0) if /THIRTY_TWO_BIT/;
1955 ($b64l,$b64,$b32,$b16,$b8)=(0,0,0,1,0) if /SIXTEEN_BIT/;
1956 ($b64l,$b64,$b32,$b16,$b8)=(0,0,0,0,1) if /EIGHT_BIT/;
1957 $export_var_as_fn=1 if /EXPORT_VAR_AS_FN/;
1960 open(IN,'<crypto/opensslconf.h.in') || die "unable to read crypto/opensslconf.h.in:$!\n";
1961 unlink("crypto/opensslconf.h.new") || die "unable to remove old crypto/opensslconf.h.new:$!\n" if -e "crypto/opensslconf.h.new";
1962 open(OUT,'>crypto/opensslconf.h.new') || die "unable to create crypto/opensslconf.h.new:$!\n";
1963 print OUT "/* opensslconf.h */\n";
1964 print OUT "/* WARNING: Generated automatically from opensslconf.h.in by Configure. */\n\n";
1966 print OUT "#ifdef __cplusplus\n";
1967 print OUT "extern \"C\" {\n";
1968 print OUT "#endif\n";
1969 print OUT "/* OpenSSL was configured with the following options: */\n";
1970 my $openssl_algorithm_defines_trans = $openssl_algorithm_defines;
1971 $openssl_experimental_defines =~ s/^\s*#\s*define\s+OPENSSL_NO_(.*)/#ifndef OPENSSL_EXPERIMENTAL_$1\n# ifndef OPENSSL_NO_$1\n# define OPENSSL_NO_$1\n# endif\n#endif/mg;
1972 $openssl_algorithm_defines_trans =~ s/^\s*#\s*define\s+OPENSSL_(.*)/# if defined(OPENSSL_$1) \&\& !defined($1)\n# define $1\n# endif/mg;
1973 $openssl_algorithm_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
1974 $openssl_algorithm_defines = " /* no ciphers excluded */\n" if $openssl_algorithm_defines eq "";
1975 $openssl_thread_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
1976 $openssl_sys_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
1977 $openssl_other_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
1978 print OUT $openssl_sys_defines;
1979 print OUT "#ifndef OPENSSL_DOING_MAKEDEPEND\n\n";
1980 print OUT $openssl_experimental_defines;
1982 print OUT $openssl_algorithm_defines;
1983 print OUT "\n#endif /* OPENSSL_DOING_MAKEDEPEND */\n\n";
1984 print OUT $openssl_thread_defines;
1985 print OUT $openssl_other_defines,"\n";
1987 print OUT "/* The OPENSSL_NO_* macros are also defined as NO_* if the application\n";
1988 print OUT " asks for it. This is a transient feature that is provided for those\n";
1989 print OUT " who haven't had the time to do the appropriate changes in their\n";
1990 print OUT " applications. */\n";
1991 print OUT "#ifdef OPENSSL_ALGORITHM_DEFINES\n";
1992 print OUT $openssl_algorithm_defines_trans;
1993 print OUT "#endif\n\n";
1995 print OUT "#define OPENSSL_CPUID_OBJ\n\n" if ($cpuid_obj ne "mem_clr.o");
1999 if (/^#define\s+OPENSSLDIR/)
2001 my $foo = $openssldir;
2002 $foo =~ s/\\/\\\\/g;
2003 print OUT "#define OPENSSLDIR \"$foo\"\n";
2005 elsif (/^#define\s+ENGINESDIR/)
2007 my $foo = "$prefix/$libdir/engines";
2008 $foo =~ s/\\/\\\\/g;
2009 print OUT "#define ENGINESDIR \"$foo\"\n";
2011 elsif (/^#((define)|(undef))\s+OPENSSL_EXPORT_VAR_AS_FUNCTION/)
2012 { printf OUT "#undef OPENSSL_EXPORT_VAR_AS_FUNCTION\n"
2013 if $export_var_as_fn;
2014 printf OUT "#%s OPENSSL_EXPORT_VAR_AS_FUNCTION\n",
2015 ($export_var_as_fn)?"define":"undef"; }
2016 elsif (/^#define\s+OPENSSL_UNISTD/)
2018 $unistd = "<unistd.h>" if $unistd eq "";
2019 print OUT "#define OPENSSL_UNISTD $unistd\n";
2021 elsif (/^#((define)|(undef))\s+SIXTY_FOUR_BIT_LONG/)
2022 { printf OUT "#%s SIXTY_FOUR_BIT_LONG\n",($b64l)?"define":"undef"; }
2023 elsif (/^#((define)|(undef))\s+SIXTY_FOUR_BIT/)
2024 { printf OUT "#%s SIXTY_FOUR_BIT\n",($b64)?"define":"undef"; }
2025 elsif (/^#((define)|(undef))\s+THIRTY_TWO_BIT/)
2026 { printf OUT "#%s THIRTY_TWO_BIT\n",($b32)?"define":"undef"; }
2027 elsif (/^#((define)|(undef))\s+SIXTEEN_BIT/)
2028 { printf OUT "#%s SIXTEEN_BIT\n",($b16)?"define":"undef"; }
2029 elsif (/^#((define)|(undef))\s+EIGHT_BIT/)
2030 { printf OUT "#%s EIGHT_BIT\n",($b8)?"define":"undef"; }
2031 elsif (/^#((define)|(undef))\s+BN_LLONG\s*$/)
2032 { printf OUT "#%s BN_LLONG\n",($bn_ll)?"define":"undef"; }
2033 elsif (/^\#define\s+DES_LONG\s+.*/)
2034 { printf OUT "#define DES_LONG unsigned %s\n",
2035 ($des_int)?'int':'long'; }
2036 elsif (/^\#(define|undef)\s+DES_PTR/)
2037 { printf OUT "#%s DES_PTR\n",($des_ptr)?'define':'undef'; }
2038 elsif (/^\#(define|undef)\s+DES_RISC1/)
2039 { printf OUT "#%s DES_RISC1\n",($des_risc1)?'define':'undef'; }
2040 elsif (/^\#(define|undef)\s+DES_RISC2/)
2041 { printf OUT "#%s DES_RISC2\n",($des_risc2)?'define':'undef'; }
2042 elsif (/^\#(define|undef)\s+DES_UNROLL/)
2043 { printf OUT "#%s DES_UNROLL\n",($des_unroll)?'define':'undef'; }
2044 elsif (/^#define\s+RC4_INT\s/)
2045 { printf OUT "#define RC4_INT unsigned %s\n",$type[$rc4_int]; }
2046 elsif (/^#undef\s+RC4_CHUNK/)
2048 printf OUT "#undef RC4_CHUNK\n" if $rc4_chunk==0;
2049 printf OUT "#define RC4_CHUNK unsigned long\n" if $rc4_chunk==1;
2050 printf OUT "#define RC4_CHUNK unsigned long long\n" if $rc4_chunk==2;
2052 elsif (/^#((define)|(undef))\s+RC4_INDEX/)
2053 { printf OUT "#%s RC4_INDEX\n",($rc4_idx)?"define":"undef"; }
2054 elsif (/^#(define|undef)\s+I386_ONLY/)
2055 { printf OUT "#%s I386_ONLY\n", ($processor eq "386")?
2057 elsif (/^#define\s+MD2_INT\s/)
2058 { printf OUT "#define MD2_INT unsigned %s\n",$type[$md2_int]; }
2059 elsif (/^#define\s+IDEA_INT\s/)
2060 {printf OUT "#define IDEA_INT unsigned %s\n",$type[$idea_int];}
2061 elsif (/^#define\s+RC2_INT\s/)
2062 {printf OUT "#define RC2_INT unsigned %s\n",$type[$rc2_int];}
2063 elsif (/^#(define|undef)\s+BF_PTR/)
2065 printf OUT "#undef BF_PTR\n" if $bf_ptr == 0;
2066 printf OUT "#define BF_PTR\n" if $bf_ptr == 1;
2067 printf OUT "#define BF_PTR2\n" if $bf_ptr == 2;
2073 print OUT "#ifdef __cplusplus\n";
2075 print OUT "#endif\n";
2077 rename("crypto/opensslconf.h","crypto/opensslconf.h.bak") || die "unable to rename crypto/opensslconf.h\n" if -e "crypto/opensslconf.h";
2078 rename("crypto/opensslconf.h.new","crypto/opensslconf.h") || die "unable to rename crypto/opensslconf.h.new\n";
2083 print "SIXTY_FOUR_BIT_LONG mode\n" if $b64l;
2084 print "SIXTY_FOUR_BIT mode\n" if $b64;
2085 print "THIRTY_TWO_BIT mode\n" if $b32;
2086 print "SIXTEEN_BIT mode\n" if $b16;
2087 print "EIGHT_BIT mode\n" if $b8;
2088 print "DES_PTR used\n" if $des_ptr;
2089 print "DES_RISC1 used\n" if $des_risc1;
2090 print "DES_RISC2 used\n" if $des_risc2;
2091 print "DES_UNROLL used\n" if $des_unroll;
2092 print "DES_INT used\n" if $des_int;
2093 print "BN_LLONG mode\n" if $bn_ll;
2094 print "RC4 uses u$type[$rc4_int]\n" if $rc4_int != $def_int;
2095 print "RC4_INDEX mode\n" if $rc4_idx;
2096 print "RC4_CHUNK is undefined\n" if $rc4_chunk==0;
2097 print "RC4_CHUNK is unsigned long\n" if $rc4_chunk==1;
2098 print "RC4_CHUNK is unsigned long long\n" if $rc4_chunk==2;
2099 print "MD2 uses u$type[$md2_int]\n" if $md2_int != $def_int;
2100 print "IDEA uses u$type[$idea_int]\n" if $idea_int != $def_int;
2101 print "RC2 uses u$type[$rc2_int]\n" if $rc2_int != $def_int;
2102 print "BF_PTR used\n" if $bf_ptr == 1;
2103 print "BF_PTR2 used\n" if $bf_ptr == 2;
2106 open (OUT,">crypto/buildinf.h") || die "Can't open buildinf.h";
2109 /* auto-generated by Configure for crypto/cversion.c:
2110 * for Unix builds, crypto/Makefile.ssl generates functional definitions;
2111 * Windows builds (and other mk1mf builds) compile cversion.c with
2112 * -DMK1MF_BUILD and use definitions added to this file by util/mk1mf.pl. */
2113 #error "Windows builds (PLATFORM=$target) use mk1mf.pl-created Makefiles"
2118 my $make_command = "$make PERL=\'$perl\'";
2119 my $make_targets = "";
2120 $make_targets .= " links" if $symlink;
2121 $make_targets .= " depend" if $depflags ne $default_depflags && $make_depend;
2122 $make_targets .= " gentests" if $symlink;
2123 (system $make_command.$make_targets) == 0 or die "make $make_targets failed"
2124 if $make_targets ne "";
2125 if ( $perl =~ m@^/@) {
2126 &dofile("tools/c_rehash",$perl,'^#!/', '#!%s','^my \$dir;$', 'my $dir = "' . $openssldir . '";', '^my \$prefix;$', 'my $prefix = "' . $prefix . '";');
2127 &dofile("apps/CA.pl",$perl,'^#!/', '#!%s');
2129 # No path for Perl known ...
2130 &dofile("tools/c_rehash",'/usr/local/bin/perl','^#!/', '#!%s','^my \$dir;$', 'my $dir = "' . $openssldir . '";', '^my \$prefix;$', 'my $prefix = "' . $prefix . '";');
2131 &dofile("apps/CA.pl",'/usr/local/bin/perl','^#!/', '#!%s');
2133 if ($depflags ne $default_depflags && !$make_depend) {
2136 Since you've disabled or enabled at least one algorithm, you need to do
2137 the following before building:
2144 # create the ms/version32.rc file if needed
2145 if ($IsMK1MF && ($target !~ /^netware/)) {
2146 my ($v1, $v2, $v3, $v4);
2147 if ($version_num =~ /(^[0-9a-f]{1})([0-9a-f]{2})([0-9a-f]{2})([0-9a-f]{2})/i) {
2153 open (OUT,">ms/version32.rc") || die "Can't open ms/version32.rc";
2160 FILEVERSION $v1,$v2,$v3,$v4
2161 PRODUCTVERSION $v1,$v2,$v3,$v4
2168 FILEOS VOS__WINDOWS32
2172 BLOCK "StringFileInfo"
2177 VALUE "CompanyName", "The OpenSSL Project, http://www.openssl.org/\\0"
2178 VALUE "FileDescription", "OpenSSL Shared Library\\0"
2179 VALUE "FileVersion", "$version\\0"
2181 VALUE "InternalName", "libeay32\\0"
2182 VALUE "OriginalFilename", "libeay32.dll\\0"
2184 VALUE "InternalName", "ssleay32\\0"
2185 VALUE "OriginalFilename", "ssleay32.dll\\0"
2187 VALUE "ProductName", "The OpenSSL Toolkit\\0"
2188 VALUE "ProductVersion", "$version\\0"
2190 //VALUE "Comments", "\\0"
2191 VALUE "LegalCopyright", "Copyright © 1998-2005 The OpenSSL Project. Copyright © 1995-1998 Eric A. Young, Tim J. Hudson. All rights reserved.\\0"
2192 //VALUE "LegalTrademarks", "\\0"
2193 //VALUE "PrivateBuild", "\\0"
2194 //VALUE "SpecialBuild", "\\0"
2199 VALUE "Translation", 0x409, 0x4b0
2208 Configured for $target.
2211 print <<\EOF if (!$no_threads && !$threads);
2213 The library could not be configured for supporting multi-threaded
2214 applications as the compiler options required on this system are not known.
2215 See file INSTALL for details if you need multi-threading.
2218 print <<\EOF if ($no_shared_warn);
2220 You gave the option 'shared'. Normally, that would give you shared libraries.
2221 Unfortunately, the OpenSSL configuration doesn't include shared library support
2222 for this platform yet, so it will pretend you gave the option 'no-shared'. If
2223 you can inform the developpers (openssl-dev\@openssl.org) how to support shared
2224 libraries on this platform, they will at least look at it and try their best
2225 (but please first make sure you have tried with a current version of OpenSSL).
2232 print STDERR $usage;
2233 print STDERR "\npick os/compiler from:\n";
2237 foreach $i (sort keys %table)
2239 next if $i =~ /^debug/;
2240 $k += length($i) + 1;
2246 print STDERR $i . " ";
2248 foreach $i (sort keys %table)
2250 next if $i !~ /^debug/;
2251 $k += length($i) + 1;
2257 print STDERR $i . " ";
2259 print STDERR "\n\nNOTE: If in doubt, on Unix-ish systems use './config'.\n";
2267 foreach $path (split /:/, $ENV{PATH})
2269 if (-f "$path/$name$exe_ext" and -x _)
2271 return "$path/$name$exe_ext" unless ($name eq "perl" and
2272 system("$path/$name$exe_ext -e " . '\'exit($]<5.0);\''));
2279 my $f; my $p; my %m; my @a; my $k; my $ff;
2282 open(IN,"<$f.in") || open(IN,"<$f") || die "unable to open $f:$!\n";
2285 foreach $k (keys %m)
2287 grep(/$k/ && ($_=sprintf($m{$k}."\n",$p)),@a);
2289 open(OUT,">$f.new") || die "unable to open $f.new:$!\n";
2292 rename($f,"$f.bak") || die "unable to rename $f\n" if -e $f;
2293 rename("$f.new",$f) || die "unable to rename $f.new\n";
2296 sub print_table_entry
2301 # Don't print the templates
2302 return if $table{$target}->{template};
2304 if ($type eq "TABLE") {
2308 \$cc = $table{$target}->{cc}
2309 \$cflags = $table{$target}->{cflags}
2310 \$debug_cflags = $table{$target}->{debug_cflags}
2311 \$release_cflags = $table{$target}->{release_cflags}
2312 \$unistd = $table{$target}->{unistd}
2313 \$thread_cflag = $table{$target}->{thread_cflag}
2314 \$sys_id = $table{$target}->{sys_id}
2315 \$lflags = $table{$target}->{lflags}
2316 \$debug_lflags = $table{$target}->{debug_lflags}
2317 \$release_lflags = $table{$target}->{release_lflags}
2318 \$bn_ops = $table{$target}->{bn_ops}
2319 \$cpuid_obj = $table{$target}->{cpuid_obj}
2320 \$bn_obj = $table{$target}->{bn_obj}
2321 \$ec_obj = $table{$target}->{ec_obj}
2322 \$des_obj = $table{$target}->{des_obj}
2323 \$aes_obj = $table{$target}->{aes_obj}
2324 \$bf_obj = $table{$target}->{bf_obj}
2325 \$md5_obj = $table{$target}->{md5_obj}
2326 \$sha1_obj = $table{$target}->{sha1_obj}
2327 \$cast_obj = $table{$target}->{cast_obj}
2328 \$rc4_obj = $table{$target}->{rc4_obj}
2329 \$rmd160_obj = $table{$target}->{rmd160_obj}
2330 \$rc5_obj = $table{$target}->{rc5_obj}
2331 \$wp_obj = $table{$target}->{wp_obj}
2332 \$cmll_obj = $table{$target}->{cmll_obj}
2333 \$modes_obj = $table{$target}->{modes_obj}
2334 \$engines_obj = $table{$target}->{engines_obj}
2335 \$perlasm_scheme = $table{$target}->{perlasm_scheme}
2336 \$dso_scheme = $table{$target}->{dso_scheme}
2337 \$shared_target= $table{$target}->{shared_target}
2338 \$shared_cflag = $table{$target}->{shared_cflag}
2339 \$shared_ldflag = $table{$target}->{shared_ldflag}
2340 \$shared_extension = $table{$target}->{shared_extension}
2341 \$ranlib = $table{$target}->{ranlib}
2342 \$arflags = $table{$target}->{arflags}
2343 \$multilib = $table{$target}->{multilib}
2345 } elsif ($type eq "HASH") {
2385 length((sort { length($a) <=> length($b) } @sequence)[-1]);
2386 print " '$target' => {\n";
2387 foreach (@sequence) {
2388 if ($table{$target}->{$_}) {
2389 print " '",$_,"'"," " x ($largest - length($_))," => '",$table{$target}->{$_},"',\n";
2400 print STDERR "=" x 70, "\n";
2401 print STDERR "=== SANITY TESTING!\n";
2402 print STDERR "=== No configuration will be done, all other arguments will be ignored!\n";
2403 print STDERR "=" x 70, "\n";
2405 foreach $target (sort keys %table)
2407 my $pre_dso_scheme = "perlasm_scheme";
2408 my $dso_scheme = "dso_scheme";
2409 my $post_dso_scheme = "shared_target";
2412 if ($table{$target}->{$pre_dso_scheme} =~ /^(beos|dl|dlfcn|win32|vms)$/)
2415 print STDERR "SANITY ERROR: '$target' has the dso_scheme values\n";
2416 print STDERR " in the previous field\n";
2418 elsif ($table{$target}->{$post_dso_scheme} =~ /^(beos|dl|dlfcn|win32|vms)$/)
2421 print STDERR "SANITY ERROR: '$target' has the dso_scheme values\n";
2422 print STDERR " in the following field\n";
2424 elsif ($table{$target}->{$dso_scheme} !~ /^(beos|dl|dlfcn|win32|vms|)$/)
2427 print STDERR "SANITY ERROR: '$target' has the dso_scheme field = ",$table{$target}->{$dso_scheme},"\n";
2428 print STDERR " valid values are 'beos', 'dl', 'dlfcn', 'win32' and 'vms'\n";
2431 print STDERR "No sanity errors detected!\n" if $errorcnt == 0;